TRELLIX-SENSOR-CONF-MIB
AI MIB Summary
The TRELLIX-SENSOR-CONF-MIB provides read-write management of Trellix IntruShield sensor node configurations, specifically defining parameters for node identification, EMS connectivity, chassis and card topology, network interface assignments, and packet logging or SSL security settings. This module enables administrators to programmatically configure the operational identity, hardware slot mapping, and service parameters of the IntruShield intrusion detection system.
The Configuration MIB for the Trellix IntruShield product.
They are furthur broken down into the following groups: systemGrp - configuration of the IntruShield node identification. emsGrp - configuration of possible EMSs identification chassisGrp - configuration of the chassis slots managementCardGrp - configuration of the management card(s) tftpGrp - configuration of TFTP based services sensorCardGp - configuration of the sensor anlysis card(s) interfacePortGrp - configuration of interface port(s) responsePortGrp - configuration of response port(s) pktLogGrp - configuration of the Packet Logging Application sslGrp - SSL configuration
Main OID:
ivSensorConfigurationMIB.1.3.6.1.4.1.8962.2.1.2.1
938
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
938 total| Object Name |
|---|
ivSensorConfigurationMIBThe Configuration MIB for the Trellix IntruShield product.
They are furthur broken down into the following groups:
systemGrp - configuration of the IntruShield node identification.
emsGrp - configuration of possible EMSs identification
chassisGrp - configuration of the chassis slots
managementCardGrp - configuration of the management card(s)
tftpGrp - configuration of TFTP based services
sensorCardGp - configuration of the sensor anlysis card(s)
interfacePortGrp - configuration of interface port(s)
responsePortGrp - configuration of response port(s)
pktLogGrp - configuration of the Packet Logging Application
sslGrp - SSL configuration MODULE-IDENTITY .1.3.6.1.4.1.8962.2.1.2.1 |
IMPORTSThe Configuration MIB for the Trellix IntruShield product.
They are furthur broken down into the following groups:
systemGrp - configuration of the IntruShield node identification.
emsGrp - configuration of possible EMSs identification
chassisGrp - configuration of the chassis slots
managementCardGrp - configuration of the management card(s)
tftpGrp - configuration of TFTP based services
sensorCardGp - configuration of the sensor anlysis card(s)
interfacePortGrp - configuration of interface port(s)
responsePortGrp - configuration of response port(s)
pktLogGrp - configuration of the Packet Logging Application
sslGrp - SSL configuration Unknown .1.3.6.1.4.1.8962.2.1.2.1 |
systemGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.1 |
ivSysNameAn administratively assigned name for this IntruShied node.
By convention, this is the node's fully-qualified domain name.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.1 |
ivSysLocationThe physical location of this node (e.g., `Building 6, IS room 443, 3rd floor').rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.2 |
ivSysContactThe textual identification of the contact person for this IntruShield node,
together with information on how to contact this person.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.3 |
ivSysModelThis object is where the manufacturer specifies the model identification
(number or type) of the network element.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.4 |
ivSysSerialNumberManufacturer-provided serial number.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.5 |
ivSysDescrA textual description of the entity. This value should include the full name and version
identification of the system's hardware type, software operating system, and networking
software. It is current that this only contains printable ASCII characters.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.6 |
ivSysObjectIDThe vendor's authoritative identification of the
network management subsystem contained in the
entity. This value is allocated within the SMI
enterprises subtree (1.3.6.1.4.1) and provides an
easy and unambiguous means for determining `what
kind of box' is being managed. For example, if
vendor `Flintstones, Inc.' was assigned the
subtree 1.3.6.1.4.1.4242, it could assign the
identifier 1.3.6.1.4.1.4242.1.1 to its `Fred
Router'.ro OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.1.7 |
ivSysUpTimeThe time (in hundredths of a second) since the network management portion of the system
was last re-initialized.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.8962.2.1.2.1.1.8 |
ivSysLastCfgTimeIndicates time when configuration was changed last.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.1.9 |
ivSysDiskSpaceLeftReturns the numbers of kbytes left on the disk.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.1.10 |
ivSysAlertChannelStatusReturns the status of the alert channel connection with
EMS.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.11 |
ivSysPacketLogChannelStatusReturns the status of the packet log channel connection with
EMS.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.12 |
ivSysHealthReturns the health of the sensor. uninitialized means
that the sensor does not have signatures hence does not
detect attacksro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.13 |
ivSysResetPasswordThis object is used to reset the password back to default
value. Returns not-applicable(0) upon read.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.14 |
ivSysDeleteSignaturesThis object is used to delete the signatures on the sensor if present.
This also reboots the sensor after deleting the signatures. Does nothing
if signatures are not present. Returns not-applicable(0) upon read.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.15 |
ivSysSlaveSerialNumberManufacturer-provided slave serial number. This is the serial number
for a cluster-slave in a palomar clusterro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.16 |
ivSysUIDSeedThis object contains the portion of the seed value to be used for generating
UIDs' for alerts and logs. In case there is a mismatch, the ISM would set the
right value, which would used by the sensor for new alerts and logs.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.1.17 |
ivSysFipsModeThis Object holds the status of the fips mode.If the sensor is operating in FIPS
mode then this Object will have enable value or else disable value.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.1.18 |
ivSysNumLbPortsThis object is set by the NSM to inform the sensors connected to the Load Balancer(LB)
of the number of ports on the LB switch.rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.1.19 |
ivSysUpTimeNewThe time (in hundredths of a second) since the network management portion of the system
was last re-initialized.ro Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.20 |
ivSysCapacityModeTo push new license from NSMro Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.21 |
ivSysCurrentCapacityModeTo get current license mode of sensorrw Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.22 |
ivSysDeviceModeTo get current device modero Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.23 |
ivSysConfDeviceModeTo get configured device modero Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.24 |
ivSysRebootStatusIf a system reboot is required and Why
REBOOT_DEFAULT_STATUS (0) // No Reboot Required
REBOOT_UPGRADE_DOWNLOAD (1)
REBOOT_SETUP_CHANGE (2)
REBOOT_IPV6_CONFIG_CHANGE (3)
REBOOT_SSL_MODE_CHANGE (4)
REBOOT_JUMBOFRAMEPARSING_CONFIG_CHANGE (5)
REBOOT_PREV_256BYTES_LOGGING_CONFIG_CHANGE (6)
NMS_USERS_WRITE_ACCESS_CONFIG_CHANGE (7)
REBOOT_LAYER7_DCAP_NUM_FLOWS_CHANGE (8)
REBOOT_LAYER7_DCAP_BUFF_SIZE_CHANGE (9)
REBOOT_LAYER7_DCAP_STATUS_CHANGE (10)
REBOOT_SBC_CORE_INCREMENT_CONFIG_CHANGE (11)
REBOOT_REQUIRED_MAX_SNMPD_RESTART_EXCEEDED (12)
REBOOT_REQUIRED_SBC_TLV_ERROR (13)
REBOOT_SNORT_CONFIG_CHANGE (15)
REBOOT_CAPACITY_MODE_CHANGE (16)
REBOOT_SSL_FLOWALLOC_CHANGE (17)ro Counter64 .1.3.6.1.4.1.8962.2.1.2.1.1.25 |
ivSysRebootReasonThis object contains reason for the sensor reboot.
NULL is stored in the object if reboot is not requiredro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.1.26 |
systemIPCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.2 |
ivSysIPAddressThis object contains the IP Address of the management card on the IntruShield node,
that interfaces with the EMS.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.2.1 |
ivSysMACAddressThis object contains the MAC address of the management card on the IntruShield node.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.2.2 |
ivSysSubnetMaskThis object specifies the Subnet mask of the management card on the IntruShield node.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.2.3 |
ivSysGatewayThis object specifies the gateway address of the management card on the IntruShield node.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.2.4 |
ivSysIPv6AddressThis object contains the IPv6 Address of the management card on the IntruShield node,
that interfaces with the EMS.ro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.2.5 |
ivSysIpv6SubnetMaskThis object specifies the number of bits that need to set to '1' from left to right,
int the Ipv6 address Subnet mask of the management card on the IntruShield node.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.2.6 |
ivSysIpv6GatewayThis object specifies the gateway Ipv6 address of the management card on the IntruShield node.ro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.2.7 |
ivSysVmHostIPAddressThis object contains the IP Address of the Vm Host on which VIPS will be running.
This mib object will be available only on V-series sensors.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.2.8 |
ivSysVmHostIPv6AddressThis object contains the IP Address of the Vm Host on which VIPS will be running.
This mib object will be available only on v-series sensors.ro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.2.9 |
ivSysVmHostNameThis object contains the Vm Host name on which VIPS will be running.
This mib object will be available only on V-series sensors.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.2.10 |
ivSysVmMgmtAdditionalInfoA textual string containing additional information about the management interface.
This mib object will be available only on v-series sensors.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.2.11 |
systemFailoverGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.3 |
ivSysFailoverStatusIndicates if IDS peer is in peer-down or peer-up mode. Default: peer-down (2).ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.3.1 |
ivSysFailoverActionThis object is used to indicate if the sensor is in failover
configuration or not. If the sensors are in failover
configuration, then both sensors have to be set to on(1).
Default: off(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.3.2 |
ivSysFailoverModeAdded for the I-3000/I-4010 sensors.
This object is used to specify to the sensor if it is primary
or secondary when failover is enabled.
This value ( 1 or 2) must be set on the sensor prior to
enabling failover.
When failover is disabled, the sensor will automatically
update this object to standalone (0).
The manager can opt to explicitly set this after disabling
failover on the sensor, however it is not necessary.
Default: standalone(0), since failover is disabledrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.3.3 |
ivSysFailopenActionThis object is used to indicate if the sensor should fail-open when
in failover mode.
Default: disable(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.3.4 |
ivSysSTPForwardConfigThis object is used to indicate if the sensor should forward the STP traffic
through peer in failover mode.
Default: disable(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.3.5 |
emsGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.4 |
emsTableThis table comprises of exactly two possible EMS entries each defined by <emsEntry>. SEQUENCE OF EmsEntry .1.3.6.1.4.1.8962.2.1.2.1.4.1 |
emsEntryEach entry specified is indexed by <emsIndex>.
Additonaly it contains the <emsIPAddress> and <emsPriority> EmsEntry .1.3.6.1.4.1.8962.2.1.2.1.4.1.1 |
emsIndexFixed index for the two EMS entries. Valid values are [1,2] only. Integer32 .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.1 |
emsPriorityIdentifies whether the EMS identifed by the IPAddress is the Primary or Secondary. This value
is only informational from sensor point of view and is set by the EMS when we have established
connection to it. Note that transition at EMS from Primary to Secondary or vice versa will have
no effect on the sensor. The only thing sensor needs to worry about while in MDR mode is the
active/standby status.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.2 |
emsIPAddressIP Address of a EMS (in this entry).ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.3 |
emsHAModeIdentifies the MDR mode of the EMS. Initially when the system comes up this would be set to
unknown till we contact the EMS and get its MDR status. This field also gets updated when a
MDR-to-Standalone or Standalone-to-MDR action is triggered.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.4 |
emsHAStatusThis object specifies if the EMS is an active or a standby when operating in failover modero Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.5 |
emsAlertChannelStatusReturns the status of the alert channel connection with
EMS identifed by the emsIPAddress of this entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.6 |
emsPacketLogChannelStatusReturns the status of the packet log channel connection with
EMS identified by the emsIPAddress of this entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.7 |
emsIPv6AddressIPv6 Address of a EMS (in this entry).ro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.8 |
emsIPAddressTypeIdentifies the type of EMS IPAddress. If set to ip-v4, then the emsIPAddress object
would be set else if this object is set to ip-v6, then the empIPv6Address object
would be set.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.9 |
emsAuthChannelStatusReturns the status of the authentication channel connection with
EMS identified by the emsIPAddress of this entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.1.1.10 |
emsChangeActionThis object is used to indicate to the sensor, changes in the EMS MDR operation mode.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.2 |
emsParamIpAddressThis object is one of the parameters that need to be set before emsChangeAction is triggered.
If the action is Switchover this specifies the IP address of the Manager that the sensor should switch to.
If the action is Standalone-to-MDR this specifies the Peer EMS IP address and this will result in using
a free entry in the emsTable.
If the action is MDR-to-Standalone this specifies the future Standalone EMS IP address which should be
one of the two EMSs specified in the emsTable.
The acutal swithover or change in MDR opearation mode will be done when indicated by the Manager through the
emsChangeAction object.
Setting this object would reset the emsParamIpv6Address and emsParamAddIpv6Address objects.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.4.3 |
emsParamPriorityThis object specifies the priority of the EMS setting the standalone-to-MDR change action.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.4.4 |
emsParamAddIpAddressThis object specifies the secondary IP address of the EMS while in MDR mode. If the emsChangeAction
is standalone-to-MDR, this specifies the secondary IP address of the new peer Manager. If the
emsChangeAction is secondary NIC address, this specifies the secondary IP address of the EMS
identified by emsParamIpAddress.
Setting this object would reset the emsParamIpv6Address and emsParamAddIpv6Address objects.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.4.5 |
emsParamIpv6AddressThis object is one of the parameters that need to be set before emsChangeAction is triggered.
If the action is Switchover this specifies the IPv6 address of the Manager that the sensor should switch to.
If the action is Standalone-to-MDR this specifies the Peer EMS IPv6 address and this will result in using
a free entry in the emsTable.
If the action is MDR-to-Standalone this specifies the future Standalone EMS IPv6 address which should be
one of the two EMSs specified in the emsTable.
The acutal swithover or change in MDR opearation mode will be done when indicated by the Manager through the
emsChangeAction object.
Setting this object would reset the emsParamIpAddress and emsParamAddIpAddress objects.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.4.6 |
emsParamAddIpv6AddressThis object specifies the secondary IPv6 address of the EMS while in MDR mode. If the emsChangeAction
is standalone-to-MDR, this specifies the secondary IPV6 address of the new peer Manager. If the
emsChangeAction is secondary NIC address, this specifies the secondary IPv6 address of the EMS
identified by emsParamIpAddress.
Setting this object would reset the emsParamIpAddress and emsParamAddIpAddress objects.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.4.7 |
emsTenantIdThis object specifies the TenantId. which identifies unique customer in Trellix eco systemrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.4.8 |
emsPrimaryNSMGUIDThis object specifies the Primary NSM Server GUID. which identifies unique NSM in Trellix eco systemrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.4.9 |
emsSecondaryNSMGUIDThis object specifies the Secondary NSM Server GUID. which identifies unique NSM in Trellix eco systemrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.4.10 |
tftpGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.5 |
tftpKeyThis specifies the tftp shared secret key between the IntruShield Sensor and EMS.
Default: All 128 octets filled with '0'.rw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.5.1 |
tftpFileSizeThe size of the file in bytes. Default: 0rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.5.2 |
tftpFileNameThis specifies the name of the file to TFTP (with the source path)rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.5.3 |
tftpServerAddressTFTP server IP address.
Is the EMS address when downloading from EMS to management card.
Setting this object would reset the tftpServerIpv6Address objects.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.5.4 |
tftpActionInvokes TFTP service using other (required) parameters defined in <tftpGrp>.
Valid values are : (0)-other, (1)-downloadimage, (2)-downloadsigfile, (3)-uploaddos,
(4)-uploadtrace, (5)-downloaddos, (6)-aborttransfer, (7)-downloadcertfile,
(8)-downloadimageandsigfile, (9)-downloadmperootcertfile,
(10)-download_sgap_ssl_cert, (11)-upload_sgap_ssl_csr,
(12)-upload_ibac_ad_file, (13)-download_ibac_ad_file,
(14)-upload_swh_learned_file,
(15)-downloadPacketCaptureFilterFile ,(16)-uploadPacketCaptureFilterFile,
(17)-downloadGeoLocationDatabase, (18)-uploadPacketCapturePCAPFile,
(19)-download_usrid_acl_file,
(20)-download-bot-dat-file,
(21)-download-ntba-ssl-cert-file,(22)-upload-dev-prof-file,
(25)-download_matd_ssl_cert, (28)-download-ffp-bulk-file,
(33)-download_zcenter_ssl_cert, (34)-download-gti-private-cloud-cert-file,
(35)-upload_suricata_failed_rules, (36)-upload_ca_sensor_csr,
(37)-download_ca_sensor_cert, (38)-download_syslog_ssl_cert,
(39)-download_ca_cert_storerw TrellixTFTPAction (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.5.5 |
tftpActionStatusThe status of the current TFTP actionro TrellixTFTPStatus (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.5.6 |
tftpActionInProgressResultSpecifies TFTP service completion percentage.ro TrellixTFTPInProgressResult (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.5.7 |
tftpActionFailedResultSee TrellixTFTPFailedResultro TrellixTFTPFailedResult (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.5.8 |
tftpActionTransactionIdUsed to ensure single file transfer at a time. Default: 0.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.5.9 |
tftpServerIpv6AddressTFTP server IPv6 address.
Is the EMS IPv6 address when downloading from EMS to management card.
Either one of the Ipv4 or Ipv6 address should be set by the ISM.
Setting this object would reset the tftpServerIpAddress objects.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.5.10 |
tftpIVKeyThis specifies the tftp Initialization Vector that is used for AES Decryption between the IntruShield Sensor and EMS.
Default: All 128 octets filled with '0'.rw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.5.11 |
chassisGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.7 |
temperatureStatusro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.7.1 |
fanStatusro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.7.2 |
primaryPowerSupplyStatusThis powerSupply MIB object gives the primary powerSupply status.
(0) - Primary PowerSupply Module is not present.
(1) - Primary PowerSupply Module is present and operational.
(2) - Primary PowerSupply Module is present and its not operational.
(3) - Error while retrieving the powerSupply status, please re-try after some time.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.7.3 |
secondaryPowerSupplyStatusThis powerSupply MIB object gives the secondary powerSupply status.
(0) - Secondary PowerSupply Module is not present.
(1) - Secondary PowerSupply Module is present and operational.
(2) - Secondary PowerSupply Module is present and its not operational.
(3) - Error while retrieving the powerSupply status, please re-try after some time.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.7.4 |
pciLegacyErrorStatusBMC PCI Legacy Error (parity error (PERR) and system error (SERR))ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.5 |
pciFatalError1StatusBMC PCI Fatal Error1 Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.6 |
pciFatalError2StatusBMC PCI Fatal Error2 Status (Continuation of Fatat Error 1)ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.7 |
systemEventLogStatusBMC System Event Log (SEL buffer) Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.8 |
bmcWatchdogStatusBMC Watchdog Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.9 |
processorStatusTableThis table contain list of processors SEQUENCE OF ProcessorStatusEntry .1.3.6.1.4.1.8962.2.1.2.1.7.10 |
processorStatusEntryThe table entries denotes various processor details for each index (processor) ProcessorStatusEntry .1.3.6.1.4.1.8962.2.1.2.1.7.10.1 |
processorStatusProcessor Presence Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.10.1.1 |
memoryECCStatusMemory ECC Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.11 |
postSysEventStatusPOST Sys Event Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.12 |
postErrorStatusPOST Error Statusro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.7.13 |
managementCardGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.8 |
mgmtCardTableThis table contains entries, one per management card, indexed by the appropriate slotIndex. SEQUENCE OF MgmtCardEntry .1.3.6.1.4.1.8962.2.1.2.1.8.1 |
mgmtCardEntryThis MIB object contains all the columnar objects,
that describe the contents of each management card within the IntruShield node.
This entry is indexed by a fixed value slotIndex of 1 (one) for all models. MgmtCardEntry .1.3.6.1.4.1.8962.2.1.2.1.8.1.1 |
mcActionActions applicable on this card, uses TC TrellixIDSAction.
Default: other
Only 'reset' and 'swupdate' action are supported.rw TrellixIDSAction (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.1 |
mcActionStatusOutcome of a SNMP set on the mcAction object. Uses TC TrellixIDSActionStatus
Default: otherro TrellixIDSActionStatus (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.2 |
mcActionResultDetail information when <mcAction> is set to 'reset', based on <mcActionStatus>
Default: 0, details not defined.ro TrellixIDSActionResult (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.3 |
mcHwVersionThe manufacturer specified hardware version information.
Typically indicated major, minor, patch information for version.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.4 |
mcCurrentSwVersionThe manufacturer specified software version information that is currently running.
Typically indicated major, minor, patch information for version.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.5 |
mcFutureSwFileNameThe new software (image) file residing on flash.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.6 |
mcDateAndTimeSystem date and time set by EMS.rw DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.8.1.1.7 |
slave-ChassisGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.9 |
slaveTemperatureStatusro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.9.1 |
slaveFanStatusro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.9.2 |
slavePrimaryPowerSupplyStatusThis powerSupply MIB object gives the primary powerSupply status.
(0) - Slave Primary PowerSupply Module is not present.
(1) - Slave Primary PowerSupply Module is present and operational.
(2) - Slave Primary PowerSupply Module is present and its not operational.
(3) - Error while retrieving the powerSupply status, please re-try after some time.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.9.3 |
slaveSecondaryPowerSupplyStatusThis powerSupply MIB object gives the secondary powerSupply status.
(0) - Slave Secondary PowerSupply Module is not present.
(1) - Slave Secondary PowerSupply Module is present and operational.
(2) - Slave Secondary PowerSupply Module is present and its not operational.
(3) - Error while retrieving the powerSupply status, please re-try after some time.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.9.4 |
sensorCardGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.10 |
sensorCardTableThis table contains entries, one per sensor card and indexed by the slotIndex. SEQUENCE OF SensorCardEntry .1.3.6.1.4.1.8962.2.1.2.1.10.1 |
sensorCardEntryThis MIB object contains all the columnar objects,
that describe the contents of each sensor card within the Trellix IDS.
This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models. SensorCardEntry .1.3.6.1.4.1.8962.2.1.2.1.10.1.1 |
scActionActions on this card. See TrellixIDSAction
Default: other
Only reset and sigupdate are supported.rw TrellixIDSAction (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.1 |
scSigUpdateResultIndicates detail results of scAction object.
Default: 0ro TrellixIDSActionResult (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.2 |
scHwVersionThe manufacturer specified hardware version information.
Typically indicated major, minor, patch information for version.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.3 |
scCurrentSwVersionThe manufacturer specified software version information that is currently running.
Typically indicated major, minor, patch information for version.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.4 |
scFutureSwFileNameThe new software (image) file residing on flash.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.5 |
scCurrentSigVersionThe manufacturer specified signature file version information that is currently running.
Typically indicated major, minor, patch information for version.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.6 |
scFutureSigFileNameThe new signature file residing on flash.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.7 |
scMACAddressReadOnly parameter, to allow SNMP manager to view the MAC address of this card.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.8 |
scCurrentBotDATVersionThe manufacturer specified BotDAT file version information that is currently running.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.10.1.1.9 |
ipTableThis table contains entries that define the IP
configuration objects per sensor card. SEQUENCE OF IpEntry .1.3.6.1.4.1.8962.2.1.2.1.10.6 |
ipEntryThis table entry contains the sensor card specific ( <slotIndex> based)
IP configuration objects.
This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models. IpEntry .1.3.6.1.4.1.8962.2.1.2.1.10.6.1 |
ipFragmentTimerIP fragment reassembly timer
Default: 30 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.1 |
ipOverlapOptionIf set to oldData(1), ip reassembly module takes old data.
Otherwise it takes new data.
Default: oldData (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.2 |
ipTTLConfigModeIf set to noTTLChecking(1), the TTL in the packet is not
checked. If set to checkThreshold(2), then TTL is checked
against the value in ipTTLThreshold object. If set to
resetTTL(3), the TTL value is reset to the value set by
ipTTLResetValue object.
Default: noTTLChecking (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.3 |
ipTTLThresholdSpecifies the minimum threshold for the TTL value. The TTL
in the packet is checked against the value configured here.
If TTL is less than the value configured here, an alert is
raised.
Default: 32rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.4 |
ipTTLResetValueSpecifies the value that TTL should be reset to.
Default: 32rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.5 |
ipSmallestFragmentSizeSpecifies the smallest fragment size that is acceptable.
Any fragments smaller than the size specified here (other
than the last one) will be counted and an alert raised if
exceeds the threshold configured. The size should be multiple
of 8.
Default: 256rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.6 |
ipSmallFragmentThresholdCount of acceptable small fragments as specified by
ipSmallestFragmentSize in 1 minute.
Default: 10000rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.7 |
ipFragmentReassemblyOptionFlag to indicate if sensor should reassemble IP Framgments. Default: enablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.8 |
ipv6OverlapOptionIf set to oldData(1), ipv6 reassembly module takes old data.
Otherwise it takes new data.
Default: oldData (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.9 |
ipv6SmallestFragmentSizeSpecifies the smallest ipv6 fragment size that is acceptable.
Any fragments smaller than the size specified here (other
than the last one) will be counted and an alert raised if
exceeds the threshold configured. The size should be multiple
of 8.
Default: 48rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.10 |
ipv6SmallFragmentThresholdCount of acceptable small fragments as specified by
ipSmallestFragmentSize in 1 minute.
Default: 10000rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.6.1.11 |
tcpTableThis table contains entries that define the TCP configuration objects per sensor card. SEQUENCE OF TcpEntry .1.3.6.1.4.1.8962.2.1.2.1.10.7 |
tcpEntryThis table entry contains the sensor card specific ( <slotIndex> based)
TCP configuration objects.
This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models. TcpEntry .1.3.6.1.4.1.8962.2.1.2.1.10.7.1 |
supportedUDPFlowsNumber of UDP flows supported.
Deafult: 1 million, UDP and TCP combined.
Default: 100000 for I4000, 25000 for I2600, 5000 for I1200, 10000 for I1400rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.1 |
tcbInactivityTimerTCB inactivity timeout
Default: 10 minutesrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.2 |
tcpSegmentTimerTCP segment reassembly timer.
Default: 60 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.3 |
tcp2MSLTimerTCP 2MSL timer
Default: 10 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.4 |
inactiveFlowsRSTEnabledOption to RST incative flows enabled (TRUE) or not (FALSE).
Default: FALSErw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.5 |
dropReTxTCPEnabledIntruShield may get TCP segments which have already been processed by it apriori
(due to the segments being dropped in between it and the destination).
By default, forward it without any processing, but provide the user with an option
to drop such selectively retransmitted segments.
This object enables the dropping of retransmitted TCP packets.
Default: FALSErw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.6 |
coldStartTimeWhen sensor powers up, it will treat the packets for flows
that did not exist without valid TCB as valid packets. After
the time configured with this object, packets without valid
flows are considered invalid packets.
Default: 60minrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.7 |
coldStartDropActionWhen this object is set to dropFlows(1), in inline mode
sensor will drop the packets without valid TCB.
When this object is set to forwardFlows(2), in inline mode
sensor will forward the packets until coldStartTime. After
that it will drop the packets without valid TCB.
Default: forwardFlows(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.8 |
normalizationOnOffOptionEnable or Disable normalization
Default: off(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.9 |
tcpOverlapOptionIf this object is set to oldData(1), tcp reassembly module
will use the old data. Otherwise it will use the newer data.
Default: newData(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.10 |
sAckPermittedOptionIf set to on, removes in SYN and clears in further packets.
This applies only in inline mode.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.11 |
tTCPOptionThresholdGenerate alert if too many. TBDrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.12 |
dropOnPAWSFailIf set to enable, drop if fails PAWS test. If set to disable
always forward the packet.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.13 |
timestampEchoMatchFailIf set to enable, drop if TS-echo was one not sent earlier.
If set to disable always forward the packet.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.14 |
dropMD5OptionIf set to enable, drop packet if SYN=0 and it contains
no MD5 but MD5 was used at setup. If set to disable always
forward the packet.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.15 |
unsolicitedUDPPacketsTimeoutIf a UDP response packet is received without a request
packet, the packet will be dropped. This object configures
the acceptable request to response time.
Default: 60rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.16 |
synProxyEnableIf set to enable, sensor will do SYN proxy for every SYN
request. SYN proxy is done only when TCP SYN flood is
detected.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.17 |
ackScanDiscardTimeThe time in which ACK scan messages should be discarded.
Default 15 minutesrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.18 |
halfOpenConnectionResetEnableResets either all or only DOS packets whose 3 Way Handshake has not finished. Default: Disable(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.19 |
outOfContextTcpPktEnableUsed to en/dis able processing of out of context TCP packets. Enable aka PERMIT, Disable aka DENY, PERMIT_OUT_OF_ORDER(3), DENY-NO-TCB (4) aka PERMIT-ACL-MODE, STATELESS_INSPECTION (5). Default: PERMIT(1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.20 |
synCookieConfigThis object specifies the directions in which to enable syn cookie when there is a
SYN flood. This option is valid only for monitoring ports operating in inline mode.
Default: 0rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.21 |
synCookieInboundThresholdThis object specifies the threshold value for the number of incomplete SYNs from outside
network beyond which SYN cookie mechanism has to be enabled.
Default: 4096rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.22 |
synCookieOutboundThresholdThis object specifies the threshold value for the number of incomplete SYNs from inside
network beyond which SYN cookie mechanism has to be enabled.
Default: 4096rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.23 |
synCookieMssThis object specifies the maximum segment size to be sent in SYN Ack, with SYN cookie mechanism enabled.
Default: 536rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.24 |
sinkHoleTimeToLiveThis object specifies the TTL duration for sinkhole. TTL duration can range from 6 hours to 18 hours,
Default: 12 hoursrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.25 |
sinkHoleIpAddressThis object is used to configure IPv4 address of sinkhole. It can be any valid ip address apart from
broadcast and multicast address.
Default: 127.0.0.1rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.10.7.1.26 |
sessionTableSession table is used by user to configure TCP and UDP flows
in the sensor. SEQUENCE OF SessionEntry .1.3.6.1.4.1.8962.2.1.2.1.10.8 |
sessionEntryIndexed with 5-tuple flow parameters and VIDS identifier.
This table is used only to send sets to the sensor. Doing
GET on this table will not return any information. SessionEntry .1.3.6.1.4.1.8962.2.1.2.1.10.8.1 |
sessionSrcIpAddressSource ip address. IpAddress .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.1 |
sessionDestIpAddressDestination ip address. IpAddress .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.2 |
sessionSrcPortNoSource port number. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.3 |
sessionDestPortNoDestination port number. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.4 |
sessionProtocolProtocol type. Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.5 |
sessionVIDSIdentifierVIDS identifier that owns this flow. If VIDS is not
enabled, this oject will be ignored. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.6 |
sessionConfigActionSetting this object to resetSession(1) causes the flow
to be reset.
Setting this object to logSession(2) causes the flow to be
logged for the time specified with sessionLogTime object.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.7 |
sessionLogTimeThe time for which the packet needs to be logged.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.8 |
sessionIntfPortNoThe sensor linear interface port index on which the attack has been detected.
This is mandatory when the sessionConfigAction is resetSession.rw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.8.1.9 |
sessionV6TableSession table v6 is used by user to configure TCP and UDP flows
over Ipv6 in the sensor. SEQUENCE OF SessionV6Entry .1.3.6.1.4.1.8962.2.1.2.1.10.9 |
sessionV6EntryIndexed with 5-tuple flow parameters and VIDS identifier.
This table is used only to send sets to the sensor. Doing
GET on this table will not return any information. SessionV6Entry .1.3.6.1.4.1.8962.2.1.2.1.10.9.1 |
sessionSrcIpv6AddressSource ipv6 address. Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.1 |
sessionDestIpv6AddressDestination ipv6 address. Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.2 |
sessionv6SrcPortNoSource port number. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.3 |
sessionv6DestPortNoDestination port number. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.4 |
sessionv6ProtocolProtocol type. Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.5 |
sessionv6VIDSIdentifierVIDS identifier that owns this flow. If VIDS is not
enabled, this oject will be ignored. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.6 |
sessionv6ConfigActionSetting this object to resetSession(1) causes the flow
to be reset.
Setting this object to logSession(2) causes the flow to be
logged for the time specified with sessionLogTime object.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.7 |
sessionv6LogTimeThe time for which the packet needs to be logged.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.8 |
sessionv6IntfPortNoThe sensor linear interface port index on which the attack has been detected.
This is mandatory when the sessionConfigAction is resetSessionrw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.10.9.1.9 |
pluggableModuleStateIndicates the state of the pluggable modules in the system. Applicable
for Rubicon models only. 32 bit starting from LSB, 4 bits for each
slot starting from 2, will contain the moduleSysType enum
=> 0000 0000 0000 0000 0000 <slot4> <slot3> 0000.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.10.10 |
interfacePortGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.11 |
intfPortTableTable containing entries for each interface port (indexed via intfPortIndex)
on each sensor card (indexed via appropriate slotIndex).
This table contains Trellix specific configuration objects.
Tables that contain MIB objects borrowed from MIB-II are in the
TRELLIX-SENSOR-PERF-MIB. SEQUENCE OF IntfPortEntry .1.3.6.1.4.1.8962.2.1.2.1.11.1 |
intfPortEntryThis MIB object contains all the columnar objects,
that describe the contents of each interface port on each IntruShield sensor card.
Indexed by slotIndex/intfPortIndex IntfPortEntry .1.3.6.1.4.1.8962.2.1.2.1.11.1.1 |
intfPortIfDescrA textual string containing information about the interface.
Returns the string that is printed on the box.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.1 |
intfPortIfTypeThe type of interface, distinguished according to the
physical/link protocol(s) immediately 'below' the network
layer in the protocol stack.
For brevity, Trellix options are as specified by the TC,
TrellixIDSPortType.
However, the SNMP MIB-II - Interfaces MIB specifies many more
valid options. See comments section for details.ro TrellixIDSPortType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.2 |
intfPortIfAdminStatusThe desired state of the interface.
The testing(3) state indicates that no operational packets
can be passed.
Default: downrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.3 |
intfPortIfOperStatusThe current operational state of the interface.
The testing(3) state indicates that no operational packets
can be passed.
Default: downro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.4 |
intfPortOperatingModeReadWrite parameter specifies the operating mode for the
Trellix IDS sensor to be used. Different modes supported are
inline-fo-passive(1), non-inline or tap(2), span(3) and
inlne-fc(4), inline-fo-active kit(5 - available on M-series only).
Default: non-inlinerw TrellixIDSOperatingMode (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.5 |
intfPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one.
Otherwise as half-duplex.
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.6 |
intfPortFullDuplexPeerThis MIB object returns the intfPortIndex value of the
interface port that is a peer. Used only when operating mode
is inline(1) or monitor-dual-intf(2).ro Integer32 .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.7 |
intfPortSpeedGet current speed/negotiation on the interface.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.8 |
intfPortSpeedConfigSet desired speed/negotiation on the interface.
Default values are as follows:
I-Series -
fixed-hundred-Mbps (infinity/hichborn/2x00(1a-3b)
auto-gig-Mbps on 3000/4010/4000/2x00(4a,4b)
M-Series -
auto-ten-gig-Mbps on palomar/pyramid(1a-4b),auto-gig-Mbps(5a-8b)
Default: see aboverw TrellixPortSpeed -- was TrellixFEType, now deprecated .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.9 |
intfPortEnableInternalTapSet to TRUE to enable feature. Applies to Fast Ethernet (FE)
ports only (see TrellixIDSPortType).
For non FE ports, set to 'FALSE' .
Setting this to 'TRUE' requires that
<intfPortCurrentOperatingMode> is already set to
'monitor-dual-intf'
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.10 |
intfPortInOutTypeThis MIB object reflects the Input or Output labeling
of this interface port. Used only when operating mode
is inline(1) or monitor-dual-intf(2).
Default: not-specified(3)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.11 |
intfGEPortSpeedConfigOnly applicable to gigabit-ethernet ports, to specify
whether auto or 1 Gbps
See TrellixGEType
Default: 'auto-negotiate'rw TrellixGEType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.12 |
intfFailOpenSwitchStatusReturns the status of the external optical bypass switch
status. For FE ports, this object will return
not-applicable(1). For GE ports, if external optical bypass
switch is connected to sensor ports, this will return
present(2). Otherwise, it will return not-present(3).ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.13 |
intfFailOpenPortStatusReturns the packet forwarding status of the sensor ports connected to the optical bypass switch.
If status is inline-fail-open(2), sensor is doing the
forwarding. If status is bypass(3), the bypass switch is
doing the forwarding and sensor will not process any
traffic in this mode. Tap(4), absent(5) , unknown (6) and layer2-bypass(7)
are available only in M-series for non RJ45(captive) ports
when connected to active FO kit and sensor operating mode
is inline-fail-open-active-kit.
tap - operational status(up), kit(present), heart-beat(tap)
absent - operational status(up), kit(absent), hear-beat(none)
unknown - operational status(down), kit(absent), heart-beat(not available).ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.14 |
intfPortEnableAntiSpoofingspoofed packet detect rcvd on the both sides .
Default: 'disable-bothsides-spoof-detect' (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.15 |
intfPortHostQRActionStatusThis object depicts the sensor level host quarantine and remediation action status
for the specific interface port. The value 'quarantine' indicates just quarantine the host and
the value 'remediate' indicates both quarantining and remediating the host.
Default: disabledrwobsolete Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.18 |
intfPortMpeQRActionStatusThis object depicts the MPE respone based host quarantine and remediation action status for the
specific interface port. The value 'mpeNotify' indicates just informing the MPE server
about the problem host; the value 'mpeQuarantine' indicates first informing the MPE server
about the problem host and then quarantine the host based on the response from the MPE-server
and the MPE based Quarantine and Remediation scope mib object value; and the value 'mpeRemediate'
indicates first informing the MPE server about the problem host and then remediating the host
based on the response from the MPE-server and the MPE based Quarantine and Remediation scope
mib object value.
Default: disabledrwobsolete Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.19 |
intfPortAllowlistACLLookupStatusThis object indicates the status of allowlist ACL lookup for this interface port.
Default: disabledrwobsolete Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.20 |
intfPortPeerDeviceAdvtStatusApplicable if sensor port is set to auto-negotiate, else other(0). Specifies the advertised speed-duplex of the peer appliance port connected to this sensor port.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.21 |
intfPortIsMcafeeConnectorTrue: connector is not inserted.
True: connector is inserted in port and McAfee certified.
False: connector is inserted and not McAfee certified.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.22 |
intfPortAllowAnyConnectorTrue: Permit usage of any connector for port.
False: Restrict usage to McAfee certified connector only.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.23 |
intfPortCageTypePhysical connector cage type on sensor chassis panel.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.24 |
intfPortGetMediaTypeGets the media of the connector present in the port cage. None (0) if cage is empty.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.25 |
intfPortSetMediaTypeSets the media of the connector the user desired for the port.
Default: opticalrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.26 |
intfPortAdditionalInfoA textual string containing information about the interface.
Typically returns connector specific information.
For V-series sensors(vmips) this object will return monitoring ports label.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.27 |
intfPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.28 |
intfPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.29 |
intfPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.30 |
intfPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation
to be sent to the NBAD server, is enabled over this monitoring port.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.31 |
intfPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring
port is connected.rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.32 |
intfPortAppIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled
over this monitoring port.
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.33 |
intfPortConnectorTypePhysical connector type plugged into the port cage.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.34 |
intfPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is
generated by the sensor appliance using the pair of slot index and the port index values.
The other MIB tables would directly use this linear index, whereever applicable.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.35 |
intfPortFecConfigThis object is used to configure FECrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.36 |
intfPortTranceiverSerialNumberA textual string containing information about the interface.
Typically returns transceiver's serial number.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.11.1.1.37 |
intfPortGBICHotSwapTimeIndicates time when the front end GBIC for any port was hot swapped last.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.11.2 |
responsePortGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.12 |
respPortTableTable containing entries for each response port (indexed via respPortIndex)
on each sensor card (indexed via valid slotIndex).
This table contains Trellix specific MIB objects. SEQUENCE OF RespPortEntry .1.3.6.1.4.1.8962.2.1.2.1.12.1 |
respPortEntryThis MIB object contains all the columnar objects,
that describe the contents of each response port within the Trellix IDS sensor card.
Indexed by slotIndex/respPortIndex RespPortEntry .1.3.6.1.4.1.8962.2.1.2.1.12.1.1 |
respPortDescrA textual string containing information about the interface.
Returns the string that is printed on the box.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.1 |
respPortTypeThe type of interface, distinguished according to the
physical/link protocol(s) immediately 'below' the network
layer in the protocol stack.
See TrellixIDSPortType.ro TrellixIDSPortType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.2 |
respPortAdminStatusThe desired state of the interface.
Default: Uprw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.3 |
respPortOperStatusThe current operational state of the interface.
The testing(3) state indicates that no operational packets
can be passed.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.4 |
respPortEnableFullDuplexTrue: Sets response port to work as a full-duplex one.
otherwise as half-duplex.
If True, respPortFullDuplexPeer must be specified.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.5 |
respPortSpeedSee TrellixPortSpeed
Default: fixed-hundred-Mbps (2)rw TrellixPortSpeed (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.6 |
respPortPktDestinationThis object is used when response ports are chosen for
sending response packets. When router mode is chosen,
packets will be sent to router with destination MAC as
defined in intfRespMacAddress.
Default value is switch (1).rw SEQUENCE OF IntfRespEntry .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.7 |
respPortMacAddressSpecifies the macaddress of the router to which the response
packets have to be sent to.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.8 |
respCUGEPortSpeedOnly applicable to copper-gigabit-ethernet ports, to specify whether
10mbps or 100mbps or 1-gbps or auto-neg. See TrellixCUGEType
Default: auto-negotiaterw TrellixCUGEType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.9 |
respAdditionalInfoA textual string containing additional information about the response interface.
This mib object will be available only on V-series sensors.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.12.1.1.11 |
intfRespTableTable containing entries for each interface port. The
table describes how responses have to be sent in monitoring
mode. Unknown .1.3.6.1.4.1.8962.2.1.2.1.12.2 |
intfRespEntryIndexed by slotIndex/intfPortIndex IntfRespEntry .1.3.6.1.4.1.8962.2.1.2.1.12.2.1 |
intfRespTypeSetting this object to responsePort (2) causes responses
to be sent via the response port. The response port no that
needs to be used is specified with intfRespPortNo object.
Setting this object to inline (3) causes responses to be
sent inline. Note that in monitoring mode, responses can
only be sent inline when the monitoring port is in
half-duplex mode.
Default action will be responsePort (1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.12.2.1.1 |
intfRespPortNoSpecifies the response port number that needs to be used
for this monitoring port. The response ports are configured
by respPortTable.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.12.2.1.2 |
dosConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.14 |
dosLearningModeActionThis object can be used to switch the mode to DOS learning or
force detection mode .
The saved profile can be reloaded by setting the object to
reloadProfile(3).
When set to forceDetection (1), user must be warned as follows,
Warning: You are about to force the sensor into Detection Mode
before the required 48-hour learning period.
The traffic profile learned by the sensor may not be
adequate for DOS attack detection and prevention.
It is desirable to place the sensor in learning mode
while receiving normal traffic for at least 48 hours.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.14.1 |
dosProfileTableTable defines profile data for each DOS VPT entry. SEQUENCE OF DosProfileEntry .1.3.6.1.4.1.8962.2.1.2.1.14.2 |
dosProfileEntryIndexed by VIDS ID and Profile ID. DosProfileEntry .1.3.6.1.4.1.8962.2.1.2.1.14.2.1 |
dosProfileVidsIdThe virtual admin domain identifier. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.2.1.1 |
dosProfileIdThe identifier of the profile. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.2.1.2 |
dosProfileStatusThe status of the profile entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.14.2.1.3 |
dosProfileLearningTimeThe time (in hundredths of a second) since learning was started for the profile.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.2.1.4 |
dosProfileBulkTableTable defines profile data for each DOS VPT entry. This table
is primarily used to get the GETNEXT and GETBULK. SEQUENCE OF DosProfileBulkEntry .1.3.6.1.4.1.8962.2.1.2.1.14.3 |
dosProfileBulkEntryIndexed by profile index. DosProfileBulkEntry .1.3.6.1.4.1.8962.2.1.2.1.14.3.1 |
dosProfileBulkIndexThe index of the profile table. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.3.1.1 |
dosProfileBulkVidsIdThe virtual admin domain identifier.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.3.1.2 |
dosProfileBulkIdThe identifier of the profile.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.3.1.3 |
dosProfileBulkStatusThe status of the profile entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.14.3.1.4 |
dosProfileBulkLearningTimeThe time (in hundredths of a second) since learning was started for the profile.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.3.1.5 |
dosProfileShortAndLongTermTableTable defines short term and long term profile data per DOS measure per VPT. Each VPT is indexed by the global VIDSID, global NIId. SEQUENCE OF DosProfileShortAndLongTermEntry .1.3.6.1.4.1.8962.2.1.2.1.14.4 |
dosProfileShortAndLongTermEntryIndexed by global VIDSIndex, global NIIndex & measureId. DosProfileShortAndLongTermEntry .1.3.6.1.4.1.8962.2.1.2.1.14.4.1 |
dosProfileShortAndLongTermVIDSIndexThe VIDS id index. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.1 |
dosProfileShortAndLongTermNIIndexThe NI id index. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.2 |
dosProfileShortAndLongTermMeasureIndexThe measure id index. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.3 |
dosProfileShortAndLongTermBinCountThe count indicates the number of short or long term values to be interpreted in their respective content objects. Max value is 32. If the value is set to 10, then only the first 80 bytes in each of the strings have valid data. Note: that 256 octet strings can accomodate a max of 32 values (3 octects each)ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.4 |
dosProfileShortTermContentThis specifies the short term profile data.
Default: All 256 octets filled with '0'.ro OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.5 |
dosProfileLongTermContentThis specifies the long term profile data.
Default: All 256 octets filled with '0'.ro OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.14.4.1.6 |
enableDosPktLoggingThis object can be used to turn on/off the logging od DOS packets. Default: disable (2).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.14.6 |
timedDosPktDropTableTable defines action and duration to enable/disable/extend the duration for which DOS pkts are to be drpped. Also provides the absolute time remaining till when it the sensor will drop these packets. SEQUENCE OF TimedDosPktDropEntry .1.3.6.1.4.1.8962.2.1.2.1.14.7 |
timedDosPktDropEntryIndexed by VIDS ID NI ID and MeasureId. TimedDosPktDropEntry .1.3.6.1.4.1.8962.2.1.2.1.14.7.1 |
timedDosPktDropVidsIdIndexThe Vids identifier. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.1 |
timedDosPktDropNiIdIndexThe NI identifier. Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.2 |
timedDosPktDropMsrIdIndexThe MeasureId identifier. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.3 |
timedDosPktDropActionThe action tells the bulkTimedDosPktDropTable to add(enable the duration for), delete(disable), modify(extend the duration for) an entry.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.4 |
timedDosPktDropDurationThe duration for which the DOS pkt drop has been enabled or extended.rw Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.5 |
timedDosPktDropEndTimeThe absolute end time when the duration for intended action expires.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.7.1.6 |
bulkTimedDosPktDropTableTable lists entries indexed by the bulkTimedDosPktDropIndex, each returns the corresponding VidsId, NiId, MeasureId and the EndTime value. SEQUENCE OF BulkTimedDosPktDropEntry .1.3.6.1.4.1.8962.2.1.2.1.14.8 |
bulkTimedDosPktDropEntryIndexed by bulk index. BulkTimedDosPktDropEntry .1.3.6.1.4.1.8962.2.1.2.1.14.8.1 |
bulkTimedDosPktDropIndexThe bulk index . INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.8.1.1 |
bulkTimedDosPktDropVidsIdThe Vids identifier.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.8.1.2 |
bulkTimedDosPktDropNiIdThe NI identifier.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.8.1.3 |
bulkTimedDosPktDropMsrIdThe MeasureId identifier.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.8.1.4 |
bulkTimedDosPktDropEndTimeThe absolute end time when the duration for intended action expires.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.14.8.1.5 |
internalVLANIdThis object identifies the VLAN ID to be used by the sensor to tag
any untagged pkts on Rx, and untag them on Tx. It must not match any
other VLAN ID assigned for the customer network. Default: 4095rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.14.9 |
pktLogGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.15 |
pktLogServerIPAddressIP Addressrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.15.1 |
pktLogServerPortTCP Port on which the pkt log server can receive packet
logs from the IntruShield IDS.rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.15.2 |
pktLogMaxPacketsPerFlowNumber of packets per flow which need to be logged,
0 means log entire flow.
Default: 1000rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.15.3 |
pktLogEncryptionEnableThis object can be used to enable encryption of packet log channel.
RC4 will be used for encryption.
Default: enable (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.15.4 |
pktLogServerIPv6AddressIPv6 Address of the ISM to which the logs need to be delivered.
ISM should set either the Ipv4 or the Ipv6 address.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.15.5 |
pktAlertThrottleGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.16 |
pktAlertThrottleGlobalThresholdOnce this threshold is exceeded, sensor will only send one
summary alert for all addresses (srcip's and destip's) that
match the attackid/vidsid.
Default: 10rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.16.1 |
pktAlertThrottleIntervalIf the number of alerts exceeds the amount configured
in pktAlertThrottleThreshold or
pktAlertThrottleGlobalThreshold in pktAlertThrottleInterval
seconds, alerts will be throttled.
Units are in seconds.
Default: 120 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.16.2 |
pktAlertThrottleActionThis object can be used to enable and disable alert
throttling.
Default: enable(1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.16.3 |
pktAlertThrottleThresholdThis object is used to configure the number of alerts that
need to be sent before sensor starts to throttle the alerts.
For example if this value is 10, it will send the first 10
alerts with the following key: attackid/vidsid/srcip/destip.
This parameters will use the pktAlertThrottleInterval as the
interval.
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.16.4 |
pktAlertCorrelationTimeThis object is used to configure the time that the sensor will
correlate multiple signatures for a single attack and only send
the signature with the lowest benign trigger probability.
Default: 5 secsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.16.5 |
sslConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.17 |
sslSessionCacheLifetimeDuration in minutes for which the SSL Session is kept alive, inspite of no
SSL data transfer between the client/server .
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.1 |
sslSupportActionThis object can be used to enable support for specific ssl flow count (non 0)
and disable SSL (0) on sensor. Sensor reboot is typically required to activate
support of requested flow count.
EMS must check for max requested ssl flows based on product type:
I4000: 100K, I2600: 25K , I1200: not supported.
Default: not supported (0)rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.2 |
sslSupportStatusThis object can be used to get SSL support status on sensor. It will show 0 if disabled, or a non 0 value indicating the ssl flow count currently supported. User must reboot sensor to ensure that requested flow count is actually supported by sensor.
EMS must check for max supported ssl flows based on product type:
I4000: 100K, I2600: 25K , I1200: not supported.
Default: not supported (0)ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.3 |
sslSessionRemoveCertsDelete all ssl certs, thereby terminating decryption of related ssl traffic, but leave ssl support enabled within sensor.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.4 |
sslPktLoggingEnableSpecifies if sensor should log decrypted SSL packets or not.
Default: 2, disabledrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.5 |
sslModesofOperationDetermines the SSL decryption direction and method.
disable(0) - No SSL decryption performed for traffic.
inbound known key only(1) - Only Inbound SSL decryption using RSA key exchange.
outbound proxy only(2) - Only Outbound SSL using MITM proxy
inbound proxy only(3) - Only Inbound SSL using MITM Proxy
inbound and outbound proxy(4) - Inbound and Outbound proxy using MITM Proxy
inbound known key and outbound proxy(5) - Inbound using RSA key exchange and Outbound using MITM Proxy
Default: disable (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.6 |
sslSessionCacheLifetimeOutboundDuration in minutes for which the SSL Session is kept alive, inspite of no
SSL data transfer between the client/server. This setting will be applied for
SSL traffic in Outbound direction.
This is not applicable on I-series and M-series
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.7 |
sslPktLoggingOutboundEnableSpecifies if sensor should log decrypted SSL packets or not on the Outbound direction.
This is not applicable on I-series and M-series
Default: 2, disabledrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.8 |
sslProxyOutboundUnknownServerCertificateThis object will be used to configure the action that the sensor will need to
take when the sensor is unable to verify the validaity of the certificate.
This is not applicable on I-series and M-series
Default: decrypt(3)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.9 |
sslProxyOutboundUntrustedServerCertficateThis object will be used to configure the action that the sensor will need to take
when the sensor receives an untrusted certificate from the external server. This could
be either due to certificate not being trusted by any root CA, expired, revoked etc.
This is not applicable on I-series and M-series
Default: decrypt (3)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.10 |
sslProxyOutboundUnsupportedCipherSuiteThis object will be used to configure the action that the sensor will need to take when an
internal client sends a list of ciphers and the sensor does not support any of the cipher suite
This is not applicable on I-series and M-series
Default: ignore (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.11 |
sslProxyInboundUnsupportedCipherSuiteThis is reserved for future used. This object is not currently implemented.
This object will be used to configure the action that the sensor will need to take when an
external client sends a list of ciphers and the sensor does not support any of the cipher suite
This is not applicable on I-series and M-series
Default: ignore (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.12 |
sslProxyOutboundUnsupportedServerCertificateThis object will be used to configure the action that the sensor will need to take
when the sensor encounters an unsupported server certificate in an outbound direction.
This is not applicable on I-series and M-series
Default: ignore (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.13 |
sslProxyInboundUnsupportedServerCertificateThis is reserved for future used. This object is not currently implemented.
This object will be used to configure the action that the sensor will need to take
when the sensor encounters an unsupported server certificate in an inbound direction.
This is not applicable on I-series and M-series
Default: ignore (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.14 |
maxSslFlowSupportedInSslDisableModeThis object specifies the max number of SSL flows supported when SSL is disabled on the sensor.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.15 |
maxFlowSupportedInSslDisableModeThis object specifies the max number of flows supported by sensor when SSL is disabled on the sensor.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.16 |
maxSslFlowSupportedInSslInboundLegacyModeThis object specifies the max number of SSL flows supported when SSL is enabled in inbound legacy mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.17 |
maxFlowSupportedInSslInboundLegacyModeThis object specifies the max number of flows supported by sensor when SSL is enabled in inbound legacy modero INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.18 |
maxSslFlowSupportedInSslOutboundModeThis object specifies the max number of SSL flows supported when SSL is enabled in outbound mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.19 |
maxFlowSupportedInSslOutboundModeThis object specifies the max number of flows supported by sensor when SSL is enabled in outbound modero INTEGER .1.3.6.1.4.1.8962.2.1.2.1.17.20 |
sslModesofOperationStatusProvides current SSL decryption method used in Sensor for inbound traffic.
disable(0) - No SSL decryption performed for traffic.
inbound known key only(1) - Only Inbound SSL decryption using RSA key exchange.
outbound proxy only(2) - Only Outbound SSL using MITM proxy
inbound proxy only(3) - Only Inbound SSL using MITM Proxy
inbound and outbound proxy(4) - Inbound and Outbound proxy using MITM Proxy
inbound known key and outbound proxy(5) - Inbound using RSA key exchange and Outbound using MITM Proxy
Default: disable (0)ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.21 |
sslProxyOutboundUnknownURLCategoryThis object will be used to configure the action that the sensor will need to take
when the sensor identifies an unknown url category in the ssl packet. This configuration
is only supported in case of outbound ssl.
This is not applicable on I-series and M-series
Default: ignore (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.22 |
sslShKeyDecryptEnableSpecifies if sensor should decrypt using shared keys from SSL probes.
Default: 2, disabledrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.17.23 |
l2ConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.18 |
l2ModeEnableThis specifies if sensor is configured to detect failure and go into L2 mode on exceeding cfg threshold within cfg duration.
Default: 2, disabledrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.18.1 |
l2ModeStatusThis object identifies the mode the sensor is currently in.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.18.2 |
l2ModeCfgDurationThis object specifies the time duration input criteria for enabling the sensor in layer2 mode.
Default: 10 minsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.18.3 |
l2ModeCfgThresholdThis object specifies the event frequency input criteria for enabling the sensor in layer2 mode.
Default: 1rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.18.4 |
l2ModeOccCountThis object identifies the frequency of event occurence when ensor was last enabled in layer2 mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.18.5 |
l2ModeReasonThis object contains reason for sensor to enter into Layer-2 mode.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.18.6 |
aclLogAlertGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.19 |
aclAlertLoggingThis object specifies various ways to enable ACL Alert logging or disable it altogether.
This is applicable on a sensor wide basis for all ports in inline mode.
Default: disable (5)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.19.1 |
aclAlertThrottleMaxIpPairOnce this threshold is exceeded, sensor will only send one
summary acl alert for all addresses (srcip's and destip's) that
match the aclid/vidsid.
Default: 10rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.19.2 |
aclAlertThrottleIntervalIf the number of acl alerts exceeds the amount configured
in aclAlertThrottleThreshold in aclAlertThrottleInterval
seconds, alerts will be throttled.
Units are in seconds.
Default: 120 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.19.3 |
aclAlertThrottleActionThis object can be used to enable and disable acl alert
throttling.
Default: enable(1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.19.4 |
aclAlertThrottleThresholdThis object is used to configure the number of alerts that
need to be sent before sensor starts to throttle the alerts.
For example if this value is 10, it will send the first 10
alerts with the following key: aclid/vidsid/srcip/destip.
This parameters will use the aclAlertThrottleInterval as the
interval.
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.19.5 |
aclAlertDirectToSyslogThis object can be used to enable sending acl logs directly to syslog viewer instead of sending it via NSM.
Default: sendViaNSM (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.19.6 |
tacacsPlusAuthGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.20 |
enableTacacsPlusAuthThis object can be used to enable or disable user authentication & accounting using TACACS+.
Default: disable (2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.20.1 |
enableTacacsPlusTrafficEncrThis object can be used to enable or disable encryption of TACACS+ traffic.
Default: disable (2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.20.2 |
tacacsPlusEncrSecretThis object specifies the secret to be used in generating the encrypted TACACS+ trafficrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.20.3 |
tacacsPlusServerIPTableThis table contains entries that specifiy the IP addresses of the TACACS+ servers SEQUENCE OF TacacsPlusServerIPEntry .1.3.6.1.4.1.8962.2.1.2.1.20.4 |
tacacsPlusServerIPEntryThis table entry specifies the IP address of the TACACS+ server TacacsPlusServerIPEntry .1.3.6.1.4.1.8962.2.1.2.1.20.4.1 |
tacIndexFixed index for the four TACACS+ Server entries. Valid values are [1,2,3,4] only. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.20.4.1.1 |
tacacsPlusServerIPAddrThis object specifies the IP Address of the TACACS+ serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.20.4.1.2 |
enableTacacsPlusAuthorizationTo enable TACACS Plus authorizationrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.20.5 |
ipV6ConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.21 |
ipV6TrafficHandlingThis object can be used to specify how the IPv6 traffic is handled on all ports of a sensor.
dont-parse-block-inline - Traffic will not be subjected to IPS/IDS. On Inline ports, traffic will be blocked.
dont-parse-allow-inline - Traffic will not be subjected to IPS/IDS. On Inline ports , traffic wll be allowed to go through the sensor.
parse-and-detect-attacks - Parse and detect attacks in IPv6 traffic and pass the traffic on inline ports
Default: dont-parse-allow-inline(2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.21.2 |
hostQGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.22 |
hostQConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.22.1 |
hostQFilterTimeOutThe number of minutes for which this entry should be in
affect.
Default: 5 minutesrwobsolete INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.1.1 |
hostQDeleteAllFiltersIf set to not-applicable(0), applied filters are not
deleted. If set to true (1) all filters are deleted.
Default: not-applicable (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.1.2 |
hostQBulkFilterV4TableTable containing entries for filters that are applied on the \
sensor in Inline mode. This table supports only GET-NEXT operations SEQUENCE OF HostQBulkFilterV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.2 |
hostQBulkFilterV4EntryIndexed by sequence number. HostQBulkFilterV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.2.1 |
hostQBulkFilterIndexV4Index which uniquely identifies the V4 filter rulero INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.1 |
hostQBulkFilterSrcIPAddrV4Source IPV4 Address.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.2 |
hostQBulkFilterVidsIdV4This objects returns the vids id for which this filter
was applied.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.3 |
hostQBulkFilterAttackIdV4This objects returns the attack id for which this filter
was applied.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.4 |
hostQBulkFilterEndTimeV4This objects returns the filter expiry time in UTC formatro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.5 |
hostQBulkFilterQRStatusV4This objects returns the host quarantine and remediation action status.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.6 |
hostQBulkFilterMPEReplyMsgV4This objects returns the message returned by the MPE server.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.7 |
hostQBulkFilterMonPortIdV4This objects returns the monitoring linear port index on which the attack was detected for
the quarantined host.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.8 |
hostQBulkFilterEZIdV4This objects returns the applied NAZ Id for the quarantined host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.2.1.9 |
hostQBulkFilterV6TableTable containing entries for IPv6 filters that are applied on the
sensor in Inline mode. SEQUENCE OF HostQBulkFilterV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.3 |
hostQBulkFilterV6EntryIndexed by sequence number. HostQBulkFilterV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.3.1 |
hostQBulkFilterIndexV6Index which uniquely identifies the IPv6 filter rule.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.1 |
hostQBulkFilterSrcIPAddrV6Source IPV6 Address.ro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.2 |
hostQBulkFilterVidsIdV6This objects returns the vids id for which this filter
was applied.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.3 |
hostQBulkFilterAttackIdV6This objects returns the attack id for which this filter
was applied.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.4 |
hostQBulkFilterEndTimeV6This objects returns the filter expiry time in UTC format.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.5 |
hostQBulkFilterQRStatusV6This objects returns the host quarantine and remediation action status.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.6 |
hostQBulkFilterMPEReplyMsgV6This objects returns the message returned by the MPE server.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.7 |
hostQBulkFilterMonPortIdV6This objects returns the monitoring linear port index on which the attack was detected for
the quarantined Ipv6 host.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.3.1.8 |
hostQNeverDenyV4TableTable defines ipaddresses from which traffic is never
blocked. Typically user will add all the critical network
elements like routers, servers, etc.obsolete SEQUENCE OF HostQNeverDenyV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.4 |
hostQNeverDenyV4EntryIndexed by hostQNeverDenyIpAddress. Supports up to 100 entries.obsolete HostQNeverDenyV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.4.1 |
hostQNeverDenyIpAddressV4The ipV4 address from which traffic will never be blocked.obsolete IpAddress .1.3.6.1.4.1.8962.2.1.2.1.22.4.1.1 |
hostQNeverDenyActionV4This object is to user to add and delete rows in to the
table.rwobsolete RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.4.1.2 |
hostQNeverDenyV6TableTable defines ipaddresses from which traffic is never
blocked. Typically user will add all the critical network
elements like routers, servers, etc.obsolete SEQUENCE OF HostQNeverDenyV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.5 |
hostQNeverDenyV6EntryIndexed by hostQNeverDenyIpAddress. Supports up to 100 entries.obsolete HostQNeverDenyV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.5.1 |
hostQNeverDenyIpAddressV6The ipV6 address from which traffic will never be blocked.obsolete Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.5.1.1 |
hostQNeverDenyActionV6This object is to user to add and delete rows in to the
table.rwobsolete RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.5.1.2 |
hostQUserDefFilterV4TableTable is used to add/delete/extend IPv4 filters on the sensor SEQUENCE OF HostQUserDefFilterV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.6 |
hostQUserDefFilterV4Entry HostQUserDefFilterV4Entry .1.3.6.1.4.1.8962.2.1.2.1.22.6.1 |
hostQUserDefFilterSrcIpV4Source IPV4 address. IpAddress .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.1 |
hostQUserDefFilterVidsIdV4Vids ID. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.2 |
hostQUserDefFilterAttackIdV4Attack ID. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.3 |
hostQUserDefFilterDurationV4Filter durationrw Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.4 |
hostQUserDefFilterActionV4Setting this object to add(1) will add the entry.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.5 |
hostQUserDefFilterRemediationV4Setting this object to TRUE, will enable host rememdiation for the user defined quarantine rule.
Default : FALSErw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.6.1.6 |
hostQUserDefFilterV6TableTable is used to add/delete/extend IPv6 filters on the sensor SEQUENCE OF HostQUserDefFilterV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.7 |
hostQUserDefFilterV6Entry HostQUserDefFilterV6Entry .1.3.6.1.4.1.8962.2.1.2.1.22.7.1 |
hostQUserDefFilterSrcIpV6Source IPV6 address. Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.22.7.1.1 |
hostQUserDefFilterVidsIdV6Vids ID. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.7.1.2 |
hostQUserDefFilterAttackIdV6Attack ID. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.22.7.1.3 |
hostQUserDefFilterDurationV6Filter durationrw Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.22.7.1.4 |
hostQUserDefFilterActionV6Setting this object to add(1) will add the entry.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.22.7.1.5 |
nmsGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.23 |
nmsUserGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.23.1 |
nmsUserTable SEQUENCE OF NMSUserEntry .1.3.6.1.4.1.8962.2.1.2.1.23.1.1 |
nmsUserEntryEach entry specified is indexed by <nmsUserIndex>.
Additonaly it contains the NMSUserEntry .1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1 |
nmsUserNameUserName nms (in this entry). DisplayString .1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.1 |
nmsAuthKeyNMS Auth Keyrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.2 |
nmsEncrKeyNMS Encryption Key.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.3 |
nmsUserChangeActionThis object used for user to add and delete rows in to the tablerw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.4 |
nmsDeleteAllUsersThis action object deletes all user entries in the nmsUserTable.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.23.1.2 |
nmsCommitUserEntryChangesThis action object commits all the changes made to the user entries in the nmsUserTable.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.23.1.3 |
nmsIpGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.23.2 |
nmsIpTable SEQUENCE OF NMSIpEntry .1.3.6.1.4.1.8962.2.1.2.1.23.2.1 |
nmsIpEntryEach entry specified is indexed by <nmsIpIndex>.
Additonaly it contains the NMSIpEntry .1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1 |
nmsIpAddressUserName nms (in this entry). IpAddress .1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1.1 |
nmsIpChangeActionThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1.2 |
nmsIpv6Table SEQUENCE OF NMSIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.23.2.2 |
nmsIpv6EntryEach entry specified is indexed by <nmsIpv6Index>. NMSIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1 |
nmsIpv6AddressIPv6 address of the system having SNMP access to the sensor Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1.1 |
nmsIpv6ChangeActionThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1.2 |
mpeGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.24 |
mpeConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.24.1 |
mpeQRScopeThis object describes about the MPE Quarantine and Remediation scope.
The value 'unmanaged-hosts', indicates that the MPE interface port based
quarantine and remediation action is applicable only to the MPE server's
unmanaged host and the value 'all-hosts' indicate that the MPE interface
port based qarantine and remediation action is applicable to all the hosts,
independent of MPE server.
Default: unmanaged-hosts(1)rwobsolete Enumeration .1.3.6.1.4.1.8962.2.1.2.1.24.1.1 |
mpeThrottleTimeoutThis depicts the MPE throttling timeout in seconds.
Default: 120rwobsolete INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.2 |
mpeInstallConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.24.1.3 |
mpeIpAddressThe ipaddress of the MPE serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.1 |
mpeAnonymousPortThe Anonymous SSL port on MPE server
Default: 8443rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.2 |
mpeTrustedSSLPortThe Trusted SSL port on MPE server
Default: 8444rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.3 |
mpeePOCredePO credentials in the form of username:passwordrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.4 |
mpeAnonymousURIURI of the MPE server which listens on Anonymous SSL portrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.5 |
mpeTrustedURIURI of the MPE server which listens on Trusted SSL portrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.6 |
mpeInstallConfigActionThis object describes about the possible MPE Install configuration actions.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.7 |
mpeInstallConfigStatusThis describes the possible MPE install configuration states.
Default : deinstalled (4)ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.24.1.3.8 |
mpeRootCertStatusThis object informs whether the MPE Root Certificate file is present on the sensor.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.24.1.4 |
mpeDeleteRootCertThis object is used to remove the MPE Root Certificate from the sensor. Deletion of the
MPE root certificate succeeds only when the MPE is not yet installed.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.24.1.5 |
mnacHealthLevelListenPortThis object is used to configure/retrieve the trusted health level message listen port
on the sensor, on which MNAC communication happens asynchronously.
Default: 8445rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.6 |
mnacConnectivityFailureTimeoutThis object is used to configure/retrieve the MNAC connectivity failure in seconds.
Default: 32rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.7 |
mnacAgentGUIDPortThis object is used to configure/retrieve the agent GUID request listen port on the
MNAC Agent, to which the intrushield sensor would send the agent GUID request.
Default: 8444rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.24.1.8 |
mpeExcludedMacTableobsolete SEQUENCE OF MPEExcludedMacEntry .1.3.6.1.4.1.8962.2.1.2.1.24.2 |
mpeExcludedMacEntryEach entry specified is indexed by MAC Adress.obsolete MPEExcludedMacEntry .1.3.6.1.4.1.8962.2.1.2.1.24.2.1 |
mpeMacAddressMac address to be excluded from Mpe processing (Floater Mac)obsolete MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.24.2.1.1 |
mpeMacChangeActionThis object used for user to add and delete rows in to the table.rwobsolete RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.24.2.1.2 |
remediationGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.25 |
remediationConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.25.1 |
remediationTimeoutTime in minutes for which the hosts needs to be quarantined so that it can be remediated.
Default: 30rwobsolete INTEGER .1.3.6.1.4.1.8962.2.1.2.1.25.1.2 |
ezLogAlertGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.26 |
ezAlertLoggingThis object specifies various ways to enable EZ(enforcement zone) alert logging or disable it altogether.
This is applicable on a sensor wide basis for all ports in inline mode.
Default: disable (5)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.26.1 |
ezAlertThrottleMaxIpPairOnce this threshold is exceeded, sensor will only send one
summary ez alert for all addresses (srcip's and destip's) that
match the aclid/vidsid.
Default: 10rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.26.2 |
ezAlertThrottleIntervalThis object specifies the enforcement zone alert throttle interval.
Default: 120 secondsrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.26.3 |
ezAlertThrottleActionThis object can be used to enable and disable ez alert throttling.
Default: enable(1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.26.4 |
ezAlertThrottleThresholdThis object is used to configure the number of alerts that
need to be sent before sensor starts to throttle the ez alerts.
For example if this value is 10, it will send the first 10
ez alerts with the following key: aclid/vidsid/srcip/destip.
This parameters will use the ezAlertThrottleInterval as the
interval.
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.26.5 |
ezAlertDirectToSyslogThis object can be used to enable sending EZ logs directly to syslog viewer instead of sending it via NSM.
Default: sendViaNSM (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.26.6 |
nbadGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.27 |
nbadConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.27.1 |
nbadSensorIpAddressThe ipaddress of the NBAD server to which all the collected flowrecords would be sent.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.27.1.1 |
nbadSensorPortThe port on which the NBAD server is listening for flow records.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.27.1.2 |
nbadIPSPriMonPortIdThis object contains the primary IPS monitoring linear port index to be used
to send flow records to the NBAD sensor.rw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.27.1.3 |
nbadIPSSecMonPortIdThis object contains the secondary IPS monitoring linear port index to be used
to send flow records to the NBAD sensor. This monitoring port would be used
only when the configured primary monitoring port cannot be utilised to send
the flow records to the NBAD sensor.rw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.27.1.4 |
nbadAppFingerPrintingEnabledThis object value if set to TRUE indicates that application finger printing is enabled.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.27.1.5 |
nbadOSFingerPrintingEnabledThis object value if set to TRUE indicates that OS finger printing is enabled.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.27.1.6 |
nbadSslFlowDataCaptureEnabledThis object value if set to TRUE indicates that ssl flow data capture is enabled.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.27.1.7 |
nbadFlowProtocolIdThis object value set indicates the protocol type of the exported flow records.
Default: netflow (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.27.1.8 |
nbadFlowProtocolVersionThis object value set indicates the protocol version of the exported flow records.
Default: netFlowVersion9 (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.27.1.9 |
nbadCaptureTCPThis object value set indicates whether netflow capture for TCP flows is enabled or not.
Default: enable (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.27.1.10 |
nbadCaptureUDPThis object value set indicates whether netflow capture for UDP flows is enabled or not.
Default: enable (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.27.1.11 |
nbadCaptureICMPThis object value set indicates whether netflow capture for ICMP flows is enabled or not.
Default: disable (2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.27.1.12 |
hostDataGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.28 |
hostDataTableTable containing entries for each discovered host. (indexed via hostDataIndex)
This table contains Trellix specific MIB objects. SEQUENCE OF HostDataEntry .1.3.6.1.4.1.8962.2.1.2.1.28.1 |
hostDataEntryThis MIB object contains all the columnar objects,
that describe the contents of each discovered host.
Indexed by hostDataIndex HostDataEntry .1.3.6.1.4.1.8962.2.1.2.1.28.1.1 |
hostDataIndexThe index of the Host Data Entryro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.1 |
hostIPAddressThe ipaddress of the detected host.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.2 |
hostMacAddressThe MAC address of the detected host.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.3 |
hostDetectedDHCPMonPortIdThe monitoring interface linear port index over which the host was detected in DHCP mode.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.4 |
hostNameThe name of the detected host.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.5 |
hostUpdatedTimeStampThe time of the host getting updated last. This would be zero intilially
at the time of host getting detected.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.6 |
hostAgentGuidThe agent GUID of the detected host.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.7 |
hostNACStatusThe detected host NAC status.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.8 |
hostStateThe state of the detected host entry.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.9 |
hostDeploymentModeThe deployment mode of the detected host.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.10 |
hostHealthLevelThe health level of the detected host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.11 |
hostEZIdThe applied enforcement zone id for the detected host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.12 |
hostUserNameThe IBAC username of the detected host.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.13 |
hostPolicyIdThe IBAC policy id of the detected host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.14 |
hostDetectedTimeStampThe time of the host getting detected.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.15 |
hostOSInfoThe Operation system information of the detected host.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.16 |
hostMNACAgentOSInfoThe OS information of the detected host provided by the MNAC agent.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.17 |
hostActiveIndicates whether the host is Active or not. If set to true, it indicates the host is activero TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.18 |
hostDetectedStdMonPortIdThe monitoring interface linear port index over which the host was detected in Standard mode.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.19 |
hostDetectionTypeThe detection type of the detected host. For OOB cases, this includes the discovery mechanism as well.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.20 |
hostUserAuthProtocolAuthentication type of the logged in IBAC user.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.21 |
hostSwitchIdSwitch instance ID on which host was detected in OOB mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.22 |
hostSwitchPortIdSwitch port ID on which host was detected in OOB modero INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.23 |
hostSwitchPortGroupIdSwitch port group ID on which host was detected in OOB modero INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.24 |
hostQuarantineVlanIdQuarantine VLAN Id corresponding to the host which was detected in OOB mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.25 |
hostProductionVlanIdProduction VLAN Id corresponding to the host which was detected in OOB mode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.26 |
nasIpAddressThe Network Server Access Ipaddress of the switch where the host is connecting to.ro IpAddress .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.27 |
nasGroupObjectIdFlexible policy Network Server Access Group Object Id for the host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.28 |
userGroupObjectIdFlexible policy User Group Object Id for the host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.29 |
deviceProfileStringThe device profile string provided by the third party device profiling ldap server for the host.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.30 |
hostOperationalModeThis object indicates the operational mode for the host.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.31 |
hostEnforcementActionThis object indicates the kind of enforcement done for the host.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.32 |
flexiblePolicyRuleIdThis indicates the flexible policy rule for the host.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.1.1.33 |
hostConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.28.2 |
hostEntryAttributeHost entry attribute to be considered for config action.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.2.1 |
hostEntryIpAddressHost entry Ip address to be considered for config action.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.28.2.2 |
hostEntryMacHost entry Mac address to be considered for config action.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.2.3 |
hostEntryConfigHost entry config action.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.28.2.4 |
hostEntryEZIdEZ-ID to be considered for modifying the NAZ of the given host entry.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.28.2.5 |
hostDataAvailabilityStatusThis object indicates the availability of the hostData through SNMP. This information
is useful immediately after the sensor reboot, as the Host Data even if
present on the sensor would be available through SNMP only after the
system health becomes GOOD, as the host data would be initialised only
during the initial sigfile processing.
True: Host Data available after the sensor initialisation or no persisted hostdata.
False: In other scenarios.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.28.3 |
sgapGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.29 |
sgapConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.29.1 |
sgapAuthTimeoutAuthentication channel timeout in seconds.
Default: 30rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.29.1.1 |
sgapCSRConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.29.1.2 |
sgapCSRCountryNameCountry name for generating the CSR. Use the two-letter code
without punctuation for country like US or CA.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.1 |
sgapCSRStateProvinceState or Province name for generating the CSR. Spell out the
state completely.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.2 |
sgapCSRLocalityCity or town name for generating the CSR.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.3 |
sgapCSRCompanyCompany name for generating the CSR. If the company name has
symbols, spell out the symbol or omit it to enroll.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.4 |
sgapCSROrganizationalUnitThe organizational unit is the name of the department or organization unit
making the request. This is an optional fieldrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.5 |
sgapCSRCommonNameThe common name is the host plus domain name. It looks like
www.company.com or company.com.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.6 |
sgapCSRGenerateActionThis action is used to generate the CSR/self signed certificate.
Default : other (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.7 |
sgapCSRGenerateStatusThis object describes the possible CSR generation states.
Default : other (0)ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.29.1.2.8 |
sgapCertStatusThis object indicates the sgap cert status on the sensor.
Default: 0ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.29.1.3 |
alarmAndTrendsGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.30 |
sensorPerfAlertGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.30.1 |
sensorPerfAlertEnableThis object is used to enable/disable generation of sensor performance alerts,
for the purpose of historical trends.
Default: false(2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.30.1.1 |
sensorPerfAlertDurationThis object is used to configure the duration of sensor performance alerts in minutes,
for the purpose of historical trends.
Default: 5rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.30.1.2 |
sensorPerfAlertParametersThis object is used to configure the parameters of sensor performance alerts,
for the purpose of historical trends. The parameter bit positions are as given below.
msb-bit(1) : cpu-utilization,
msb-bit(2) : tcpudp-flows,
msb-bit(3) : sensor-throughput,
msb-bit(4) : mon-port-data-rate,
msb-bit(5) : reserved
msb-bit(6) : reserved
msb-bit(7) : system-memory,
msb-bit(8) : packet-buffers,
msb-bit(9) : decrypted-ssl-flowsrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.30.1.3 |
alarmConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.30.2 |
alarmStatusThis object is used to enable/disable generation of threshold based alarms.
Default: false(2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.30.2.1 |
alarmDeleteAllEntriesThis object is used to delete all alarm entries in a single operation.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.30.2.2 |
alarmDurationThis object indicates the duration in minutes, at which the sensor needs to perform
threshold checks and if required generate the specific alarm.
Default : 1rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.30.2.3 |
alarmTableTable containing entries for configured threshold based alarms. (indexed via alarmIndex)
This table contains Trellix specific MIB objects. SEQUENCE OF AlarmEntry .1.3.6.1.4.1.8962.2.1.2.1.30.2.4 |
alarmEntryThis MIB object contains all the columnar objects,
that describe the contents of each threshold based alarm.
Indexed by alarmIndex AlarmEntry .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1 |
alarmIndexThe index of the threshold based alarm entry INTEGER .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.1 |
alarmSampleTypeThis object indicates the alarm sample type for which the sensor needs to generate alarms
based on alarm threshold settings. The threshold value range vary based on the sample types :
cpu-utilization-abs : 0 - 100,
tcpudp-flows : 0 - 100,
sensor-throughput-delta : 0 - 100,
mon-port-throughput-delta : 0 - 100,
l2-error-drop-delta : 0 - 4294967295,
l3-l4-error-drop-delta : 0 - 4294967295,
system-memory : 0 - 100,
packet-buffers : 0 - 100,
decrypted-ssl-flows : 0 - 100rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.2 |
alarmSampleTypeIndexBitmapThis object provides the index bit map for the alarm sample type id. The bit
setting would be similar to the BITS type and in network order. The bitmap would be as
given below :
cpu-utilization-abs - 0,
sensor-throughput-delta - 0,
mon-port-throughput-delta - Bit position indicates the <linear portIndex>
sensor-l2-error-drop-delta - 0,
sensor-l3-l4-error-drop-delta - 0rw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.3 |
alarmSampleTypeDescThis object provides the alarm sample type description such as 'lower-band', 'higher-band', etc.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.4 |
alarmRaisingThresholdThis object indicates the raising threshold value. The sensor would generate raising
threshold alarm when the sample type counter exceeds this value.rw Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.5 |
alarmFallingThresholdThis object indicates the falling threshold value. The sensor would generate falling
threshold alarm when the sample type counter reduces below this value.rw Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.6 |
alarmStartupTypeThis object indicates the first alarm type that the sensor must generate before
generating the other threshold based alarm. For eg; if the value is set to 'raising (1)',
then the sensor has to first raise an alarm based on raising threshold value and only
then based on falling threshold value.
Default : raising (1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.7 |
alarmEntryStatusThis object is used to create a new threshold based alarm.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.8 |
bwSavingStatusThis object is used to enable/disable bandwidth saving.
Default: false(2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.30.2.5 |
oobnacGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.31 |
oobnacSwDiscoveryGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.31.1 |
swInstanceTableTable containing entries for each switch instance(indexed via switch id). SEQUENCE OF SwInstanceEntry .1.3.6.1.4.1.8962.2.1.2.1.31.1.1 |
swInstanceEntryThis MIB object contains all the attributes that are specific to the switch instance. Indexed by swIdIndex SwInstanceEntry .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1 |
swIdIndexThe index INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.1 |
swDetDescDescription returned by the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.2 |
swProfileIdswitch profile id returned by the switch.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.3 |
swIPAddressIP address of the switch instance sent down from ISM when a new switch is being added.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.4 |
swIPV6AddressIPV6 address of the switch instance sent down from ISM when a new switch is being added.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.5 |
swNameSwitch name returned by the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.6 |
swDescSwitch name returned by the switch. This can be modified by ISM.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.7 |
swEnableOption to enable/disable the specific switch upon discovery. The default value is enable(1).rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.8 |
swSNMPsupportSupport for snmp communication between sensor and the switch.Currently the value always remains true.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.9 |
swSnmpVerSupportsnmp version supported by the switch. The default will be version 2.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.10 |
swREADCommunityStrString used for all read-only snmp data communication between sensor and the switch. The default string is public.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.11 |
swWRITECommunityStrString used for all read-write snmp data communication between sensor and the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.12 |
swTRAPCommunityStrcommunity string used for the all the traps received from the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.13 |
swSNMPPortsnmp port for snmp communication with the switch(161).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.14 |
swV3UserNameUser name for snmp v3 communication.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.15 |
swV3SecurityLevelLevel of security supported by the switch. The default value is authPriv(3).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.16 |
swV3AuthProtocolprotocol for authentication of the user. The default value is Md5(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.17 |
swV3AuthKeyKey for authentication of the user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.18 |
swV3EncrProtocolprotocol for encryption of snmp communication messages. The default value is DES(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.19 |
swV3EncrKeykey for encryting messages.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.20 |
swCLIsupportSupport for CLI communication between sensor and the switch.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.21 |
swCLINwProtocolsupport for a command line interfaces network protocol such as TELNET or ssh. Default value is telnet(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.22 |
swCLIUserNameuser name for CLI communication.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.23 |
swCLIPwdpassword to authenticate CLI user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.24 |
swCLIEnablePwdEnable password to authenticate CLI user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.25 |
swCLIAutoSaveConfigIf this option is enabled then auto save CLI configuration changes to flash.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.26 |
swRadiusSupportSupport for radius communication between sensor and the switch. The default value is enable(1).rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.27 |
swRadiusSharedSecretA case-sensitive text string used to validate communications between two radius devices.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.28 |
swPlaceHolderVlanspecial vlan value used for assigning qvlan value to an empty port.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.29 |
swUseDefaultQVlanPoolOption to use globally set qvlan pool range.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.30 |
swQVlanPoolRangeQvlan pool range assigned for the switch instance.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.31 |
swDiscoverActionThis action data will add a switch entry in the table. Default action is createAndGo(4).rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.32 |
swCLILoginTypeDifferent login types supported for CLI.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.33 |
swAuthMacAddRadSrvOptionSupport for option to authenticate MAC addresses against radius server.Default option is to disabled(0).rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.34 |
swActionStatusVariable to poll the status of the switch(in case sw goes down).ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.35 |
swPortDefaultVlanVariable used for updating port default vlan for universal control point (UCP)switches. For non-ucp switches the value will default to zero.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.36 |
swActionStatusTimeTime when swActionStatus variable was updated.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.37 |
swIpAddressIP address of the switch instance sent down from ISM when a new switch is being added.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.31.1.2 |
swIpV6AddressIPV6 address of the switch instance sent down from ISM when a new switch is being added.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.1.3 |
readCommunityStringThis string is used for all read-only snmp data communication between sensor and the switch. The default string is public.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.4 |
snmpPortThe default port on which snmp runs(161).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.5 |
snmpVerSupportsnmp version supported by the switch. The default will be version 2.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.6 |
writeCommunityStrString used for all read-write snmp data communication between sensor and the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.7 |
trapCommunityStrcommunity string used for the all the traps received from the switch.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.8 |
v3UserNameUser name for snmp v3 communication.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.9 |
v3SecurityLevelLevel of security supported by the switch. The default value is authPriv(3).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.10 |
v3AuthProtocolprotocol for authentication of the user. The default value is Md5(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.11 |
v3AuthKeyKey for authentication of the user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.12 |
v3EncrProtocolprotocol for encryption of snmp communication messages. The default value is DES(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.13 |
v3EncrKeykey for encryting messages.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.14 |
cliNwProtocolsupport for a command line interfaces network protocol such as TELNET or ssh. Default value is telnet(1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.15 |
cliUserNameuser name for CLI communication.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.16 |
cliPwdpassword to authenticate CLI user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.17 |
cliEnablePwdEnable password to authenticate CLI user.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.1.18 |
swQueryActionaction to get preliminary data (like sys uptime, sys description etc) from the switch. also to test cli and snmp.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.19 |
cliLoginTypeDifferent login types supported for CLI.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.1.20 |
profileIdswitch profile id returned by the switch.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.21 |
switchIdThe sw global id used to re-learn the switch.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.1.22 |
oobnacAllSwitchesGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.31.2 |
oobnDefaultQvlanPooldefault qvlan pool range assigned for the all switches using default qvlan pool.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.31.2.1 |
oobnacRadNumRetriesThe default number of retries(3) allowed for radius users.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.2.2 |
oobnacRadRespTimeOutThe default timeout value(3 seconds) for radius response timeout.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.2.3 |
oobnacFailoverGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.31.3 |
oobnacFloatingIpAddressFloating Management Port IP Address.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.31.3.1 |
oobnacFloatingIpv6AddressFloating Management Port IPv6 Address.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.3.2 |
oobnacFloatingNetMaskFloating Management Port Network mask as a IPAddress prefix.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.3.3 |
oobnacFloatingv6NetMaskFloating Management Port IPv6 Network mask as a IPAddress prefix.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.31.3.4 |
oobnacFloatingGatewayIpAddressFloating Management Port Gateway IP Address.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.31.3.5 |
oobnacFloatingGatewayIpv6AddressFloating Management Port Gateway IP Address.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.3.6 |
oobnacPeerIpAddressFailover Peer Management Port IP Address.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.31.3.7 |
oobnacPeerIpv6AddressFailover Peer Management Port IPv6 Address.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.31.3.8 |
oobnacFailoverSensorStatusStatus of the sensor in OOBNac failover.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.31.3.9 |
malwareGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.32 |
malwarePriDNSServerIpIP address of the primary DNS server.rwobsolete IpAddress .1.3.6.1.4.1.8962.2.1.2.1.32.1 |
malwareSecDNSServerIpIP address of the secondary DNS server.rwobsolete IpAddress .1.3.6.1.4.1.8962.2.1.2.1.32.2 |
malwarePriDNSServerIpV6IPV6 address of the primary DNS server.rwobsolete Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.32.3 |
malwareSecDNSServerIpV6IPV6 address of the secondary DNS server.rwobsolete Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.32.4 |
malwareRiskLevelMalware risk level threshold value set by the user. The default level is Very Low.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.32.5 |
malwareArtemisDetectionModeartemis configuration to do either of the settings
Alert only,
Alert and Block or
Alert, Block and TCP-Reset.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.32.6 |
malwareUDFDetectionModeuser-defined configuration to do either of the settings
Alert only,
Alert and Block or
Alert, Block and TCP-Reset.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.32.7 |
gamEngSensorCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.32.8 |
gamEngSensorAutoUpdateConfigEnable / disable the Sensor auto update config.
Default : True (Enable)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.32.8.1 |
gamEngSensorAutoUpdateIntervalSets the Sensor auto update Interval in minutes.
Default : 90rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.32.8.2 |
gamEngVerProvides the current gam engine version available on sensor.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.32.8.3 |
gamDatVerProvides the current gam dat version available on sensor.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.32.8.4 |
avEngVerProvides the current AV engine version available on sensor.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.32.8.5 |
avDatVerProvides the current AV dat version available on sensor.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.32.8.6 |
gamEngUpdatedTimeProvides the time in UTC format when sensor had updated GAM engine successfully.ro Unsigned32 .1.3.6.1.4.1.8962.2.1.2.1.32.8.7 |
gamManualFullUpdateFileUploadStatusProvides the current file upload status.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.32.8.8 |
miscCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.33 |
jumboframeParsingConfigConfiguration option to enable/disable jumboframe parsing.
The new setting would be effective only after a sensor reboot.
Default: disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.33.1 |
currentJumboframeParsingStatusThe current running jumboframe parsing status.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.33.2 |
appIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled for the sensor.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.3 |
hitlessRebootStatusStatus option to read whether hitless reboot is possible or not at this time.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.33.4 |
existingGeoDBFilenameThis specifies the name of geo database file present in sensor. NULL would be returned
when there is no geo DB file on the sensor.ro OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.33.5 |
nsmTrackUserLoggingStatusConfiguration option to enable/disable NSM audit logging.
Default: disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.33.6 |
accelerateFTPInboundConfigConfiguration option to enable/disable accelerate ftp in inbound direction
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.7 |
accelerateFTPOutboundConfigConfiguration option to enable/disable accelerate ftp in outbound direction.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.8 |
parseTunnellingConfigConfiguration option to enable/disable parsing of tunnelled packet.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.9 |
prev256ByteLoggingConfigConfiguration option to enable/disable prev 256 byte logging.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.10 |
cliAuditLoggingConfigConfiguration option to enable/disable cli audit logging through SNMP.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.11 |
snortRuleEngineConfigConfiguration option to switch snort rule engine between traditional and next generation.
The new setting would be effective only after a sensor reboot.
Default: traditionalrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.33.12 |
currentSnortRuleEngineStatusThe current running snort rule engine on sensor.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.33.13 |
insightsTelemetryConfigConfiguration option to enable/disable usage of configured telemetry data for Insightsrw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.33.14 |
layer2FwdGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.34 |
layer2FwdCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.34.1 |
layer2FwdTypeDifferent modes for using layer2 forward feature.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.34.1.1 |
layer2IntfPortThe intf linear port index of the sensor for the mode chosen.rw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.34.1.2 |
layer2FwdActionAction to take for the specified port(s).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.34.1.3 |
layer2FwdBeginIdStart port id(range 1-65535) for the mode selected(tcp/udp/vlan).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.1.4 |
layer2FwdEndIdEnd port id(range 1-65535) for the mode selected(tcp/udp/vlan).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.1.5 |
layer2FwdConfigLayer2 forward configuration to enable or disable this feature. Each bit represents the
layer2 forward type. From the LSB the 1st bit for TCP, 2nd bit for UDP, 3rd bit for VLAN.
Default will be 7, indicating this feature is enablerw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.1.6 |
layer2FwdTCPTableTable containing TCP port ranges configured for L2 forwarding.(indexed via intf port number and entry number). SEQUENCE OF Layer2FwdTCPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.2 |
layer2FwdTCPEntryThis MIB object contains all the attributes that are specific to the L2 fwd entry for TCP table. Indexed by intfPortLinearIndex and entry number. Layer2FwdTCPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.2.1 |
tcpIntfPortIndexThe intfPort linear index TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.34.2.1.1 |
tcpEntryIndexThe index INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.2.1.2 |
tcpPortRangerange for which L2 forwarding feature is enabled.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.34.2.1.3 |
layer2FwdUDPTableTable containing UDP port ranges configured for L2 forwarding.(indexed via intfPortIndex and entry number). SEQUENCE OF Layer2FwdUDPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.3 |
layer2FwdUDPEntryThis MIB object contains all the attributes that are specific to the L2 fwd entry for UDP table. Indexed by intfPortLinearIndex and entry number. Layer2FwdUDPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.3.1 |
udpIntfPortIndexThe intfPort linear index TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.34.3.1.1 |
udpEntryIndexThe index INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.3.1.2 |
udpPortRangerange for which L2 forwarding feature is enabled.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.34.3.1.3 |
layer2FwdVLANTableTable containing VLAN port ranges configured for L2 forwarding.(indexed via interface number and entry number). SEQUENCE OF Layer2FwdVLANEntry .1.3.6.1.4.1.8962.2.1.2.1.34.4 |
layer2FwdVLANEntryThis MIB object contains all the attributes that are specific to the
L2 fwd entry for VLAN table(indexed via intfPortLinearIndex and entry number). Layer2FwdVLANEntry .1.3.6.1.4.1.8962.2.1.2.1.34.4.1 |
vlanIntfPortIndexThe intfPort linear index TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.34.4.1.1 |
vlanEntryIndexThe entry index INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.4.1.2 |
vlanPortRangerange for which L2 forwarding feature is enabled. Maximum vlan range supported on each interface is 4k.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.34.4.1.3 |
layer2FwdIPTableTable containing IP protocol ranges configured for L2 forwarding.(indexed via intfPortIndex and entry number). SEQUENCE OF Layer2FwdIPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.5 |
layer2FwdIPEntryThis MIB object contains all the attributes that are specific to the L2 fwd. entry for IP table. Indexed by intfPortLinearIndex and entry number. Layer2FwdIPEntry .1.3.6.1.4.1.8962.2.1.2.1.34.5.1 |
ipIntfPortIndexThe intfPort linear index TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.34.5.1.1 |
ipEntryIndexThe index INTEGER .1.3.6.1.4.1.8962.2.1.2.1.34.5.1.2 |
ipPortRangerange for which L2 forwarding feature is enabled.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.34.5.1.3 |
pktCapCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.35 |
pktCapModeOption to select packet capture Mode.
File mode is not supported in 6.x release.
Default: disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.1 |
pktCapDurationThe duration for which capture will be enabled..
Units are in seconds. Default: 120 seconds
duration value 0 indicate indefinite capture till the capture
is stopped.
Default: 120rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.35.2 |
pktCapPmSpanPortForCaptureSpan linear port index for the capture:
ISM also needs to verify that port should be configured
as Span port.
Applicable only for port mode capture. Zero indicates no port assigned.
Default: 0rw TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.35.3 |
pktCapFmLocationThis will determine whether capture file is to be uploaded to manager, tftpServer or ScpServer.
Note :Applicable only for file mode capture
Default: managerrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.4 |
pktCapFmMaxSizeThe size of the maximum capture file.
It will be configurable but to the maximum value
of sensor define limit.
Default: 100 MB for M8000, M6050, M4050, M3050
58 MB for N450, Wilson
40 MB for Eagle, Diablo
Note :Applicable only for file mode capturerw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.35.5 |
pktCapFmFUServerAddressFile Upload server IPv4 / IPv6 address.
Note :Applicable only for file mode capturerw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.35.6 |
pktCapFmFUFileNameThis specifies the name of the file with the source path on the file upload server.
This is optional. If not set, the filename used will be of the format
'%DEVICE_NAME%-PacketCapture-%TimeStamp%.
Note :Applicable only for file mode capturerw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.35.7 |
pktCapFmFUSettingThis option will determine whether user needs to
initiate the file upload or it will be done automatically.
Default: automatic
Note :Applicable only for file mode capturerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.8 |
pktCapFilterFileNamePacket Capture Filter File Name send by NSM using secure TFTP channelro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.35.9 |
pktCapFilterFileTimeStampPacket Capture FilterFile creationTimeStampro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.35.10 |
pktCapCommandGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.35.11 |
pktCapCmdOption to start/stop packet capture feature and also
to delete filter file.
Default: stoprw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.1 |
pktCapStatusOption to access packet capture Status.
Default: idlero Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.2 |
packetCaptureFmFUControlOption to control manual upload of the file.
Note :Applicable only for file mode capture
Default: stoprw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.3 |
packetCaptureFmFileStatusPacket Capture File status.
Note :Applicable only for file mode capture
Default : fileUploadNotStartedro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.4 |
packetCaptureFmTestOption to test packet capture file upload function.
Note :Applicable only for file mode capture
Default: stoprw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.5 |
packetCaptureFmTestStatusPacket Capture File upload test status.
Note :Applicable only for file mode capture
Default : resultNotValidro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.35.11.6 |
pktCapFmSCPUserNameSCP Server Username.
Note :Applicable only for file mode capture and upload method is SCPrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.35.12 |
pktCapFmSCPPasswordSCP Server Password.
Note :Applicable only for file mode capture and upload method is SCPrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.35.13 |
dnsCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.36 |
priDNSServerIpIP address of the primary DNS server.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.36.1 |
secDNSServerIpIP address of the secondary DNS server.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.36.2 |
priDNSServerIpV6IPV6 address of the primary DNS server.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.36.3 |
secDNSServerIpV6IPV6 address of the secondary DNS server.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.36.4 |
dnsSearchListThis specifies the space separated list of search suffix for DNS lookuprw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.36.5 |
layer7DCapConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.37 |
layer7DCapPercentageOfFlowsThis object specifies percentage of flows allocated for L7 Dcap when
layer7 DCap feature is enabled.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.37.1 |
layer7DCapBuffSizeThis object specifies the size of the buffer to be captured when L7 Dap feature is enabled .
. Default: 1500rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.37.2 |
layer7DCapMaxSupportedFlowsThis object specifies maximum number of flows supported for L7 Dcap when L7 Dap feature is enabled .ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.37.3 |
interfacePhysicalPortGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.38 |
intfPhysicalPortTableTable containing entries for each interface physical port (indexed via intfPhysicalPortIndex)
on each sensor card (indexed via appropriate slotIndex).
This table contains Trellix specific configuration objects.
Tables that contain MIB objects borrowed from MIB-II are in the
TRELLIX-SENSOR-PERF-MIB. SEQUENCE OF IntfPhysicalPortEntry .1.3.6.1.4.1.8962.2.1.2.1.38.1 |
intfPhysicalPortEntryThis MIB object contains all the columnar objects,
that describe the contents of each interface physical port on each IntruShield sensor card.
Indexed by slotIndex/intfPhysicalPortIndex IntfPhysicalPortEntry .1.3.6.1.4.1.8962.2.1.2.1.38.1.1 |
intfPhysicalPortIfDescrA textual string containing information about the interface.
Returns the string that is printed on the box.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.1 |
intfPhysicalPortIfTypeThe type of interface, distinguished according to the
physical/link protocol(s) immediately 'below' the network
layer in the protocol stack.
For brevity, Trellix options are as specified by the TC,
TrellixIDSPortType.
However, the SNMP MIB-II - Interfaces MIB specifies many more
valid options. See comments section for details.ro TrellixIDSPortType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.2 |
intfPhysicalPortIfAdminStatusThe desired state of the interface.
The testing(3) state indicates that no operational packets
can be passed.
Default: downrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.3 |
intfPhysicalPortIfOperStatusThe current operational state of the interface.
The testing(3) state indicates that no operational packets
can be passed.
Default: downro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.4 |
intfPhysicalPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one.
Otherwise as half-duplex.
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.5 |
intfPhysicalPortSpeedGet current speed/negotiation on the interface.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.6 |
intfPhysicalPortSpeedConfigSet desired speed/negotiation on the interface.
Default values are as follows:
I-Series -
fixed-hundred-Mbps (infinity/hichborn/2x00(1a-3b)
auto-gig-Mbps on 3000/4010/4000/2x00(4a,4b)
M-Series -
auto-ten-gig-Mbps on palomar/pyramid(1a-4b),auto-gig-Mbps(5a-8b)
Default: see aboverw TrellixPortSpeed -- was TrellixFEType, now deprecated .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.7 |
intfPhysicalPortIsMcafeeConnectorTrue: connector is not inserted.
True: connector is inserted in port and McAfee certified.
False: connector is inserted and not McAfee certified.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.8 |
intfPhysicalPortAllowAnyConnectorTrue: Permit usage of any connector for port.
False: Restrict usage to McAfee certified connector only.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.9 |
intfPhysicalPortCageTypePhysical connector cage type on sensor chassis panel.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.10 |
intfPhysicalPortGetMediaTypeGets the media of the connector present in the port cage. None (0) if cage is empty.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.11 |
intfPhysicalPortSetMediaTypeSets the media of the connector the user desired for the port.
Default: opticalrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.12 |
intfPhysicalPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.13 |
intfPhysicalPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.14 |
intfPhysicalPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.15 |
intfPhysicalPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation
to be sent to the NBAD server, is enabled over this monitoring port.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.16 |
intfPhysicalPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring
port is connected.rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.17 |
intfPhysicalPortLBSerialNumberThis MIB object indicates the manufacturer provided serial number of
the Load Balancer switch to which the sensor port is connected.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.18 |
intfPhysicalPortLBPortNumberThis MIB object returns the port number on the Load Balancer switch to
which the sensor port is connected.ro Integer32 .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.19 |
intfPhysicalPortConnectorTypePhysical connector type plugged into the port cage.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.20 |
intfPhysicalPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is
generated by the sensor appliance using the pair of slot index and the port index values.
The other MIB tables would directly use this linear index, whereever applicable.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.38.1.1.21 |
gtiConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.39 |
gtiProxyServerNameThe proxy server name is the domain name of the HTTP proxy
server in front of the sensor. It looks like www.company.com.
It can also be the IP address of the HTTP proxy server.
0.0.0.0 is the default valuerw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.1 |
gtiProxyPortTCP Port on which the HTTP proxy server is listening.
0 is the default valuerw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.39.2 |
gtiProxyUsernameThe username to be used to connect to the HTTP proxy server.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.3 |
gtiProxyPasswordThe password to be used to connect to the HTTP proxy server.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.4 |
gtiConfigPrivateCloudGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.39.5 |
gtiPrivateCloudServerIPAddressTypeIdentifies the type of GTI Private Cloud Server IP Address. If set to ip-v4, then the
gtiPrivateCloudServerIPv4Address object would be set else if this object is set to ip-v6, then
the gtiPrivateCloudServerIPv6Address object would be set.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.5.1 |
gtiPrivateCloudServerIPv4AddressThis object is used to configure the IPv4 address of the GTI Private Cloud server.
The gtiPrivateCloudServerIPv6Address would be zero if the current object is initialized.rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.39.5.2 |
gtiPrivateCloudServerIPv6AddressThis object is used to configure the IPv6 address of the GTI Private Cloud server.
The gtiPrivateCloudServerIPv4Address would be zero if the current object is initialized.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.39.5.3 |
gtiPrivateCloudServerConnectionConfigThis object is used to enable or disable or reconnect the Connection with
the GTI Private Cloud Server.
Default: 2, disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.5.4 |
gtiPrivateCloudServerDeleteCertificateThis object is used to delete the GTI Private Cloud Server Certificate at the sensor.
For deleting this certificate, the gtiPrivateCloudServerConnectionConfig should be
disabled. DEFAULT: 2, dont-deleterw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.5.5 |
gtiPrivateCloudServerCertificateStatusThis object is used to indicate the GTI Private Cloud server
certificate status at the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.5.6 |
gtiPrivateCloudChannelStatusThis object is used to indicate the gtiPrivateCloud channel status at
the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.5.7 |
gtiUnifiedConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.39.6 |
gtiFileRESTGTITypeThis object is used to send type of GTI server to use for file reputation feature.
DEFAULT: 2, public-gti-serverrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.6.1 |
gtiFileRESTPublicGTIFQDNThis object is used to send Name Server or FQDN of File Rep GTI server.
Default value is NULLrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.6.2 |
gtiFileRESTUsernameThis object is used to send username for configured GTI server.
It should be sent in both cases, public server and private server.
Default value is NULLrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.6.3 |
gtiFileRESTPasswordThis object is used to send password for configured GTI server.
It should be sent in both cases, public server and private server.
Default value is NULLrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.39.6.4 |
gtiFileRESTConnectionConfigThis object is used to send action to take with the recieved config.
Value 1 will be sent when config is changed to private GTI server first time.
Value 2 will be sent when config is changed to public GTI server.
Value 3 will be sent when private GTI server config is changed, given that
private GTI server is enabled already. Default value: 2rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.6.5 |
gtiFileRESTPvtGTIIPTypeThis object is used to send address type of configured GTI server.
Default value: 4, IPv4rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.39.6.6 |
gtiFileRESTPvtGTIIPv4AddressThis object is used to configure the IPv4 address of the GTI File-Rep REST Cloud server.
The gtiFileRESTPvtGTIIPV6Address would be zero if the current object is initialized.
Default Value: NULLrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.39.6.7 |
gtiFileRESTPvtGTIIPV6AddressThis object is used to configure the IPv6 address of the GTI File-Rep REST Cloud server.
The gtiFileRESTPvtGTIIPv4Address would be zero if the current object is initialized.
Default Value: NULLrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.39.6.8 |
ntpConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.40 |
ntpConfigTableTable containing entries for each NTP(Network Time Protocol) server that is specified (indexed via ntpServerIndex).
A maximum of two entries will be supported. Valid ntpServerIndex values are 1 and 2. SEQUENCE OF NtpConfigEntry .1.3.6.1.4.1.8962.2.1.2.1.40.1 |
ntpConfigEntryEach entry comprises the ntp client side configuration for each of the ntp servers specified. NtpConfigEntry .1.3.6.1.4.1.8962.2.1.2.1.40.1.1 |
ntpConfigServerIPv4This object is used to specify the IPv4 address of the remote NTP server.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.1 |
ntpConfigServerIPv6This object is used to specify the IPv6 address of the remote NTP server.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.2 |
ntpConfigPollIntervalThis object specifies the minimum poll interval.
The value which is received represents the exponent of 2. If the received value is
x then NTPD daemon process will calculate the min poll as 2^x seconds.
Default: 6rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.3 |
ntpConfigAuthenticationEnableThis object specifies if ntp server authentication is enabled or not for the specified
ntp server.
False : Authentication Disable
True : Authentication Enable
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.4 |
ntpConfigKeyIdThis MIB object specifies the key id for the corresponding association between an
ntp server and ntp client. This object is used only if ntp server authentication is enabled.
Default: 1rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.5 |
ntpConfigKeyTypeThis object specifies the key type for the corresponding key id. This object is used
only if ntp server authentication is enabled.
Default: MD5(1)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.6 |
ntpConfigKeyValueThis object specifies the symmetric key value for the corresponding key id. This object
is used only if ntp server authentication is enabled.rw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.40.1.1.7 |
ntpConfigFileCreateThis object is used to (create ntp.conf file and start)/(stop) ntpd process.
Default: stop-ntpd (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.40.2 |
pluggableModuleGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.41 |
pluggableModuleTableTable containing entries for each pluggable Module (indexed via slotIndex). SEQUENCE OF PluggableModuleEntry .1.3.6.1.4.1.8962.2.1.2.1.41.1 |
pluggableModuleEntryThis MIB object contains all the columnar objects,
that describe the contents of each pluggable module on each IntruShield sensor
card. Indexed by slotIndex PluggableModuleEntry .1.3.6.1.4.1.8962.2.1.2.1.41.1.1 |
moduleSerialNumberThis object describes the Manufacturer-provided serial number
of the pluggable module.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.41.1.1.1 |
moduleSysTypeThis object describes the type of the module plugged in.ro TrellixPluggableModuleType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.41.1.1.2 |
modulePresentTrue: Indicates the module is present.
Otherwise not present.
Default: Falsero TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.41.1.1.3 |
moduleNumPortsThis MIB object returns the number of ports in this module.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.41.1.1.4 |
moduleRebootRequiredThis MIB object returns whether a reboot is needed to apply the module.
Default: Falsero TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.41.1.1.5 |
insightixNetworkGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.42 |
insightixCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.42.1 |
ldapServerIPAddressTypeIdentifies the type of Insightix LDAP server IPAddress. If set to ip-v4, then the
ldapServerIpv4Address object would be set else if this object is set to ip-v6, then
the ldapServerIpv6Address object would be set.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.42.1.1 |
ldapServerIPv4AddressThe IPv4 address of the Insightix LDAP serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.42.1.2 |
ldapServerIPv6AddressIPv6 Address of the Insightix LDAP server.rw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.42.1.3 |
ldapServerPortThe ldap server listener port on the insightix server. If SSL is enabled, the standard portnum is 636,
else if ssl is disabled, the standard portnum is 389.
Default: 636rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.42.1.4 |
ldapServerSSLConfigSpecifies if SSL is enabled for insightix ldap server.
Default: 1, enablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.42.1.5 |
ldapServerBaseDNBase Distinguished Name to be used for retrieving device profile information from the Insightix ldap server.
Default : dc=insightixrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.42.1.6 |
ldapServerUserNameUserName to be used for authenticating to the Insightix ldap server.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.42.1.7 |
ldapServerPasswordPassword to be used for authenticating to the Insightix ldap server.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.42.1.8 |
ldapServerConfigActionThis object describes about the sensor's possible configuration actions with the insightix ldap server.
Default: 2, disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.42.1.9 |
ldapServerConfigStatusThis describes the sensor's possible insightix ldap server configuration states.
Default : deinstalled (4)ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.42.1.10 |
ntbaChannelCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.43 |
ntbaServerIPAddressTypeThis object is used to configure the IP address type of the
mgmt port at the NTBA endrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.43.1 |
ntbaServerIPv4AddressThis object is used to configure the IPv4 address of the NTBA server.
The ntbaServerIPv6Address would be zero if the current object is initializedrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.43.2 |
ntbaServerIPv6AddressThis object is used to configure the IPv6 address of the NTBA server.
The ntbaServerIPv4Address would be zero if the current object is initializedrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.43.3 |
ntbaServerPortThis object is used to configure the NTBA Server Listening TCP port
Default: 8505rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.43.4 |
ntbaServerConnectionConfigThis object is used to enable or disable the TCP Connection with
the NTBA server
Default: 2, disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.43.5 |
ntbaServerDeleteCertificateThis object is used to delete the ntba Server Certificate at the sensor.
For deleting this certificate, the ntbaServerConnectionConfig should be
disabled. DEFAULT: 2, dont-deleterw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.43.6 |
ntbaServerCertificateStatusThis object is used to indicate the NTBA server certificate status at
the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.43.7 |
ntbaShdKeySHAValueThis object contains the SHA1 hashed value of sensor name and sensormodel from NSMrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.43.8 |
ntbaChannelStatusThis object is used to indicate the NTBA SSL channel status at
the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.43.9 |
validEdgeChannelCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.44 |
validEdgeServerIPAddressTypeThis object is used to configure the IP address type of the
mgmt port at the validEdge endrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.44.1 |
validEdgeServerIPv4AddressThis object is used to configure the IPv4 address of the validEdge server.
The validEdgeServerIPv6Address would be zero if the current object is initializedrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.44.2 |
validEdgeServerIPv6AddressThis object is used to configure the IPv6 address of the validEdge server.
The validEdgeServerIPv4Address would be zero if the current object is initializedrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.44.3 |
validEdgeServerPortThis object is used to configure the validEdge Server Listening TCP port
Default: 8505rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.44.4 |
validEdgeServerConnectionConfigThis object is used to enable or disable the TCP Connection with
the validEdge server
Default: 2, disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.44.5 |
validEdgeServerDeleteCertificateThis object is used to delete the validEdge Server Certificate at the sensor.
For deleting this certificate, the validEdgeServerConnectionConfig should be
disabled. DEFAULT: 2, dont-deleterw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.44.6 |
validEdgeServerCertificateStatusThis object is used to indicate the validEdge server certificate status at
the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.44.7 |
validEdgeShdKeySHAValueThis object contains the SHA1 hashed value of sensor name and sensormodel from NSMrw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.44.8 |
validEdgeChannelStatusThis object is used to indicate the validEdge SSL channel status at
the sensorro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.44.9 |
validEdgeChannelGlobalUserIdThis object is used to configure global matd user id/profile id assigned to a sensor.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.44.10 |
validEdgeChannelGlobalUserNameThis object is used to configure global matd user name/profile name assigned to a sensor.rw OCTET STRING .1.3.6.1.4.1.8962.2.1.2.1.44.11 |
dxlCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.45 |
dxlConfigOption to enable(1) or dissable(2) the DXL on Sensor.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.45.1 |
epoCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.46 |
epoIPAddressTypeIdentifies the type of EPO IPAddress. If set to ip-v4, then the epoIPAddress object
would be set else if this object is set to ip-v6, then the epoIPv6Address object
would be set.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.46.1 |
epoIpAddressThe IPv4 Address of the EPO Serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.46.2 |
epoIPv6AddressIPv6 Address of a EPO Serverro Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.46.3 |
epoPortThe EPO port through which MA connects to EPO Server Default: 8443rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.46.4 |
epoCredUsernameEPO server :usernamerw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.46.5 |
epoCredPasswdEPO server :Passwordrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.46.6 |
epoActionThis config object indicates the epo action (1-Connect, 2-Disconnect, 3-Reconnect) to be taken
by all the dependent modules in the sensor.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.46.7 |
radiusAuthGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.47 |
radiusAuthConfigThis action object can be used to enable/re-init or disable user authentication using RADIUS.
The value of 'True/Enable' would be interpreted as 're-init', when the configuration is already set to True/Enable.
Default: False (2)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.47.1 |
radiusPrimaryServerIPAddrTypeIdentifies the type of IPAddress of the Primary Radius Server. If set to ip-v4, then the radiusPrimaryServerIPAddr object
would be set else if this object is set to ip-v6, then the radiusPrimaryServerIPv6Addr object
would be set.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.47.2 |
radiusPrimaryServerIPAddrThis object specifies the IPv4 Address of the Primary RADIUS serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.47.3 |
radiusPrimaryServerIPv6AddrThis object specifies the IPv6 Address of the Primary RADIUS Serverrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.47.4 |
radiusPrimaryServerEncrSecretThis object specifies the secret to be used in generating the encrypted RADIUS traffic between the client and Primary Radius Serverrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.47.5 |
radiusPriServerAuthPortThis object specifies the port on which Primary RADIUS Server is listening for authentication requests.
Default: 1812rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.6 |
radiusPriServerAccConfigThis object specifies whether accounting has to be enabled on the Primary Radius Server or not.
Default: True (1)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.47.7 |
radiusPriServerAccPortThis object specifies the port on which Primary RADIUS Server is listening for accounting requests.
Default: 1813rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.8 |
radiusPriServerConnTimeOutThis object specifies the time in seconds the client has to wait before it can contact the Backup RADIUS Server in case the Primary RADIUS Server fails.
Default: 6rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.9 |
radiusBackupServerIPAddrTypeThis object specifies the IP Address Type of the Backup RADIUS serverrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.47.10 |
radiusBackupServerIPAddrThis object specifies the IPv4 Address of the Backup RADIUS serverrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.47.11 |
radiusBackupServerIPv6AddrThis object specifies the IPv6 Address of the Backup RADIUS Serverrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.47.12 |
radiusBackupServerEncrSecretThis object specifies the secret to be used in generating the encrypted RADIUS traffic between the client and Backup Radius Serverrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.47.13 |
radiusBackupServerAuthPortThis object specifies the port on which Backup RADIUS Server is listening for authentication requests.
Default: 1812rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.14 |
radiusBackupServerAccConfigThis object specifies whether accounting has to be enabled on the Backup Radius Server or not.
Default: True (1)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.47.15 |
radiusBackupServerAccPortThis object specifies the port on which Backup RADIUS Server is listening for accounting requests.
Default: 1813rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.16 |
radiusBackupServerConnTimeOutThis object specifies the time in seconds before which the the sensor decides that the Backup server is not responding.
Default: 6rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.47.17 |
sshAccessGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.48 |
sshAccessCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.48.1 |
sshAccessControlStatusConfiguration option to enable/disable ssh access control list for ipv4.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.1.1 |
sshAccessControlResetIpv4Configuration option to to delete/reset the ssh access ipv4 contol list.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.1.2 |
sshAccessLogSupportConfiguration option to enable/disable ssh access messages logging support.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.1.3 |
sshAccessControlResetIpv6Configuration option to delete/reset ssh access control list for ipv6.
Default: false (2)rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.1.4 |
sshAccessNumIpv4EntriesThis object ranges from 1 to 100, as only a maximum of 100 entries are supported.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.2 |
sshAccessIpTable SEQUENCE OF SSHAccessIpEntry .1.3.6.1.4.1.8962.2.1.2.1.48.3 |
sshAccessIpEntryEach entry specified is indexed by <sshIpv4Index>. SSHAccessIpEntry .1.3.6.1.4.1.8962.2.1.2.1.48.3.1 |
sshIpv4IndexThis object sshIpv4Index ranges from 1 to 100, It support only 100 entries. INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.3.1.1 |
sshIpAddressIP Address of a SSH Access Control(ipv4).rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.48.3.1.2 |
sshMaskIpv4Mask of a SSH Access Control(ipv4).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.3.1.3 |
sshAccessIpConfigThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.3.1.4 |
sshAccessNumIpv6EntriesThis object ranges from 1 to 100, as only a maximum of 100 entries are supported.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.4 |
sshAccessIpv6Table SEQUENCE OF SSHAccessIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.48.5 |
sshAccessIpv6EntryEach entry specified is indexed by <sshIpv6Index>. SSHAccessIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.48.5.1 |
sshIpv6IndexThis object sshIpv6Index range from 1 to 100, It support max
100 entries INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.5.1.1 |
sshAccessIpv6AddressIPv6 address for the ssh access control listrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.5.1.2 |
sshAccessIpv6MaskIPv6 Mask for the ssh access control listrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.48.5.1.3 |
sshAccessIpv6ConfigThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.48.5.1.4 |
virtualPluggableModuleGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.49 |
moduleOneNumPortsThis MIB object returns the number of ports in the first module of VSS Box.
To be used in conjunction with interfacePortGrp of { ivSensorConfigurationMIB 11 } to represent attributes of VSS switch virtual ports.
Default: 0 (If the module is not inserted)rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.49.1 |
moduleTwoNumPortsThis MIB object returns the number of ports in the first module of VSS Box.
To be used in conjunction with interfacePortGrp of { ivSensorConfigurationMIB 11 } to represent attributes of VSS switch virtual ports.
Default: 0 (If the module is not inserted)rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.49.2 |
sslProbeAccessGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.51 |
sslProbeAccessCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.51.1 |
sslProbeAccessMaxAgentConnConfiguration option to restrict the total number of connections
that the sensor can handle from the SSL Probes.
Default: 1024rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.51.1.1 |
sslProbeAccessNumIpv4EntriesThis object ranges from 1 to 64, as only a maximum of 64 entries are supported.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.51.2 |
sslProbeAccessIpTable SEQUENCE OF SSLProbeAccessIpEntry .1.3.6.1.4.1.8962.2.1.2.1.51.3 |
sslProbeAccessIpEntryEach entry specified is indexed by <sslProbeIpv4Index>. SSLProbeAccessIpEntry .1.3.6.1.4.1.8962.2.1.2.1.51.3.1 |
sslProbeIpAddressIP Address of a SSL Probe Access Control(ipv4).rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.51.3.1.1 |
sslProbeMaskIpv4Mask of a SSL Probe Access Control(ipv4).rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.51.3.1.2 |
sslProbeAccessIpConfigThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.51.3.1.3 |
sslProbeAccessNumIpv6EntriesThis object ranges from 1 to 64, as only a maximum of 64 entries are supported.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.51.4 |
sslProbeAccessIpv6Table SEQUENCE OF SSLProbeAccessIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.51.5 |
sslProbeAccessIpv6EntryEach entry specified is indexed by <sslProbeIpv6Index>. SSLProbeAccessIpv6Entry .1.3.6.1.4.1.8962.2.1.2.1.51.5.1 |
sslProbeAccessIpv6AddressIPv6 address for the sslProbe access control listrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.51.5.1.1 |
sslProbeAccessIpv6MaskIPv6 Mask for the sslProbe access control listrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.51.5.1.2 |
sslProbeAccessIpv6ConfigThis object used for user to add and delete rows in to the table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.51.5.1.3 |
sensorCertificateGroup OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.52 |
sensorCertificateConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.52.1 |
sensorCertificateCSRConfigGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.52.1.1 |
sensorCertificateCSRCountryNameCountry name for generating the CSR. Use the two-letter code
without punctuation for country like US or CA.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.1 |
sensorCertificateCSRStateProvinceState or Province name for generating the CSR. Spell out the
state completely.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.2 |
sensorCertificateCSRLocalityCity or town name for generating the CSR.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.3 |
sensorCertificateCSRCompanyCompany name for generating the CSR. If the company name has
symbols, spell out the symbol or omit it to enroll.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.4 |
sensorCertificateCSROrganizationalUnitThe organizational unit is the name of the department or organization unit
making the request. This is an optional fieldrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.5 |
sensorCertificateCSRCommonNameThe common name is the host plus domain name. It looks like
www.company.com or company.com.rw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.6 |
sensorCertificateCSRGenerateActionThis action is used to generate the CSR/self signed certificate.
Default : other (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.7 |
sensorCertificateCSRGenerateStatusThis object describes the possible CSR generation states.
Default : other (0)ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.8 |
sensorCertSubAltNameTo push sensorCert subject alternative namerw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.52.1.1.9 |
sensorCertificateStatusThis object indicates the cert status on the sensor.
Default: 0ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.52.1.2 |
sensorCertMigrateActionTo push request for sensor cert migrationrw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.52.1.3 |
sensorStackGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.53 |
stackNameStack Namero DisplayString .1.3.6.1.4.1.8962.2.1.2.1.53.1 |
stackNodeIdID of stackNode.ro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.53.2 |
stackNodeLeftNeighbourNode id of Left Neighbour, configured in stackro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.53.3 |
stackNodeRightNeighbourNode id of Right Neighbour, configured in stackro INTEGER .1.3.6.1.4.1.8962.2.1.2.1.53.4 |
interfaceVirtualPortGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.54 |
intfVirtualPortTableTable containing entries for each interface port (indexed via intfPortIndex)
on each sensor card (indexed via appropriate slotIndex).
This table contains Trellix specific configuration objects.
Tables that contain MIB objects borrowed from MIB-II are in the
TRELLIX-SENSOR-PERF-MIB. SEQUENCE OF IntfVirtualPortEntry .1.3.6.1.4.1.8962.2.1.2.1.54.1 |
intfVirtualPortEntryThis MIB object contains all the columnar objects,
that describe the contents of each interface port on each IntruShield sensor card.
Indexed by slotIndex/intfPortIndex IntfVirtualPortEntry .1.3.6.1.4.1.8962.2.1.2.1.54.1.1 |
intfVirtualPortIfDescrA textual string containing information about the interface.
Returns the string that is printed on the box.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.1 |
intfVirtualPortIfTypeThe type of interface, distinguished according to the
physical/link protocol(s) immediately 'below' the network
layer in the protocol stack.
For brevity, Trellix options are as specified by the TC,
TrellixIDSPortType.
However, the SNMP MIB-II - Interfaces MIB specifies many more
valid options. See comments section for details.rw TrellixIDSPortType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.2 |
intfVirtualPortIfAdminStatusThe desired state of the interface.
The testing(3) state indicates that no operational packets
can be passed.
Default: downrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.3 |
intfVirtualPortOperatingModeReadWrite parameter specifies the operating mode for the
Trellix IDS sensor to be used. Different modes supported are
inline-fo-passive(1), non-inline or tap(2), span(3) and
inlne-fc(4), inline-fo-active kit(5 - available on M-series only).
Default: non-inlinerw TrellixIDSOperatingMode (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.4 |
intfVirtualPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one.
Otherwise as half-duplex.
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.5 |
intfVirtualPortSpeedConfigSet desired speed/negotiation on the interface.rw TrellixPortSpeed -- was TrellixFEType, now deprecated .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.6 |
intfVirtualPortEnableInternalTapSet to TRUE to enable feature. Applies to Fast Ethernet (FE)
ports only (see TrellixIDSPortType).
For non FE ports, set to 'FALSE' .
Setting this to 'TRUE' requires that
<intfPortCurrentOperatingMode> is already set to
'monitor-dual-intf'
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.7 |
intfVirtualPortInOutTypeThis MIB object reflects the Input or Output labeling
of this interface port. Used only when operating mode
is inline(1) or monitor-dual-intf(2).
Default: not-specified(3)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.8 |
intfVirtualFailOpenSwitchStatusReturns the status of the external optical bypass switch
status. For FE ports, this object will return
not-applicable(1). For GE ports, if external optical bypass
switch is connected to sensor ports, this will return
present(2). Otherwise, it will return not-present(3).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.9 |
intfVirtualFailOpenPortStatusReturns the packet forwarding status of the sensor ports connected to the optical bypass switch.
If status is inline-fail-open(2), sensor is doing the
forwarding. If status is bypass(3), the bypass switch is
doing the forwarding and sensor will not process any
traffic in this mode. Tap(4), absent(5) , unknown (6) and layer2-bypass(7)
are available only in M-series for non RJ45(captive) ports
when connected to active FO kit and sensor operating mode
is inline-fail-open-active-kit.
tap - operational status(up), kit(present), heart-beat(tap)
absent - operational status(up), kit(absent), hear-beat(none)
unknown - operational status(down), kit(absent), heart-beat(not available).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.10 |
intfVirtualPortEnableAntiSpoofingspoofed packet detect rcvd on the both sides .
Default: 'disable-bothsides-spoof-detect' (0)rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.11 |
intfVirtualPortAllowAnyConnectorTrue: Permit usage of any connector for port.
False: Restrict usage to McAfee certified connector only.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.12 |
intfVirtualPortCageTypePhysical connector cage type on sensor chassis panel.rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.13 |
intfVirtualPortSetMediaTypeSets the media of the connector the user desired for the port.
Default: opticalrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.14 |
intfVirtualPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.15 |
intfVirtualPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.16 |
intfVirtualPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway.
Default: 0.0.0.0rw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.17 |
intfVirtualPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation
to be sent to the NBAD server, is enabled over this monitoring port.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.18 |
intfVirtualPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring
port is connected.rw Integer32 .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.19 |
intfVirtualPortAppIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled
over this monitoring port.
Default: Truerw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.20 |
intfVirtualPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is
generated by the sensor appliance using the pair of slot index and the port index values.
The other MIB tables would directly use this linear index, whereever applicable.ro TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.21 |
intfVirtualPortFECConfigThis object value if set to TRUE indicates that FEC is enabled, FALSE for FEC disbaled
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.54.1.1.22 |
responseVirtualPortGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.55 |
respVirtualPortTableTable containing entries for each response port (indexed via respPortIndex)
on each sensor card (indexed via valid slotIndex).
This table contains Trellix specific MIB objects. SEQUENCE OF RespVirtualPortEntry .1.3.6.1.4.1.8962.2.1.2.1.55.1 |
respVirtualPortEntryThis MIB object contains all the columnar objects,
that describe the contents of each response port within the Trellix IDS sensor card.
Indexed by slotIndex/respPortIndex RespVirtualPortEntry .1.3.6.1.4.1.8962.2.1.2.1.55.1.1 |
respVirtualPortDescrA textual string containing information about the interface.
Returns the string that is printed on the box.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.1 |
respVirtualPortTypeThe type of interface, distinguished according to the
physical/link protocol(s) immediately 'below' the network
layer in the protocol stack.
See TrellixIDSPortType.ro TrellixIDSPortType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.2 |
respVirtualPortAdminStatusThe desired state of the interface.
Default: Uprw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.3 |
respVirtualPortOperStatusThe current operational state of the interface.
The testing(3) state indicates that no operational packets
can be passed.ro Enumeration .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.4 |
respVirtualPortEnableFullDuplexTrue: Sets response port to work as a full-duplex one.
otherwise as half-duplex.
If True, respPortFullDuplexPeer must be specified.
Default: Falserw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.5 |
respVirtualPortSpeedSee TrellixPortSpeed
Default: fixed-hundred-Mbps (2)rw TrellixPortSpeed (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.6 |
respVirtualPortPktDestinationThis object is used when response ports are chosen for
sending response packets. When router mode is chosen,
packets will be sent to router with destination MAC as
defined in intfRespMacAddress.
Default value is switch (1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.7 |
respVirtualPortMacAddressSpecifies the macaddress of the router to which the response
packets have to be sent to.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.8 |
respVirtualCUGEPortSpeedOnly applicable to copper-gigabit-ethernet ports, to specify whether
10mbps or 100mbps or 1-gbps or auto-neg. See TrellixCUGEType
Default: auto-negotiaterw TrellixCUGEType (TRELLIX-INTRUVERT-TC) .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.9 |
respVirtualAdditionalInfoA textual string containing additional information about the response interface.
This mib object will be available only on V-series sensors.ro DisplayString .1.3.6.1.4.1.8962.2.1.2.1.55.1.1.11 |
intfVirtualRespTableTable containing entries for each interface port. The
table describes how responses have to be sent in monitoring
mode. SEQUENCE OF IntfVirtualRespEntry .1.3.6.1.4.1.8962.2.1.2.1.55.2 |
intfVirtualRespEntryIndexed by slotIndex/intfPortIndex IntfVirtualRespEntry .1.3.6.1.4.1.8962.2.1.2.1.55.2.1 |
intfVirtualRespTypeSetting this object to responsePort (2) causes responses
to be sent via the response port. The response port no that
needs to be used is specified with intfRespPortNo object.
Setting this object to inline (3) causes responses to be
sent inline. Note that in monitoring mode, responses can
only be sent inline when the monitoring port is in
half-duplex mode.
Default action will be responsePort (1).rw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.55.2.1.1 |
intfVirtualRespPortNoSpecifies the response port number that needs to be used
for this monitoring port. The response ports are configured
by respPortTable.rw INTEGER .1.3.6.1.4.1.8962.2.1.2.1.55.2.1.2 |
mvxCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.56 |
mvxConnectionConfigThis object is used to enable or disable the MVX integration
Default: 2, disablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.56.1 |
mvxIPAddressTypeThis object is used to configure the IP address type of the
mgmt port at the MVX engine endrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.56.2 |
mvxBrokerIPv4AddressThis object is used to configure the IPv4 address of the MVX engine.
The mvxBrokerIPv4Address would be zero if the current object is initializedrw IpAddress .1.3.6.1.4.1.8962.2.1.2.1.56.3 |
mvxBrokerIPv6AddressThis object is used to configure the IPv6 address of the MVX engine.
The mvxBrokerIPv6Address would be zero if the current object is initializedrw Ipv6Address (IPV6-TC) .1.3.6.1.4.1.8962.2.1.2.1.56.4 |
mvxUserNameThis object is used to send username for configured MVX engine.
Default value is NULLrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.56.5 |
mvxPasswordThis object is used to send password for configured MVX engine.
Default value is NULLrw DisplayString .1.3.6.1.4.1.8962.2.1.2.1.56.6 |
mvxCertificateValidationThis object is used to indicate the MVX server certificate flag at
the sensorrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.56.7 |
mvxAuthStatusThis object is used to indicate the authentication status between
sensor and MVX enginero Enumeration .1.3.6.1.4.1.8962.2.1.2.1.56.8 |
mvxUseProxyThis object is used to indicate the configured proxy is used by the MVX engine or notrw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.56.9 |
arpCfgGrp OBJECT IDENTIFIER .1.3.6.1.4.1.8962.2.1.2.1.103 |
arpSDEnableOption to enable/disable ARP Spoof Detection.
Default: enablerw Enumeration .1.3.6.1.4.1.8962.2.1.2.1.103.1 |