Home/Catalog/ZYXEL-AclV2-MIB

ZYXEL-AclV2-MIB

AI MIB Summary

The ZYXEL-AclV2-MIB enables SNMP-based monitoring and configuration of Access Control List (ACL) version 2 rules on Zyxel network devices, specifically tracking rule identifiers, hit counts, packet/byte counters, and permit/deny action states for traffic filtering enforcement.

The subtree for access control list (ACL) version 2
Main OID:
zyxelAclV2.1.3.6.1.4.1.890.1.15.3.105
90
Objects
Active
Status
6
Dependencies

Imported Objects

Objects

90 total
Object Name
zyxelAclV2The subtree for access control list (ACL) version 2
MODULE-IDENTITY
.1.3.6.1.4.1.890.1.15.3.105
IMPORTSThe subtree for access control list (ACL) version 2
Unknown
.1.3.6.1.4.1.890.1.15.3.105
zyxelAclV2ClassifierStatus
OBJECT IDENTIFIER
.1.3.6.1.4.1.890.1.15.3.105.1
zyxelAclV2ClassifierTableThe table contains classifier general configuration and information.
SEQUENCE OF ZyxelAclV2ClassifierEntry
.1.3.6.1.4.1.890.1.15.3.105.1.1
zyxelAclV2ClassifierEntryAn entry contains classifier general configuration and information.
ZyxelAclV2ClassifierEntry
.1.3.6.1.4.1.890.1.15.3.105.1.1.1
zyAclV2ClassifierNameThe name of classifier rule is used for identifying purposes.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.1
zyAclV2ClassifierStateEnable/Disable classifier rule on this switch.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.2
zyAclV2ClassifierWeightWeght value for classifier rule, 0~65535. Default 32767. When the match order is manual, the higher weight the higher priorit When the match order is auto, the priority depends on the depth of qualifier.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.3
zyAclV2ClassifierCountStateEnable/disable count on this classifier rule. To Enable counting the matched packet number of this rule.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.4
zyAclV2ClassifierLogStateEnable/disable log on this classifier rule. To Enable recording the matched packet number of this rule in a configurable time interval.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.5
zyAclV2ClassifierTimeRangeTime Range Name for classifier rule. Bind a time range profile with this rule to active this rule in specific time.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.6
zyAclV2ClassifierMatchCountMatch-Count of this classifier rule. It will show the matched packet count of this rule if zyAclV2ClassifierCount is enabled.ro
Counter64
.1.3.6.1.4.1.890.1.15.3.105.1.1.1.7
zyxelAclV2ClassifierEthernetTableThe table contains classifier ethernet configuration.
SEQUENCE OF ZyxelAclV2ClassifierEthernetEntry
.1.3.6.1.4.1.890.1.15.3.105.1.2
zyxelAclV2ClassifierEthernetEntryAn entry contains classifier ethernet configuration.
ZyxelAclV2ClassifierEthernetEntry
.1.3.6.1.4.1.890.1.15.3.105.1.2.1
zyAclV2ClassifierEthernetSourcePortsSource Port List for classifier rule.ro
PortList (Q-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.1
zyAclV2ClassifierEthernetSourceTrunksSource Trunk List for classifier rule.ro
PortList (Q-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.2
zyAclV2ClassifierEthernetPacketFormatPacket format for classifier rule. A value of 802.3 indicates that the packets are formatted according to the IEEE 802.3 standards. A value of Ethernet II indicates that the packets are formatted according to RFC 894, Ethernet II encapsulation.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.3
zyAclV2ClassifierEthernet8021pPriority802.1p priority for classifier rule. 0~7. The range is 0~7 and value -1 means any priority level.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.4
zyAclV2ClassifierEthernetInner8021pPriorityInner 802.1p priority for classifier rule, 0~7. Value -1 means any priority level.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.5
zyAclV2ClassifierEthernetTypeEthernet type for classifier rule. It is represented in decimal expression and value 65535 means any Ethernet type.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.6
zyAclV2ClassifierEthernetSourceMacAddressSource MAC address for classifier rule. 00:00:00:00:00:00 means any source MAC address.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.7
zyAclV2ClassifierEthernetSourceMACMaskSource MAC Mask for classifier rule.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.8
zyAclV2ClassifierEthernetDestinationMacAddressDestination MAC address for classifier rule. 00:00:00:00:00:00 means any destination MAC address.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.9
zyAclV2ClassifierEthernetDestinationMACMaskDestination MAC Mask for classifier rule.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.1.2.1.10
zyxelAclV2ClassifierVlanTableAn entry contains classifier VLAN configuration.
SEQUENCE OF ZyxelAclV2ClassifierVlanEntry
.1.3.6.1.4.1.890.1.15.3.105.1.3
zyxelAclV2ClassifierVlanEntryAn entry contains classifier VLAN configuration.
ZyxelAclV2ClassifierVlanEntry
.1.3.6.1.4.1.890.1.15.3.105.1.3.1
zyAclV2ClassifierVlanMap1kVLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.3.1.1
zyAclV2ClassifierVlanMap2kVLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.3.1.2
zyAclV2ClassifierVlanMap3kVLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.3.1.3
zyAclV2ClassifierVlanMap4kVLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.3.1.4
zyxelAclV2ClassifierInnerVlanTableAn entry contains classifier inner VLAN configuration.
SEQUENCE OF ZyxelAclV2ClassifierInnerVlanEntry
.1.3.6.1.4.1.890.1.15.3.105.1.4
zyxelAclV2ClassifierInnerVlanEntryAn entry contains classifier inner VLAN configuration.
ZyxelAclV2ClassifierInnerVlanEntry
.1.3.6.1.4.1.890.1.15.3.105.1.4.1
zyAclV2ClassifierInnerVlanMap1kinner VLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.4.1.1
zyAclV2ClassifierInnerVlanMap2kinner VLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.4.1.2
zyAclV2ClassifierInnerVlanMap3kinner VLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.4.1.3
zyAclV2ClassifierInnerVlanMap4kinner VLAN ID List for classifer rule. range : 1~4094.ro
OCTET STRING
.1.3.6.1.4.1.890.1.15.3.105.1.4.1.4
zyxelAclV2ClassifierIpTableThe table contains classifier IP configuration.
SEQUENCE OF ZyxelAclV2ClassifierIpEntry
.1.3.6.1.4.1.890.1.15.3.105.1.5
zyxelAclV2ClassifierIpEntryAn entry contains classifier IP configuration.
ZyxelAclV2ClassifierIpEntry
.1.3.6.1.4.1.890.1.15.3.105.1.5.1
zyAclV2ClassifierIpPacketLenRangeStartThe Start value of IP packet length range, 0~65535. And it must smaller then the zyAclV2ClassifierIpPacketLenRangeEnd. Value -1 means any start value.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.1
zyAclV2ClassifierIpPacketLenRangeEndThe End value of IP packet length range, 0~65535. And it must larger then the zyAclV2ClassifierIpPacketLenRangeStart. Value -1 means any start value.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.2
zyAclV2ClassifierIpDSCPDSCP (DiffServ Code Point) for classifier rule. The range is 0~63 and value -1 means any DSCP.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.3
zyAclV2ClassifierIpPrecedencePrecedence for calssifier rule, 0~7. Value -1 means any Precedence.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.4
zyAclV2ClassifierIpToSToS for calssifier rule, 0~127. Value -1 means any ToS.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.5
zyAclV2ClassifierIpProtocolIP Protocol for classifier rule. Value 255 means any IP protocol.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.6
zyAclV2ClassifierIpEstablishOnlyEstablish Only for TCP protocol type in classifier rule. This means that the switch will pick out the packets that are sent to establish TCP connections.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.7
zyAclV2ClassifierIpSourceIpAddressSource IP address for classifier rule. 0.0.0.0 means any source IP address.ro
IpAddress
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.8
zyAclV2ClassifierIpSourceIpMaskBitsSource IP mask bits for classifier rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.9
zyAclV2ClassifierIpDestinationIpAddressDestination IP address for classifier rule. 0.0.0.0 means any destination IP address.ro
IpAddress
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.10
zyAclV2ClassifierIpDestinationIpMaskBitsDestination IP mask bits for classifier rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.11
zyAclV2ClassifierIpSourceSocketRangeStartSource Socket Number range start for classifier rule, 0~65535. If not qualifying a range of socket numbers, the zyAclV2ClassifierSourceSocketRangeEnd is no need to configure.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.12
zyAclV2ClassifierIpSourceSocketRangeEndDestination Socket Number range end for classifier rule. This object is not necessary.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.13
zyAclV2ClassifierIpDestinationSocketRangeStartSource Socket Number range start for classifier rule, 0~65535. If not qualifying a range of socket numbers, the zyAclV2ClassifierDestinationSocketRangeEnd is no need to configure.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.14
zyAclV2ClassifierIpDestinationSocketRangeEndDestination Socket Number range end for classifier rule. This object is not necessary.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.5.1.15
zyxelAclV2ClassifierIpv6TableThe table contains classifier IPv6 configuration.
SEQUENCE OF ZyxelAclV2ClassifierIpv6Entry
.1.3.6.1.4.1.890.1.15.3.105.1.6
zyxelAclV2ClassifierIpv6EntryAn entry contains classifier IPv6 configuration.
ZyxelAclV2ClassifierIpv6Entry
.1.3.6.1.4.1.890.1.15.3.105.1.6.1
zyAclV2ClassifierIPv6DSCPDSCP (DiffServ Code Point) for classifier rule. The range is 0~63 and value -1 means any DSCP.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.1
zyAclV2ClassifierIPv6NextHeaderIPv6 next header protocol type for classifier rule. Value 255 means any protocol type.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.2
zyAclV2ClassifierIPv6EstablishOnlyEstablish Only for TCP protocol type in classifier rule. This means that the switch will pick out the packets that are sent to establish TCP connections.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.3
zyAclV2ClassifierIPv6SourceIpAddressIPv6 source address for classifier rule. :: means any IPv6 source ip address.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.4
zyAclV2ClassifierIPv6SourceIpPrefixLengthIPv6 source address prefix length for classifier rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.5
zyAclV2ClassifierIPv6DestinationIpAddressIPv6 destination address for classifier rule. :: means any IPv6 destination ip address.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.6
zyAclV2ClassifierIPv6DestinationIpPrefixLengthIPv6 destination address prefix length for classifier rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.6.1.7
zyxelAclV2ClassifierMatchOrderManual or Auto to determine the rule ordering. When the match order is manual, the higher weight the higher priority. When the match order is auto, the priority is depended on the depth of the qualifier.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.1.7
zyxelAclV2ClassifierLoggingStateEnable/disable Logging for classifier.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.1.8
zyxelAclV2ClassifierLoggingIntervalLogging Interval for classifier, 0~65535.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.1.9
zyxelAclV2PolicyStatus
OBJECT IDENTIFIER
.1.3.6.1.4.1.890.1.15.3.105.2
zyxelAclV2PolicyTableThe table contains policy configuration.
SEQUENCE OF ZyxelAclV2PolicyEntry
.1.3.6.1.4.1.890.1.15.3.105.2.1
zyxelAclV2PolicyEntryAn entry contains policy configuration.
ZyxelAclV2PolicyEntry
.1.3.6.1.4.1.890.1.15.3.105.2.1.1
zyAclV2PolicyNameThe name of policy rule is used for identifying purposes.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.1
zyAclV2PolicyStateEnable/Disable policy rule on this switch.ro
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.2
zyAclV2PolicyClassifierThe classifier(s) applies in this policy rule.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.3
zyAclV2PolicyVidVLAN ID for policy rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.4
zyAclV2PolicyEgressPortThe outgoing port number in this policy rule.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.5
zyAclV2Policy8021pPrioritySpecify a 802.1p priority level for policy rule. The value of 802.1p is between 0 and 7.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.6
zyAclV2PolicyDSCPSpecify a DSCP (DiffServ Code Point) for policy rule. DSCP number is between 0 and 63.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.7
zyAclV2PolicyTOSSpecify the type of service (TOS) priority level for policy rule. The value of TOS is between 0 and 7.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.8
zyAclV2PolicyBandwidthSpecify the bandwidth for policy rule in kilobit per second (Kbps).ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.9
zyAclV2PolicyOutOfProfileDSCPSpecify a new DSCP number (between 0 and 63) for policy rule if you want to replace or remark the DSCP number for out-of-profile traffic.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.10
zyAclV2PolicyForwardingActionThere are three forwarding actions for policy rule. 'No change' is forward the packets. 'Discard the packet' is drop the packets. 'Do not drop the matching frame previously marked for dropping' is retain the frames that were marked to be dropped before.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.11
zyAclV2PolicyPriorityActionThere are four priority actions for policy rule. 'No change' is keep the priority setting of the frames. 'Set the packet's 802.1 priority' is replace the packet's 802.1 priority field with the value you set in the Priority field. 'Send the packet to priority queue' is put the packets in the designated queue. 'Replace the 802.1 priority field with the IP TOS value' to replace the packet's 802.1 priority field with the value you set in the TOS field. 'Replace the 802.1p priority by inner 802.1p priority' to replace 802.1p priority by inner 802.1p priority if there is an inner vlan tag.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.12
zyAclV2PolicyDiffServActionThere are four DiffServ actions for policy rule. 'No change' is keeping the TOS and/or DSCP fields in the packets. 'Set the packet's TOS field' is set the TOS field with the value you configure in the TOS field. 'Replace the IP TOS with the 802.1 priority value' is replace the TOS field with the value you configure in the Priority field. 'Set the Diffserv Codepoint field in the frame' to set the DSCP field with the value you configure in the DSCP field.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.13
zyAclV2PolicyOutgoingActionThere are four outgoing actions for policy rule. 'Send the packet to the mirror port' is sent the packet to the mirror port. 'Send the packet to the egress port' is sent the packet to the egress port. 'Send the matching frames to the egress port' is sent the matching policy rule frames to the egress port. 'Set the packets VLAN ID' is set packet with tag.ro
Bits
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.14
zyAclV2PolicyMeteringStateEnable/Disable bandwidth limitation on the traffic flow(s) then set the actions to be taken on out-of-profile packets.ro
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.15
zyAclV2PolicyOutOfProfileActionThere are four out of profile actions for policy rule. 'Drop the packet' is discard the out-of-profile traffic. 'Change the DSCP value' is replace the DSCP field with the value specified in the Out of profile DSCP field. 'Set Out-Drop Precedence' is mark out-of-profile traffic and drop it when network is congested. 'Do not drop the matching frame previously marked for dropping' to queue the frames that are marked to be dropped.ro
Bits
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.16
zyAclV2PolicyRowstatusThis object shows the entry of policy rule status.ro
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.17
zyAclV2PolicyQueueActionThere are two queue actions for policy rule. 'No change' is keep the priority setting of the frames. 'Send the packet to priority queue' is put the packets in the designated queue.ro
Enumeration
.1.3.6.1.4.1.890.1.15.3.105.2.1.1.18
zyxelAclV2TrapInfoObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.890.1.15.3.105.3
zyAclV2TrapClassifierLogMatchCountdisplay log match count of specific classifier rule.
INTEGER
.1.3.6.1.4.1.890.1.15.3.105.3.1
zyxelAclV2Notifications
OBJECT IDENTIFIER
.1.3.6.1.4.1.890.1.15.3.105.4
zyAclV2ClassifierLogNotificationclassifier log information.
NOTIFICATION-TYPE
.1.3.6.1.4.1.890.1.15.3.105.4.1
ZYXEL-AclV2-MIB - SNMP MIB Reference | MIBs Explorer