ZYXEL-PORT-AUTHENTICATION-MIB
AI MIB Summary
The ZYXEL-PORT-AUTHENTICATION-MIB enables monitoring and management of IEEE 802.1X and MAC Authentication Bypass (MAB) session states, authentication failures, and port access control lists on ZyXEL network switches. This module provides visibility into active user sessions, authentication server interactions, and port security violation counters to enforce network access policies.
The subtree for port authentication
Main OID:
zyxelPortAuthentication.1.3.6.1.4.1.890.1.15.3.62
18
Objects
Active
Status
14
Dependencies
Imported Objects
Objects
18 total| Object Name |
|---|
zyxelPortAuthenticationThe subtree for port authentication MODULE-IDENTITY .1.3.6.1.4.1.890.1.15.3.62 |
RFC1155-SMIThe subtree for port authentication Unknown .1.3.6.1.4.1.890.1.15.3.62 |
IF-MIBThe subtree for port authentication NOTIFICATION-TYPE .1.3.6.1.4.1.890.1.15.3.62 |
zyxelPortAuthenticationSetup OBJECT IDENTIFIER .1.3.6.1.4.1.890.1.15.3.62.1 |
zyPortAuthenticationStateEnable/Disable 802.1x port authentication for the switch.rw EnabledStatus (P-BRIDGE-MIB) .1.3.6.1.4.1.890.1.15.3.62.1.1 |
zyxelPortAuthenticationPortTableThe table contains port authentication configuration SEQUENCE OF ZyxelPortAuthenticationPortEntry .1.3.6.1.4.1.890.1.15.3.62.1.2 |
zyxelPortAuthenticationPortEntryAn entry contains port authentication configuration. ZyxelPortAuthenticationPortEntry .1.3.6.1.4.1.890.1.15.3.62.1.2.1 |
zyPortAuthenticationPortStateEnable/Disable 802.1x port authentication on the port. You must first allow 802.1x authentication on
the Switch before configuring it on each port.rw EnabledStatus (P-BRIDGE-MIB) .1.3.6.1.4.1.890.1.15.3.62.1.2.1.1 |
zyPortReAuthenticationPortStateEnable/Disable 802.1x port re-authentication on the port. Specify if a subscriber has to periodically
re-enter his or her username and password to stay connected to the port.rw EnabledStatus (P-BRIDGE-MIB) .1.3.6.1.4.1.890.1.15.3.62.1.2.1.2 |
zyPortReAuthenticationPortTimerSpecify the length of time required to pass before a client has to re-enter his or her username and
password to stay connected to the port.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.3 |
zyPortAuthenticationPortQuietPeriodSpecify the number of seconds the port remains in the HELD state and rejects further authentication
requests from the connected client after a failed authentication exchange.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.4 |
zyPortAuthenticationPortTxPeriodSpecify the number of seconds the Switch waits for client's response before re-sending an identity
request to the client.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.5 |
zyPortAuthenticationPortSupplicantTimeoutSpecify the number of seconds the Switch waits for client's response to a challenge request before
sending another request.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.6 |
zyPortAuthenticationPortMaxRequestSpecify the number of times the Switch tries to authenticate client(s) before sending unresponsive
ports to the Guest VLAN. This is set to 2 by default. That is, the Switch attempts to authenticate a
client twice. If the client does not respond to the first authentication request, the Switch tries again. If the client still does not respond to the second request, the Switch sends the client to the Guest VLAN. The client needs to send a new request to be authenticated by the Switch again.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.7 |
zyPortAuthenticationPortGuestVlanStateEnable/Disable Guest VLAN on the port. Clients that fail authentication are placed in the guest VLAN
and can receive limited services.rw EnabledStatus (P-BRIDGE-MIB) .1.3.6.1.4.1.890.1.15.3.62.1.2.1.8 |
zyPortAuthenticationPortGuestVlanEnter the number that identifies the guest VLAN. Make sure this is a VLAN recognized in your network.
A guest VLAN is a pre-configured VLAN on the Switch that allows non-authenticated users to access
limited network resources through the Switch. You must also enable IEEE 802.1x authentication on the
Switch and the associated ports.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.9 |
zyPortAuthenticationPortGuestVlanHostModeSpecify how the Switch authenticates users when more than one user connect to the port (using a hub).
Select Multi-Host to authenticate only the first user that connects to this port. If the first user
enters the correct credential, any other users are allowed to access the port without authentication.
If the first user fails to enter the correct credential, they are all put in the guest VLAN. Once the
first user who did authentication logs out or disconnects from the port, rest of the users are blocked
until a user does the authentication process again.
Select Multi-Secure to authenticate each user that connects to this port.rw Enumeration .1.3.6.1.4.1.890.1.15.3.62.1.2.1.10 |
zyPortAuthenticationPortGuestVlanHostModeMultiSecureNumberIf you set Host-mode to Multi-Secure, specify the maximum number of users that the
Switch will authenticate on this port.rw INTEGER .1.3.6.1.4.1.890.1.15.3.62.1.2.1.11 |