ALCATEL-ENT1-NETSEC-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
52
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1 · 1 row entry · 4 columns
Table for collecting port-range and monitoring-group associations.
A port belongs to at most one monitoring-group.
alaNetSecPortRangeGroupEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1.1
Each entry is identified by a unique port-range.
Indexes
alaNetSecPortRangeGroupStartIfId alaNetSecPortRangeGroupEndIfId
Column Syntax OID
alaNetSecPortRangeGroupStartIfId
Starting interface index of a port-range
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1.1.1
alaNetSecPortRangeGroupEndIfId
Ending interface index of a port-range
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1.1.2
alaNetSecPortRangeGroupName
Name of monitoring-group with which this port-range is associated.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1.1.3
alaNetSecPortRangeGroupRowStatus
identifies state of this entry. CREATEANDGO will only work, if the name of alaNetSecPortRangeGroupName is part of the create request
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.1.1.1.4
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1 · 1 row entry · 10 columns
Table for collecting monitoring-groups' anomaly configurations
alaNetSecMonitoringGroupEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1
Each entry identifies configuration of a monitoring-group's anomaly-type's parameter
Indexes
alaNetSecMonitoringGroupName alaNetSecMonitoringGroupAnomaly
Column Syntax OID
alaNetSecMonitoringGroupName
name of the monitoring-group
OctetString
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.1
alaNetSecMonitoringGroupAnomaly
monitoring-group's anomaly-type
AlaAnomalyType
Textual Convention: AlaAnomalyType Enumeration
Type Values:
0all
1arpaddressscan
2arpflood
3reserved
4arpfailure
5icmpaddressscan
6icmpflood
7icmpunreachable
8tcpportscan
9tcpaddressscan
10synflood
11synfailure
12synackscan
13finscan
14finackdiff
15rstcount
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.2
alaNetSecMonitoringGroupAnomalyState
State of detecting indexed anomaly.
AlaNetsecStatusr/w
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.3
alaNetSecMonitoringGroupAnomalyLog
State of logging upon detecting anomaly.
AlaNetsecStatusr/w
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.4
alaNetSecMonitoringGroupAnomalyTrap
State of sending traps upon detecting anomaly.
AlaNetsecStatusr/w
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.5
alaNetSecMonitoringGroupAnomalyQuarantine
State of Quarantining anomalous port upon detecting anomaly.
AlaNetsecStatusr/w
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.6
alaNetSecMonitoringGroupAnomalyCount
Count of packets that must be seen during monitoring period
to initiate anomaly detection check.
Default value varies as below with anomaly:
Anomaly Count
------- -----
ARP addr…
Integer32r/w
Constraints:
range: 1-100000
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.7
alaNetSecMonitoringGroupAnomalySensitivity
Sensitivity of Anomaly Check to deviation from expected behavior.
Integer32r/w
Constraints:
range: 1-100
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.8
alaNetSecMonitoringGroupAnomalyPeriod
Time in seconds to monitor packets before checking for anomaly.
Integer32r/w
Constraints:
range: 5-3600
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.9
alaNetSecMonitoringGroupRowStatus
CREATEANDGO will only work if, besides RowStatus, at least one of State, Log, Trap, Quarantine, Count, Sensitivity or Period is part of the request.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.2.1.1.10
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1 · 1 row entry · 6 columns
Table for reporting port specific statistics
alaNetSecPortStatsEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1
Stats are collected on a <port,packet-type,packet-direction,total/last> basis
Indexes
alaNetSecPortStatsIfId alaNetSecPortStatsPacket
Column Syntax OID
alaNetSecPortStatsIfId
Interface Index of the port
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.1
alaNetSecPortStatsPacket
Packet type
AlaPacketType
Textual Convention: AlaPacketType Enumeration
Type Values:
1arpreply
2arprequest
3icmpechoreply
4icmpechorequest
5icmpdnr
6tcpsynonly
7tcpsynack
8tcpsynnack
9tcpfinack
10tcpfinnack
11tcprst
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.2
alaNetSecPortStatsLastIngress
Count of Indexed Ingress packets observed during last 5 seconds
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.3
alaNetSecPortStatsLastEgress
Count of Indexed Egress packets observed during last 5 seconds
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.4
alaNetSecPortStatsTotalIngress
Count of Indexed Ingress packets observed since monitoring was enabled, Counter will loop back from zero upon reaching the maximum
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.5
alaNetSecPortStatsTotalEgress
Count of Indexed Egress packets observed since monitoring was enabled. Counter will loop back from zero upon reaching the maximum
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.3.1.1.6
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1 · 1 row entry · 7 columns
Table for reporting Anomaly statistics
alaNetSecPortAnomalyStatsEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1
Stats are collected on a <port,anomaly-type,packet-type,packet-direction,current/last> basis
Indexes
alaNetSecPortAnomalyStatsIfId alaNetSecPortAnomalyStatsAnomaly alaNetSecPortAnomalyStatsPacket
Column Syntax OID
alaNetSecPortAnomalyStatsIfId
Interface Index of the port
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.1
alaNetSecPortAnomalyStatsAnomaly
Anomaly type
AlaAnomalyType
Textual Convention: AlaAnomalyType Enumeration
Type Values:
0all
1arpaddressscan
2arpflood
3reserved
4arpfailure
5icmpaddressscan
6icmpflood
7icmpunreachable
8tcpportscan
9tcpaddressscan
10synflood
11synfailure
12synackscan
13finscan
14finackdiff
15rstcount
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.2
alaNetSecPortAnomalyStatsPacket
Packet type
AlaPacketType
Textual Convention: AlaPacketType Enumeration
Type Values:
1arpreply
2arprequest
3icmpechoreply
4icmpechorequest
5icmpdnr
6tcpsynonly
7tcpsynack
8tcpsynnack
9tcpfinack
10tcpfinnack
11tcprst
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.3
alaNetSecPortAnomalyStatsCurrentIngress
Count of Indexed packets ingress during current monitoring period.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.4
alaNetSecPortAnomalyStatsCurrentEgress
Count of Indexed packets egress during current monitoring period.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.5
alaNetSecPortAnomalyStatsLastIngress
Count of Indexed packets ingress during last monitoring period.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.6
alaNetSecPortAnomalyStatsLastEgress
Count of Indexed packets egress during last monitoring period.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.4.1.1.7
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1 · 1 row entry · 4 columns
Table for reporting Anomaly summaries
alaNetSecPortAnomalySummaryEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1.1
Summary are reported on a <port,summary-type,anomaly-type> basis
Indexes
alaNetSecPortAnomalySummaryIfId alaNetSecPortAnomalySummaryAnomaly
Column Syntax OID
alaNetSecPortAnomalySummaryIfId
Interface Index of port
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1.1.1
alaNetSecPortAnomalySummaryAnomaly
Anomaly type
AlaAnomalyType
Textual Convention: AlaAnomalyType Enumeration
Type Values:
0all
1arpaddressscan
2arpflood
3reserved
4arpfailure
5icmpaddressscan
6icmpflood
7icmpunreachable
8tcpportscan
9tcpaddressscan
10synflood
11synfailure
12synackscan
13finscan
14finackdiff
15rstcount
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1.1.2
alaNetSecPortAnomalySummaryObserved
Count of observations for indexed anomaly on indexed port since monitoring was enabled.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1.1.3
alaNetSecPortAnomalySummaryDetected
Count of detections for indexed anomaly on indexed port since monitoring was enabled.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.5.1.1.4
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1 · 1 row entry · 9 columns
Table for reporting port anomaly operation parameters
alaNetSecPortOpEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1
Each entry is identified by a unique port, and anomaly-type combination
Indexes
alaNetSecPortOpIfId alaNetSecPortOpAnomaly
Column Syntax OID
alaNetSecPortOpIfId
interface index of port
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.1
alaNetSecPortOpAnomaly
anomaly-type
AlaAnomalyType
Textual Convention: AlaAnomalyType Enumeration
Type Values:
0all
1arpaddressscan
2arpflood
3reserved
4arpfailure
5icmpaddressscan
6icmpflood
7icmpunreachable
8tcpportscan
9tcpaddressscan
10synflood
11synfailure
12synackscan
13finscan
14finackdiff
15rstcount
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.2
alaNetSecPortOpState
state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.3
alaNetSecPortOpLog
Logging state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.4
alaNetSecPortOpTrap
Trap state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.5
alaNetSecPortOpQuarantine
Quarantine state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.6
alaNetSecPortOpCount
activation-count being used by netsec on the indexed object
Integer32
Constraints:
range: 1-100000
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.7
alaNetSecPortOpSensitivity
sensitivity being used by netsec on the indexed object
Integer32
Constraints:
range: 1-100
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.8
alaNetSecPortOpPeriod
monitoring period being used by netsec on the indexed object
Integer32
Constraints:
range: 5-3600
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.6.1.1.9
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1 · 1 row entry · 9 columns
Table for reporting group anomaly operation parameters
alaNetSecGroupOpEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1
Each entry is identified by a unique group, and anomaly-type combination
Indexes
alaNetSecGroupOpName alaNetSecGroupOpAnomaly
Column Syntax OID
alaNetSecGroupOpName
name of the group
OctetString
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.1
alaNetSecGroupOpAnomaly
anomaly-type
AlaAnomalyType
Textual Convention: AlaAnomalyType Enumeration
Type Values:
0all
1arpaddressscan
2arpflood
3reserved
4arpfailure
5icmpaddressscan
6icmpflood
7icmpunreachable
8tcpportscan
9tcpaddressscan
10synflood
11synfailure
12synackscan
13finscan
14finackdiff
15rstcount
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.2
alaNetSecGroupOpState
state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.3
alaNetSecGroupOpLog
Logging state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.4
alaNetSecGroupOpTrap
Trap state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.5
alaNetSecGroupOpQuarantine
Quarantine state of anomaly
AlaNetsecStatus
Textual Convention: AlaNetsecStatus Enumeration
Type Values:
0default
1enable
2disable
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.6
alaNetSecGroupOpCount
activation-count being used by netsec on the indexed object
Integer32
Constraints:
range: 1-100000
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.7
alaNetSecGroupOpSensitivity
sensitivity being used by netsec on the indexed object
Integer32
Constraints:
range: 1-100
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.8
alaNetSecGroupOpPeriod
monitoring period being used by netsec on the indexed object
Integer32
Constraints:
range: 5-3600
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.7.1.1.9
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.8.1 · 1 row entry · 3 columns
Table of groups configured
alaNetSecGroupEntry entry .1.3.6.1.4.1.6486.801.1.2.1.48.1.1.8.1.1
Each entry identifies a configured group
Indexes
alaNetSecGroupName
Column Syntax OID
alaNetSecGroupName
Name of configured group
OctetString
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.8.1.1.1
alaNetSecGroupMemberPorts
Yes if there are ports in this group.
SNMPv2-TCTruthValue
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.8.1.1.2
alaNetSecGroupAnomalyCfg
Yes if any of this group's anomaly has a non-default configuration.
SNMPv2-TCTruthValue
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.6486.801.1.2.1.48.1.1.8.1.1.3