CISCO-AUTH-FRAMEWORK-MIB
MIB module for Authentication Framework in the system.
Authentication Framework provides generic configurations
for authentication methods in the system and manage the
failover sequence of these methods in a flexible manner.
- Source file
CISCO-AUTH-FRAMEWORK-MIB- Last revised
- Identity
ciscoAuthFrameworkMIB- Base OID
1.3.6.1.4.1.9.9.656
Imported Objects
| CISCO-NAC-TC-MIB | CnnEouPostureTokenString |
| CISCO-PRIVATE-VLAN-MIB | VlanIndexOrZero |
| CISCO-SMI | ciscoMgmt |
| IF-MIB | ifIndex ifName |
| INET-ADDRESS-MIB | InetAddress InetAddressType |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | MacAddress TEXTUAL-CONVENTION (no object page) TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-AUTH-FRAMEWORK-MIB::ciscoAuthFrameworkMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::ciscoAuthFrameworkMIB'
Objects (88)
Showing 88 of 88 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.656 |
||
.1.3.6.1.4.1.9.9.656.0 |
||
.1.3.6.1.4.1.9.9.656.1 |
||
.1.3.6.1.4.1.9.9.656.1.1 |
||
|
millisecondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.1.1 |
|
.1.3.6.1.4.1.9.9.656.1.1.2 |
||
.1.3.6.1.4.1.9.9.656.1.1.2.1 |
||
.1.3.6.1.4.1.9.9.656.1.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.1.2.1.2 |
||
.1.3.6.1.4.1.9.9.656.1.1.2.1.3 |
||
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.1.3 |
.1.3.6.1.4.1.9.9.656.1.1.4 |
||
.1.3.6.1.4.1.9.9.656.1.1.5 |
||
.1.3.6.1.4.1.9.9.656.1.2 |
||
.1.3.6.1.4.1.9.9.656.1.2.1 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.2.1.1.10 |
|
.1.3.6.1.4.1.9.9.656.1.2.1.1.2 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1.4 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1.5 |
||
.1.3.6.1.4.1.9.9.656.1.2.1.1.6 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.2.1.1.7 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.2.1.1.8 |
|
|
secondsInteger32
|
.1.3.6.1.4.1.9.9.656.1.2.1.1.9 |
|
.1.3.6.1.4.1.9.9.656.1.2.2 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1.2 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1.3 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1.4 |
||
.1.3.6.1.4.1.9.9.656.1.2.2.1.5 |
||
.1.3.6.1.4.1.9.9.656.1.3 |
||
.1.3.6.1.4.1.9.9.656.1.3.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.1.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.1.1.2 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.656.1.3.1.1.3 |
|
.1.3.6.1.4.1.9.9.656.1.3.1.1.4 |
||
.1.3.6.1.4.1.9.9.656.1.3.2 |
||
.1.3.6.1.4.1.9.9.656.1.3.2.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.2.1.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.656.1.3.2.1.2 |
|
.1.3.6.1.4.1.9.9.656.1.3.3 |
||
.1.3.6.1.4.1.9.9.656.1.3.3.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.3.1.1 |
||
.1.3.6.1.4.1.9.9.656.1.3.3.1.2 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.656.1.3.3.1.3 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.3.3.1.4 |
|
.1.3.6.1.4.1.9.9.656.1.4 |
||
.1.3.6.1.4.1.9.9.656.1.4.1 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.1 |
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.10 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.11 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.12 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.13 |
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.14 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.15 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.16 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.17 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.18 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.19 |
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.2 |
||
|
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.20 |
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.21 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.22 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.3 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.5 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.6 |
|
.1.3.6.1.4.1.9.9.656.1.4.1.1.7 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.8 |
||
.1.3.6.1.4.1.9.9.656.1.4.1.1.9 |
||
.1.3.6.1.4.1.9.9.656.1.4.2 |
||
.1.3.6.1.4.1.9.9.656.1.4.2.1 |
||
.1.3.6.1.4.1.9.9.656.1.4.2.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.656.1.4.2.1.2 |
|
.1.3.6.1.4.1.9.9.656.1.5 |
||
.1.3.6.1.4.1.9.9.656.1.5.1 |
||
.1.3.6.1.4.1.9.9.656.1.5.2 |
||
.1.3.6.1.4.1.9.9.656.1.6 |
||
.1.3.6.1.4.1.9.9.656.1.6.1 |
||
.1.3.6.1.4.1.9.9.656.1.6.2 |
||
.1.3.6.1.4.1.9.9.656.2 |
||
.1.3.6.1.4.1.9.9.656.2.1 |
||
.1.3.6.1.4.1.9.9.656.2.2 |
Dependencies (14) 9 direct · 5 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-NAC-TC-MIBcisco
- CISCO-TCcisco
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- INET-ADDRESS-MIBrfc
- RMON-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-VTP-MIBcisco
- CISCO-PRIVATE-VLAN-MIBcisco
- CISCO-AUTH-FRAMEWORK-MIBciscoselected
Type Definitions (5)
| Enumeration |
both(0)in(1) |
|
| Enumeration |
forceUnauthorized(1)auto(2)forceAuthorized(3) |
|
| Enumeration |
singleHost(1)multiHost(2)multiAuth(3)multiDomain(4) |
|
| Enumeration |
other(1)dot1x(2)macAuthBypass(3)webAuth(4) |
|
| OctetString |
Conformance Groups (18)
|
A collection of objects that provides registration
information of authentication methods in Authentication Framework. |
.1.3.6.1.4.1.9.9.656.2.2.1
|
|
|
A collection of objects that provides AAA recovery delay
configuration for Authentication Framework in the system. |
.1.3.6.1.4.1.9.9.656.2.2.2
|
|
|
cafPortControlledDirection cafPortFallBackProfile cafPortAuthHostMode cafPortPreAuthOpenAccess cafPortAuthorizeControl cafPortReauthEnabled cafPortReauthInterval cafPortRestartInterval cafPortInactivityTimeout cafPortViolationAction
A collection of objects that provides configuration of
Authentication Framework for capable ports in the system. |
.1.3.6.1.4.1.9.9.656.2.2.3
|
|
|
cafPortMethodAdminExecOrder cafPortMethodAdminPriority cafPortMethodAvailable cafPortMethodOperExecOrder cafPortMethodOperPriority
A collection of objects that provides configuration and
information of authentication methods within Authentication Framework for capable ports in the system. |
.1.3.6.1.4.1.9.9.656.2.2.4
|
|
|
cafAuthFailedMaxRetry cafAuthFailedNoActionEnabled cafAuthFailedAuthorizedVlan cafAuthFailedNextMethodEnabled
A collection of objects that provides configuration of
Auth-Failed behaviour of Authentication Framework for ports in the system. |
.1.3.6.1.4.1.9.9.656.2.2.5
|
|
|
A collection of objects that provides configuration of
Authentication Framework when no-responsive client is detected on a port in the system. |
.1.3.6.1.4.1.9.9.656.2.2.6
|
|
|
cafServerDeadNoActionEnabled cafServerDeadRemainAuthorized cafServerDeadAuthorizedVlan cafServerAliveAction
A collection of objects that provides configuration of
Authentication Framework when AAA Server Reachability event occurs. |
.1.3.6.1.4.1.9.9.656.2.2.7
|
|
|
cafSessionClientMacAddress cafSessionClientAddrType cafSessionClientAddress cafSessionDomain cafSessionStatus cafSessionAuthHostMode cafSessionControlledDirection cafSessionPostureToken cafSessionAuthUserName cafSessionClientFramedIpPool cafSessionAuthorizedBy cafSessionCriticalTimeLeft cafSessionAuthVlan cafSessionTimeout cafSessionTimeLeft cafSessionTimeoutAction cafSessionInactivityTimeout cafSessionInactivityTimeLeft cafSessionReauth cafSessionTerminate
A collection of objects that provides authentication session
management information for Authentication Framework. |
.1.3.6.1.4.1.9.9.656.2.2.8
|
|
|
A collection of objects that provides information about
authentication methods associate with Authentication Framework 's authentication sessions in the system. |
.1.3.6.1.4.1.9.9.656.2.2.9
|
|
|
A collection of objects that provides control over
security violation notification for Authentication Framework in the system. |
.1.3.6.1.4.1.9.9.656.2.2.10
|
|
|
A collection of notification providing information
about port's security violation in Authentication Framework. |
.1.3.6.1.4.1.9.9.656.2.2.11
|
|
|
A collection of objects providing MAC address of the offending
client in the security violation notification. |
.1.3.6.1.4.1.9.9.656.2.2.12
|
|
|
A collection of objects providing VLAN group information of
authenticated session in Authentication Framework. |
.1.3.6.1.4.1.9.9.656.2.2.13
|
|
|
A collection of objects providing MAC move cofiguration
information for Authentication Framework on the device. |
.1.3.6.1.4.1.9.9.656.2.2.14
|
|
|
A collection of objects providing configuration information
for the device's behaviour on CoA commands. |
.1.3.6.1.4.1.9.9.656.2.2.15
|
|
|
A collection of notification providing information
about port's authentication failure in Authentication Framework. |
.1.3.6.1.4.1.9.9.656.2.2.16
|
|
|
A collection of objects that provides control over
authentication failure notification for Authentication Framework in the system. |
.1.3.6.1.4.1.9.9.656.2.2.17
|
|
|
A collection of objects providing MAC address of the failed
client in the authentication failure notification. |
.1.3.6.1.4.1.9.9.656.2.2.18
|
Compliance Statements (4)
OID
.1.3.6.1.4.1.9.9.656.2.1.1The compliance statement for entities which implement
CISCO-AUTH-FRAMEWORK-MIB.
CISCO-AUTH-FRAMEWORK-MIB.
Required groups
| mandatory | cafAuthMethodRegGroup | |
| mandatory | cafAuthPortConfigGroup | |
| mandatory | cafPortMethodGroup | |
| mandatory | cafSessionGroup | |
| mandatory | cafSessionMethodInfoGroup | |
| optional | cafAaaNoRespRecoveryDelayGroup |
This group is mandatory in devices running software which provide AAA recovery delay configuration for Authentication Framework. |
| optional | cafAuthFailedEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on its capable ports, when Authentication Fail event occurs. |
| optional | cafClientNoRespEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework to authorize ports in a special VLAN when non-capable clients are detected. |
| optional | cafServerEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on authenticated ports when AAA Server Reachability event occurs. |
| optional | cafSecViolationNotifEnableGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationNotifGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationClientGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cafAaaNoRespRecoveryDelay | readonly | Write access is not required. | |
| cafPortControlledDirection | readonly | Write access is not required. | |
| cafPortFallBackProfile | readonly | Write access is not required. | |
| cafPortAuthHostMode | readonly | Write access is not required. | |
| cafPortPreAuthOpenAccess | readonly | Write access is not required. | |
| cafPortAuthorizeControl | readonly | Write access is not required. | |
| cafPortReauthEnabled | readonly | Write access is not required. | |
| cafPortReauthInterval | readonly | Write access is not required. | |
| cafPortRestartInterval | readonly | Write access is not required. | |
| cafPortInactivityTimeout | readonly | Write access is not required. | |
| cafPortViolationAction | readonly | Write access is not required. | |
| cafPortMethodAdminExecOrder | readonly | Write access is not required. | |
| cafPortMethodAdminPriority | readonly | Write access is not required. | |
| cafAuthFailedMaxRetry | readonly | Write access is not required. | |
| cafAuthFailedNoActionEnabled | readonly | Write access is not required. | |
| cafAuthFailedAuthorizedVlan | readonly | Write access is not required. | |
| cafAuthFailedNextMethodEnabled | readonly | Write access is not required. | |
| cafClientNoRespNoActionEnabled | readonly | Write access is not required. | |
| cafClientNoRespAuthorizedVlan | readonly | Write access is not required. | |
| cafServerDeadNoActionEnabled | readonly | Write access is not required. | |
| cafServerDeadRemainAuthorized | readonly | Write access is not required. | |
| cafServerDeadAuthorizedVlan | readonly | Write access is not required. | |
| cafServerAliveAction | readonly | Write access is not required. | |
| cafSessionReauth | readonly | Write access is not required. | |
| cafSessionTerminate | readonly | Write access is not required. | |
| cafSecurityViolationNotifEnable | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.656.2.1.2The compliance statement for entities which implement
CISCO-AUTH-FRAMEWORK-MIB.
CISCO-AUTH-FRAMEWORK-MIB.
Required groups
| mandatory | cafAuthMethodRegGroup | |
| mandatory | cafAuthPortConfigGroup | |
| mandatory | cafPortMethodGroup | |
| mandatory | cafSessionGroup | |
| mandatory | cafSessionMethodInfoGroup | |
| optional | cafAaaNoRespRecoveryDelayGroup |
This group is mandatory in devices running software which provide AAA recovery delay configuration for Authentication Framework. |
| optional | cafAuthFailedEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on its capable ports, when Authentication Fail event occurs. |
| optional | cafClientNoRespEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework to authorize ports in a special VLAN when non-capable clients are detected. |
| optional | cafServerEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on authenticated ports when AAA Server Reachability event occurs. |
| optional | cafSecViolationNotifEnableGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationNotifGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationClientGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSessionVlanGroupNameGroup |
This group is mandatory in devices running software which provide VLAN group information for Authentication Framework. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cafAaaNoRespRecoveryDelay | readonly | Write access is not required. | |
| cafPortControlledDirection | readonly | Write access is not required. | |
| cafPortFallBackProfile | readonly | Write access is not required. | |
| cafPortAuthHostMode | readonly | Write access is not required. | |
| cafPortPreAuthOpenAccess | readonly | Write access is not required. | |
| cafPortAuthorizeControl | readonly | Write access is not required. | |
| cafPortReauthEnabled | readonly | Write access is not required. | |
| cafPortReauthInterval | readonly | Write access is not required. | |
| cafPortRestartInterval | readonly | Write access is not required. | |
| cafPortInactivityTimeout | readonly | Write access is not required. | |
| cafPortViolationAction | readonly | Write access is not required. | |
| cafPortMethodAdminExecOrder | readonly | Write access is not required. | |
| cafPortMethodAdminPriority | readonly | Write access is not required. | |
| cafAuthFailedMaxRetry | readonly | Write access is not required. | |
| cafAuthFailedNoActionEnabled | readonly | Write access is not required. | |
| cafAuthFailedAuthorizedVlan | readonly | Write access is not required. | |
| cafAuthFailedNextMethodEnabled | readonly | Write access is not required. | |
| cafClientNoRespNoActionEnabled | readonly | Write access is not required. | |
| cafClientNoRespAuthorizedVlan | readonly | Write access is not required. | |
| cafServerDeadNoActionEnabled | readonly | Write access is not required. | |
| cafServerDeadRemainAuthorized | readonly | Write access is not required. | |
| cafServerDeadAuthorizedVlan | readonly | Write access is not required. | |
| cafServerAliveAction | readonly | Write access is not required. | |
| cafSessionReauth | readonly | Write access is not required. | |
| cafSessionTerminate | readonly | Write access is not required. | |
| cafSecurityViolationNotifEnable | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.656.2.1.3The compliance statement for entities which implement
CISCO-AUTH-FRAMEWORK-MIB.
CISCO-AUTH-FRAMEWORK-MIB.
Required groups
| mandatory | cafAuthMethodRegGroup | |
| mandatory | cafAuthPortConfigGroup | |
| mandatory | cafPortMethodGroup | |
| mandatory | cafSessionGroup | |
| mandatory | cafSessionMethodInfoGroup | |
| optional | cafAaaNoRespRecoveryDelayGroup |
This group is mandatory in devices running software which provide AAA recovery delay configuration for Authentication Framework. |
| optional | cafAuthFailedEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on its capable ports, when Authentication Fail event occurs. |
| optional | cafClientNoRespEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework to authorize ports in a special VLAN when non-capable clients are detected. |
| optional | cafServerEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on authenticated ports when AAA Server Reachability event occurs. |
| optional | cafSecViolationNotifEnableGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationNotifGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationClientGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSessionVlanGroupNameGroup |
This group is mandatory in devices running software which provide VLAN group information for Authentication Framework. |
| optional | cafMacMoveConfigGroup |
This group is mandatory in devices running software which provide MAC move configuration for Authentication Framework. |
| optional | cafCoACommandConfigGroup |
This group is mandatory in devices running software which provide configuration for behavor for CoA commands for Authentication Framework. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cafAaaNoRespRecoveryDelay | readonly | Write access is not required. | |
| cafPortControlledDirection | readonly | Write access is not required. | |
| cafPortFallBackProfile | readonly | Write access is not required. | |
| cafPortAuthHostMode | readonly | Write access is not required. | |
| cafPortPreAuthOpenAccess | readonly | Write access is not required. | |
| cafPortAuthorizeControl | readonly | Write access is not required. | |
| cafPortReauthEnabled | readonly | Write access is not required. | |
| cafPortReauthInterval | readonly | Write access is not required. | |
| cafPortRestartInterval | readonly | Write access is not required. | |
| cafPortInactivityTimeout | readonly | Write access is not required. | |
| cafPortViolationAction | readonly | Write access is not required. | |
| cafPortMethodAdminExecOrder | readonly | Write access is not required. | |
| cafPortMethodAdminPriority | readonly | Write access is not required. | |
| cafAuthFailedMaxRetry | readonly | Write access is not required. | |
| cafAuthFailedNoActionEnabled | readonly | Write access is not required. | |
| cafAuthFailedAuthorizedVlan | readonly | Write access is not required. | |
| cafAuthFailedNextMethodEnabled | readonly | Write access is not required. | |
| cafClientNoRespNoActionEnabled | readonly | Write access is not required. | |
| cafClientNoRespAuthorizedVlan | readonly | Write access is not required. | |
| cafServerDeadNoActionEnabled | readonly | Write access is not required. | |
| cafServerDeadRemainAuthorized | readonly | Write access is not required. | |
| cafServerDeadAuthorizedVlan | readonly | Write access is not required. | |
| cafServerAliveAction | readonly | Write access is not required. | |
| cafSessionReauth | readonly | Write access is not required. | |
| cafSessionTerminate | readonly | Write access is not required. | |
| cafSecurityViolationNotifEnable | readonly | Write access is not required. | |
| cafMacMoveMode | readonly | Write access is not required. | |
| cafCoABouncePortCommandIgnoreEnabled | readonly | Write access is not required. | |
| cafCoADisablePortCommandIgnoreEnabled | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.656.2.1.4The compliance statement for entities which implement
CISCO-AUTH-FRAMEWORK-MIB.
CISCO-AUTH-FRAMEWORK-MIB.
Required groups
| mandatory | cafAuthMethodRegGroup | |
| mandatory | cafAuthPortConfigGroup | |
| mandatory | cafPortMethodGroup | |
| mandatory | cafSessionGroup | |
| mandatory | cafSessionMethodInfoGroup | |
| optional | cafAaaNoRespRecoveryDelayGroup |
This group is mandatory in devices running software which provide AAA recovery delay configuration for Authentication Framework. |
| optional | cafAuthFailedEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on its capable ports, when Authentication Fail event occurs. |
| optional | cafClientNoRespEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework to authorize ports in a special VLAN when non-capable clients are detected. |
| optional | cafServerEventGroup |
This group is mandatory in devices running software which provide configuration for Authentication Framework on authenticated ports when AAA Server Reachability event occurs. |
| optional | cafSecViolationNotifEnableGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationNotifGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSecurityViolationClientGroup |
This group is mandatory in devices running software which support security violation notification for Authentication Framework. |
| optional | cafSessionVlanGroupNameGroup |
This group is mandatory in devices running software which provide VLAN group information for Authentication Framework. |
| optional | cafMacMoveConfigGroup |
This group is mandatory in devices running software which provide MAC move configuration for Authentication Framework. |
| optional | cafCoACommandConfigGroup |
This group is mandatory in devices running software which provide configuration for behavor for CoA commands for Authentication Framework. |
| optional | cafAuthFailNotifGroup |
This group is mandatory in devices running software which support authentication failure notification for Authentication Framework. |
| optional | cafAuthFailNotifEnableGroup |
This group is mandatory in devices running software which support authentication failure notification for Authentication Framework. |
| optional | cafAuthFailClientGroup |
This group is mandatory in devices running software which support authentication failure notification for Authentication Framework. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cafAaaNoRespRecoveryDelay | readonly | Write access is not required. | |
| cafPortControlledDirection | readonly | Write access is not required. | |
| cafPortFallBackProfile | readonly | Write access is not required. | |
| cafPortAuthHostMode | readonly | Write access is not required. | |
| cafPortPreAuthOpenAccess | readonly | Write access is not required. | |
| cafPortAuthorizeControl | readonly | Write access is not required. | |
| cafPortReauthEnabled | readonly | Write access is not required. | |
| cafPortReauthInterval | readonly | Write access is not required. | |
| cafPortRestartInterval | readonly | Write access is not required. | |
| cafPortInactivityTimeout | readonly | Write access is not required. | |
| cafPortViolationAction | readonly | Write access is not required. | |
| cafPortMethodAdminExecOrder | readonly | Write access is not required. | |
| cafPortMethodAdminPriority | readonly | Write access is not required. | |
| cafAuthFailedMaxRetry | readonly | Write access is not required. | |
| cafAuthFailedNoActionEnabled | readonly | Write access is not required. | |
| cafAuthFailedAuthorizedVlan | readonly | Write access is not required. | |
| cafAuthFailedNextMethodEnabled | readonly | Write access is not required. | |
| cafClientNoRespNoActionEnabled | readonly | Write access is not required. | |
| cafClientNoRespAuthorizedVlan | readonly | Write access is not required. | |
| cafServerDeadNoActionEnabled | readonly | Write access is not required. | |
| cafServerDeadRemainAuthorized | readonly | Write access is not required. | |
| cafServerDeadAuthorizedVlan | readonly | Write access is not required. | |
| cafServerAliveAction | readonly | Write access is not required. | |
| cafSessionReauth | readonly | Write access is not required. | |
| cafSessionTerminate | readonly | Write access is not required. | |
| cafSecurityViolationNotifEnable | readonly | Write access is not required. | |
| cafMacMoveMode | readonly | Write access is not required. | |
| cafCoABouncePortCommandIgnoreEnabled | readonly | Write access is not required. | |
| cafCoADisablePortCommandIgnoreEnabled | readonly | Write access is not required. |
Notifications / Traps (2)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.656.0.1 |
A cafSecurityViolationNotif is sent if a security violation
is detected on a port, and the instance value of cafSecurityViolationNotifEnable is 'true'. |
|
.1.3.6.1.4.1.9.9.656.0.2 |
A cafAuthFailNotif is sent if an authentication failure is
detected on a port, and the instance value of cafAuthFailNotifEnable is 'true'. ifName contains the name of the interface where the authentication failure happened. cafAuthFailClient contains the mac address of the client which failed to authenticate. |