CISCO-AUTH-FRAMEWORK-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
52
.1.3.6.1.4.1.9.9.656.1.1.2 · 1 row entry · 3 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafAuthMethodRegTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafAuthMethodRegTable'
A list of authentication methods which are currrently
registered with Authentication Framework. 
          
An entry is created by the agent when an authentication method 
has successfully registered with Authentication Framework. 
          
An entry is deleted by the agent upon de-registration of the 
authentication method.
cafAuthMethodRegEntry row .1.3.6.1.4.1.9.9.656.1.1.2.1
An entry containing registration information of a particular
authentication method with Authentication Framework.
Indexes
Column Syntax OID
The authentication method registered with Authentication
Framework.
CiscoAuthMethod
Type Values:
1other
2dot1x
3macAuthBypass
4webAuth
.1.3.6.1.4.1.9.9.656.1.1.2.1.1
A unique number which indicates the default priority of a
authentication method.

The default priority is assigned by Authentication Framework
during method registration. The method with smallest value
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.1.2.1.2
A unique number which indicates the default execution order
of a authentication method.

The default execution order is assigned by Authentication
Framework during method registration. The method with
sm…
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.1.2.1.3
.1.3.6.1.4.1.9.9.656.1.2.1 · 1 row entry · 10 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafPortConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafPortConfigTable'
A list of port entries.  An entry will exist for each
interface which support Authentication Framework feature.
cafPortConfigEntry row .1.3.6.1.4.1.9.9.656.1.2.1.1
An entry containing management information of Authentication
Framework applicable to a particular port.
Indexes
Column Syntax OID
Specifies the controlled direction of this port.
CiscoAuthControlledDirectionsr/w
Type Values:
0both
1in
.1.3.6.1.4.1.9.9.656.1.2.1.1.1
Specifies the name of the fallback profile to be used when
failing over to Web Proxy Authentication. A zero length
string indicates that fallback mechanism to Web Proxy
Authentication is disabled in Authentication Fram…
SNMP-FRAMEWORK-MIBSnmpAdminStringr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.2.1.1.2
Specifies the authentication host mode for this port.
CiscoAuthHostModer/w
Type Values:
1singleHost
2multiHost
3multiAuth
4multiDomain
.1.3.6.1.4.1.9.9.656.1.2.1.1.3
Specifies if the Pre-Authentication Open Access feature
allows clients/devices to gain network access before
authentication is performed.

A value of 'true' for this object indicates that client/device
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.2.1.1.4
Specifies the authorization control for this port.
CiscoAuthControlledPortControlr/w
Type Values:
1forceUnauthorized
2auto
3forceAuthorized
.1.3.6.1.4.1.9.9.656.1.2.1.1.5
Specifies if reauthentication is enabled for this port.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.2.1.1.6
Specifies the reauthentication interval, after which the port
will be reauthenticated if value of the corresponding instance
of cafPortReauthEnabled is 'true'.

A value of zero indicates that the reauthent…
secondsSNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.2.1.1.7
Specifies the interval after which a further authentication
attempt should be made to this port if it is not authorized.

A value of zero indicates that no further authentication attempt
will be made if th…
secondsSNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.2.1.1.8
Specifies the period of time that a client associating with
this
port is allowed to be inactive before being terminated.

A value of zero indicates that inactivity timeout is disabled on

thi…
secondsInteger32r/w
Constraints:
range: -1-65535
.1.3.6.1.4.1.9.9.656.1.2.1.1.9
Specifies the action to be taken due to a security violation
occurs on this port.

restrict: This port will be moved to restricted state.

shutdown: This port will be shutdown fro…
Enumerationr/w
Enumerated Values:
1restrict
2shutdown
3protect
4replace
.1.3.6.1.4.1.9.9.656.1.2.1.1.10
.1.3.6.1.4.1.9.9.656.1.2.2 · 1 row entry · 5 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafPortMethodTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafPortMethodTable'
The table contains a list of port entries.  An entry will exist
for each port which supports Authentication Framework feature.
cafPortMethodEntry row .1.3.6.1.4.1.9.9.656.1.2.2.1
Entry containing configuration and information of
authentication methods for a particular port.
Indexes
Column Syntax OID
This object specifies the administrative execution order of
authentication methods on the port. Methods are executed in
the order as specified in the method list.

Method which is at the beginning of the …
CiscoAuthMethodListr/w .1.3.6.1.4.1.9.9.656.1.2.2.1.1
This object specifies the administrative priority of
authentication methods on the port. The priority of
each method is assigned based on the method list.

Method which is at the beginning of the method l…
CiscoAuthMethodListr/w .1.3.6.1.4.1.9.9.656.1.2.2.1.2
This object indicates the authentication methods currently
available on this port.
CiscoAuthMethodList .1.3.6.1.4.1.9.9.656.1.2.2.1.3
This object indicates the operational execution order of
authentication methods on this port. Methods are executed in
the order as specified in the method list.

Method which is at the beginning of the me…
CiscoAuthMethodList .1.3.6.1.4.1.9.9.656.1.2.2.1.4
This object indicates the operational priority of
authentication methods on this port. Methods have the
priority as specified in the method list.

Method which is at the beginning of the method list has
h…
CiscoAuthMethodList .1.3.6.1.4.1.9.9.656.1.2.2.1.5
.1.3.6.1.4.1.9.9.656.1.3.1 · 1 row entry · 4 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafAuthFailedEventPortTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafAuthFailedEventPortTable'
The table contains a list of port entries.
          
An entry will exist for each port which supports Authentication
Fail event within the Authentication Framework.
cafAuthFailedEventPortEntry row .1.3.6.1.4.1.9.9.656.1.3.1.1
Entry containing management information of Authentication
Fail event for a particular port.
Indexes
Column Syntax OID
This object specifies the maximum number of retry should be
performed before generating Authentication Fail event.

A value of zero indicates that Authentication Fail event will
be generated upon authentic…
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.3.1.1.1
This object specifies whether no action will be performed
when an Authentication Fail event occurs.

Setting 'true' on this object indicates that no action will
be performed when Authentication Fail event …
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.3.1.1.2
This object specifies the Authentication Failed VLAN number.

The read-only value of -1 indicates that this object is not
applicable on this port.

The read-only value of zero indicates that …
Integer32r/w
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.656.1.3.1.1.3
This object specifies whether the next authentication method
will be used if an Authentication Fail event is generated by the
current authentication method.

Setting this object to 'true' indicates that th…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.3.1.1.4
.1.3.6.1.4.1.9.9.656.1.3.2 · 1 row entry · 2 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafClientNoRespEventPortTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafClientNoRespEventPortTable'
The table contains a list of port entries.
          
An entry exists for each port which supports No Response
event within the Authentication Framework.
cafClientNoRespEventPortEntry row .1.3.6.1.4.1.9.9.656.1.3.2.1
Entry containing management information of No Response
event for a particular port.
Indexes
Column Syntax OID
This object specifies whether an action is performed when No
Response event occurs.

Setting 'true' on this object indicates that no action will
be performed when No Response event occurs.

T…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.3.2.1.1
This object specifies the No Response Authorized VLAN number.

The read-only value of -1 indicates that this object is not
applicable on this port.

The read-only value of zero indicates that…
Integer32r/w
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.656.1.3.2.1.2
.1.3.6.1.4.1.9.9.656.1.3.3 · 1 row entry · 4 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafServerEventPortTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafServerEventPortTable'
The table contains a list of port entries.
          
An entry exists for each port which supports AAA Server
Reachability event within the Authentication Framework.
cafServerEventPortEntry row .1.3.6.1.4.1.9.9.656.1.3.3.1
Entry containing management information of AAA Server
Reachability event for a particular port.
Indexes
Column Syntax OID
This object indicates whether an action is performed if an
AAA Server Reachability event occurs.

Setting 'true' on this object indicates that no action
will be performed when AAA Server Reachability event…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.3.3.1.1
This object specifies if current authorization will remain
unchanged for the port when AAA Server Reachability event
occurs.

Setting 'true' on this object indicates that current
authorization will remain …
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.3.3.1.2
This object specifies the AAA Server Reachability
Authorized VLAN number.

The read-only value of -1 indicates that this object is not
applicable on this port.

The read-only value of zero in…
Integer32r/w
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.656.1.3.3.1.3
This object specifies the action applied to the port upon AAA
recovery.

none : no action will be applied.
reinitialize: the port will be reinitialized with the current
authentication m…
Enumerationr/w
Enumerated Values:
1none
2reinitialize
.1.3.6.1.4.1.9.9.656.1.3.3.1.4
.1.3.6.1.4.1.9.9.656.1.4.1 · 1 row entry · 22 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafSessionTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafSessionTable'
The table contains a list of authentication session.
          
An entry is created when an authentication session has
successfully created within Authentication Framework.
          
An entry is deleted when an authentication session has been
removed.
cafSessionEntry row .1.3.6.1.4.1.9.9.656.1.4.1.1
Entry containing management information for a particular
authentication session.
Column Syntax OID
A unique identifier of the authentication session.
OctetString
Constraints:
range: 1-64
.1.3.6.1.4.1.9.9.656.1.4.1.1.1
Indicates the MAC address of the device associates with the
authentication session.
SNMPv2-TCMacAddress
Type Constraints:
range: 6
Description:
Represents an 802 MAC address represented in the
`canonical' order defined by IEEE 802.1a, i.e., as if it
were transmitted least significant bit first, even though
802.5 (in contrast to other 802.x protocols) requires M…
.1.3.6.1.4.1.9.9.656.1.4.1.1.2
Indicates the type of Internet address of the client
associates with the authentication session.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.656.1.4.1.1.3
Indicates the Internet address of the client associates with
the authentication session. The type of this address is
determined by the value of cafSessionClientAddrType object.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.4
Indicates the current status of the authentication session.

idle : the session has been initialized and no
method has run yet.

running : an authentication method is r…
Enumeration
Enumerated Values:
1idle
2running
3noMethod
4authenticationSuccess
5authenticationFailed
6authorizationSuccess
7authorizationFailed
.1.3.6.1.4.1.9.9.656.1.4.1.1.5
Indicates the type of domain that the authentication session
belongs to.

other : none of the below.

data : indicates the data domain.

voice: indicates the voice domain.
Enumeration
Enumerated Values:
1other
2data
3voice
.1.3.6.1.4.1.9.9.656.1.4.1.1.6
Indicates the authentication host mode of the port in the
authentication session.
CiscoAuthHostMode
Type Values:
1singleHost
2multiHost
3multiAuth
4multiDomain
.1.3.6.1.4.1.9.9.656.1.4.1.1.7
Indicates the operational controlled directions parameter
for this port in the authentication session.
CiscoAuthControlledDirections
Type Values:
0both
1in
.1.3.6.1.4.1.9.9.656.1.4.1.1.8
Indicates the posture token associates with the authentication
session.
CISCO-NAC-TC-MIBCnnEouPostureTokenString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.9
Indicates the name of the authenticated user for the
authentication session.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.10
Indicates the name of the address pool from which the
session's client IP address is assigned.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.11
Indicates the name of the feature which authorizes the
authentication session.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.12
Indicates the leftover time before the next authentication
attempt for the authentication session after Server Reachability
event occurred. Value zero indicates that this session is
currently being authenticated or it …
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.4.1.1.13
Indicates the authorized VLAN applied to the authentication
session. Value zero indicates that no authorized VLAN has been
applied, or it is not applicable.
CISCO-PRIVATE-VLAN-MIBVlanIndexOrZero
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.656.1.4.1.1.14
Indicates the session timeout used by Authentication
Framework in the authentication session.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.4.1.1.15
Indicates the leftover time of the current authentication
session.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.4.1.1.16
Indicates the timeout action on the authentication session,
when value of the corresponding instance of cafSessionTimeLeft
reaches zero.

unknown : None of the below.

terminate …
Enumeration
Enumerated Values:
1unknown
2terminate
3reauthenticate
.1.3.6.1.4.1.9.9.656.1.4.1.1.17
Indicates the inactivity timeout used by Authentication
Framework in the authentication session.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.4.1.1.18
Indicates the leftover time of the inactivity timer of
the authentication session.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.656.1.4.1.1.19
The reauthentication control for the authentication session.
Setting this object to 'true' cause the current authenticated
session to reauthenticate the authenticated client. Setting
this object to 'false' has no effect…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.4.1.1.20
The termination request control for the authentication session.
Setting this object to 'true' terminates the current session.
Setting this object to 'false' has no effect.

This object always returns 'fals…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.656.1.4.1.1.21
The name of the VLAN group that has been used during VLAN
assignment for this session.

A zero length string indicates that there is no VLAN group been
used during VLAN assignment.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.656.1.4.1.1.22
.1.3.6.1.4.1.9.9.656.1.4.2 · 1 row entry · 2 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cafSessionMethodsInfoTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-AUTH-FRAMEWORK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-AUTH-FRAMEWORK-MIB::cafSessionMethodsInfoTable'
The table contains a list of authentication method for every
authentication session.
          
An entry exists for each authentication method that can
authenticate an authentication session within
Authentication Framework.
cafSessionMethodsInfoEntry row .1.3.6.1.4.1.9.9.656.1.4.2.1
Entry containing method information for a particular runnable
authentication methods which is associated with a session for
an Authentication Framework managed port.
Column Syntax OID
Indicates this authentication method.
CiscoAuthMethod
Type Values:
1other
2dot1x
3macAuthBypass
4webAuth
.1.3.6.1.4.1.9.9.656.1.4.2.1.1
Indicates the state of this authentication method.

notRun : The method has not run for this session.

running : The method is running for this session.

failedOver : …
Enumeration
Enumerated Values:
1notRun
2running
3failedOver
4authcSuccess
5authcFailed
.1.3.6.1.4.1.9.9.656.1.4.2.1.2