CISCO-CATOS-ACL-QOS-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
37
Rows
37
Columns
245
.1.3.6.1.4.1.9.9.179.1.1.1 · 1 row entry · 2 columns
This table contains the mapping of Cos values to DSCP values.
This map is used to associate the Cos of packets arriving at a
port to a DSCP where the port's trust state is trustCoS(2). 
This map is a table of eight Cos values (0 through 7) and their
corresponding DSCP values. This mapping applies to every port on
the device.
caqCosToDscpEntry entry .1.3.6.1.4.1.9.9.179.1.1.1.1
Each row contains the mapping from a CoS value to a DSCP
value.
Indexes
caqCosToDscpCos
Column Syntax OID
caqCosToDscpCos
The CoS value being mapped to the DSCP value in this device.
CISCO-QOS-PIB-MIBQosLayer2Cos
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.1.1.1.1
caqCosToDscpDscp
The DSCP value which the CoS value maps to. The default
configuration is :

CoS DSCP
0 0
1 8
2 16
3 24
4 32
5 40
6 48
7 56
.
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.1.1.2
.1.3.6.1.4.1.9.9.179.1.1.2 · 1 row entry · 2 columns
This table contains the mapping of IP Precedence to DSCP.
This map is used to associate the IP Precedence of IP packets
arriving at a port to a DSCP where the port's trust state is 
trustIpPrec(3).  This map is a table of eight IpPrecedence
values (0 through 7) and their corresponding DSCP values. 
This mapping applies to every port on the device.
caqIpPrecToDscpEntry entry .1.3.6.1.4.1.9.9.179.1.1.2.1
Each row contains the mapping from an IP Precedence value to
a DSCP value.
Indexes
caqIpPrecToDscpIpPrec
Column Syntax OID
caqIpPrecToDscpIpPrec
The IP Precedence value being mapped to the DSCP value in
this device.
CaqIpPrecedence
Textual Convention: CaqIpPrecedence Unsigned32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.1.2.1.1
caqIpPrecToDscpDscp
The DSCP value which the IP Precedence value maps to. The
default configuration is the identity function :

IPPrec DSCP
0 0
1 8
2 16
3 24
4 32
5 …
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.2.1.2
.1.3.6.1.4.1.9.9.179.1.1.3 · 1 row entry · 4 columns
This table always has 64 entries, one for each DSCP value. The
table contains three mappings from the DSCP value assigned to
a packet. One mapping is to the egress CoS to be stored in the
layer-2 frame headers for output on 802.1Q or ISL interfaces.
The other two mappings are to the remarked (or 'marked down')
DSCP values which are used when a policer's requires that 
a packet's DSCP value to be modified. Of these two mappings,
one is for a Normal Rate policer, and the other is for an 
Excess Rate policer.  These mappings apply for every port on the
device.
caqDscpMappingEntry entry .1.3.6.1.4.1.9.9.179.1.1.3.1
Each row contains the mapping from DSCP value to CoS value
and policed DSCP.
Indexes
caqDscpMappingDscp
Column Syntax OID
caqDscpMappingDscp
The DSCP value being mapped to the CoS value and policed DSCP
value in this device.
CISCO-QOS-PIB-MIBDscp
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.3.1.1
caqDscpMappingCos
The CoS value which the DSCP values maps to.

The default configuration is calculated from the
formula CoS = DSCP divide by 8.
That is:
DSCP 0-7 all map to CoS 0;
DSCP 8-15 all map to CoS 1;
...
DSCP …
CISCO-QOS-PIB-MIBQosLayer2Cosr/w
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.1.3.1.2
caqDscpMappingNRPolicedDscp
The normal rate policed DSCP value which the DSCP values maps
to. The normal rate default mapping of DSCP to 'marked down'
DSCP is the identity function.
That is:
63 -> 63
62 -> 62
...
31 -> 31
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.3.1.3
caqDscpMappingERPolicedDscp
The excess rate policed DSCP value which the DSCP values maps
to. If the value of caqFlowPolicerExcessRateSupport object is
false(2), this object cannot be instantiated. The excess rate
default DSCP mapping of DSCP to '…
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.3.1.4
.1.3.6.1.4.1.9.9.179.1.1.4 · 1 row entry · 4 columns
This table provides the information for and configuration of
assigning packets to queues and thresholds based on their CoS
value.
caqCosAssignmentEntry entry .1.3.6.1.4.1.9.9.179.1.1.4.1
The assignment of packets to a pair of queue and threshold
based on their Cos value. The packets assignment also depends
on port types. For each port type, there is a set of Cos
value (0..7) associated with a pair o…
Indexes
caqCosAssignQueueType caqCosAssignCos
Column Syntax OID
caqCosAssignQueueType
The queue type of this interface.
CISCO-QOS-PIB-MIBQosInterfaceQueueType
Textual Convention: CISCO-QOS-PIB-MIBQosInterfaceQueueType Enumeration
Type Values:
1oneQ1t
2oneQ2t
3oneQ4t
4oneQ8t
5twoQ1t
6twoQ2t
7twoQ4t
8twoQ8t
9threeQ1t
10threeQ2t
11threeQ4t
12threeQ8t
13fourQ1t
14fourQ2t
15fourQ4t
16fourQ8t
17eightQ1t
18eightQ2t
19eightQ4t
20eightQ8t
21sixteenQ1t
22sixteenQ2t
23sixteenQ4t
24sixtyfourQ1t
25sixtyfourQ2t
26sixtyfourQ4t
27oneP1Q0t
28oneP1Q4t
29oneP1Q8t
30oneP2Q1t
31oneP2Q2t
32oneP3Q1t
33oneP7Q8t
34oneP3Q8t
35sixteenQ8t
36oneP15Q8t
37oneP15Q1t
38oneP7Q1t
39oneP31Q1t
40thirtytwoQ1t
41thirtytwoQ8t
42oneP31Q8t
43oneP7Q4t
44oneP3Q4t
45oneP7Q2t
.1.3.6.1.4.1.9.9.179.1.1.4.1.1
caqCosAssignCos
Indicates the Cos value which is used to match the
Cos value of packets for queue assignment.
CISCO-QOS-PIB-MIBQosLayer2Cos
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.1.4.1.2
caqCosAssignQueueNumber
The queue number which the Cos value denoted by
caqCosAssignCos will be associated with. This queue number
must not larger than the queue count defined by
caqCosAssignQueueType.
CaqQueueNumberr/w
Textual Convention: CaqQueueNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.1.4.1.3
caqCosAssignThresholdNumber
The threshold number which the Cos value denoted by
caqCosAssignCos will be associated with. This threshold
number must not larger than the threshold count defined
by caqCosAssignQueueType.
CaqThresholdNumberr/w
Textual Convention: CaqThresholdNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.1.4.1.4
.1.3.6.1.4.1.9.9.179.1.1.5 · 1 row entry · 7 columns
This table maintains threshold parameters for the specified
queue number and threshold number of a port type.
caqQueueThresholdEntry entry .1.3.6.1.4.1.9.9.179.1.1.5.1
For each threshold of a queue, there are parameters to set on
the threshold. This entry contains the parameters.
Indexes
caqQueueThreshQueueType caqQueueThreshQueueIndex caqQueueThreshThresholdIndex
Column Syntax OID
caqQueueThreshQueueType
Indicates the queue type.
CISCO-QOS-PIB-MIBQosInterfaceQueueType
Textual Convention: CISCO-QOS-PIB-MIBQosInterfaceQueueType Enumeration
Type Values:
1oneQ1t
2oneQ2t
3oneQ4t
4oneQ8t
5twoQ1t
6twoQ2t
7twoQ4t
8twoQ8t
9threeQ1t
10threeQ2t
11threeQ4t
12threeQ8t
13fourQ1t
14fourQ2t
15fourQ4t
16fourQ8t
17eightQ1t
18eightQ2t
19eightQ4t
20eightQ8t
21sixteenQ1t
22sixteenQ2t
23sixteenQ4t
24sixtyfourQ1t
25sixtyfourQ2t
26sixtyfourQ4t
27oneP1Q0t
28oneP1Q4t
29oneP1Q8t
30oneP2Q1t
31oneP2Q2t
32oneP3Q1t
33oneP7Q8t
34oneP3Q8t
35sixteenQ8t
36oneP15Q8t
37oneP15Q1t
38oneP7Q1t
39oneP31Q1t
40thirtytwoQ1t
41thirtytwoQ8t
42oneP31Q8t
43oneP7Q4t
44oneP3Q4t
45oneP7Q2t
.1.3.6.1.4.1.9.9.179.1.1.5.1.1
caqQueueThreshQueueIndex
Indicates queue number. This queue number must not be larger
than the queue count defined by caqQueueThreshQueueType.
CaqQueueNumber
Textual Convention: CaqQueueNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.1.5.1.2
caqQueueThreshThresholdIndex
Indicates threshold number. This threshold number must not
be larger than the threshold count defined by
caqQueueThreshQueueType.
CaqThresholdNumber
Textual Convention: CaqThresholdNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.1.5.1.3
caqQueueThreshDropAlgorithm
Indicates the drop algorithm used at this queue and threshold.

tailDrop(1) indicates that tailDrop is used.

wred(2) indicates that WRED is used.
Enumeration
Enumerated Values:
1tailDrop
2wred
.1.3.6.1.4.1.9.9.179.1.1.5.1.4
caqQueueThreshDropThreshold
This object specifies the drop threshold parameter for a
pair of queue and threshold of an interface queue type when the
drop algorithm is tail drop. Once the packets in the buffer is
more than the value of this object,…
percentUnsigned32r/w
Constraints:
range: 1-100
.1.3.6.1.4.1.9.9.179.1.1.5.1.5
caqQueueThreshMinWredThreshold
This object specifies the min WRED threshold parameter of a
threshold number for the specific port type when WRED drop
algorithm is used.

WRED (Weighted Random Early Detect) is a mechanism which drops
pac…
CISCO-QOS-PIB-MIBPercentr/w
Textual Convention: CISCO-QOS-PIB-MIBPercent Integer32
Type Constraints:
range: 0..100
.1.3.6.1.4.1.9.9.179.1.1.5.1.6
caqQueueThreshMaxWredThreshold
This object specifies the max WRED threshold parameter of a
threshold number for the specific port type when WRED drop
algorithm is used.

This object is instantiated only if the value of
caqQueueThreshDr…
percentUnsigned32r/w
Constraints:
range: 1-100
.1.3.6.1.4.1.9.9.179.1.1.5.1.7
.1.3.6.1.4.1.9.9.179.1.1.6 · 1 row entry · 5 columns
A table used to configure the WRR (weighted round robin)
weights for queues and the ratio of memory buffer allocation
for each queue. It only contains entries for the specific port 
types which supports either WRR or buffer allocation.
caqQueueEntry entry .1.3.6.1.4.1.9.9.179.1.1.6.1
A set of WRR weight and memory buffer allocation ratio for
ingress or egress of a specific queue.
Indexes
caqQueueDirection caqQueueType caqQueueNumber
Column Syntax OID
caqQueueDirection
Indicates whether this row's queue parameters are to
be applied for ingress or for egress traffic.
CaqDirection
Textual Convention: CaqDirection Enumeration
Type Values:
1ingress
2egress
.1.3.6.1.4.1.9.9.179.1.1.6.1.1
caqQueueType
Indicates the queue type.
CISCO-QOS-PIB-MIBQosInterfaceQueueType
Textual Convention: CISCO-QOS-PIB-MIBQosInterfaceQueueType Enumeration
Type Values:
1oneQ1t
2oneQ2t
3oneQ4t
4oneQ8t
5twoQ1t
6twoQ2t
7twoQ4t
8twoQ8t
9threeQ1t
10threeQ2t
11threeQ4t
12threeQ8t
13fourQ1t
14fourQ2t
15fourQ4t
16fourQ8t
17eightQ1t
18eightQ2t
19eightQ4t
20eightQ8t
21sixteenQ1t
22sixteenQ2t
23sixteenQ4t
24sixtyfourQ1t
25sixtyfourQ2t
26sixtyfourQ4t
27oneP1Q0t
28oneP1Q4t
29oneP1Q8t
30oneP2Q1t
31oneP2Q2t
32oneP3Q1t
33oneP7Q8t
34oneP3Q8t
35sixteenQ8t
36oneP15Q8t
37oneP15Q1t
38oneP7Q1t
39oneP31Q1t
40thirtytwoQ1t
41thirtytwoQ8t
42oneP31Q8t
43oneP7Q4t
44oneP3Q4t
45oneP7Q2t
.1.3.6.1.4.1.9.9.179.1.1.6.1.2
caqQueueNumber
Indicates queue number.
CaqQueueNumber
Textual Convention: CaqQueueNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.1.6.1.3
caqQueueWrrWeight
This object is to configure the weight for the specified
queue type and for the specified direction.
Unsigned32r/w
Constraints:
range: 1-255
.1.3.6.1.4.1.9.9.179.1.1.6.1.4
caqQueueBufferSizeRatio
Indicates the percentage of ingress or egress packet buffer
memory allocated to the specified queue.
percentUnsigned32r/w
Constraints:
range: 1-99
.1.3.6.1.4.1.9.9.179.1.1.6.1.5
.1.3.6.1.4.1.9.9.179.1.1.7 · 1 row entry · 3 columns
The table provides the DSCP mutation mapping configuration
on the device. This table is only instantiated if DSCP
Mutation is supported by the device.
caqDscpMutationMapEntry entry .1.3.6.1.4.1.9.9.179.1.1.7.1
Each row contains the mapping from old DSCP value to new
DSCP value per specific mutation table.
Indexes
caqDscpMutationTableId caqDscpMutationOldDscp
Column Syntax OID
caqDscpMutationTableId
The mutation table ID number.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.1.7.1.1
caqDscpMutationOldDscp
The old DSCP value.
CISCO-QOS-PIB-MIBDscp
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.7.1.2
caqDscpMutationNewDscp
The new DSCP value which the old DSCP values maps to for
a specific mutation table. The default mapping of old DSCP to
new DSCP for mutation purpose is the identity function.
That is:
63 -> 63
62 -> 62
.…
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.1.7.1.3
.1.3.6.1.4.1.9.9.179.1.1.8 · 1 row entry · 2 columns
The table provides the VLAN to mutation table mapping
configuration on the device. This table is only
instantiated if DSCP Mutation is supported by the 
device.
caqVlanMutationIdMapEntry entry .1.3.6.1.4.1.9.9.179.1.1.8.1
When the first time a VLAN is created in a device supporting
this table, a corresponding entry of this table will be added.
The value of caqVlanMutationTableId object in such row will be
initialized to 0.
Indexes
caqVlanMutationIndex
Column Syntax OID
caqVlanMutationIndex
Indicates the VLAN number.
CISCO-VTP-MIBVlanIndex
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.1.8.1.1
caqVlanMutationTableId
Indicates the mutation table ID number. The value of this
object should match one of caqDscpMutationTableId object
value in caqDscpMutationMapTable.

Mutation table 0 always provides the identity mapping.
SNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.1.8.1.2
.1.3.6.1.4.1.9.9.179.1.2.1 · 1 row entry · 5 columns
This table describes the trust state and the default Cos
value configured at each physical interface. It also 
indicates whether an ACL attached to a Qos capable physical
interface is applied per VLAN or per physical interface if
the platform supports ACL configuration.
caqIfConfigEntry entry .1.3.6.1.4.1.9.9.179.1.2.1.1
The index of this table is the ifIndex of a
physical port with QoS capability.
Indexes
IF-MIBifIndex
Column Syntax OID
caqIfCos
This object indicates the default Cos value configured at this
physical interface. This default value will be assigned to
packet which does not have a Cos value in its layer-2 header
when the packet arrives at this inte…
CISCO-QOS-PIB-MIBQosLayer2Cosr/w
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.2.1.1.1
caqIfTrustStateConfig
This object is used to set the trust state of an interface.
(whether the packets arriving at an interface are trusted to
carry the correct data for classification.)

If the object is untrusted(1), then th…
Enumerationr/w
Enumerated Values:
1untrusted
2trustCoS
3trustIpPrec
4trustDscp
.1.3.6.1.4.1.9.9.179.1.2.1.1.2
caqIfAclBase
For a given physical interface, this object indicates whether
packets arriving at that interface are classified and policed
based on port's ACL or based on the ACL of the VLAN which the
port belongs to. This object is…
Enumerationr/w
Enumerated Values:
1vlan
2port
.1.3.6.1.4.1.9.9.179.1.2.1.1.3
caqIfTrustDevice
For a given physical interface, this object indicates the
restriction on trusting only a specific type of device which
is connected to this interface to carry the correct data for
classification.

trustCis…
Bitsr/w
Enumerated Values:
0trustCiscoIPPhone
.1.3.6.1.4.1.9.9.179.1.2.1.1.4
caqIfOperTrustState
This object is used to indicate the operational trust state of
an interface. The operational trust state may or may not be
identical to the config trust state denoted by
caqIfTrustStateConfig. The value of this object …
Enumeration
Enumerated Values:
1untrusted
2trustCoS
3trustIpPrec
4trustDscp
.1.3.6.1.4.1.9.9.179.1.2.1.1.5
.1.3.6.1.4.1.9.9.179.1.2.2 · 1 row entry · 4 columns
This table identifies which ACLs are in use on which
interfaces. Some devices may impose constraints on the number
of ACLs that can be attached to each interface; for example a
constraint that at most three Qos ACLs, one for each type: IP,
IPX and MAC, and at most three Security ACLs, one for each
type: IP, IPX and MAC, can be attached to an interface.
caqClassifierEntry entry .1.3.6.1.4.1.9.9.179.1.2.2.1
An entry identifies that a particular ACL is in use on a
particular interface. An interface can be a physical port
or a VLAN.
Indexes
IF-MIBifIndex caqClassifierAclType caqClassifierAclName
Column Syntax OID
caqClassifierAclType
Indicates the type of ACL attached to this interface.

ipQos(1) indicates that this ACL is an IP Qos ACL.

ipxQos(2) indicates that this ACL is an IPX Qos ACL.

macQos(3) indica…
Enumeration
Enumerated Values:
1ipQos
2ipxQos
3macQos
4ipSecurity
5ipxSecurity
6macSecurity
.1.3.6.1.4.1.9.9.179.1.2.2.1.1
caqClassifierAclName
Indicates the ACL name which should exist in the ACL tables
e.g. in caqIpAceTable. This ACL can be a Qos ACL or a
Security ACL.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.2.2.1.2
caqClassifierMapStatus
The status of this classifier conceptual row entry.
An entry may not exist in the active state unless the
ACL name denoted by caqClassifierAclName object in the
entry exist and active (i.e. its RowStatus object is
act…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.2.2.1.3
caqClassifierMapDirection
Indicates whether this ACL are to be attached to ingress or
egress direction.
Bitsr/w
Enumerated Values:
0ingress
1egress
.1.3.6.1.4.1.9.9.179.1.2.2.1.4
.1.3.6.1.4.1.9.9.179.1.2.3 · 1 row entry · 1 columns
A list of the interfaces which support the security
ACL feature.
caqIfSecurityAclConfigEntry entry .1.3.6.1.4.1.9.9.179.1.2.3.1
An entry contains configuration information about
a security ACL mapped to a interface which is capable
for this feature.
Indexes
IF-MIBifIndex
Column Syntax OID
caqIfSecurityAclBase
The security ACL configuration mode for an interface.

Setting this variable to the value port(1) will cause the
packets (L3 forwarded packets and L2 packets) arriving at that
interface to be filtered bas…
Enumerationr/w
Enumerated Values:
1port
2vlan
3merge
.1.3.6.1.4.1.9.9.179.1.2.3.1.1
.1.3.6.1.4.1.9.9.179.1.2.4 · 1 row entry · 3 columns
This table identifies which operational IP ACLs are in use 
on which interfaces.
caqIpOperClassifierEntry entry .1.3.6.1.4.1.9.9.179.1.2.4.1
An entry in this table identifies operational IP ACLs that
are currently in use on a particular interface. An interface
can be a physical port or a VLAN.
Indexes
IF-MIBifIndex caqIpOperAclFeature
Column Syntax OID
caqIpOperAclFeature
An index indicates the feature to which the operational
IP ACLs mapped at this interface are applied.

'ingressIpQos' indicates the ACL mapped at this interface
is used to classify ingress IP traffic for Q…
Enumeration
Enumerated Values:
1ingressIpQos
2egressIpQos
3ipSecurity
.1.3.6.1.4.1.9.9.179.1.2.4.1.1
caqIpOperAclName
This object indicates the name of an operational IP ACL
which is mapped at this interface to classify IP traffic
for feature denoted by caqIpOperAclFeature object.
SNMP-FRAMEWORK-MIBSnmpAdminString
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.2.4.1.2
caqIpOperAclMapSource
This object indicates the sources that map the operational
IP ACLs at this interface.

'configured' indicates that the ACL mapping is introduced
by manual configuration through CLI or an NMS application.
Bits
Enumerated Values:
0configured
1dot1x
2macAuth
3webAuth
4eou
.1.3.6.1.4.1.9.9.179.1.2.4.1.3
.1.3.6.1.4.1.9.9.179.1.2.5 · 1 row entry · 4 columns
This table identifies ACLs assignment to capable
interface which is downloaded using different 
security features.
caqDownloadClassifierEntry entry .1.3.6.1.4.1.9.9.179.1.2.5.1
An entry identifies ACLs assignment on a capable
physical interface.
Indexes
IF-MIBifIndex caqDownloadAclFeature
Column Syntax OID
caqDownloadAclFeature
This object indicates the feature that ACLs mapped
at this interface is used for.

'ingressIpQos' indicates the ACL mapped at this interface
is used to classify ingress IP traffic for QoS feature.
Enumeration
Enumerated Values:
1ingressIpQos
2egressIpQos
3ipSecurity
.1.3.6.1.4.1.9.9.179.1.2.5.1.1
caqDownloadClassifierAclName
This object indicates the ACL name mapped to this
interface to classify traffic for a specific feature
denoted by the corresponding caqDownloadAclFeature.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.2.5.1.2
caqDownloadMapSource
This object indicates the source that maps the ACLs at this
interface.

'dot1x' indicates that the ACL mapping is introduced by
the operation of 802.1x feature.

'macAuth' indicates that …
Enumeration
Enumerated Values:
1dot1x
2macAuth
.1.3.6.1.4.1.9.9.179.1.2.5.1.3
caqDownloadAclType
This object indicates the type of the ACL.

'pacl' indicates this is a port-based ACL.
'vacl' indicates this is a VLAN-based ACL.
Enumeration
Enumerated Values:
1pacl
2vacl
.1.3.6.1.4.1.9.9.179.1.2.5.1.4
.1.3.6.1.4.1.9.9.179.1.3.2 · 1 row entry · 30 columns
This table contains a list of IP ACEs. Each ACE consists of
a filter specification and behavior associated with it which
describes what action to carry out on packets which match.
          
An ACL is defined as the set of ACEs of the same type (all
QoS, or all Security).  Within a feature (qos or security),
each ACE is named by a combination of an AclName and an ACE
index, such that all the ACEs which are named using the same
AclName are part of the same ACL.
caqIpAceEntry entry .1.3.6.1.4.1.9.9.179.1.3.2.1
An entry defines an ACE, consisting of a set of match
criteria. For a packet to match an entry, it has to match
all the criteria specified in that entry.
Indexes
caqIpAceFeature caqIpAclName caqIpAceIndex
Column Syntax OID
caqIpAceFeature
Indicates whether this entry is a Qos ACL or Security ACL.
ACEs belongs to the same ACL should have the same value
for this object.
Enumeration
Enumerated Values:
1qos
2security
.1.3.6.1.4.1.9.9.179.1.3.2.1.1
caqIpAclName
The name of an ACL. Within a feature (qos or security), the
name is unique across all of the ACL tables that identifies
the list to which the entry belongs in the device.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.3.2.1.2
caqIpAceIndex
The index of an ACE within an ACL.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.3
caqIpAceMatchedAction
Indicates the action to be taken if a packet matches this ACE.
If the value of this ACE's caqIpAceFeature object is: 'qos(1)',
then this object contains the index of an active row in
caqQosActionSelectTable. If the val…
Unsigned32r/w
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.4
caqIpAceProtocolType
The protocol number field in the IP header used to indicate
the higher layer protocol as specified in RFC 1700. A value
value of 0 matches every IP packet.

For example :
0 is IP, 1 is ICMP, 2 is IGMP, 4…
Unsigned32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.179.1.3.2.1.5
caqIpAceAddrType
The type of IP address used by this ACE entry.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.179.1.3.2.1.6
caqIpAceSrcIp
The specified source IP address. The packet's source address is
AND-ed with the value of caqIpAceSrcIpMask and then compared
against the value of this object. If this object value is
0.0.0.0, and the value of caqIpAceSr…
INET-ADDRESS-MIBInetAddressr/w
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.7
caqIpAceSrcIpMask
The specified source IP address mask.
INET-ADDRESS-MIBInetAddressr/w
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.8
caqIpAceSrcPortOp
Indicates how a packet's source TCP/UDP port number is
to be compared.

If the caqIpAceProtocolType object in the same row does not
indicate TCP or UDP, this object has to be 'noOperator(1)' and
cannot be …
Enumerationr/w
Enumerated Values:
1noOperator
2lt
3gt
4eq
5neq
6range
.1.3.6.1.4.1.9.9.179.1.3.2.1.9
caqIpAceSrcPort
The source port number of the TCP or UDP protocol. If the
caqIpAceSrcPortOp object in the same row is range(6), this
object will be the starting port number of the port range.
This object cannot be configured if caqIpAc…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.10
caqIpAceSrcPortRange
The source port number of the TCP or UDP protocol. If the
caqIpAceSrcPortOp object in the same row is range(6), this
object will be the ending port number of the port range.
This object cannot be configured if caqIpAceS…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.11
caqIpAceDestIp
The specified destination IP address. The packet's destination
address is AND-ed with the value of caqIpAceDestIpMask and then
compared against the value of this object. If this object value
is 0.0.0.0 and the value of …
INET-ADDRESS-MIBInetAddressr/w
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.12
caqIpAceDestIpMask
The specified destination IP address mask.
INET-ADDRESS-MIBInetAddressr/w
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.13
caqIpAceDestPortOp
Indicates how a packet's destination TCP/UDP port number is
to be compared.

If the caqIpAceProtocolType object in the same row does not
indicate TCP or UDP, this object has to be 'noOperator(1)' and
canno…
Enumerationr/w
Enumerated Values:
1noOperator
2lt
3gt
4eq
5neq
6range
.1.3.6.1.4.1.9.9.179.1.3.2.1.14
caqIpAceDestPort
The destination port number of the TCP or UDP protocol.
If the caqIpAceDestPortOp object in the same row is range(6),
this object will be the starting port number of the port range.
This object cannot be configured if c…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.15
caqIpAceDestPortRange
The destination port number of the TCP or UDP protocol.
If the caqIpAceDestPortOp object in the same row is range(6),
this object will be the ending port number of the port range.
This object cannot be configured if caq…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.16
caqIpAceTosMatchCriteria
Indicates what field of Tos octet in the packet header
to be matched.

none(1) means that there is no need to match the ToS octet.

matchDscp(2) means that the DSCP value of packet header ne…
Enumerationr/w
Enumerated Values:
1none
2matchDscp
3matchIpPrec
.1.3.6.1.4.1.9.9.179.1.3.2.1.17
caqIpAceIpPrec
Specifies the IP precedence value to be matched against.
This object could not be configured when the status of the
entry, caqIpAceStatus, is active(1).

The value of this object is ignored whenever the …
CaqIpPrecedencer/w
Textual Convention: CaqIpPrecedence Unsigned32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.3.2.1.18
caqIpAceDscp
Specifies the Dscp value to be matched against.
This object could not be configured when the status of the
entry, caqIpAceStatus, is active(1). Packets can be matched
the DSCP level from 0 to 63.

The va…
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.3.2.1.19
caqIpAceProtocolMatchCriteria
Indicates what field in the packet header for ICMP or IGMP
or TCP protocol or IPv4 ESP (Enscrypted Security Payload)
to be matched.

none(1) = no comparison is to be done for ICMP/IGMP/TCP/ESP.
Enumerationr/w
Enumerated Values:
1none
2matchIgmpType
3matchIcmpType
4matchIcmpTypeAndCode
5matchEstablished
6matchSecurityId
7matchEapoudp
8matchUrlRedirect
.1.3.6.1.4.1.9.9.179.1.3.2.1.20
caqIpAceIcmpType
Indicates the message type of ICMP packets. The type is
a number from 0 to 255.

The value of this object is ignored whenever the value of
caqIpAceProtocolMatchCritial object is not matchIcmpType(3) or
m…
Unsigned32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.179.1.3.2.1.21
caqIpAceIcmpCode
Indicates the message code of ICMP packets. The code is
a number from 0 to 255.

The value of this object is ignored whenever the value of
caqIpAceProtocolMatchCritial object is not
matchIcmpTypeAndCode(…
Unsigned32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.179.1.3.2.1.22
caqIpAceIgmpType
Indicates the message type of IGMP packets. The code is
a number from 0 to 15.

The value of this object is ignored whenever the value of
caqIpAceProtocolMatchCritial object is not matchIgmpType(2).
Unsigned32r/w
Constraints:
range: 0-15
.1.3.6.1.4.1.9.9.179.1.3.2.1.23
caqIpAceOrderPosition
The ordering position of this ACE in the ACL. If this entry
is not in active(1) state, this object has value of 0.
Unsigned32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.24
caqIpAceBeforePosition
The object is to control the position of an ACE in the ACL.
Indicates the order position of a new ACE before an active ACE
which is already in the ACL. It means that the new ACE will
replace the position of the ACE wh…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.2.1.25
caqIpAceStatus
The status of this IP ACE conceptual row entry. This object is
used to manage creation, deletion and modification of rows in
this table.

An entry may not exist in the active state unless all objects
in …
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.2.1.26
caqIpAceSecurityId
Indicates the Security Association Identifier of IPv4 ESP
packets.

The value of this object is ignored whenever the value of
caqIpAceProtocolMatchCritial object is not matchSecurityId(6).
Unsigned32r/w
Constraints:
range: 0-0
range: 4-233
.1.3.6.1.4.1.9.9.179.1.3.2.1.27
caqIpAceSrcGroup
Indicates the source group name which the source IP address
in the IP packet header belongs to. If this object is
configured, the value of caqIpAceProtocolType object in the
same row will have the value of 0.
SNMP-FRAMEWORK-MIBSnmpAdminStringr/w
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.28
caqIpAceDestGroup
Indicates the destination group name which the destination
IP address in the IP packet header belongs to. If this object
is configured, the value of caqIpAceProtocolType object in
the same row will have the value of 0.
SNMP-FRAMEWORK-MIBSnmpAdminStringr/w
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.3.2.1.29
caqIpAceType
Indicates the ACE type.
Enumeration
Enumerated Values:
1configured
2systemGenerated
.1.3.6.1.4.1.9.9.179.1.3.2.1.30
.1.3.6.1.4.1.9.9.179.1.3.3 · 1 row entry · 14 columns
This table contains a list of IPX ACEs. Each ACE consists of
a filter specification and behavior associated with it which
describes what action to carry out on packets which match.
          
An ACL is defined as the set of ACEs of the same type (all
QoS, or all Security).  Within each feature (qos or security),
each ACE is named by a combination of an AclName and an ACE
index, such that all the ACEs which are named using the same
AclName are part of the same ACL. This table is instantiated
only if the ipxQos bit or ipxSecurity bit of caqAclCapabilities
object is turned on.
caqIpxAceEntry entry .1.3.6.1.4.1.9.9.179.1.3.3.1
Each entry of caqIpxAceTable consists of a set of match
creteria. For a IPX flow to match an entry, it has to match
all the conditions specified in that entry.
Indexes
caqIpxAceFeature caqIpxAclName caqIpxAceIndex
Column Syntax OID
caqIpxAceFeature
Indicates whether this entry is a Qos ACL or Security ACL.
ACEs belongs to the same ACL should have the same value
for this object.
Enumeration
Enumerated Values:
1qos
2security
.1.3.6.1.4.1.9.9.179.1.3.3.1.1
caqIpxAclName
The name of an ACL. Within a feature (qos or security), this
name is unique across all of the ACL tables that identifies
the list to which the entry belongs in the device.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.3.3.1.2
caqIpxAceIndex
The index of an IPX ACE within an ACL.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.3.1.3
caqIpxAceMatchedAction
Indicates the action to be taken if a packet matches this ACE.
If the value of this ACE's caqIpxAceFeature object is: 'qos(1)',
then this object contains the index of an active row in
caqQosActionSelectTable. If the va…
Unsigned32r/w
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.3.1.4
caqIpxAceSrcNet
Indicates the source network from which the packet is
being sent. This is a 32-bits value that uniquely identifies
network cable segment in IPX protocol.
A network number of 0xFFFFFFFF matches all networks.
OctetStringr/w
Constraints:
range: 4-4
.1.3.6.1.4.1.9.9.179.1.3.3.1.5
caqIpxAceDestMatchCriteria
Indicate which matches to be checked for the
destination network of the flow.

matchProtocol(0) means that the flow protocol
will be matched against the value specified by
caqIpxAceProtocolType object in t…
Bitsr/w
Enumerated Values:
0matchProtocol
1matchIpxDestNet
2matchIpxDestNode
3matchIpxDestNetMask
4matchIpxDestNodeMask
.1.3.6.1.4.1.9.9.179.1.3.3.1.6
caqIpxAceProtocolType
The protocol number field in the IPX header used to indicate
the higher layer protocol. It can be any, ncp, netbios, rip,
sap or an integer between 0 to 255.
Unsigned32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.179.1.3.3.1.7
caqIpxAceDestNet
Number of the destination network to which the packet
is being sent. This is a 32-bit value that uniquely identifies
the IPX network cable segment in IPX protocol. A network
number of 0xFFFFFFFF matches all networks.
OctetStringr/w
Constraints:
range: 4-4
.1.3.6.1.4.1.9.9.179.1.3.3.1.8
caqIpxAceDestNode
Node on the destination network to which the packet is being
sent. This is a 48 bits value.

The value of this object is ignored whenever the
matchIpxDestNode(2) and matchIpxDestNodeMask(4) bits of
caqIpxA…
OctetStringr/w
Constraints:
range: 6-6
.1.3.6.1.4.1.9.9.179.1.3.3.1.9
caqIpxAceDestNetMask
Mask to be applied to the destination net. This is an
32-bit value that has the same format as destination net.

The value of this object is ignored whenever the
matchIpxDestNetMask(3) bit of caqIpxAceDest…
OctetStringr/w
Constraints:
range: 4-4
.1.3.6.1.4.1.9.9.179.1.3.3.1.10
caqIpxAceDestNodeMask
Mask to be applied to the destination node. This is a 48-bit
value.

The value of this object is ignored whenever the
matchIpxDestNodeMask(4) bit of caqIpxAceDestMatchCriteria
object is not on.
OctetStringr/w
Constraints:
range: 6-6
.1.3.6.1.4.1.9.9.179.1.3.3.1.11
caqIpxAceOrderPosition
The ordering position of this ACE in the ACL. If this entry
is not in active(1) state, this object has value of 0.
Unsigned32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.3.1.12
caqIpxAceBeforePosition
The object is to control the position of an ACE in the ACL.
Specifies the order position of a new ACE before an active ACE
which is already in the ACL. It means that the new ACE will
replace the position of the ACE wh…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.3.1.13
caqIpxAceStatus
The status of this IPX ACE conceptual row entry. This object
is used to manage creation, deletion and modification of rows
in this table.

An entry may not exist in the active state unless all objects
in…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.3.1.14
.1.3.6.1.4.1.9.9.179.1.3.4 · 1 row entry · 15 columns
This table contains a list of MAC ACEs. Each ACE consists of
a filter specification and behavior associated with it which
describes what action to carry out on packets which match.
          
An ACL is defined as the set of ACEs of the same type (all
QoS, or all Security).  Within a feature (qos or security), each
ACE is named by a combination of an AclName and an ACE index,
such that all the ACEs which are named using the same AclName
are part of the same ACL. This table is instantiated only if
the macQos bit or macSecurity bit of caqAclCapabilities object
is turned on.
caqMacAceEntry entry .1.3.6.1.4.1.9.9.179.1.3.4.1
Each entry of caqMacAceTable consist of a set of match
criteria. For a layer 2 flow to match an entry, it has to
match all the conditions specified in that entry.
Indexes
caqMacAceFeature caqMacAclName caqMacAceIndex
Column Syntax OID
caqMacAceFeature
Indicates whether this entry is a Qos ACL or Security ACL.
Enumeration
Enumerated Values:
1qos
2security
.1.3.6.1.4.1.9.9.179.1.3.4.1.1
caqMacAclName
The name of an ACL. Within a feature (qos or security), this
name is unique across all the ACL tables that identifies the
list to which the entry belongs in the device.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.3.4.1.2
caqMacAceIndex
The index of an Mac ACE within an ACL.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.4.1.3
caqMacAceMatchedAction
Indicates the action to be taken if a packet matches this ACE.
If the value of this ACE's caqMacAceFeature object is: 'qos(1)',
then this object contains the index of an active row in
caqQosActionSelectTable. If the va…
Unsigned32r/w
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.4.1.4
caqMacAceSrcMac
Indicates the 48 bits source MAC address. The packet's source
address is AND-ed with the value of caqMacAceSrcMacMask and then
compared against the value of this object. If this object value
is 00-00-00-00-00-00, and th…
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.3.4.1.5
caqMacAceSrcMacMask
Indicates the 48 bit source MAC address mask.
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.3.4.1.6
caqMacAceDestMac
Indicates the 48 bits destination MAC address. The packet's
destination address is AND-ed with the value of
caqMacAceDestMacMask and then compared against the value of
this object. If this object value is 00-00-00-00-0…
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.3.4.1.7
caqMacAceDestMacMask
Indicates the 48 bit destination MAC address mask.
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.3.4.1.8
caqMacAceEthertype
This 16-bit hexadecimal number indicates the matched Ethernet
type. 0x0000 means any Ethernet type will be matched.
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.4.1.9
caqMacAceOrderPosition
The ordering position of this ACE in the ACL. If this entry
is not in active(1) state, this object has value of 0.
Unsigned32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.4.1.10
caqMacAceBeforePosition
The object is to control the position of an ACE in the ACL.
Specifies the order position of a new ACE before a ACE which
is already in the ACL. It means that the new ACE will replace
the position of the ACE which the ob…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.4.1.11
caqMacAceStatus
The status of this MAC ACE conceptual row entry. This object
is used to manage creation, deletion and modification of rows
in this table.

An entry may not exist in the active state unless all objects
in…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.4.1.12
caqMacAceMatchCriteria
Indicates which field in the packet header to be matched.

matchCos(0) means that the packet Cos value
will be matched against the value specified by
caqMacAceCos object in the same row.

Bitsr/w
Enumerated Values:
0matchCos
1matchVlan
.1.3.6.1.4.1.9.9.179.1.3.4.1.13
caqMacAceCos
Indicates the packet Cos value to be matched.

The value of this object is ignored whenever the
matchCos(0) bit of caqMacAceMatchCriteria object
is not on.
CISCO-QOS-PIB-MIBQosLayer2Cosr/w
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.3.4.1.14
caqMacAceVlan
Indicates the packet VLAN number to be matched.

The value of this object is ignored whenever the
matchVlan(1) bit of caqMacAceMatchCriteria object
is not on.
CISCO-VTP-MIBVlanIndexr/w
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.3.4.1.15
.1.3.6.1.4.1.9.9.179.1.3.6 · 1 row entry · 6 columns
This table describes the actions of ACEs.  Once an ACE is
matched, it follows its MatchedAction object to an entry of this
table to get an action for the matching ACE. 
An action includes policer information as well as an DSCP 
associated with trust state information of the matching ACE.
caqQosActionSelectEntry entry .1.3.6.1.4.1.9.9.179.1.3.6.1
An entry of an ACE action. It links to the entries of
caqFlowPolicerTable with caqQosActionSelectMicroflow,
caqQosActionSelectAggregate objects.
Indexes
caqQosActionSelectIndex
Column Syntax OID
caqQosActionSelectIndex
The index of this table for indicating an ACE Action for QoS.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.6.1.1
caqQosActionSelectTrust
Determines if the packets matching the ACE should be trusted
or if a specific DSCP should be assigned to it.

If trustCos(2) is specified, the final DSCP value should refer
to caqCosToDscpDscp object in ca…
Enumerationr/w
Enumerated Values:
1noTrust
2trustCos
3trustIpPrec
4trustDscp
.1.3.6.1.4.1.9.9.179.1.3.6.1.2
caqQosActionSelectDscp
This object is only instantiated when the
caqQosActionSelectTrust object in the same entry has been set
to noTrust(1).
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.3.6.1.4
caqQosActionSelectMicroflow
Indicates a policer name. The value of this object either
matches the value of caqFlowPolicerName object of an active
entry in caqFlowPolicerTable or has an empty string value. The
ACE uses this object to link to a poli…
CaqPolicerNameOrEmptyr/w
Textual Convention: CaqPolicerNameOrEmpty OctetString
Type Constraints:
range: 0..31
.1.3.6.1.4.1.9.9.179.1.3.6.1.5
caqQosActionSelectAggregate
Indicates a policer name. The value of this object either
matches the value of caqFlowPolicerName object of an active
entry in caqFlowPolicerTable or has an empty string value.
The ACE uses this object to link to a pol…
CaqPolicerNameOrEmptyr/w
Textual Convention: CaqPolicerNameOrEmpty OctetString
Type Constraints:
range: 0..31
.1.3.6.1.4.1.9.9.179.1.3.6.1.6
caqQosActionSelectStatus
The status of this Qos Action Select conceptual row entry. This
object is used to manage creation, deletion and modification of
rows in this table.

An entry may not exist in the active state unless all …
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.6.1.7
.1.3.6.1.4.1.9.9.179.1.3.8 · 1 row entry · 13 columns
This table defines the flow policing rules. A flow policing
rule comprises a rate, burst size and drop-or-mark indication.
caqFlowPolicerEntry entry .1.3.6.1.4.1.9.9.179.1.3.8.1
The attributes defining a flow policing rule.
Indexes
caqFlowPolicerName
Column Syntax OID
caqFlowPolicerName
The name of a policer. This name has to be unique to identify
a microflow or an aggregate policer in the device.
CaqPolicerName
Textual Convention: CaqPolicerName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.3.8.1.1
caqFlowPolicerType
The type of this policer.
Enumerationr/w
Enumerated Values:
1microflow
2aggregate
.1.3.6.1.4.1.9.9.179.1.3.8.1.2
caqFlowPolicerNormalRateRequest
The requested average rate of the flow. The base unit of this
object is 1 kilo-bits per second. 0 may be specified for a
rate which causes all packets to be out-of-profile.
Out-of-profile indicates that a packet cause…
kbpsInteger32r/w
Constraints:
range: 32-8000000
range: 0-0
.1.3.6.1.4.1.9.9.179.1.3.8.1.3
caqFlowPolicerNormalRateGrant
The granted average rate of the flow. The base unit of this
object is 1 kilo-bits per second. If the status of this row is
not active, the value of this object will be the same as
caqFlowPolicerNormalRateRequest's valu…
kbpsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.9.9.179.1.3.8.1.4
caqFlowPolicerNormalRateAction
The action for those normal rate out-of-profile packets. The
action is to drop the packets or mark down its DSCP to the
value of caqDscpMappingNRPolicedDscp defined in
caqDscpMappingTable.

If the caqFlo…
Enumerationr/w
Enumerated Values:
1drop
2policedDscp
.1.3.6.1.4.1.9.9.179.1.3.8.1.5
caqFlowPolicerExcessRateRequest
The requested excess rate of the flow. The base unit of this
object is 1 kilo-bits per second. 0 may be specified for a
rate which causes all packets to be out-of-profile.
Out-of-profile indicates that a packet causes…
kbpsInteger32r/w
Constraints:
range: 32-8000000
range: 0-0
.1.3.6.1.4.1.9.9.179.1.3.8.1.6
caqFlowPolicerExcessRateGrant
The granted excess rate of the flow. The base unit of this
object is 1 kilo-bits per second. If the status of this row is
not active, the value of this object will be the same as
caqFlowPolicerExcessRateRequest's value…
kbpsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.9.9.179.1.3.8.1.7
caqFlowPolicerExcessRateAction
The action for those excess rate out-of-profile packets. The
action is to drop the packets or mark down its DSCP value to
value of caqDscpMappingERPolicedDscp defined in
caqDscpMappingTable.

If the caqF…
Enumerationr/w
Enumerated Values:
1drop
2policedDscp
.1.3.6.1.4.1.9.9.179.1.3.8.1.8
caqFlowPolicerBurstSizeRequest
The requested burst rate of the flow. The base unit of this
object is 1 kilo-bits.
kilo-bitsInteger32r/w
Constraints:
range: 1-32000
.1.3.6.1.4.1.9.9.179.1.3.8.1.9
caqFlowPolicerBurstSizeGrant
The granted burst rate of the flow. The base unit of this
object is 1 kilo-bits. If the status of this row is not
active, the value of this object will be the same as
caqFlowPolicerBurstSizeRequest's value.
kilo-bitsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.9.9.179.1.3.8.1.10
caqFlowPolicerStatus
The status of this flow policer conceptual row entry. This
object is used to manage creation, deletion and modification of
rows in this table.

An entry may not exist in the active state unless all obje…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.8.1.11
caqFlowPolicerExcessBurstRequest
The requested excess burst size of the flow.

If the caqFlowPolicerExcessBurstSupport is false(2), this
object cannot be instantiated.
kilo-bitsUnsigned32r/w
Constraints:
range: 1-32000
.1.3.6.1.4.1.9.9.179.1.3.8.1.12
caqFlowPolicerExcessBurstGrant
The granted excess burst size of the flow. If the status of
this row is not active, the value of this object will be the
same as caqFlowPolicerExcessBurstRequest's value.

If the QoS function is enabled an…
kilo-bitsUnsigned32
Constraints:
range: 1-32000
.1.3.6.1.4.1.9.9.179.1.3.8.1.13
.1.3.6.1.4.1.9.9.179.1.3.9 · 1 row entry · 9 columns
This table describes the actions of Security ACEs. Once an ACE
is matched and it can go through an entry of this table to find
the Security action.
caqSecurityActionEntry entry .1.3.6.1.4.1.9.9.179.1.3.9.1
An entry of a Security ACE action. It provides the action for
for the traffic matching Security ACEs.
Indexes
caqSecurityActionIndex
Column Syntax OID
caqSecurityActionIndex
The index of this table for indicating a Security ACE action
entry.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.3.9.1.1
caqSecurityAction
Determines the action that the device will take if the traffic
matches the ACE.

If permit(1) is specified, the matched traffic will be allowed
through the device.

If deny(2) is specified, t…
Enumerationr/w
Enumerated Values:
1permit
2deny
3redirect
4redirectWithAdj
5denyWithLog
6denyArpInspection
7denyArpInspWithLog
8permitArpInspection
9include
.1.3.6.1.4.1.9.9.179.1.3.9.1.2
caqSecurityRedirectPortList deprecated
Indicates the set of physical port(s) that matched
traffic is redirected to. Each octet within the value of
this object specifies a set of eight ports, with the first
octet specifying ports 1 through 8, the second octet…
OctetStringr/w
Constraints:
range: 0-128
.1.3.6.1.4.1.9.9.179.1.3.9.1.3
caqSecurityCapture
Indicates whether the matched traffic is to be captured.
Capture means the packet is not only switched normally but also
a copy of the switched packet is transmitted on the capture
port(s). Traffic which is dropped cann…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.179.1.3.9.1.4
caqSecurityActionStatus
The status of this Security ACE action conceptual row entry.
This object is used to manage creation, deletion and
modification of rows in this table.

An entry may not exist in the active state unless al…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.3.9.1.5
caqSecurityAdjIndex
Indicates the index of an active adjacency entry in
caqAdjacencyTable. The value of this object is ignored whenever
the value of caqSecurityAction object in the same row is not
redirectWithAdj(4).
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.179.1.3.9.1.6
caqSecurityArpMacAddress
Indicates the 48 bits Mac address used in ARP packet.
The value of this object is ignored whenever the value of
caqSecurityAction object in the same row is not one of
the following values denyArpInspection(6), denyArpIn…
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.3.9.1.7
caqSecurityRedirect2kPortList
Indicates the set of physical port(s) that matched
traffic is redirected to. Each octet within the value of
this object specifies a set of eight ports, with the first
octet specifying ports 1 through 8, the second octet…
OctetStringr/w
Constraints:
range: 0-256
.1.3.6.1.4.1.9.9.179.1.3.9.1.8
caqSecurityDownloadedAceFeature
Indicates the feature type of the downloaded ACE.

'notApplicable' indicates that this security action
entry is not applied to any downloaded ACE.

'dot1x' indicates that this security action…
Enumerationr/w
Enumerated Values:
1notApplicable
2dot1x
3macAuth
4webAuth
5eou
6ipPhone
.1.3.6.1.4.1.9.9.179.1.3.9.1.9
.1.3.6.1.4.1.9.9.179.1.3.10 · 1 row entry · 1 columns
This table contains all the physical ports which are capable
of being capture interfaces on which captured packets are
output.
caqSecurityAclCaptureIfEntry entry .1.3.6.1.4.1.9.9.179.1.3.10.1
The index of this table is the ifIndex value of a
physical port which is capable of being a capture interface
on which captured packets are output.
Indexes
IF-MIBifIndex
Column Syntax OID
caqSecurityAclCaptureEnable
An interface can be a destination of captured traffic which
matched any Security ACL.

This object is to specify whether to enable or disable this
interface as a destination of captured traffic.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.179.1.3.10.1.1
.1.3.6.1.4.1.9.9.179.1.3.14 · 1 row entry · 6 columns
This table contains the QoS default action taken by the
device for traffic which is not matched by a specific
QoS ACE.
caqQosDefaultActionEntry entry .1.3.6.1.4.1.9.9.179.1.3.14.1
The entries in this table are corresponding to the type of
traffic as well as its direction and contain the default
DSCP value, trust state and policers information. The number
of entry in this table depends on what typ…
Indexes
caqQosTrafficDirection caqQosTrafficType
Column Syntax OID
caqQosTrafficDirection
Indicates whether this row's parameters are to
be applied for ingress or for egress traffic.
CaqDirection
Textual Convention: CaqDirection Enumeration
Type Values:
1ingress
2egress
.1.3.6.1.4.1.9.9.179.1.3.14.1.1
caqQosTrafficType
Indicates whether this row's parameters are to
be applied for Ethernet, IP or IPX traffic.
Enumeration
Enumerated Values:
1mac
2ip
3ipx
.1.3.6.1.4.1.9.9.179.1.3.14.1.2
caqQosDefaultTrustState
Indicates the default assigned trust state.

If trustCos(2) is specified, the default DSCP value of an
unmatched packet should refer to caqCosToDscpDscp
object in caqCosToDscpTable to transfer layer 2…
Enumerationr/w
Enumerated Values:
1noTrust
2trustCos
3trustIpPrec
4trustDscp
.1.3.6.1.4.1.9.9.179.1.3.14.1.3
caqQosDefaultDscp
This object is only instantiated when the
caqQosDefaultTrust object in the same entry has been set
to noTrust(1).
CISCO-QOS-PIB-MIBDscpr/w
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.3.14.1.4
caqQosDefaultMicroflow
Indicates a microflow policer name. The value of
this object either matches the value of caqFlowPolicerName
object of an active entry in caqFlowPolicerTable or has an
empty string value.
If there is no default microflow…
CaqPolicerNameOrEmptyr/w
Textual Convention: CaqPolicerNameOrEmpty OctetString
Type Constraints:
range: 0..31
.1.3.6.1.4.1.9.9.179.1.3.14.1.5
caqQosDefaultAggregate
Indicates an aggregate policer name. The value of this object
either matches the value of caqFlowPolicerName object of an
active entry in caqFlowPolicerTable or has an empty string
value. If there is no default aggregat…
CaqPolicerNameOrEmptyr/w
Textual Convention: CaqPolicerNameOrEmpty OctetString
Type Constraints:
range: 0..31
.1.3.6.1.4.1.9.9.179.1.3.14.1.6
.1.3.6.1.4.1.9.9.179.1.4.5 · 1 row entry · 6 columns
A table containing QoS statistics counters per physical
interface.
caqPortStatsEntry entry .1.3.6.1.4.1.9.9.179.1.4.5.1
An entry contains QoS statistics maintained by the switching
engine.
Indexes
IF-MIBifIndex caqPortStatsDirection caqPortStatsQueueNumber caqPortStatsThresholdNumber
Column Syntax OID
caqPortStatsDirection
Indicates traffic direction of an physical interface.
CaqDirection
Textual Convention: CaqDirection Enumeration
Type Values:
1ingress
2egress
.1.3.6.1.4.1.9.9.179.1.4.5.1.1
caqPortStatsQueueNumber
Indicates the queue number of the interface for which
statistics are collected. For example : if the port type of
this interface is 1P2Q2T, this object can be 1, 2, 3.
CaqQueueNumber
Textual Convention: CaqQueueNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.4.5.1.2
caqPortStatsThresholdNumber
Indicates the threshold number of a queue on the interface for
which statistics are collected. For example : if the port type
of this interface is 1P2Q2T, this object can be 1, 2.
CaqThresholdNumber
Textual Convention: CaqThresholdNumber Unsigned32
Type Constraints:
range: 1..100
.1.3.6.1.4.1.9.9.179.1.4.5.1.3
caqPortStatsDropPkts
The number of packets have been received then dropped from the
interface because they exceeded the threshold value configured
at this queue and threshold of this interface.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.5.1.4
caqPortStatsDropPktsAveRate
The five minute linearly-decayed moving average of packets
have been received then dropped from the interface because
they exceeded the threshold value configured at this queue
and threshold of this interface.
packets per secondSNMPv2-SMIGauge32
Textual Convention: SNMPv2-SMIGauge32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.4.5.1.5
caqPortStatsDropPktsPeakRate
The peak rate of packets have been received then dropped from
the interface because they exceeded the threshold value
configured at this queue and threshold of this interface over
the past five minutes.
packets per secondSNMPv2-SMIGauge32
Textual Convention: SNMPv2-SMIGauge32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.4.5.1.6
.1.3.6.1.4.1.9.9.179.1.4.6 · 1 row entry · 1 columns
A table containing QoS statistics counter per flow.
caqFlowStatsEntry entry .1.3.6.1.4.1.9.9.179.1.4.6.1
An entry contains the number of out of profile packet
per flow maintained by the switching engine.
Indexes
No indexes recorded
Column Syntax OID
caqFlowStatsOutOfProfilePackets
Indicates the number of out-of-profile packets in
this flow.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.6.1.1
.1.3.6.1.4.1.9.9.179.1.4.7 · 1 row entry · 15 columns
A table containing QoS statistics counter per aggregate
policer.
caqAggPolicerStatsEntry entry .1.3.6.1.4.1.9.9.179.1.4.7.1
An entry contains the number of packet policed and the
number of out of profile packets per aggregate policer.
Indexes
caqAggPolicerName
Column Syntax OID
caqAggPolicerName
The name of a policer. This name has to be unique to identify
an aggregate policer in the device.
CaqPolicerName
Textual Convention: CaqPolicerName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.4.7.1.1
caqAggPolicerPackets
Indicates the number of packets is policed by this aggregate
policer. This object is only instantiated if such info is
available in the device.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.2
caqAggPolicerNRExceedPackets
Indicates the number of packets exceeded the normal rate of
this aggregate policer. This object in only instantiated if
such info is available in the device.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.3
caqAggPolicerERExceedPackets
Indicates the number of packets exceeded the excess rate of
this policer. This object is only instantiated if such info
is available in the device and if excess rate is supported
by the device as indicated by caqFlowPol…
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.4
caqAggPolicerOctets
Indicates the number of octets is policed by this aggregate
policer. This object is only instantiated if such info is
available in the device.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.5
caqAggPolicerNRExceedOctets
Indicates the number of octets exceeded the normal rate of
this aggregate policer. This object is only instantiated if
such info is available in the device.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.6
caqAggPolicerERExceedOctets
Indicates the number of octets exceeded the excess rate of
this policer. This object is only instantiated if such info
is available in the device and if excess rate is supported
by the device as indicated by caqFlowPoli…
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.4.7.1.7
caqAggPolicerOctetsRate
Indicates five minute linearly-decayed moving average of
octets policed by this aggregate policer.
This object is only instantiated if such info is available in
the device.
kbpsHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.8
caqAggPolicerNRExceedOctetsRate
Indicates five minute linearly-decayed moving average of
octets exceeded the normal rate of this aggregate policer.
This object is only instantiated if such info is available in
the device.
kbpsHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.9
caqAggPolicerERExceedOctetsRate
Indicates five minute linearly-decayed moving average of
octets exceeded the excess rate of this policer. This object
is only instantiated if such info is available in the device
and if excess rate is supported by the d…
kbpsHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.10
caqAggPolicerOctetsPeakRate
Indicates peak rate of octets is policed by this aggregate
policer over the past five minute. This object is only
instantiated if such info is available in the device.
kbpsHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.11
caqAggPolicerPacketsRate
Indicates five minute linearly-decayed moving average of
packets policed by this aggregate policer.
This object is only instantiated if such info is available in
the device.
packets per secondHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.12
caqAggPolicerNRExceedPacketsRate
Indicates five minute linearly-decayed moving average of
packets exceeded the normal rate of this aggregate policer.
This object is only instantiated if such info is available in
the device.
packets per secondHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.13
caqAggPolicerERExceedPacketsRate
Indicates five minute linearly-decayed moving average of
packets exceeded the excess rate of this policer. This object
is only instantiated if such info is available in the device
and if excess rate is supported by the …
packets per secondHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.14
caqAggPolicerPacketsPeakRate
Indicates peak rate of packets is policed by this aggregate
policer over the past five minutes. This object is only
instantiated if such info is available in the device.
packets per secondHCNUM-TCCounterBasedGauge64
Textual Convention: HCNUM-TCCounterBasedGauge64 Unsigned64
.1.3.6.1.4.1.9.9.179.1.4.7.1.15
.1.3.6.1.4.1.9.9.179.1.5.1 · 1 row entry · 2 columns
This table provides configuration information for each
(existing) VLAN on whether or not bridged packets are policed
at the microflow level on that VLAN. This configuration is
useful in situations in which there are insufficient resources
to police bridged packets at the microflow level on all VLANs.
This configuration has no effect on aggregate policing.
caqBridgedPolicerEntry entry .1.3.6.1.4.1.9.9.179.1.5.1.1
A conceptual row in the caqBridgedPolicerTable
to control if bridged packets are policed at microflow
level on a particular VLAN.
Indexes
caqBridgedFlowVlanIndex
Column Syntax OID
caqBridgedFlowVlanIndex
The VLAN-id of this VLAN.
CISCO-VTP-MIBVlanIndex
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.5.1.1.1
caqBridgedFlowEnabled
Enable or Disable this function. If this objects is set to
true, the bridged packets will be policed at microflow level.
If it is set to false, bridged packets won't be policed at
microflow level. This value has no effe…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.179.1.5.1.1.2
.1.3.6.1.4.1.9.9.179.1.5.2 · 1 row entry · 5 columns
This table is used either to assign a Cos value to frames
on a specific VLAN and which have a specific destination MAC
address and/or to indicate if the configured destination MAC
address is of a router. This table is applied only for platform
that supports these features.
caqCosMacVlanRouterEntry entry .1.3.6.1.4.1.9.9.179.1.5.2.1
The Cos value to be assigned to frames on a specific VLAN and
which have a specific destination MAC address and/or the
configured destination MAC address is of a router.
Indexes
caqCosMacAddress caqCosVlanNumber
Column Syntax OID
caqCosMacAddress
Indicates the destination MAC address to match against the
flow.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.5.2.1.1
caqCosVlanNumber
Indicates the VLAN number.
CISCO-VTP-MIBVlanIndex
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.5.2.1.2
caqMacAddressCpb
Indicates the capability of the destination MAC address denoted
by caqCosMacAddress object in the same row.

routerMac(0) means that it is a router Mac address.

cosVlanMac(1) means that a C…
Bitsr/w
Enumerated Values:
0routerMac
1cosVlanMac
.1.3.6.1.4.1.9.9.179.1.5.2.1.3
caqCosValue
Indicates the Cos value. This object is only instantiated
if the cosVlanMac bit in caqMacAddressCpb object is turned
on.
CISCO-QOS-PIB-MIBQosLayer2Cosr/w
Textual Convention: CISCO-QOS-PIB-MIBQosLayer2Cos Integer32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.5.2.1.4
caqCosMacVlanRouterStatus
The status of this conceptual row entry. This object is
used to manage creation, deletion and modification of rows in
this table.

An entry may not exist in the active state unless all objects
in the e…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.5.2.1.5
.1.3.6.1.4.1.9.9.179.1.6.3 · 1 row entry · 8 columns
This table contains a list of adjacencies to use in
policy-based forwarding (PBF). PBF is a feature that
makes possible forwarding between two different VLANs
without having a router.
caqAdjacencyEntry entry .1.3.6.1.4.1.9.9.179.1.6.3.1
An entry defines an adjacency. Each adjacency consists
of a destination VLAN, source and destination MAC address as
well as adjacency name and MTU configuration.
Indexes
caqAdjIndex
Column Syntax OID
caqAdjIndex
Indicates the index of this adjacency.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.6.3.1.1
caqAdjDstVlanNumber
Indicates the destination VLAN number of this adjacency.
CISCO-VTP-MIBVlanIndexr/w
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.6.3.1.2
caqAdjDstMacAddress
Indicates the adjacency destination MAC address.
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.6.3.1.3
caqAdjSrcMacAddress
Indicates the adjacency source MAC address. If this object
is not configured, it will contain the MAC address of the
PBF engine which is denoted by caqPbfMacAddress object.
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.6.3.1.4
caqAdjName
Indicates the adjacency name. The adjacency name should be
unique among all entries in this table.
CaqAdjacencyNamer/w
Textual Convention: CaqAdjacencyName OctetString
Type Constraints:
range: 1..18
.1.3.6.1.4.1.9.9.179.1.6.3.1.5
caqAdjMtu
Indicates the adjacency MTU.
bytesUnsigned32r/w
Constraints:
range: 576-18190
.1.3.6.1.4.1.9.9.179.1.6.3.1.6
caqAdjHitCount
Indicates the number of packets that have matched this
adjacency's criteria. The value of this object is cleared when
this row is derefenced by entries in caqSecurityActionTable.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.6.3.1.7
caqAdjStatus
Indicates the status of this adjacency conceptual entry.
This object is used to manage creation, deletion and
modification of rows in this table.

An entry may not exist in the active state unless all obje…
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.179.1.6.3.1.8
.1.3.6.1.4.1.9.9.179.1.7.4 · 1 row entry · 20 columns
This table contains a list of IP flows that describes the 
IP traffic denied and logged by the device.
caqIpFlowLoggingEntry entry .1.3.6.1.4.1.9.9.179.1.7.4.1
An entry describes an IP flow, consisting of a set of data
such as source and destination address, source and destination
port as well as protocol specific information. To keep the
table from overflow, each entry conta…
Indexes
caqIpFlowLoggingIndex
Column Syntax OID
caqIpFlowLoggingIndex
The index of this table for indicating a logged IP flow.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.7.4.1.1
caqIpFlowVlan
Indicates the VLAN number which this logged IP flow belongs.
CISCO-VTP-MIBVlanIndex
Textual Convention: CISCO-VTP-MIBVlanIndex Integer32
Type Constraints:
range: 0..4095
.1.3.6.1.4.1.9.9.179.1.7.4.1.2
caqIpFlowIfIndex
Indicates the ifIndex of the interface where this logged
IP flow arrived.
IF-MIBInterfaceIndex
Textual Convention: IF-MIBInterfaceIndex Integer32
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.9.9.179.1.7.4.1.3
caqIpFlowProtocolType
The protocol number field in the IP header of this logged
IP flow as specified in RFC 1700.
Unsigned32
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.179.1.7.4.1.4
caqIpFlowAddrType
Indicates the address type for addresses specified in
caqIpFlowSrcIp and caqIpFlowDestIp of this logged IP
flow.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.179.1.7.4.1.5
caqIpFlowSrcIp
Indicates the source address of this logged IP flow.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.7.4.1.6
caqIpFlowSrcPort
Indicates the source port number of this logged IP flow
when its protocol field is TCP or UDP. The value of this
object is -1 if the flow is not UDP or TCP traffic.
Integer32
Constraints:
range: -1-65535
.1.3.6.1.4.1.9.9.179.1.7.4.1.7
caqIpFlowDestIp
Indicates the destination address of this logged IP flow.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.7.4.1.8
caqIpFlowDestPort
Indicates the destination port number of this logged IP flow
when its protocol field is TCP or UDP. The value of this
object is -1 if the flow is not UDP or TCP traffic.
Integer32
Constraints:
range: -1-65535
.1.3.6.1.4.1.9.9.179.1.7.4.1.9
caqIpFlowIcmpType
Indicates the message type of ICMP packets. The value of this
object is -1 if the flow is not ICMP traffic.
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.9.9.179.1.7.4.1.10
caqIpFlowIcmpCode
Indicates the message code of ICMP packets. The value of this
object is -1 if the flow is not ICMP traffic.
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.9.9.179.1.7.4.1.11
caqIpFlowIgmpType
Indicates the message type of IGMP packets. The value of this
object is -1 if the flow is not IGMP traffic.
Integer32
Constraints:
range: -1-15
.1.3.6.1.4.1.9.9.179.1.7.4.1.12
caqIpFlowArpOpcode
Indicates the ARP opcode value of this ARP flow.

If the value of this object is notApplicable(1), this flow
is not ARP traffic.

If the value of this object is request(2), this flow
is ARP r…
Enumeration
Enumerated Values:
1notApplicable
2request
3reply
.1.3.6.1.4.1.9.9.179.1.7.4.1.13
caqIpFlowArpSrcMacAddr
Indicates the Ethernet Source Address value of this ARP
flow. This object is ignored if the flow is not ARP
traffic.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.7.4.1.14
caqIpFlowArpHeaderSrcMacAddr
Indicates the Ethernet Source Address value included in the
ARP header of this ARP flow. This object is ignored if the
flow is not ARP traffic.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.9.9.179.1.7.4.1.15
caqIpFlowPacketsCount
Indicates the number of packets that belong to this IP flow.
packetsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.7.4.1.16
caqIpFlowLoggingTTL
Indicates the TTL (Time to Live) of this entry. The entry
is removed when its value of this object reaches 0.
secondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.7.4.1.17
caqIpFlowArpLoggingSource
Indicates the source that triggered the logging of this
ARP flow. This object value is 'notApplicable' if the
flow is not ARP traffic.

'dai' indicates the logging source is Dynamic Arp Inspection
feature…
Enumeration
Enumerated Values:
1notApplicable
2dai
3acl
.1.3.6.1.4.1.9.9.179.1.7.4.1.18
caqIpFlowArpAclName
Indicates the security ACL name which triggered the
logging of this ARP flow. This object is ignored if
the value of caqIpFlowArpLoggingSource object in the
same row is not 'acl'.
SNMP-FRAMEWORK-MIBSnmpAdminString
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.7.4.1.19
caqIpFlowArpAceNumber
Indicates the ACE number within the ACL denoted by
caqIpFlowArpAclName object which triggered the logging
of this ARP flow. This object is ignored if the value of
caqIpFlowArpLoggingSource object in the same row is no…
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.7.4.1.20
.1.3.6.1.4.1.9.9.179.1.8.10 · 1 row entry · 3 columns
A table containing ARP Inspection statistics counter per ACL.
caqArpInspStatsEntry entry .1.3.6.1.4.1.9.9.179.1.8.10.1
An entry contains the numbers of packet permitted or denied
per ACL.
Indexes
caqArpInspAclName
Column Syntax OID
caqArpInspAclName
The name of an ACL that contains ACE used for ARP Inspection.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.8.10.1.1
caqArpInspForwardedPackets
Indicates the number of packets subjected to ARP Inspection
is forwarded by this ACL.
packetsSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.8.10.1.2
caqArpInspDroppedPackets
Indicates the number of packets subjected to ARP Inspection
is dropped by this ACL.
packetsSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.8.10.1.3
.1.3.6.1.4.1.9.9.179.1.8.11 · 1 row entry · 2 columns
This table contains the configuration of several threshold
values related to ARP Inspection at each physical interface.
caqIfArpInspConfigEntry entry .1.3.6.1.4.1.9.9.179.1.8.11.1
Each entry contains the configuration for drop threshold
and shutdown threshold for ARP Inspection at each physical
interface that supports this feature. Some of the
interfaces (but not limited to) for which this featu…
Indexes
IF-MIBifIndex
Column Syntax OID
caqIfArpInspDropThreshold
Indicates the drop threshold value where excess packets of
a traffic flow subjected to ARP Inspection will be dropped
if its rate is greater than this threshold value. If the value
of this object is 0, no rate limit is …
packet per secondUnsigned32r/w
Constraints:
range: 0-5000
.1.3.6.1.4.1.9.9.179.1.8.11.1.1
caqIfArpInspShutdownThreshold
Indicates the threshold value where the interface will be
shutdown if traffic rate subjected to ARP Inspection is greater
than this threshold value. If the value of this object is 0,
no ARP traffic rate limit is applied…
packet per secondUnsigned32r/w
Constraints:
range: 0-5000
.1.3.6.1.4.1.9.9.179.1.8.11.1.2
.1.3.6.1.4.1.9.9.179.1.9.4 · 1 row entry · 3 columns
This table provides the hit count configuration on 
ACLs which support this feature.
caqAclHitCountEntry entry .1.3.6.1.4.1.9.9.179.1.9.4.1
An entry indicates whether the hit count feature is enabled
on a particular ACL as well as its statistic collection mode.
Indexes
caqAclHitCountAclType caqAclHitCountAclName
Column Syntax OID
caqAclHitCountAclType
Indicates the type of ACL.

ipSecurity(1) indicates that this ACL is an IP Security ACL.

ipxSecurity(2) indicates that this ACL is an IPX Security ACL.

macSecurity(3) indicate…
CaqHitCountAclType
Textual Convention: CaqHitCountAclType Enumeration
Type Values:
1ipSecurity
2ipxSecurity
3macSecurity
.1.3.6.1.4.1.9.9.179.1.9.4.1.1
caqAclHitCountAclName
Indicates the ACL name which should exist in the ACL tables
e.g. in caqIpAceTable. This ACL must be matching the type
specified in caqAclHitCountAclType in the same row.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.9.4.1.2
caqAclHitCountEnable
Indicates whether this ACL hit count is enabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.179.1.9.4.1.3
.1.3.6.1.4.1.9.9.179.1.9.5 · 1 row entry · 6 columns
This table provides the hit count configuration on 
ACEs which support this feature.
caqAceHitCountEntry entry .1.3.6.1.4.1.9.9.179.1.9.5.1
An entry indicates whether the hit count feature is enabled
on a particular ACE as well as its hit count statistic.
Indexes
caqAceHitCountAclType caqAceHitCountAclName caqAceHitCountAceIndex
Column Syntax OID
caqAceHitCountAclType
Indicates the type of ACL.

ipSecurity(1) indicates that this ACL is an IP Security ACL.

ipxSecurity(2) indicates that this ACL is an IPX Security ACL.

macSecurity(3) indicate…
CaqHitCountAclType
Textual Convention: CaqHitCountAclType Enumeration
Type Values:
1ipSecurity
2ipxSecurity
3macSecurity
.1.3.6.1.4.1.9.9.179.1.9.5.1.1
caqAceHitCountAclName
Indicates the ACL name which should exist in the ACL tables
e.g. in caqIpAceTable. This ACL must be matching the type
specified in caqAceHitCountAclType in the same row.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.9.5.1.2
caqAceHitCountAceIndex
The index of an ACE within an ACL.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.9.5.1.3
caqAceHitCountEnable
Indicates whether this ACE hit count is enabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.179.1.9.5.1.4
caqAceIngressHitCount
Indicates number of hit count for this ACE for
ingress traffic.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.9.5.1.5
caqAceEgressHitCount
Indicates number of hit count for this ACE for
egress traffic.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.9.5.1.6
.1.3.6.1.4.1.9.9.179.1.9.6 · 1 row entry · 5 columns
This table provides the ACL hit count statistics at
an interface. An interface can be a physical port if
the bit portAclHitCount(1) is set in the object
caqAclFeatureCpb or a VLAN if the bit vlanAclHitCount(0)
is set in the object caqAclFeatureCpb.
caqIfAclHitCountEntry entry .1.3.6.1.4.1.9.9.179.1.9.6.1
Each entry indicates the number of hit count at each
ACE belonged to an ACL which supports hit count collection
at an interface where the ACL is attached.
Indexes
IF-MIBifIndex caqIfAclHitCountAclType caqIfAclHitCountAclName caqIfAclHitCountAceIndex
Column Syntax OID
caqIfAclHitCountAclType
Indicates the type of ACL.

ipSecurity(1) indicates that this ACL is an IP Security ACL.

ipxSecurity(2) indicates that this ACL is an IPX Security ACL.

macSecurity(3) indicate…
CaqHitCountAclType
Textual Convention: CaqHitCountAclType Enumeration
Type Values:
1ipSecurity
2ipxSecurity
3macSecurity
.1.3.6.1.4.1.9.9.179.1.9.6.1.1
caqIfAclHitCountAclName
Indicates the ACL name which should exist in the ACL tables
e.g. in caqIpAceTable. This ACL must be matching the type
specified in caqIfAclHitCountAclType in the same row.
CaqAclName
Textual Convention: CaqAclName OctetString
Type Constraints:
range: 1..31
.1.3.6.1.4.1.9.9.179.1.9.6.1.2
caqIfAclHitCountAceIndex
The index of an ACE within an ACL.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.179.1.9.6.1.3
caqIfAclIngressHitCount
Indicates the number of hit count of this ACE for
ingress traffic on this interface.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.9.6.1.4
caqIfAclEgressHitCount
Indicates the number of hit count of this ACE for
egress traffic on this interface.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.179.1.9.6.1.5
.1.3.6.1.4.1.9.9.179.1.10.1 · 1 row entry · 3 columns
This table provides the management information for 
downloaded ACLs.
caqDownloadAclInfoEntry entry .1.3.6.1.4.1.9.9.179.1.10.1.1
An entry is populated for each downloaded ACL in
the device.
Indexes
caqDownloadAclName
Column Syntax OID
caqDownloadAclName
This object indicates the name of a downloaded ACL.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.9.9.179.1.10.1.1.1
caqDownloadAclUserCount
This object indicates the number of users (i.e.,
authenticated hosts) who are using this downloaded ACL.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.10.1.1.2
caqDownloadAclDownloadTime
This object indicates the time when this ACL is downloaded
to the device.
SNMPv2-TCDateAndTime
Textual Convention: SNMPv2-TCDateAndTime OctetString
Type Constraints:
range: 8
range: 11
.1.3.6.1.4.1.9.9.179.1.10.1.1.3
.1.3.6.1.4.1.9.9.179.1.10.2 · 1 row entry · 21 columns
This table contains a list of downloaded IP ACEs for 
security purpose. Each ACE consists of a filter specification
and behavior associated with it which describes what action
to carry out on packets which match.
          
An ACL is defined as the set of ACEs. Each ACE is named by
a combination of an AclName and an ACE index, such that all
the ACEs which are named using the same AclName are part of
the same ACL.
caqIpDownloadAceEntry entry .1.3.6.1.4.1.9.9.179.1.10.2.1
An entry defines an ACE, consisting of a set of match
criteria. For a packet to match an entry, it has to match
all the criteria specified in that entry.
Indexes
caqIpDownloadAclName caqIpDownloadAceIndex
Column Syntax OID
caqIpDownloadAclName
The name of a downloaded IP ACL.
SNMP-FRAMEWORK-MIBSnmpAdminString
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.1
caqIpDownloadAceIndex
The index of an ACE within a downloaded ACL.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.10.2.1.2
caqIpDownloadAceMatchedAction
Indicates the action to be taken if a packet matches this ACE.

If 'permit' is specified, the matched packet will be allowed
through the device.

If 'deny' is specified, the matched packet wi…
Enumeration
Enumerated Values:
1permit
2deny
3denyAndLog
4permitAndCapture
.1.3.6.1.4.1.9.9.179.1.10.2.1.3
caqIpDownloadAceProtocolType
The protocol number field in the IP header used to indicate
the higher layer protocol as specified in RFC 1700. A value
value of 0 matches every IP packet.

For example :
0 is IP, 1 is ICMP, 2 is IGMP, 4…
CISCO-TCCiscoIpProtocol
Textual Convention: CISCO-TCCiscoIpProtocol Integer32
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.4
caqIpDownloadAceAddrType
The type of IP address used by this ACE entry.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.179.1.10.2.1.5
caqIpDownloadAceSrcIp
The specified source IP address. The packet's source address
is AND-ed with the value of caqIpDownloadAceSrcIpMask and then
compared against the value of this object. If this object value
is 0.0.0.0, and the value of ca…
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.6
caqIpDownloadAceSrcIpMask
The specified source IP address mask.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.7
caqIpDownloadAceSrcPortOp
Indicates how a packet's source TCP/UDP port number is
to be compared.

'noOperator', which is the default value, means that no
comparison is to be made with the source TCP/UDP port number.

Enumeration
Enumerated Values:
1noOperator
2lt
3gt
4eq
5neq
6range
.1.3.6.1.4.1.9.9.179.1.10.2.1.8
caqIpDownloadAceSrcPort
The source port number of the TCP or UDP protocol. If the
caqIpDownloadAceSrcPortOp object in the same row is 'range',
this object will be the starting port number of the port
range.
INET-ADDRESS-MIBInetPortNumber
Textual Convention: INET-ADDRESS-MIBInetPortNumber Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.179.1.10.2.1.9
caqIpDownloadAceSrcPortRange
The source port number of the TCP or UDP protocol. If the
caqIpDownloadAceSrcPortOp object in the same row is 'range',
this object will be the ending port number of the port range,
otherwise the value of this object is …
INET-ADDRESS-MIBInetPortNumber
Textual Convention: INET-ADDRESS-MIBInetPortNumber Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.179.1.10.2.1.10
caqIpDownloadAceDestIp
The specified destination IP address. The packet's destination
address is AND-ed with the value of caqIpDownloadAceDestIpMask
and then compared against the value of this object. If this
object value is 0.0.0.0 and the v…
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.11
caqIpDownloadAceDestIpMask
The specified destination IP address mask.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.2.1.12
caqIpDownloadAceDestPortOp
Indicates how a packet's destination TCP/UDP port number is
to be compared.

'noOperator', which is the default value, means that no
comparison is to be made with the destination TCP/UDP port
number.
Enumeration
Enumerated Values:
1noOperator
2lt
3gt
4eq
5neq
6range
.1.3.6.1.4.1.9.9.179.1.10.2.1.13
caqIpDownloadAceDestPort
The destination port number of the TCP or UDP protocol.
If the caqIpDownloadAceDestPortOp object in the same row is
'range' this object will be the starting port number of the
port range.
INET-ADDRESS-MIBInetPortNumber
Textual Convention: INET-ADDRESS-MIBInetPortNumber Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.179.1.10.2.1.14
caqIpDownloadAceDestPortRange
The destination port number of the TCP or UDP protocol.
If the caqIpDownloadAceDestPortOp object in the same row is
'range', this object will be the ending port number of the
port range, otherwise this object value is i…
INET-ADDRESS-MIBInetPortNumber
Textual Convention: INET-ADDRESS-MIBInetPortNumber Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.179.1.10.2.1.15
caqIpDownloadAceTosMatchCriteria
Indicates what field of Tos octet in the packet header
to be matched.

'none' means that there is no need to match the ToS octet.

'matchDscp' means that the DSCP value of packet header need…
Enumeration
Enumerated Values:
1none
2matchDscp
3matchIpPrec
.1.3.6.1.4.1.9.9.179.1.10.2.1.16
caqIpDownloadAceIpPrec
Specifies the IP precedence value to be matched against.

The value of this object is ignored whenever the value of
caqIpDownloadAceTosMatchCritial object is not 'matchIpPrec'.
CaqIpPrecedence
Textual Convention: CaqIpPrecedence Unsigned32
Type Constraints:
range: 0..7
.1.3.6.1.4.1.9.9.179.1.10.2.1.17
caqIpDownloadAceDscp
Specifies the Dscp value to be matched against.
Packets can be matched to DSCP value from 0 to 63.

The value of this object is ignored whenever the value of
caqIpDownloadAceTosMatchCritial object is not…
CISCO-QOS-PIB-MIBDscp
Textual Convention: CISCO-QOS-PIB-MIBDscp Integer32
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.179.1.10.2.1.18
caqIpDnldAcePrtocolMatchCriteria
Indicates what field in the packet header for ICMP or IGMP
or TCP protocol to be matched.

'none' means no comparison is to be done for ICMP/TCP.

'matchIcmpType' means that the Type field o…
Enumeration
Enumerated Values:
1none
2matchIcmpType
3matchIcmpTypeAndCode
4matchEstablished
.1.3.6.1.4.1.9.9.179.1.10.2.1.19
caqIpDownloadAceIcmpType
Indicates the message type of ICMP packets. The type is
a number from 0 to 255.

The value of this object is ignored whenever the value of
caqIpDnldAcePrtocolMatchCriteria object is not 'matchIcmpType'
o…
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.10.2.1.20
caqIpDownloadAceIcmpCode
Indicates the message code of ICMP packets. The code is
a number from 0 to 255.

The value of this object is ignored whenever the value of
caqIpDnldAcePrtocolMatchCriteria object is not
'matchIcmpTypeAnd…
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.179.1.10.2.1.21
.1.3.6.1.4.1.9.9.179.1.10.3 · 1 row entry · 3 columns
This table provides the management information for 
physical interface where downloaded ACLs are applied.
caqIfDownloadAclEntry entry .1.3.6.1.4.1.9.9.179.1.10.3.1
An entry is populated for each interface that utilies
downloaded ACLs in the device.
Indexes
IF-MIBifIndex caqDownloadAclName
Column Syntax OID
caqIfDownloadAclFeature
This object indicates the security feature running at this
interface and trigger the download of this ACL.

'dot1x' indicates that the 802.1x feature is running at this
interface and trigger the download o…
Enumeration
Enumerated Values:
1dot1x
2eou
3macAuth
4webAuth
.1.3.6.1.4.1.9.9.179.1.10.3.1.1
caqIfDownloadAclAddressType
This object indicates the type of IP address of the host.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.179.1.10.3.1.2
caqIfDownloadAclHostAddress
This object indicates IP address of the host connected
to this interface. The type of this address is determined
by the value of caqIfDownloadAclAddressType object.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.3.1.3
.1.3.6.1.4.1.9.9.179.1.10.4 · 1 row entry · 2 columns
This table provides the management information for 
the mapping of IP Phone to interface that utilizes
downloaded ACL.
caqIfIpPhoneMapEntry entry .1.3.6.1.4.1.9.9.179.1.10.4.1
An entry is populated for each interface that has
an IP Phone connected to and utilizes downloaded ACL.
Indexes
IF-MIBifIndex
Column Syntax OID
caqIfIpPhoneAddressType
This object indicates the type of IP address of the
IP Phone connected to this interface.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.179.1.10.4.1.1
caqIfIpPhoneHostAddress
This object indicates the IP address of the IP Phone.
The type of this address is determined by the value of
the caqIfIpPhoneAddressType object.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.179.1.10.4.1.2