CISCO-LWAPP-AAA-MIB
This MIB is intended to be implemented on all those
devices operating as Central Controllers (CC), that
terminate the Light Weight Access Point Protocol
tunnel from Cisco Light-weight LWAPP Access Points.
Information provided by this MIB is used to manage
AAA information on the controller.
The relationship between CC and the LWAPP APs
can be depicted as follows:
+......+ +......+ +......+
+ + + + + +
+ CC + + CC + + CC +
+ + + + + +
+......+ +......+ +......+
.. . .
.. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ AP + + AP + + AP + + AP +
+ + + + + + + +
+......+ +......+ +......+ +......+
. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ MN + + MN + + MN + + MN +
+ + + + + + + +
+......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and
the APs. The MNs communicate with the APs through
the protocol defined by the 802.11 standard.
LWAPP APs, upon bootup, discover and join one of the
controllers and the controller pushes the configuration,
that includes the WLAN parameters, to the LWAPP APs.
The APs then encapsulate all the 802.11 frames from
wireless clients inside LWAPP frames and forward
the LWAPP frames to the controller.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access
control ( MAC ) and physical layer ( PHY ) interface
and provides access to the distribution services via
the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in
LWAPP frames and sends them to the controller to which
it is logically connected.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the
communication between the Access Points and the
Central Controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless
network associated with an access point. Mobile Node
and client are used interchangeably.
Terminal Access Controller Access-Control System
( TACACS )
A remote authentication protocol that is used to
communicate with an authentication server.
TACACS allows a remote access server to communicate
with an authentication server in order to determine
if the user has access to the network.
Remote Authentication Dial In User Service (RADIUS)
It is an AAA (authentication, authorization and accounting)
protocol for applications such as network access or
IP mobility. It is intended to work in both local and
roaming situations.
Wireless LAN ( WLAN )
It is a wireless local area network, which is the
linking of two or more computers without using wires.
It uses radio communication to accomplish the same
functionality of a wired LAN.
PAP - Password Authentication Protocol
CHAP - Challenge Handshake Authentication Protocol
MD5-CHAP - Message Digest 5 Challenge Handshake Authentication
Protocol
LSC - Local Significant Certificate
LSC can be used if we want our own public key
infrastructure (PKI) to provide better security,
to have control of our certificate authority (CA),
and to define policies, restrictions, and usages
on the generated certificates.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and
Physical Layer ( PHY ) Specifications
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light
Weight Access Point Protocol
- Source file
CISCO-LWAPP-AAA-MIB- Last revised
- Identity
ciscoLwappAAAMIB- Base OID
1.3.6.1.4.1.9.9.598
Imported Objects
| CISCO-LWAPP-TC-MIB | CLSecKeyFormat |
| CISCO-LWAPP-WLAN-MIB | cLWlanIndex (no object page) |
| CISCO-SMI | ciscoMgmt |
| CISCO-TC | CiscoURLString |
| INET-ADDRESS-MIB | InetAddress InetAddressType InetPortNumber |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | MacAddress RowStatus StorageType TimeInterval TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-LWAPP-AAA-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-LWAPP-AAA-MIB::ciscoLwappAAAMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-LWAPP-AAA-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-LWAPP-AAA-MIB::ciscoLwappAAAMIB'
Objects (127)
Showing 127 of 127 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.598 |
||
.1.3.6.1.4.1.9.9.598.0 |
||
.1.3.6.1.4.1.9.9.598.1 |
||
.1.3.6.1.4.1.9.9.598.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.1.1.1 |
|
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.598.1.1.1.1.2 |
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.10 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.11 |
|
.1.3.6.1.4.1.9.9.598.1.1.12 |
||
|
secondsInteger32
|
.1.3.6.1.4.1.9.9.598.1.1.13 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.14 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.15 |
|
.1.3.6.1.4.1.9.9.598.1.1.16 |
||
.1.3.6.1.4.1.9.9.598.1.1.17 |
||
.1.3.6.1.4.1.9.9.598.1.1.18 |
||
.1.3.6.1.4.1.9.9.598.1.1.19 |
||
.1.3.6.1.4.1.9.9.598.1.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.2.1.1 |
|
.1.3.6.1.4.1.9.9.598.1.1.2.1.10 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.11 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.3 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.4 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.5 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.6 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.1.2.1.8 |
||
|
secondsUnsigned32
|
.1.3.6.1.4.1.9.9.598.1.1.2.1.9 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.598.1.1.20 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.598.1.1.21 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.598.1.1.22 |
|
.1.3.6.1.4.1.9.9.598.1.1.23 |
||
.1.3.6.1.4.1.9.9.598.1.1.23.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.1 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.2 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.3 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.4 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.5 |
|
.1.3.6.1.4.1.9.9.598.1.1.23.1.6 |
||
.1.3.6.1.4.1.9.9.598.1.1.23.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.1.24 |
||
.1.3.6.1.4.1.9.9.598.1.1.24.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.1 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.2 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.3 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.4 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.5 |
|
.1.3.6.1.4.1.9.9.598.1.1.24.1.6 |
||
.1.3.6.1.4.1.9.9.598.1.1.24.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.1.25 |
||
.1.3.6.1.4.1.9.9.598.1.1.25.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.25.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.25.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.1.26 |
||
.1.3.6.1.4.1.9.9.598.1.1.26.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.26.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.26.1.2 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.598.1.1.27 |
|
.1.3.6.1.4.1.9.9.598.1.1.3 |
||
|
CISCO-LWAPP-WLAN-MIBcLWlanIndex
|
.1.3.6.1.4.1.9.9.598.1.1.3.1 |
|
.1.3.6.1.4.1.9.9.598.1.1.3.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.1.3.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.1.3.1.3 |
||
.1.3.6.1.4.1.9.9.598.1.1.3.1.4 |
||
|
secondsInteger32
|
.1.3.6.1.4.1.9.9.598.1.1.3.1.5 |
|
.1.3.6.1.4.1.9.9.598.1.1.4 |
||
.1.3.6.1.4.1.9.9.598.1.1.5 |
||
.1.3.6.1.4.1.9.9.598.1.1.6 |
||
.1.3.6.1.4.1.9.9.598.1.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.1.8 |
||
|
|
.1.3.6.1.4.1.9.9.598.1.1.9 |
|
.1.3.6.1.4.1.9.9.598.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.2.1 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1.4 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.598.1.2.1.1.5 |
|
.1.3.6.1.4.1.9.9.598.1.2.1.1.6 |
||
.1.3.6.1.4.1.9.9.598.1.2.1.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.2.2 |
||
.1.3.6.1.4.1.9.9.598.1.2.3 |
||
.1.3.6.1.4.1.9.9.598.1.2.4 |
||
.1.3.6.1.4.1.9.9.598.1.2.5 |
||
.1.3.6.1.4.1.9.9.598.1.2.6 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1.1 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1.2 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1.3 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1.4 |
||
.1.3.6.1.4.1.9.9.598.1.2.6.1.5 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.2.6.1.6 |
|
.1.3.6.1.4.1.9.9.598.1.2.6.1.7 |
||
.1.3.6.1.4.1.9.9.598.1.3 |
||
.1.3.6.1.4.1.9.9.598.1.3.1 |
||
.1.3.6.1.4.1.9.9.598.1.3.10 |
||
.1.3.6.1.4.1.9.9.598.1.3.11 |
||
.1.3.6.1.4.1.9.9.598.1.3.12 |
||
.1.3.6.1.4.1.9.9.598.1.3.13 |
||
.1.3.6.1.4.1.9.9.598.1.3.14 |
||
.1.3.6.1.4.1.9.9.598.1.3.15 |
||
.1.3.6.1.4.1.9.9.598.1.3.16 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.598.1.3.17 |
|
.1.3.6.1.4.1.9.9.598.1.3.18 |
||
.1.3.6.1.4.1.9.9.598.1.3.19 |
||
.1.3.6.1.4.1.9.9.598.1.3.2 |
||
.1.3.6.1.4.1.9.9.598.1.3.20 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.598.1.3.21 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.598.1.3.22 |
|
.1.3.6.1.4.1.9.9.598.1.3.23 |
||
.1.3.6.1.4.1.9.9.598.1.3.24 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.598.1.3.25 |
|
.1.3.6.1.4.1.9.9.598.1.3.26 |
||
.1.3.6.1.4.1.9.9.598.1.3.3 |
||
.1.3.6.1.4.1.9.9.598.1.3.4 |
||
.1.3.6.1.4.1.9.9.598.1.3.5 |
||
.1.3.6.1.4.1.9.9.598.1.3.6 |
||
.1.3.6.1.4.1.9.9.598.1.3.7 |
||
.1.3.6.1.4.1.9.9.598.1.3.8 |
||
.1.3.6.1.4.1.9.9.598.1.3.9 |
||
.1.3.6.1.4.1.9.9.598.2 |
||
.1.3.6.1.4.1.9.9.598.2.1 |
||
.1.3.6.1.4.1.9.9.598.2.2 |
Dependencies (9) 9 direct Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-LWAPP-TC-MIBcisco
- CISCO-TCcisco
- INET-ADDRESS-MIBrfc
- SNMPv2-CONFrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-LWAPP-WLAN-MIBcisco
- CISCO-LWAPP-AAA-MIBciscoselected
Conformance Groups (8)
Compliance Statements (2)
OID
.1.3.6.1.4.1.9.9.598.2.1.1The compliance statement for the SNMP entities that
implement the ciscoLwappAAAMIB module.
implement the ciscoLwappAAAMIB module.
Required groups
| mandatory | ciscoLwappAAAMIBConfigGroup | |
| mandatory | ciscoLwappAAAMIBNotifsGroup | |
| mandatory | ciscoLwappAAAMIBStatusObjsGroup |
OID
.1.3.6.1.4.1.9.9.598.2.1.2The compliance statement for the SNMP entities that
implement the ciscoLwappAAAMIB module.
implement the ciscoLwappAAAMIB module.
Required groups
| mandatory | ciscoLwappAAAMIBConfigGroup | |
| mandatory | ciscoLwappAAAMIBSaveUserConfigGroup | |
| mandatory | ciscoLwappAAAMIBRadiusConfigGroup | |
| mandatory | ciscoLwappAAAMIBAPPolicyConfigGroup | |
| mandatory | ciscoLwappAAAMIBWlanAuthAccServerConfigGroup | |
| mandatory | ciscoLwappAAAMIBNotifsGroup | |
| mandatory | ciscoLwappAAAMIBStatusObjsGroup | |
| mandatory | ciscoLwappAAAMIBDBEntriesGroup |
Notifications / Traps (9)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.598.0.1 |
This notification is sent by the agent when the
controller detects that the RADIUS server is activated in the global list. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.2 |
This notification is sent by the agent when the
controller detects that the RADIUS server is deactivated in the global list. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.3 |
This notification is sent by the agent when the
controller detects that the RADIUS server is activated on the WLAN. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.4 |
This notification is sent by the agent when the
controller detects that the RADIUS server is deactivated on the WLAN. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.5 |
This notification is sent by the agent when the
controller detects that the RADIUS server failed to respond to request from a client/user. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.6 |
This notification is sent by the agent when the
controller detects that the RADIUS authenticating server is available/responsive when it was previously unavailable/unresponsive. The state change triggers this notification. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.7 |
This notification is sent by the agent when the
controller detects that the RADIUS authenticating server is unavailable/unresponsive when it was previously available/responsive. The state change triggers this notification. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.8 |
This notification is sent by the agent when the
controller detects that the RADIUS accounting server is available/responsive when it was previously unavailable/unresponsive. The state change triggers this notification. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |
|
.1.3.6.1.4.1.9.9.598.0.9 |
This notification is sent by the agent when the
controller detects that the RADIUS accounting server is unavailable/unresponsive when it was previously available/responsive. The state change triggers this notification. The RADIUS server is identified by the address (claRadiusAddress) and port number (claRadiusPortNum). |