CISCO-LWAPP-IDS-MIB
This MIB is intended to be implemented on all those
devices operating as Central Controllers (CC) that
terminate the Light Weight Access Point Protocol
tunnel from Light-weight LWAPP Access Points.
This MIB provides the information used to integrate
the LWAPP controller with external IDS/IPS
applications. LWAPP controllers interact with
these applications to protect the network against
various threats that would compromise the overall
security of the network.
The arrangement of the IDS / IPS applications,
controller (referred to as CC in the diagram) and the
LWAPP APs appear as follows.
+.......+ +.......+
+ + + +
+ IDS + + IDS +
+ IPS + + IPS +
+.......+ +.......+
. .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ CC + + CC + + CC + + CC +
+ + + + + + + +
+......+ +......+ +......+ +......+
.. . . .
.. . . .
. . . . .
. . . . .
. . . . .
. . . . .
+......+ +......+ +......+ +......+ +......+
+ + + + + + + + + +
+ AP + + AP + + AP + + AP + + AP +
+ + + + + + + + + +
+......+ +......+ +......+ +......+ +......+
. . . .
. . . . .
. . . . .
. . . . .
. . . . .
+......+ +......+ +......+ +......+ +......+
+ + + + + + + + + +
+ MN + + MN + + MN + + MN + + MN +
+ + + + + + + + + +
+......+ +......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and
the APs. The MNs communicate with the APs through
the protocol defined by the 802.11 standard. The
controllers and the IDS systems exchange information
through Cisco proprietary event exchange mechanisms.
LWAPP APs, upon bootup, discover and join one of the
controllers and the controller pushes the configuration,
that includes the WLAN parameters, to the LWAPP APs.
The APs then encapsulate all the 802.11 frames from
wireless clients inside LWAPP frames and forward
the LWAPP frames to the controller.
One or more controllers hold logical connections to
an IDS / IPS and interact with it to enforce security
on the network.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access
control ( MAC ) and physical layer ( PHY ) interface
and provides access to the distribution services via
the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in
LWAPP frames and sends them to the controller to which
it is logically connected.
Central Controller ( CC )
The central entity that terminates the LWAPP protocol
tunnel from the LWAPP APs. Throughout this MIB,
this entity is also referred to as 'controller'.
HyperText Transfer Protocol Over Secure Socket Layer
(HTTPS)
HTTPS is a Web based protocol that encrypts and
decrypts user page requests as well as the pages
that are returned by the Web server. HTTPS uses
port 443 instead of HTTP port 80 in its
interactions with the lower layer, TCP/IP. SSL
uses a 40-bit key for the RC4 stream encryption
algorithm, which is considered an adequate degree
of encryption for commercial exchange.
Intrusion Detection System ( IDS )
An IDS performs activities like enforcing security
related policies, identifying and reporting attacks
on the network etc., thereby helping to improve
the overall security of the enterprise network.
Intrusion Prevention System ( IPS )
An IPS offers significant protection to the network
against viruses, worms, signature attacks etc. This
system detects L3 - L7 attacks. This system can also
instruct other IPS clients through standards based
protocols to allow/block network access for specific
network entities.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the
communication between the Access Points and the
controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless
network associated with an access point.
Network Management System ( NMS )
The station from which the administrator manages the
wired and wireless networks.
Secure Hash Algorithm ( SHA )
The SHA, developed by NIST for use with the Digital
Signature Standard (DSS) is specified within the
Secure Hash Standard (SHS). SHA is a cryptographic
message digest algorithm similar to the MD4 family
of hash functions developed by Rivest. It differs
from the MD4 hash functions in that it adds an
additional expansion operation, an extra round and
the whole transformation was designed to
accomodate the DSS block size for efficiency.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and
Physical Layer ( PHY ) Specifications.
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light
Weight Access Point Protocol
- Source file
CISCO-LWAPP-IDS-MIB- Last revised
- Identity
ciscoLwappIdsMIB- Base OID
1.3.6.1.4.1.9.9.519
Imported Objects
| CISCO-SMI | ciscoMgmt |
| INET-ADDRESS-MIB | InetAddress InetAddressType |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | RowStatus TimeInterval TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-LWAPP-IDS-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-LWAPP-IDS-MIB::ciscoLwappIdsMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-LWAPP-IDS-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-LWAPP-IDS-MIB::ciscoLwappIdsMIB'
Objects (24)
Showing 24 of 24 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.519 |
||
.1.3.6.1.4.1.9.9.519.0 |
||
.1.3.6.1.4.1.9.9.519.1 |
||
.1.3.6.1.4.1.9.9.519.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.1.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.1.1.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.1.1.1.2 |
||
.1.3.6.1.4.1.9.9.519.1.1.1.1.3 |
||
.1.3.6.1.4.1.9.9.519.1.1.1.1.4 |
||
|
Hundredths-secondsInteger32
|
.1.3.6.1.4.1.9.9.519.1.1.1.1.5 |
|
.1.3.6.1.4.1.9.9.519.1.1.1.1.6 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.519.1.1.1.1.7 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.519.1.1.1.1.8 |
|
.1.3.6.1.4.1.9.9.519.1.1.1.1.9 |
||
.1.3.6.1.4.1.9.9.519.1.2 |
||
.1.3.6.1.4.1.9.9.519.1.2.1 |
||
.1.3.6.1.4.1.9.9.519.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.2.1.1.1 |
||
.1.3.6.1.4.1.9.9.519.1.2.1.1.2 |
||
|
hundredths-secondsSNMPv2-TCTimeInterval
|
.1.3.6.1.4.1.9.9.519.1.2.1.1.3 |
|
.1.3.6.1.4.1.9.9.519.2 |
||
.1.3.6.1.4.1.9.9.519.2.1 |
||
.1.3.6.1.4.1.9.9.519.2.2 |
Dependencies (6) 6 direct Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- INET-ADDRESS-MIBrfc
- SNMPv2-CONFrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-LWAPP-IDS-MIBciscoselected
Conformance Groups (3)
|
cLIdsIpsSensorUserName cLIdsIpsSensorPassword cLIdsIpsSensorQueryInterval cLIdsIpsSensorEnabled cLIdsIpsSensorFingerPrintHex cLIdsIpsSensorPort cLIdsIpsSensorRowStatus
This collection of objects provides the
information used to integrate a controller with external IDS/IPS applications. |
.1.3.6.1.4.1.9.9.519.2.2.1
|
|
|
This collection of objects provides the status
of the various operations the controller performs together with external IDS/IPS applications. |
.1.3.6.1.4.1.9.9.519.2.2.2
|
|
|
This collection of objects provides the information
about the notifications sent by the agent related to IDS. |
.1.3.6.1.4.1.9.9.519.2.2.3
|
Compliance Statements (1)
OID
.1.3.6.1.4.1.9.9.519.2.1.1The compliance statement for the SNMP entities that
implement the ciscoLwappIdsMIB module.
implement the ciscoLwappIdsMIB module.
Required groups
| mandatory | ciscoLwappIdsConfigGroup | |
| mandatory | ciscoLwappIdsStatusGroup | |
| mandatory | ciscoLwappIdsNotifsGroup |
Notifications / Traps (1)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.519.0.1 |
This notification is sent by the agent with
cLIdsClientTimeRemaining indicating a value greater than 0, whenever it adds a row to cLIdsClientExclTable. The agent also sends this notification with cLIdsClientTimeRemaining equal to 0, when it removes a row from cLIdsClientExclTable. |