CISCO-LWAPP-ROGUE-MIB

        This MIB is intended to be implemented on all those
devices operating as Central Controllers, that
terminate the Light Weight Access Point Protocol
tunnel from Cisco Light-weight LWAPP Access Points.
        
This MIB provides information about the Rogue APs
and Clients that are detected by the controller.
        
The relationship between CC and the LWAPP APs
can be depicted as follows:
        
      +......+     +......+     +......+
      +      +     +      +     +      +
      +  CC  +     +  CC  +     +  CC  +
      +      +     +      +     +      +
      +......+     +......+     +......+
        ..            .             .
        ..            .             .
       .  .            .             .
      .    .            .             .
     .      .            .             .
    .        .            .             .
+......+ +......+     +......+      +......+
+      + +      +     +      +      +      +
+  AP  + +  AP  +     +  AP  +      +  AP  +
+      + +      +     +      +      +      +
+......+ +......+     +......+      +......+
           .              .             .
         .  .              .             .
        .    .              .             .
       .      .              .             .
      .        .              .             .
   +......+ +......+     +......+      +......+
   +      + +      +     +      +      +      +
   +  MN  + +  MN  +     +  MN  +      +  MN  +
   +      + +      +     +      +      +      +
   +......+ +......+     +......+      +......+
        
        
The LWAPP tunnel exists between the controller and
the APs.  The MNs communicate with the APs through
the protocol defined by the 802.11 standard.
        
LWAPP APs, upon bootup, discover and join one of the
controllers and the controller pushes the configuration,
that includes the WLAN parameters, to the LWAPP APs.
The APs then encapsulate all the 802.11 frames from
wireless clients inside LWAPP frames and forward
the LWAPP frames to the controller.
        
                   GLOSSARY
        
Access Point ( AP )
        
An entity that contains an 802.11 medium access
control ( MAC ) and physical layer ( PHY ) interface
and provides access to the distribution services via
the wireless medium for associated clients.  
        
LWAPP APs encapsulate all the 802.11 frames in
LWAPP frames and sends them to the controller to which
it is logically connected.
        
Light Weight Access Point Protocol ( LWAPP )
        
This is a generic protocol that defines the 
communication between the Access Points and the
Central Controller. 
        
Mobile Node ( MN )
        
A roaming 802.11 wireless device in a wireless
network associated with an access point. Mobile Node 
and client are used interchangeably. 
        
Rogue
        
Any 802.11 device which is not part of the RF network 
is a Rogue device.
        
Ad-hoc Network 
        
A set of mobile devices within direct communication 
range establishing a network among themselves for 
transmitting data, without the use of a Access point 
is called a ad-hoc network. 
        
Rogue Ad-hoc Client
        
Any 802.11 client which is part of that ad-hoc network, 
but not in the trusted list.
        
Service Set Identifier ( SSID )
        
SSID is a unique identifier that APs and clients
use to identify with each other.  SSID is a simple
means of access control and is not for security.
The SSID can be any alphanumeric entry up to 32
characters.
        
RSSI
        
Received Signal Strength Indication (RSSI), the IEEE 802.11
standard defines a mechanism by which RF energy is to be
measured by the circuitry on a wireless NIC. Its value is
measured in dBm and ranges from -128 to 0.
        
Rogue Location Detection Protocol (RLDP)
        
RLDP is a protocol to detect and automatically 
contain rogue devices. When the controller discovers 
a rogue access point, it uses the Rogue Location 
Discovery Protocol (RLDP) to determine if the 
rogue is attached to your network.
RLDP can be enabled/disabled per controller level.
        
LRAD (LWAPP RADIO)
        
Light Weight Access Point Protocol Radio 
basically ones own AP.       
REFERENCE
        
[1] Wireless LAN Medium Access Control ( MAC ) and
    Physical Layer ( PHY ) Specifications.
        
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light 
    Weight Access Point Protocol.
    
Source file
CISCO-LWAPP-ROGUE-MIB
Last revised
Identity
ciscoLwappRogueMIB
Base OID
1.3.6.1.4.1.9.9.610
Imported Objects
CISCO-LWAPP-AP-MIB cLApDot11IfType cLApDot11RadioChannelNumber cLApDot11RadioMACAddress cLApIfSmtDot11Bssid cLApName cLApRogueApMacAddress cLApRogueDetectedChannel cLApRogueDot11RadioBand cLApRogueMode
CISCO-LWAPP-DOT11-CLIENT-MIB cldcClientMacAddress
CISCO-SMI ciscoMgmt
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC MacAddress RowStatus StorageType TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-LWAPP-ROGUE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-LWAPP-ROGUE-MIB::ciscoLwappRogueMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-LWAPP-ROGUE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-LWAPP-ROGUE-MIB::ciscoLwappRogueMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (115)
.1.3.6.1.4.1.9.9.610
.1.3.6.1.4.1.9.9.610.0
.1.3.6.1.4.1.9.9.610.1
.1.3.6.1.4.1.9.9.610.1.1
.1.3.6.1.4.1.9.9.610.1.1.1
.1.3.6.1.4.1.9.9.610.1.1.1.1
.1.3.6.1.4.1.9.9.610.1.1.1.10
secondsUnsigned32
.1.3.6.1.4.1.9.9.610.1.1.1.2
dBmInteger32
.1.3.6.1.4.1.9.9.610.1.1.1.3
secondsUnsigned32
.1.3.6.1.4.1.9.9.610.1.1.1.4
.1.3.6.1.4.1.9.9.610.1.1.1.5
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.1.6
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.1.7
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.1.8
.1.3.6.1.4.1.9.9.610.1.1.1.9
.1.3.6.1.4.1.9.9.610.1.1.2
.1.3.6.1.4.1.9.9.610.1.1.3
.1.3.6.1.4.1.9.9.610.1.1.3.1
.1.3.6.1.4.1.9.9.610.1.1.3.1.1
OctetString
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.10
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.11
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.2
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.3
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.4
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.5
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.6
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.7
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.8
.1.3.6.1.4.1.9.9.610.1.1.3.1.1.9
.1.3.6.1.4.1.9.9.610.1.1.3.2
.1.3.6.1.4.1.9.9.610.1.1.3.2.1
OctetString
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.1
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.10
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.11
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.2
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.3
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.4
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.5
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.6
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.7
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.8
.1.3.6.1.4.1.9.9.610.1.1.3.2.1.9
.1.3.6.1.4.1.9.9.610.1.1.3.3
.1.3.6.1.4.1.9.9.610.1.1.3.3.1
OctetString
.1.3.6.1.4.1.9.9.610.1.1.3.3.1.1
.1.3.6.1.4.1.9.9.610.1.1.3.3.1.2
.1.3.6.1.4.1.9.9.610.1.1.3.3.1.3
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.3.3.1.4
.1.3.6.1.4.1.9.9.610.1.1.4
.1.3.6.1.4.1.9.9.610.1.1.4.1
.1.3.6.1.4.1.9.9.610.1.1.4.1.1
.1.3.6.1.4.1.9.9.610.1.1.4.1.1.1
.1.3.6.1.4.1.9.9.610.1.1.4.1.1.2
.1.3.6.1.4.1.9.9.610.1.1.4.1.1.3
.1.3.6.1.4.1.9.9.610.1.1.5
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.5.1
.1.3.6.1.4.1.9.9.610.1.1.5.2
.1.3.6.1.4.1.9.9.610.1.1.5.3
.1.3.6.1.4.1.9.9.610.1.1.5.4
Integer32
.1.3.6.1.4.1.9.9.610.1.1.5.5
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.5.6
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.5.7
.1.3.6.1.4.1.9.9.610.1.1.6
cLRogueApTable deprecated
.1.3.6.1.4.1.9.9.610.1.1.6.1
cLRogueApEntry deprecated
.1.3.6.1.4.1.9.9.610.1.1.6.1.1
cLRogueApMACAddress deprecated
.1.3.6.1.4.1.9.9.610.1.1.6.1.1.1
cLRogueApClassType deprecated r/w
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.6.1.1.2
cLRogueApState deprecated r/w
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.6.1.1.3
cLRogueApStorageType deprecated r/w
.1.3.6.1.4.1.9.9.610.1.1.6.1.1.4
cLRogueApRowStatus deprecated r/w
.1.3.6.1.4.1.9.9.610.1.1.6.1.1.5
.1.3.6.1.4.1.9.9.610.1.1.6.2
.1.3.6.1.4.1.9.9.610.1.1.6.2.1
.1.3.6.1.4.1.9.9.610.1.1.6.2.1.1
.1.3.6.1.4.1.9.9.610.1.1.6.2.1.2
.1.3.6.1.4.1.9.9.610.1.1.6.2.1.3
.1.3.6.1.4.1.9.9.610.1.1.6.2.1.4
.1.3.6.1.4.1.9.9.610.1.1.7
.1.3.6.1.4.1.9.9.610.1.1.7.1
.1.3.6.1.4.1.9.9.610.1.1.7.1.1
.1.3.6.1.4.1.9.9.610.1.1.7.1.1.1
.1.3.6.1.4.1.9.9.610.1.1.7.1.1.2
.1.3.6.1.4.1.9.9.610.1.1.8
.1.3.6.1.4.1.9.9.610.1.1.8.1
.1.3.6.1.4.1.9.9.610.1.1.8.1.1
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.1
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.10
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.11
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.12
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.13
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.14
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.15
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.16
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.17
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.18
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.19
Unsigned32
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.2
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.20
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.3
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.4
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.5
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.6
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.7
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.8
Enumeration
.1.3.6.1.4.1.9.9.610.1.1.8.1.1.9
.1.3.6.1.4.1.9.9.610.2
.1.3.6.1.4.1.9.9.610.2.1
.1.3.6.1.4.1.9.9.610.2.2
.1.3.6.1.4.1.9.9.610.3
Enumeration
.1.3.6.1.4.1.9.9.610.3.1
.1.3.6.1.4.1.9.9.610.3.2
.1.3.6.1.4.1.9.9.610.3.3
.1.3.6.1.4.1.9.9.610.3.4
.1.3.6.1.4.1.9.9.610.3.5
.1.3.6.1.4.1.9.9.610.3.6
Dependencies (32) 7 direct · 25 transitive 1 circular Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Circular imports detected
CISCO-LWAPP-AP-MIB → CISCO-LWAPP-DOT11-MIB → CISCO-LWAPP-AP-MIB
Dependency tree
Type Definitions (1)
Enumeration
alarmOnly(1)
contain(2)
Conformance Groups (7)
This collection of objects represent the
rogue configuration on the controller.
.1.3.6.1.4.1.9.9.610.2.2.1
This collection of objects specifies the
notifications for rogue detection.
.1.3.6.1.4.1.9.9.610.2.2.2
This collection of objects represent the
rogue configuration on the controller.
ciscoLwappRogueConfigSup1Group object is superseded
by ciscoLwappRogueConfigSup2Group.
.1.3.6.1.4.1.9.9.610.2.2.3
This collection of objects represent the
rogue configuration on the controller.
ciscoLwappRogueConfigSup2Group object is
superseded by ciscoLwappRogueConfigSup3Group.
.1.3.6.1.4.1.9.9.610.2.2.4
This collection of objects represent the
rogue configuration on the controller.
.1.3.6.1.4.1.9.9.610.2.2.5
This collection of objects represent the
rogue configuration on the controller.
.1.3.6.1.4.1.9.9.610.2.2.6
This collection of objects represent the
rogue configuration on the controller.
.1.3.6.1.4.1.9.9.610.2.2.7
Compliance Statements (6)

OID .1.3.6.1.4.1.9.9.610.2.1.1
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups

OID .1.3.6.1.4.1.9.9.610.2.1.2
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups
Object refinements
ObjectAccessSyntaxDescription
cLRogueIgnoreListRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRuleRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionSsidRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRogueIgnoreListStorageType readonly
This object represents that write access is not required.
cLRuleStorageType readonly
Write access is not required.
cLConditionStorageType readonly
Write access is not required.
cLConditionSsidStorageType readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.610.2.1.3
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups
Object refinements
ObjectAccessSyntaxDescription
cLRogueIgnoreListRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRuleRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionSsidRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRogueIgnoreListStorageType readonly
Write access is not required.
cLRuleStorageType readonly
Write access is not required.
cLConditionStorageType readonly
Write access is not required.
cLConditionSsidStorageType readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.610.2.1.4
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups
Object refinements
ObjectAccessSyntaxDescription
cLRogueIgnoreListRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRuleRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionSsidRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRogueIgnoreListStorageType readonly
Write access is not required.
cLRuleStorageType readonly
Write access is not required.
cLConditionStorageType readonly
Write access is not required.
cLConditionSsidStorageType readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.610.2.1.5
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups
mandatory ciscoLwappRogueConfigGroup
mandatory ciscoLwappRogueNotifsGroup
mandatory ciscoLwappRogueConfigSup3Group
optional ciscoLwappRogueConfigSup4Group This group is mandatory for platforms which support
rogue functionality.
Object refinements
ObjectAccessSyntaxDescription
cLRogueIgnoreListRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRuleRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLConditionSsidRowStatus
active(1), createAndGo(4), destroy(6)
An implementation is only required to support
three of the six enumerated values of the
RowStatus textual convention, specifically,
'active', 'createAndGo' and 'destroy'.
cLRogueIgnoreListStorageType readonly
Write access is not required.
cLRuleStorageType readonly
Write access is not required.
cLConditionStorageType readonly
Write access is not required.
cLConditionSsidStorageType readonly
Write access is not required.
cLRogueClientNumThreshold readonly
Write access is not required.
cLRogueDetectionSecurityLevel readonly
Write access is not required.
cLRogueValidateRogueClientsAgainstMse readonly
Write access is not required.
cLConditionRssi readonly
Write access is not required.
cLConditionClientCount readonly
Write access is not required.
cLConditionNoEncryptionEnabled readonly
Write access is not required.
cLConditionManagedSsidEnabled readonly
Write access is not required.
cLConditionDuration readonly
Write access is not required.
cLRogueApClassType readonly
Write access is not required.
cLRogueApState readonly
Write access is not required.
cLRogueApStorageType readonly
Write access is not required.
cLRogueApRowStatus readonly
active(1)
Write access is not required.
Support for createAndWait and notInService
is not required.

OID .1.3.6.1.4.1.9.9.610.2.1.6
The compliance statement for the SNMP entities that
implement the ciscoLwappRogueMIB module.
Required groups
Notifications / Traps (5)
NameOIDDescription
.1.3.6.1.4.1.9.9.610.0.1
This notification is generated by the controller when a
a rogue is detected. The name of the AP that
detected this rogue is sent in the notification.
.1.3.6.1.4.1.9.9.610.0.2
This notification is generated by the controller
when a rogue client exceeds its maximum
threshold configured. The details of Rogue AP
and Rogue Clients is sent in the notification.
.1.3.6.1.4.1.9.9.610.0.3
This notification is generated by the controller
when a rogue client is removed from the rogue AP
and still the client count of the rogue AP is greater
than the maximum threshold configured. The details
of Rogue AP and Rogue Clients is sent in the
notification.
.1.3.6.1.4.1.9.9.610.0.4
This notification is generated by the controller
when a rogue AP is contained due to Rogue Rule.
.1.3.6.1.4.1.9.9.610.0.5
This notification is generated by the controller
when a rogue client is detected.