CISCO-NAC-NAD-MIB
This MIB module is for the configuration of a Network
Access Device (NAD) on the Cisco Network Admission
Control (NAC) system.
EndPoint -------------- NAD ------- AAA ------ PVS
(SecurApp) EAPoUDP/802.1x RADIUS HCAP
(Plugin)
(PA)
Cisco NAC system
The Cisco Network Admission Control (NAC) security
solution offers a systems approach to customers for
ensuring endpoint device compliancy and vulnerability
checks prior to production access to the network. Cisco
refers to these compliancy checks as posture
validations. The intent of this systems approach is to
prevent the spread of works, viruses, and rogue
applications across the network. This systems approach
requires integration with third party end point security
applications, as well as endpoint security servers.
The Network Access Device (NAD) enforces network access
control privileges by controlling which endpoint devices
have access to network destinations and services
reachable through that NAD. Endpoint devices that do
not have the PA installed, enabled, or cannot otherwise
respond to the NAD posture challenges are considered
non-responsive hosts. Upon recognition of an incoming
endpoint device at L2 or L3, the NAD issues a challenge
to the endpoint device for posture credentials. Endpoint
devices with a PA will recognize the challenge and
respond with the necessary posture credentials. The NAD
acts as a relay agent between the endpoint device and
AAA server for all messages in the posture validation
exchange. Once the validation is complete, the NAD
enforces the access policy profile downloaded from the
AAA Server, e.g. (i) provide full access (ii) deny all
access through the NAD restrict access (quarantine) or
(iii) some intermediate level of network access
restriction or quarantine. Between posture
revalidations, the NAD may issue periodic status queries
to determine that the each endpoint device using the NAD
is still the same device that was first postured, and
that the endpoint device's posture credentials have not
changed. This mechanism is a challenge response protocol
that does not involve the AAA Server nor does it require
the posture plugins to resend any credentials. It is
used to trigger a full posture revalidation with the AAA
Server when the endpoint device's credentials have
changed (e.g. to revalidate the host endpoint device
after remediation), or a new host endpoint device
connects with a previously authorized IP address. The
NAD supports a local exception list based on IP, MAC
address or device type so that certain endpoint devices
can bypass the posture validation process based on
system administrator configuration. Also, the NAD may be
configured to query the AAA server for access policies
associated with endpoint devices that do not have a
Posture Agent installed, clientless host endpoint
devices.
Posture Validation occurs when a NAC-enabled network
access device (NAC) detects an endpoint device
attempting to connect or use its network resources and
it issues the endpoint device a posture challenge. An
endpoint device with a resident posture agent will
respond to the challenge with sets of posture
credentials from one or more posture plugins which can
detail the state of the various hardware and software
components on the endpoint device. The posture agent
response is forwarded by the network access device to an
AAA server which may in turn delegate parts of the
decision to posture validation server. Evaluation of the
credentials against posture validation policies results
in an authorization decision or posture token,
representing the endpoint device's relative compliance
to the network compliance policy. The AAA server then
sends the respective network access profile to the
network access device for enforcement of the endpoint
device authorization.
The Cisco Technology consists of the following:
Endpoint Device - Any host attempting to connect or use
the resource of a network. - e.g., a personal computer,
personal data digital assistant, or data server, or
other network attached device.
NAD - Network Access Device that enforces network
access control policies through layer 2 or layer 3
challenge-responses with a network enabled Endpoint
device.
PC - Posture Credentials that describe the state of
an application and/or operating system that is running
on an endpoint device at the time a layer 2 or layer 3
challenge response is issued by a NAD.
PP - Posture Plugin. A module implemented by an
application or agent provider that is responsible for
supplying the relevant posture credentials for the
application or agent.
PA - Posture Agent. Host agent software that serves as
a broker on the host for aggregating credential from
potentially multiple posture plugins and communicating
with the network.
CTA - Cisco Trust Agent. Cisco's implementation of
the posture agent.
EAP - Extensible Authentication Protocol. An extension
to PPP.
EOU - Extensible Authentication Protocol over UDP.
ACS/AAA - Cisco Secure Access Control Server. The
primary authorization server that is the network policy
decision point and is extended to support posture
validation.
PVS - Posture Validation Server.
UCT - Un Conditional Transition.
Clientless - Client without Cisco Posture Agent.
Tag - Tag is a policy specifier which is mapped to a
policy template based on specific rules. The Tag allows
network administrators to define enforcement policies
on local device and have a RADIUS server specify the
policy Template to be enforced.
- Source file
CISCO-NAC-NAD-MIB- Last revised
- Identity
ciscoNacNadMIB- Base OID
1.3.6.1.4.1.9.9.484
Imported Objects
| CISCO-NAC-TC-MIB | CnnEouAuthType CnnEouDeviceType CnnEouPostureToken CnnEouPostureTokenString CnnEouState |
| CISCO-POLICY-GROUP-MIB | CpgPolicyNameOrEmpty |
| CISCO-SMI | ciscoMgmt |
| CISCO-TC | CiscoURLString |
| IF-MIB | ifIndex InterfaceIndex InterfaceIndexOrZero |
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType InetPortNumber |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Integer32 MODULE-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | MacAddress RowStatus StorageType TimeStamp TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-NAC-NAD-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-NAC-NAD-MIB::ciscoNacNadMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-NAC-NAD-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-NAC-NAD-MIB::ciscoNacNadMIB'
Objects (109)
Showing 109 of 109 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.484 |
||
.1.3.6.1.4.1.9.9.484.0 |
||
.1.3.6.1.4.1.9.9.484.1 |
||
.1.3.6.1.4.1.9.9.484.1.1 |
||
.1.3.6.1.4.1.9.9.484.1.1.1 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.10 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.11 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.12 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.13 |
|
|
millisecondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.14 |
|
.1.3.6.1.4.1.9.9.484.1.1.15 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.1.2 |
|
.1.3.6.1.4.1.9.9.484.1.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.1.4 |
||
.1.3.6.1.4.1.9.9.484.1.1.5 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.1.6 |
|
|
|
.1.3.6.1.4.1.9.9.484.1.1.7 |
|
|
|
.1.3.6.1.4.1.9.9.484.1.1.8 |
|
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.1.9 |
.1.3.6.1.4.1.9.9.484.1.2 |
||
.1.3.6.1.4.1.9.9.484.1.2.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.1.1.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.484.1.2.1.1.2 |
|
.1.3.6.1.4.1.9.9.484.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.2.1.1.4 |
||
.1.3.6.1.4.1.9.9.484.1.2.1.1.5 |
||
.1.3.6.1.4.1.9.9.484.1.2.1.1.6 |
||
.1.3.6.1.4.1.9.9.484.1.2.2 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1.2 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1.4 |
||
.1.3.6.1.4.1.9.9.484.1.2.2.1.5 |
||
.1.3.6.1.4.1.9.9.484.1.2.3 |
||
.1.3.6.1.4.1.9.9.484.1.2.3.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.3.1.1 |
||
.1.3.6.1.4.1.9.9.484.1.2.3.1.2 |
||
.1.3.6.1.4.1.9.9.484.1.2.3.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.3.1 |
||
.1.3.6.1.4.1.9.9.484.1.3.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.1 |
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.10 |
||
.1.3.6.1.4.1.9.9.484.1.3.1.1.11 |
||
.1.3.6.1.4.1.9.9.484.1.3.1.1.12 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.2 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.3 |
|
|
Bits
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.4 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.5 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.6 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.7 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.8 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.3.1.1.9 |
|
.1.3.6.1.4.1.9.9.484.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.484.1.4.1 |
|
.1.3.6.1.4.1.9.9.484.1.4.2 |
||
.1.3.6.1.4.1.9.9.484.1.4.3 |
||
.1.3.6.1.4.1.9.9.484.1.4.4 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.4.5 |
|
.1.3.6.1.4.1.9.9.484.1.4.6 |
||
.1.3.6.1.4.1.9.9.484.1.4.7 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.10 |
|
|
Integer32
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.11 |
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.12 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.13 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.14 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.2 |
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.4 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.5 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.6 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.7 |
|
.1.3.6.1.4.1.9.9.484.1.4.7.1.8 |
||
.1.3.6.1.4.1.9.9.484.1.4.7.1.9 |
||
.1.3.6.1.4.1.9.9.484.1.4.8 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.1 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.10 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.11 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.12 |
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.13 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.14 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.15 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.16 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.17 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.18 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.2 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.3 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.4 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.5 |
||
.1.3.6.1.4.1.9.9.484.1.4.8.1.6 |
||
|
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.7 |
|
|
minutesSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.8 |
|
.1.3.6.1.4.1.9.9.484.1.4.8.1.9 |
||
.1.3.6.1.4.1.9.9.484.1.4.9 |
||
.1.3.6.1.4.1.9.9.484.1.5 |
||
.1.3.6.1.4.1.9.9.484.1.5.1 |
||
.1.3.6.1.4.1.9.9.484.1.5.2 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.484.1.5.3 |
|
.1.3.6.1.4.1.9.9.484.1.5.4 |
||
.1.3.6.1.4.1.9.9.484.1.5.4.1 |
||
.1.3.6.1.4.1.9.9.484.1.5.4.1.1 |
||
.1.3.6.1.4.1.9.9.484.2 |
||
.1.3.6.1.4.1.9.9.484.2.1 |
||
.1.3.6.1.4.1.9.9.484.2.2 |
Dependencies (12) 10 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-NAC-TC-MIBcisco
- INET-ADDRESS-MIBrfc
- SNMPv2-CONFrfc
- CISCO-POLICY-GROUP-MIBcisco
- CISCO-TCcisco
- IANAifType-MIBrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-NAC-NAD-MIBciscoselected
Conformance Groups (21)
|
cnnEouVersion cnnEouEnabled cnnEouAllowClientless cnnEouAllowIpStationId cnnEouLoggingEnabled cnnEouMaxRetry cnnEouPort cnnEouTimeoutAAA cnnEouTimeoutHoldPeriod cnnEouTimeoutRetransmit cnnEouTimeoutRevalidation cnnEouTimeoutStatusQuery
A collection of objects providing the global configuration on
the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.1
|
|
|
A collection of objects providing the configuration for
the static authorization IP device with policy associated. |
.1.3.6.1.4.1.9.9.484.2.2.2
|
|
|
A collection of objects providing the configuration for
the static authorization MAC device with policy associated. |
.1.3.6.1.4.1.9.9.484.2.2.3
|
|
|
A collection of objects providing the configuration for
the static authorization device identified by device type. |
.1.3.6.1.4.1.9.9.484.2.2.4
|
|
|
A collection of objects providing the interface configuration
on the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.5
|
|
|
ciscoNacNadEouHostGroup
deprecated
|
cnnEouHostValidateAction cnnEouHostValidateIpAddrType cnnEouHostValidateIpAddr cnnEouHostValidateMacAddr cnnEouHostValidatePostureToken cnnEouHostMaxQueries cnnEouHostQueryMask cnnEouHostQueryInterface cnnEouHostQueryIpAddrType cnnEouHostQueryIpAddr cnnEouHostQueryMacAddr cnnEouHostQueryPostureToken cnnEouHostQuerySkipNHosts cnnEouHostQueryMaxResultRows cnnEouHostQueryTotalHosts cnnEouHostQueryRows cnnEouHostQueryCreateTime cnnEouHostQueryStatus cnnEouHostResultAssocIf cnnEouHostResultIpAddrType cnnEouHostResultIpAddr cnnEouHostResultMacAddr cnnEouHostResultAuthType cnnEouHostResultPostureToken cnnEouHostResultStatusQryPeriod cnnEouHostResultRevalidatePeriod cnnEouHostResultState
A collection of objects providing the host configuration
on the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.6
|
|
cnnEouIfTimeoutGlobalConfig cnnEouIfTimeoutAAA cnnEouIfTimeoutHoldPeriod cnnEouIfTimeoutRetransmit cnnEouIfTimeoutRevalidation cnnEouIfTimeoutStatusQuery
A collection of objects providing the timeout configuration
on the interface. |
.1.3.6.1.4.1.9.9.484.2.2.7
|
|
|
A collection of objects providing the max-retry configuration
on the interface. |
.1.3.6.1.4.1.9.9.484.2.2.8
|
|
|
A collection of objects providing the rate limit
configuration. |
.1.3.6.1.4.1.9.9.484.2.2.9
|
|
|
A collection of objects providing the administrative
configuration on the interfaces. |
.1.3.6.1.4.1.9.9.484.2.2.10
|
|
|
A collection of objects providing the age information
on the interface. |
.1.3.6.1.4.1.9.9.484.2.2.11
|
|
|
A collection of objects providing the redirect URL
information on the interface. |
.1.3.6.1.4.1.9.9.484.2.2.12
|
|
|
A collection of objects providing the ACL(Access Control List)
information on the interface. |
.1.3.6.1.4.1.9.9.484.2.2.13
|
|
|
A collection of objects providing the AAA failed policy
for the interface. |
.1.3.6.1.4.1.9.9.484.2.2.14
|
|
|
cnnEouHostValidateAction cnnEouHostValidateIpAddrType cnnEouHostValidateIpAddr cnnEouHostValidateMacAddr cnnEouHostValidatePostureTokenStr cnnEouHostMaxQueries cnnEouHostQueryMask cnnEouHostQueryInterface cnnEouHostQueryIpAddrType cnnEouHostQueryIpAddr cnnEouHostQueryMacAddr cnnEouHostQueryPostureTokenStr cnnEouHostQuerySkipNHosts cnnEouHostQueryMaxResultRows cnnEouHostQueryTotalHosts cnnEouHostQueryRows cnnEouHostQueryCreateTime cnnEouHostQueryStatus cnnEouHostResultAssocIf cnnEouHostResultIpAddrType cnnEouHostResultIpAddr cnnEouHostResultMacAddr cnnEouHostResultAuthType cnnEouHostResultPostureTokenStr cnnEouHostResultStatusQryPeriod cnnEouHostResultRevalidatePeriod cnnEouHostResultState
A collection of objects providing the host configuration
on the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.15
|
|
|
A collection of objects providing IP device tracking
for the device. |
.1.3.6.1.4.1.9.9.484.2.2.16
|
|
|
A collection of objects providing critical recovery delay
for the device. |
.1.3.6.1.4.1.9.9.484.2.2.17
|
|
|
A collection of objects providing EOU IP device tracking
per interface in the device. |
.1.3.6.1.4.1.9.9.484.2.2.18
|
|
|
A collection of objects providing the globally configuration
for the system. |
.1.3.6.1.4.1.9.9.484.2.2.19
|
|
|
cnnEouHostResultUrlRedirectAcl cnnEouHostResultTagName cnnEouHostResultAuditSessionId cnnEouHostResultAaaFailPolicy
A collection of objects providing the host extension
configuration on the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.20
|
|
|
A collection of objects providing the interface extension
configuration on the NAD. |
.1.3.6.1.4.1.9.9.484.2.2.21
|
Compliance Statements (4)
OID
.1.3.6.1.4.1.9.9.484.2.1.1The compliance statement for the CISCO-NAC-NAD-MIB.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
Required groups
| mandatory | ciscoNacNadEouGlobalGroup | |
| mandatory | ciscoNacNadEouAuthIpGroup | |
| mandatory | ciscoNacNadEouIfConfigGroup | |
| mandatory | ciscoNacNadEouHostGroup | |
| optional | ciscoNacNadEouIfTimeoutGroup |
This group is mandatory only for the platforms which support the timeout configuration on interface. |
| optional | ciscoNacNadEouIfMaxRetryGroup |
This group is mandatory only for the platforms which support the max-retry configuration on interface. |
| optional | ciscoNacNadEouRateLimitGroup |
This group is mandatory only for the platforms which support the rate-limit configuration. |
| optional | ciscoNacNadEouIfAdminGroup |
This group is mandatory only for the platforms which support enabled/disabled/bypassed EOU feature on the interface. |
| optional | ciscoNacNadEouAuthMacGroup |
This group is mandatory only for the platforms which support the exempted MAC device with a policy associated. |
| optional | ciscoNacNadEouAuthDeviceTypeGrp |
This group is mandatory only for the platforms which support statically authorize device identified by device type. |
| optional | ciscoNacNadEouHostAgeGroup |
This group is mandatory only for the platforms which support the age information on the interface. |
| optional | ciscoNacNadEouHostUrlRedir |
This group is mandatory only for the platforms which support the redirection URL information on the interface. |
| optional | ciscoNacNadEouHostAclGroup |
This group is mandatory only for the platforms which support the ACL(Access Control List) information on the interface. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cnnEouEnabled | readonly | Write access is not required. | |
| cnnEouAllowIpStationId | readonly | Write access is not required. | |
| cnnEouPort | readonly | Write access is not required. | |
| cnnEouHostResultIpAddrType |
ipv4(1)
|
An implementation is only required to support IPv4 addresses. |
|
| cnnEouAuthIpStorageType | readonly | Write access is not required. | |
| cnnEouAuthMacStorageType | readonly | Write access is not required. | |
| cnnEouAuthDeviceTypeStorageType | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.484.2.1.2The compliance statement for the CISCO-NAC-NAD-MIB.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
Required groups
| mandatory | ciscoNacNadEouGlobalGroup | |
| mandatory | ciscoNacNadEouAuthIpGroup | |
| mandatory | ciscoNacNadEouIfConfigGroup | |
| mandatory | ciscoNacNadEouHostGrp | |
| optional | ciscoNacNadEouIfTimeoutGroup |
This group is mandatory only for the platforms which support the timeout configuration on interface. |
| optional | ciscoNacNadEouIfMaxRetryGroup |
This group is mandatory only for the platforms which support the max-retry configuration on interface. |
| optional | ciscoNacNadEouRateLimitGroup |
This group is mandatory only for the platforms which support the rate-limit configuration. |
| optional | ciscoNacNadEouIfAdminGroup |
This group is mandatory only for the platforms which support enabled/disabled/bypassed EOU feature on the interface. |
| optional | ciscoNacNadEouAuthMacGroup |
This group is mandatory only for the platforms which support the exempted MAC device with a policy associated. |
| optional | ciscoNacNadEouAuthDeviceTypeGrp |
This group is mandatory only for the platforms which support statically authorize device identified by device type. |
| optional | ciscoNacNadEouHostAgeGroup |
This group is mandatory only for the platforms which support the age information on the interface. |
| optional | ciscoNacNadEouHostUrlRedir |
This group is mandatory only for the platforms which support the redirection URL information on the interface. |
| optional | ciscoNacNadEouHostAclGroup |
This group is mandatory only for the platforms which support the ACL(Access Control List) information on the interface. |
| optional | ciscoNacNadEouIfAaaFailPolicyGrp |
This group is mandatory only for the platforms which support IAB(Inaccessible Authentication Bypass) feature on the interface. |
| optional | cnnIpDeviceTrackingConfigGrp |
This group is mandatory only for the platforms which support IP device tracking feature. |
| optional | cnnEouCriticalRecoveryDelayGrp |
This group is mandatory only for the platforms which support critical recovery delay feature. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cnnEouEnabled | readonly | Write access is not required. | |
| cnnEouAllowIpStationId | readonly | Write access is not required. | |
| cnnEouPort | readonly | Write access is not required. | |
| cnnEouHostResultIpAddrType |
ipv4(1)
|
An implementation is only required to support IPv4 addresses. |
|
| cnnEouAuthIpStorageType | readonly | Write access is not required. | |
| cnnEouAuthMacStorageType | readonly | Write access is not required. | |
| cnnEouAuthDeviceTypeStorageType | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.484.2.1.3The compliance statement for the CISCO-NAC-NAD-MIB.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
Required groups
| mandatory | ciscoNacNadEouGlobalGroup | |
| mandatory | ciscoNacNadEouAuthIpGroup | |
| mandatory | ciscoNacNadEouIfConfigGroup | |
| mandatory | ciscoNacNadEouHostGrp | |
| optional | ciscoNacNadEouIfTimeoutGroup |
This group is mandatory only for the platforms which support the timeout configuration on interface. |
| optional | ciscoNacNadEouIfMaxRetryGroup |
This group is mandatory only for the platforms which support the max-retry configuration on interface. |
| optional | ciscoNacNadEouRateLimitGroup |
This group is mandatory only for the platforms which support the rate-limit configuration. |
| optional | ciscoNacNadEouIfAdminGroup |
This group is mandatory only for the platforms which support enabled/disabled/bypassed EOU feature on the interface. |
| optional | ciscoNacNadEouAuthMacGroup |
This group is mandatory only for the platforms which support the exempted MAC device with a policy associated. |
| optional | ciscoNacNadEouAuthDeviceTypeGrp |
This group is mandatory only for the platforms which support statically authorize device identified by device type. |
| optional | ciscoNacNadEouHostAgeGroup |
This group is mandatory only for the platforms which support the age information on the interface. |
| optional | ciscoNacNadEouHostUrlRedir |
This group is mandatory only for the platforms which support the redirection URL information on the interface. |
| optional | ciscoNacNadEouHostAclGroup |
This group is mandatory only for the platforms which support the ACL(Access Control List) information on the interface. |
| optional | ciscoNacNadEouIfAaaFailPolicyGrp |
This group is mandatory only for the platforms which support IAB(Inaccessible Authentication Bypass) feature on the interface. |
| optional | cnnIpDeviceTrackingConfigGrp |
This group is mandatory only for the platforms which support IP device tracking feature. |
| optional | cnnEouCriticalRecoveryDelayGrp |
This group is mandatory only for the platforms which support critical recovery delay feature. |
| optional | cnnEouIfIpDevTrackConfigGrp |
This group is mandatory only for the platforms which support EOU IP Device Tracking per interface in the device. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cnnEouEnabled | readonly | Write access is not required. | |
| cnnEouAllowIpStationId | readonly | Write access is not required. | |
| cnnEouPort | readonly | Write access is not required. | |
| cnnEouHostResultIpAddrType |
ipv4(1)
|
An implementation is only required to support IPv4 addresses. |
|
| cnnEouAuthIpStorageType | readonly | Write access is not required. | |
| cnnEouAuthMacStorageType | readonly | Write access is not required. | |
| cnnEouAuthDeviceTypeStorageType | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.484.2.1.4The compliance statement for the CISCO-NAC-NAD-MIB.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
OBJECT cnnEouAuthIpAddrType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to support IPv4
addresses.
Required groups
| mandatory | ciscoNacNadEouGlobalGroup | |
| mandatory | ciscoNacNadEouAuthIpGroup | |
| mandatory | ciscoNacNadEouIfConfigGroup | |
| mandatory | ciscoNacNadEouHostGrp | |
| optional | ciscoNacNadEouIfTimeoutGroup |
This group is mandatory only for the platforms which support the timeout configuration on interface. |
| optional | ciscoNacNadEouIfMaxRetryGroup |
This group is mandatory only for the platforms which support the max-retry configuration on interface. |
| optional | ciscoNacNadEouRateLimitGroup |
This group is mandatory only for the platforms which support the rate-limit configuration. |
| optional | ciscoNacNadEouIfAdminGroup |
This group is mandatory only for the platforms which support enabled/disabled/bypassed EOU feature on the interface. |
| optional | ciscoNacNadEouAuthMacGroup |
This group is mandatory only for the platforms which support the exempted MAC device with a policy associated. |
| optional | ciscoNacNadEouAuthDeviceTypeGrp |
This group is mandatory only for the platforms which support statically authorize device identified by device type. |
| optional | ciscoNacNadEouHostAgeGroup |
This group is mandatory only for the platforms which support the age information on the interface. |
| optional | ciscoNacNadEouHostUrlRedir |
This group is mandatory only for the platforms which support the redirection URL information on the interface. |
| optional | ciscoNacNadEouHostAclGroup |
This group is mandatory only for the platforms which support the ACL(Access Control List) information on the interface. |
| optional | ciscoNacNadEouIfAaaFailPolicyGrp |
This group is mandatory only for the platforms which support IAB(Inaccessible Authentication Bypass) feature on the interface. |
| optional | cnnIpDeviceTrackingConfigGrp |
This group is mandatory only for the platforms which support IP device tracking feature. |
| optional | cnnEouCriticalRecoveryDelayGrp |
This group is mandatory only for the platforms which support critical recovery delay feature. |
| optional | cnnEouIfIpDevTrackConfigGrp |
This group is mandatory only for the platforms which support EOU IP Device Tracking per interface in the device. |
| optional | ciscoNacNadRevalidateConfigGrp | Implementation of this group is optional. |
| optional | ciscoNacNadEouHostGroup1 | Implementation of this group is optional. |
| optional | ciscoNacNadEouIfExtGroup | Implementation of this group is optional. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cnnEouEnabled | readonly | Write access is not required. | |
| cnnEouAllowIpStationId | readonly | Write access is not required. | |
| cnnEouPort | readonly | Write access is not required. | |
| cnnEouHostResultIpAddrType |
ipv4(1)
|
An implementation is only required to support IPv4 addresses. |
|
| cnnEouAuthIpStorageType | readonly | Write access is not required. | |
| cnnEouAuthMacStorageType | readonly | Write access is not required. | |
| cnnEouAuthDeviceTypeStorageType | readonly | Write access is not required. |