CISCO-PAE-MIB

        Cisco Port Access Entity (PAE) module for managing
IEEE Std 802.1x.
        
This MIB provides Port Access Entity information
that are either excluded by IEEE8021-PAE-MIB or
specific to Cisco products.
    
Source file
CISCO-PAE-MIB
Last revised
Identity
ciscoPaeMIB
Base OID
1.3.6.1.4.1.9.9.220
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-PAE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-PAE-MIB::ciscoPaeMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-PAE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-PAE-MIB::ciscoPaeMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (134)
.1.3.6.1.4.1.9.9.220
.1.3.6.1.4.1.9.9.220.0
.1.3.6.1.4.1.9.9.220.1
.1.3.6.1.4.1.9.9.220.1.1
.1.3.6.1.4.1.9.9.220.1.1.1
cpaeMultipleHost deprecated r/w
.1.3.6.1.4.1.9.9.220.1.1.1.1
Bits
.1.3.6.1.4.1.9.9.220.1.1.1.10
Enumeration
.1.3.6.1.4.1.9.9.220.1.1.1.2
.1.3.6.1.4.1.9.9.220.1.1.1.3
cpaeInGuestVlan deprecated
.1.3.6.1.4.1.9.9.220.1.1.1.4
.1.3.6.1.4.1.9.9.220.1.1.1.5
.1.3.6.1.4.1.9.9.220.1.1.1.6
.1.3.6.1.4.1.9.9.220.1.1.1.7
Enumeration
.1.3.6.1.4.1.9.9.220.1.1.1.8
.1.3.6.1.4.1.9.9.220.1.1.1.9
.1.3.6.1.4.1.9.9.220.1.10
.1.3.6.1.4.1.9.9.220.1.10.1
.1.3.6.1.4.1.9.9.220.1.10.1.1
.1.3.6.1.4.1.9.9.220.1.10.1.2
.1.3.6.1.4.1.9.9.220.1.10.1.3
.1.3.6.1.4.1.9.9.220.1.10.1.4
Enumeration
.1.3.6.1.4.1.9.9.220.1.10.1.5
.1.3.6.1.4.1.9.9.220.1.10.1.6
.1.3.6.1.4.1.9.9.220.1.10.1.7
.1.3.6.1.4.1.9.9.220.1.10.1.8
.1.3.6.1.4.1.9.9.220.1.11
.1.3.6.1.4.1.9.9.220.1.11.1
.1.3.6.1.4.1.9.9.220.1.11.1.1
Enumeration
.1.3.6.1.4.1.9.9.220.1.11.1.10
OctetString
.1.3.6.1.4.1.9.9.220.1.11.1.11
.1.3.6.1.4.1.9.9.220.1.11.1.2
.1.3.6.1.4.1.9.9.220.1.11.1.3
.1.3.6.1.4.1.9.9.220.1.11.1.4
.1.3.6.1.4.1.9.9.220.1.11.1.5
.1.3.6.1.4.1.9.9.220.1.11.1.6
.1.3.6.1.4.1.9.9.220.1.11.1.7
.1.3.6.1.4.1.9.9.220.1.11.1.8
.1.3.6.1.4.1.9.9.220.1.11.1.9
.1.3.6.1.4.1.9.9.220.1.12
.1.3.6.1.4.1.9.9.220.1.13
.1.3.6.1.4.1.9.9.220.1.13.1
Enumeration
.1.3.6.1.4.1.9.9.220.1.13.1.1
.1.3.6.1.4.1.9.9.220.1.13.1.2
.1.3.6.1.4.1.9.9.220.1.14
.1.3.6.1.4.1.9.9.220.1.14.1
.1.3.6.1.4.1.9.9.220.1.14.2
.1.3.6.1.4.1.9.9.220.1.15
.1.3.6.1.4.1.9.9.220.1.15.1
.1.3.6.1.4.1.9.9.220.1.15.1.1
Unsigned32
.1.3.6.1.4.1.9.9.220.1.16
Enumeration
.1.3.6.1.4.1.9.9.220.1.17
.1.3.6.1.4.1.9.9.220.1.18
.1.3.6.1.4.1.9.9.220.1.19
.1.3.6.1.4.1.9.9.220.1.19.1
.1.3.6.1.4.1.9.9.220.1.19.1.1
.1.3.6.1.4.1.9.9.220.1.19.1.1.1
.1.3.6.1.4.1.9.9.220.1.19.1.1.2
.1.3.6.1.4.1.9.9.220.1.19.2
.1.3.6.1.4.1.9.9.220.1.19.2.1
Unsigned32
.1.3.6.1.4.1.9.9.220.1.19.2.1.1
.1.3.6.1.4.1.9.9.220.1.19.2.1.2
Enumeration
.1.3.6.1.4.1.9.9.220.1.19.2.1.3
Enumeration
.1.3.6.1.4.1.9.9.220.1.19.2.1.4
.1.3.6.1.4.1.9.9.220.1.19.2.1.5
cpaeGuestVlanId deprecated r/w
.1.3.6.1.4.1.9.9.220.1.2
secondsUnsigned32
.1.3.6.1.4.1.9.9.220.1.3
.1.3.6.1.4.1.9.9.220.1.4
.1.3.6.1.4.1.9.9.220.1.5
.1.3.6.1.4.1.9.9.220.1.5.1
OctetString
.1.3.6.1.4.1.9.9.220.1.5.1.1
.1.3.6.1.4.1.9.9.220.1.5.1.2
.1.3.6.1.4.1.9.9.220.1.5.1.3
.1.3.6.1.4.1.9.9.220.1.5.1.4
.1.3.6.1.4.1.9.9.220.1.5.1.5
.1.3.6.1.4.1.9.9.220.1.5.1.6
.1.3.6.1.4.1.9.9.220.1.5.1.7
.1.3.6.1.4.1.9.9.220.1.6
.1.3.6.1.4.1.9.9.220.1.6.1
.1.3.6.1.4.1.9.9.220.1.6.1.1
.1.3.6.1.4.1.9.9.220.1.7
.1.3.6.1.4.1.9.9.220.1.7.1
.1.3.6.1.4.1.9.9.220.1.7.2
.1.3.6.1.4.1.9.9.220.1.7.3
.1.3.6.1.4.1.9.9.220.1.7.4
.1.3.6.1.4.1.9.9.220.1.8
.1.3.6.1.4.1.9.9.220.1.8.1
.1.3.6.1.4.1.9.9.220.1.8.2
Enumeration
.1.3.6.1.4.1.9.9.220.1.8.3
.1.3.6.1.4.1.9.9.220.1.8.4
.1.3.6.1.4.1.9.9.220.1.8.5
.1.3.6.1.4.1.9.9.220.1.8.6
.1.3.6.1.4.1.9.9.220.1.8.6.1
.1.3.6.1.4.1.9.9.220.1.8.6.1.1
.1.3.6.1.4.1.9.9.220.1.8.6.1.10
OctetString
.1.3.6.1.4.1.9.9.220.1.8.6.1.11
.1.3.6.1.4.1.9.9.220.1.8.6.1.2
.1.3.6.1.4.1.9.9.220.1.8.6.1.3
.1.3.6.1.4.1.9.9.220.1.8.6.1.4
Enumeration
.1.3.6.1.4.1.9.9.220.1.8.6.1.5
Enumeration
.1.3.6.1.4.1.9.9.220.1.8.6.1.6
.1.3.6.1.4.1.9.9.220.1.8.6.1.7
Enumeration
.1.3.6.1.4.1.9.9.220.1.8.6.1.8
.1.3.6.1.4.1.9.9.220.1.8.6.1.9
.1.3.6.1.4.1.9.9.220.1.8.7
.1.3.6.1.4.1.9.9.220.1.8.8
.1.3.6.1.4.1.9.9.220.1.8.9
.1.3.6.1.4.1.9.9.220.1.8.9.1
.1.3.6.1.4.1.9.9.220.1.8.9.1.1
.1.3.6.1.4.1.9.9.220.1.9
.1.3.6.1.4.1.9.9.220.1.9.1
minutesUnsigned32
.1.3.6.1.4.1.9.9.220.1.9.10
.1.3.6.1.4.1.9.9.220.1.9.2
.1.3.6.1.4.1.9.9.220.1.9.3
.1.3.6.1.4.1.9.9.220.1.9.4
.1.3.6.1.4.1.9.9.220.1.9.5
.1.3.6.1.4.1.9.9.220.1.9.6
.1.3.6.1.4.1.9.9.220.1.9.7
.1.3.6.1.4.1.9.9.220.1.9.7.1
.1.3.6.1.4.1.9.9.220.1.9.7.1.1
.1.3.6.1.4.1.9.9.220.1.9.7.1.2
.1.3.6.1.4.1.9.9.220.1.9.7.1.3
.1.3.6.1.4.1.9.9.220.1.9.7.1.4
.1.3.6.1.4.1.9.9.220.1.9.8
.1.3.6.1.4.1.9.9.220.1.9.8.1
.1.3.6.1.4.1.9.9.220.1.9.8.1.1
OctetString
.1.3.6.1.4.1.9.9.220.1.9.8.1.2
.1.3.6.1.4.1.9.9.220.1.9.8.1.3
.1.3.6.1.4.1.9.9.220.1.9.8.1.4
Enumeration
.1.3.6.1.4.1.9.9.220.1.9.8.1.5
.1.3.6.1.4.1.9.9.220.1.9.8.1.6
.1.3.6.1.4.1.9.9.220.1.9.9
.1.3.6.1.4.1.9.9.220.2
.1.3.6.1.4.1.9.9.220.2.1
.1.3.6.1.4.1.9.9.220.2.2
Dependencies (15) 12 direct · 3 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (2)
Enumeration
other(1)
initialize(2)
disconnected(3)
connecting(4)
authenticating(5)
authenticated(6)
aborting(7)
held(8)
forceAuth(9)
forceUnauth(10)
guestVlan(11)
authFailVlan(12)
criticalAuth(13)
ipAwaiting(14)
policyConfig(15)
authFinished(16)
restart(17)
authFallback(18)
authCResult(19)
authZSuccess(20)
Enumeration
local(1)
server(2)
auto(3)
Conformance Groups (56)
A collection of objects that provide the multiple
host configuration information for a PAE port.
These are additional to the IEEE Std 802.1x PAE MIB.
.1.3.6.1.4.1.9.9.220.2.2.1
A collection of objects that provides the port-mode
configuration for a PAE port.
.1.3.6.1.4.1.9.9.220.2.2.2
A collection of objects that provides the Guest Vlan
configuration information for the system.
.1.3.6.1.4.1.9.9.220.2.2.3
A collection of objects that provides the per-interface
Guest Vlan configuration information for the system.
.1.3.6.1.4.1.9.9.220.2.2.4
A collection of objects that provides the dot1x
shutdown timeout configuration information for
the system.
.1.3.6.1.4.1.9.9.220.2.2.5
A collection of objects that provides the RADIUS
configuration information for the system.
.1.3.6.1.4.1.9.9.220.2.2.6
A collection of objects that provides the group manager
information of authenticated users in the system.
.1.3.6.1.4.1.9.9.220.2.2.7
A collection of objects that provides the per-interface
Guest Vlan configuration information for the system.
.1.3.6.1.4.1.9.9.220.2.2.8
A collection of object(s) that provides the
information about Operational Vlan for each PAE port.
.1.3.6.1.4.1.9.9.220.2.2.9
A collection of object(s) that provides the
Auth-Fail (Authentication Fail) Vlan configuration
and Auth-Fail user information for the system.
.1.3.6.1.4.1.9.9.220.2.2.10
A collection of object(s) that provides control over
Guest Vlan related notification(s).
.1.3.6.1.4.1.9.9.220.2.2.11
A collection of object(s) that provides control over
Auth-Fail related notification(s).
.1.3.6.1.4.1.9.9.220.2.2.12
A collection of notification(s) providing the
information for unconfigured Guest Vlan.
.1.3.6.1.4.1.9.9.220.2.2.13
A collection of notifications providing the
information for unconfigured Auth-Fail Vlan.
.1.3.6.1.4.1.9.9.220.2.2.14
A collection of object(s) that provides the
MAC Auth-Bypass configuration and information
for the system.
.1.3.6.1.4.1.9.9.220.2.2.15
A collection of object(s) that provides the
Web Proxy Authentication configuration and
information for the system.
.1.3.6.1.4.1.9.9.220.2.2.16
A collection of object(s) that provides additional
configuration information about an Authenticator PAE.
.1.3.6.1.4.1.9.9.220.2.2.17
A collection of object(s) that provides information
about an host connecting to a PAE port.
.1.3.6.1.4.1.9.9.220.2.2.18
A collection of object(s) that provides Inaccessible
Authentication Bypass configuration and information
for Web Proxy Authentication in the system.
.1.3.6.1.4.1.9.9.220.2.2.19
A collection of object(s) that provides additional
information of MAC Auth-bypass feature in the system.
.1.3.6.1.4.1.9.9.220.2.2.20
A collection of object(s) that provides information
about if connecting hosts are EAPOL capable.
.1.3.6.1.4.1.9.9.220.2.2.21
A collection of object(s) that provides information
about an host connecting to a PAE port.
.1.3.6.1.4.1.9.9.220.2.2.22
A collection of object(s) that provides configuration
for authentication method for MAC Auth-bypass feature
in the system.
.1.3.6.1.4.1.9.9.220.2.2.23
A collection of object(s) that provides configuration
for maximum authentication attempts for Auth-Fail Vlan
feature in the system.
.1.3.6.1.4.1.9.9.220.2.2.24
A collection of object(s) that provides additional
states in the PAE state machine.
.1.3.6.1.4.1.9.9.220.2.2.25
A collection of object(s) that provides recovery delay
configuration for 802.1x Critical Authentication
in the system.
.1.3.6.1.4.1.9.9.220.2.2.26
A collection of object(s) that provides configuration
and information related to re-authentication of 802.1x
ports in the system.
.1.3.6.1.4.1.9.9.220.2.2.27
A collection of object(s) that provides configuration
of maximum reauthentication attempts of 802.1x
ports in the system.
.1.3.6.1.4.1.9.9.220.2.2.28
A collection of object(s) to enable/disable IAB feature
on capable interface for the system.
.1.3.6.1.4.1.9.9.220.2.2.29
A collection of object(s) that provides global configuration
and information about maximum authentication attempts for
Auth-Fail Vlan feature in the system.
.1.3.6.1.4.1.9.9.220.2.2.30
A collection of object(s) that provides control over
critical configuration for Mac Authentication Bypass.
.1.3.6.1.4.1.9.9.220.2.2.31
A collection of object(s) that provides control over
critical configuration for Web Proxy Authentication.
.1.3.6.1.4.1.9.9.220.2.2.32
A collection of object(s) that provides EAPOL
configuration for 802.1x Critical Authentication
in the system.
.1.3.6.1.4.1.9.9.220.2.2.33
A collection of object(s) that provides information
about Posture Token of an host connecting to a PAE port.
.1.3.6.1.4.1.9.9.220.2.2.34
A collection of object(s) that provides information about
MAC Auth-Bypass Audit sessions.
.1.3.6.1.4.1.9.9.220.2.2.35
A collection of object(s) that provides configuration and
information about MAC Auth-Bypass IP Device Tracking
feature.
.1.3.6.1.4.1.9.9.220.2.2.36
A collection of object(s) that provides configuration and
information about 802.1x IP Device Tracking feature.
.1.3.6.1.4.1.9.9.220.2.2.37
A collection of object(s) that provides information about
URL-redirection of 802.1x authenticated hosts.
.1.3.6.1.4.1.9.9.220.2.2.38
A collection of object(s) that provides configuration and
information about Web Proxy Authentication IP Device
Tracking feature.
.1.3.6.1.4.1.9.9.220.2.2.39
A collection of object(s) that provides configuration and
information about Init State Timeout of Web Proxy
Authentication.
.1.3.6.1.4.1.9.9.220.2.2.40
A collection of object(s) that provides user and the
address information for 802.1x authenticated host.
.1.3.6.1.4.1.9.9.220.2.2.41
A collection of object(s) that provides global configuration
and information about security violation action on PAE ports
in the system.
.1.3.6.1.4.1.9.9.220.2.2.42
A collection of object(s) to enable/disable Mac Auth-Bypass
on capable interfaces for the system.
.1.3.6.1.4.1.9.9.220.2.2.43
A collection of object(s) that provides the
MAC Auth-Bypass configuration and information
for the system.
.1.3.6.1.4.1.9.9.220.2.2.44
A collection of object(s) that provides session
identification information for 802.1x hosts in the system.
.1.3.6.1.4.1.9.9.220.2.2.45
A collection of object(s) that provides state machines and
authentication information for 802.1x authenticated hosts
in the system.
.1.3.6.1.4.1.9.9.220.2.2.46
A collection of object(s) that provides configuration and
information about PAE functionalities of ports in the systems.
.1.3.6.1.4.1.9.9.220.2.2.47
A collection of object(s) that provides configuration that
allows moving ports with 802.1x supplicants to Guest Vlan.
.1.3.6.1.4.1.9.9.220.2.2.48
A collection of object(s) that provides control over
Guest Vlan related notification(s).
.1.3.6.1.4.1.9.9.220.2.2.49
A collection of notifications providing information
for Guest Vlan.
.1.3.6.1.4.1.9.9.220.2.2.50
A collection of object(s) that provides control over
Auth-Fail Vlan related notification(s).
.1.3.6.1.4.1.9.9.220.2.2.51
A collection of notifications providing information
for Auth-Fail Vlan.
.1.3.6.1.4.1.9.9.220.2.2.52
A collection of object(s) that provides the Auth-Fail
(Authentication Fail) Vlan configuration for the system.
.1.3.6.1.4.1.9.9.220.2.2.53
A collection of object(s) that provides the Auth-Fail user
information for the system.
.1.3.6.1.4.1.9.9.220.2.2.54
A collection of object(s) that provides Credential and
EAP profiles configuration for a Supplicant PAE.
.1.3.6.1.4.1.9.9.220.2.2.55
A collection of object(s) that provides information about
supplicants in the system.
.1.3.6.1.4.1.9.9.220.2.2.56
Compliance Statements (10)

OID .1.3.6.1.4.1.9.9.220.2.1.1
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups

OID .1.3.6.1.4.1.9.9.220.2.1.2
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup This group is mandatory in devices running software
which supports Guest Vlan feature.

OID .1.3.6.1.4.1.9.9.220.2.1.3
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup2 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout feature.

OID .1.3.6.1.4.1.9.9.220.2.1.4
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup2 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout feature.
optional cpaeRadiusConfigGroup This group is mandatory in devices running software
which support RADIUS configuration for 802.1x feature.
optional cpaeUserGroupGroup This group is mandatory in devices running software
which support Group Manager for 802.1x feature.

OID .1.3.6.1.4.1.9.9.220.2.1.5
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout feature.
optional cpaeRadiusConfigGroup This group is mandatory in devices running software
which support RADIUS configuration for 802.1x feature.
optional cpaeUserGroupGroup This group is mandatory in devices running software
which support Group Manager for 802.1x feature.
optional cpaePortOperVlanGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup This group is mandatory in devices running software
which support Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup Implementation of this group is optional.
optional cpaeNoAuthFailVlanNotifGroup Implementation of this group is optional.
optional cpaeMacAuthBypassGroup This group is mandatory in devices running software
which support MAC Authentication Bypass feature.
optional cpaeWebAuthGroup This group is mandatory in devices running software
which support Web Proxy Authentication feature.
optional cpaeAuthConfigGroup This group is mandatory in devices running software
which support remote reauthentication timer.
optional cpaeHostInfoGroup Implementation of this group is optional.

OID .1.3.6.1.4.1.9.9.220.2.1.6
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout feature.
optional cpaeRadiusConfigGroup This group is mandatory in devices running software
which support RADIUS configuration for 802.1x feature.
optional cpaeUserGroupGroup This group is mandatory in devices running software
which support Group Manager for 802.1x feature.
optional cpaePortOperVlanGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup This group is mandatory in devices running software
which support Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup Implementation of this group is optional.
optional cpaeNoAuthFailVlanNotifGroup Implementation of this group is optional.
optional cpaeMacAuthBypassGroup This group is mandatory in devices running software
which support MAC Authentication Bypass feature.
optional cpaeMacAuthBypassGroup2 This group is mandatory in devices running software
which provides additional information of
MAC Authentication Bypass feature.
optional cpaeWebAuthGroup This group is mandatory in devices running software
which support Web Proxy Authentication feature.
optional cpaeWebAuthAaaFailGroup This group is mandatory in devices running software
which support Inaccessible Authentication Bypass
for Web Proxy Authentication feature.
optional cpaeHostInfoGroup2 Implementation of this group is optional.
optional cpaePortEapolTestGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup2 This group is mandatory in devices running software
which provides configuration for maximum authentication
attempts for Auth-Fail Vlan feature.
optional cpaeAuthConfigGroup This group is mandatory in devices running software
which support remote reauthentication timer,
re-authentication action, maximum re-authentication
attempts and critical configuration for PAE ports.
optional cpaeAuthConfigGroup2 This group is mandatory in devices running software
which provides additional states in the PAE state
machines.
optional cpaeCriticalRecoveryDelayGroup This group is mandatory in devices running software
which provides recovery delay configuration for 802.1x
Critical Authentication.
optional cpaeMacAuthBypassCriticalGroup This group is mandatory in devices running software
which support critical recovery delay configuration for
MAC Authentication Bypass.
optional cpaeWebAuthCriticalGroup This group is mandatory in devices running software
which support critical recovery delay configuration for
Web Proxy Authentication.
Object refinements
ObjectAccessSyntaxDescription
cpaePortEapolTestStatus
active(1), createAndGo(4), destroy(6)
Only 'active', 'createAndGo' and 'destroy' are
needed to be supported.

OID .1.3.6.1.4.1.9.9.220.2.1.7
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout feature.
optional cpaeRadiusConfigGroup This group is mandatory in devices running software
which support RADIUS configuration for 802.1x feature.
optional cpaeUserGroupGroup This group is mandatory in devices running software
which support Group Manager for 802.1x feature.
optional cpaePortOperVlanGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup This group is mandatory in devices running software
which support Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup Implementation of this group is optional.
optional cpaeNoAuthFailVlanNotifGroup Implementation of this group is optional.
optional cpaeMacAuthBypassGroup This group is mandatory in devices running software
which support MAC Authentication Bypass feature.
optional cpaeMacAuthBypassGroup2 This group is mandatory in devices running software
which provides additional information of
MAC Authentication Bypass feature.
optional cpaeMacAuthBypassGroup3 This group is mandatory in devices running software
which provides configuration for authentication
method for MAC Authentication Bypass feature.
optional cpaeWebAuthGroup This group is mandatory in devices running software
which support Web Proxy Authentication feature.
optional cpaeWebAuthAaaFailGroup This group is mandatory in devices running software
which support Inaccessible Authentication Bypass
for Web Proxy Authentication feature.
optional cpaeHostInfoGroup2 Implementation of this group is optional.
optional cpaeHostInfoGroup3 Implementation of this group is optional.
optional cpaePortEapolTestGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup2 This group is mandatory in devices running software
which provides configuration for maximum authentication
attempts for Auth-Fail Vlan feature.
optional cpaeAuthConfigGroup This group is mandatory in devices running software
which support remote reauthentication timer,
re-authentication action, maximum re-authentication
attempts and critical configuration for PAE ports.
optional cpaeAuthConfigGroup2 This group is mandatory in devices running software
which provides additional states in the PAE state
machines.
optional cpaeCriticalRecoveryDelayGroup This group is mandatory in devices running software
which provides recovery delay configuration for 802.1x
Critical Authentication.
optional cpaeMacAuthBypassCriticalGroup This group is mandatory in devices running software
which support critical recovery delay configuration for
MAC Authentication Bypass.
optional cpaeWebAuthCriticalGroup This group is mandatory in devices running software
which support critical recovery delay configuration for
Web Proxy Authentication.
optional cpaeHostPostureTokenGroup This group is mandatory in devices running software
which provides information about Posture Token of
host(s) connecting to a PAE port.
Object refinements
ObjectAccessSyntaxDescription
cpaePortEapolTestStatus
active(1), createAndGo(4), destroy(6)
Only 'active', 'createAndGo' and 'destroy' are
needed to be supported.

OID .1.3.6.1.4.1.9.9.220.2.1.8
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup Implementation of this group is optional.
optional cpaeRadiusConfigGroup Implementation of this group is optional.
optional cpaeUserGroupGroup Implementation of this group is optional.
optional cpaePortOperVlanGroup This group is mandatory for the devices which assign
interfaces to specific VLANs based on 802.1x authentication.
optional cpaePortAuthFailVlanGroup Implementation of this group is optional.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifGroup This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeMacAuthBypassGroup2 Implementation of this group is optional.
optional cpaeMacAuthBypassGroup3 Implementation of this group is optional.
optional cpaeWebAuthGroup Implementation of this group is optional.
optional cpaeWebAuthAaaFailGroup Implementation of this group is optional.
optional cpaeHostInfoGroup2 Implementation of this group is optional.
optional cpaeHostInfoGroup3 Implementation of this group is optional.
optional cpaePortEapolTestGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup2 This group is mandatory in devices running software
which provides configuration for maximum authentication
attempts for Auth-Fail Vlan feature.
optional cpaeAuthConfigGroup2 Implementation of this group is optional.
optional cpaeCriticalRecoveryDelayGroup Implementation of this group is optional.
optional cpaeMacAuthBypassCriticalGroup Implementation of this group is optional.
optional cpaeWebAuthCriticalGroup Implementation of this group is optional.
optional cpaeHostPostureTokenGroup Implementation of this group is optional.
optional cpaeMabAuditInfoGroup Implementation of this group is optional.
optional cpaeMabPortIpDevTrackConfGroup Implementation of this group is optional.
optional cpaePortIpDevTrackConfGroup Implementation of this group is optional.
optional cpaeHostUrlRedirectGroup Implementation of this group is optional.
optional cpaeWebAuthIpDevTrackingGroup Implementation of this group is optional.
optional cpaeWebAuthUnAuthTimeoutGroup Implementation of this group is optional.
optional cpaeGlobalAuthFailVlanGroup Implementation of this group is optional.
optional cpaeGlobalSecViolationGroup Implementation of this group is optional.
optional cpaeCriticalEapolConfigGroup This group is mandatory in devices running software
which provides EAPOL configuration for 802.1x
Critical Authentication.
optional cpaeMacAuthBypassPortEnableGroup Implementation of this group is optional.
optional cpaeMacAuthBypassGroup4 Implementation of this group is optional.
optional cpaeAuthIabConfigGroup Implementation of this group is optional.
optional cpaeAuthConfigGroup3 This group is mandatory in devices running software
which provides configuration and information related
to re-authentication of 802.1x ports in the system.
optional cpaeAuthConfigGroup4 Implementation of this group is optional.
Object refinements
ObjectAccessSyntaxDescription
cpaePortEapolTestStatus
active(1), createAndGo(4), destroy(6)
Only 'active', 'createAndGo' and 'destroy' are
needed to be supported.

OID .1.3.6.1.4.1.9.9.220.2.1.9
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup Implementation of this group is optional.
optional cpaeRadiusConfigGroup Implementation of this group is optional.
optional cpaeUserGroupGroup Implementation of this group is optional.
optional cpaePortOperVlanGroup This group is mandatory for the devices which assign
interfaces to specific VLANs based on 802.1x authentication.
optional cpaePortAuthFailVlanGroup Implementation of this group is optional.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifGroup This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeMacAuthBypassGroup2 Implementation of this group is optional.
optional cpaeMacAuthBypassGroup3 Implementation of this group is optional.
optional cpaeWebAuthGroup Implementation of this group is optional.
optional cpaeWebAuthAaaFailGroup Implementation of this group is optional.
optional cpaeHostInfoGroup2 Implementation of this group is optional.
optional cpaeHostInfoGroup3 Implementation of this group is optional.
optional cpaePortEapolTestGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanGroup2 This group is mandatory in devices running software
which provides configuration for maximum authentication
attempts for Auth-Fail Vlan feature.
optional cpaeAuthConfigGroup2 Implementation of this group is optional.
optional cpaeCriticalRecoveryDelayGroup Implementation of this group is optional.
optional cpaeMacAuthBypassCriticalGroup Implementation of this group is optional.
optional cpaeWebAuthCriticalGroup Implementation of this group is optional.
optional cpaeHostPostureTokenGroup Implementation of this group is optional.
optional cpaeMabAuditInfoGroup Implementation of this group is optional.
optional cpaeMabPortIpDevTrackConfGroup Implementation of this group is optional.
optional cpaePortIpDevTrackConfGroup Implementation of this group is optional.
optional cpaeHostUrlRedirectGroup Implementation of this group is optional.
optional cpaeWebAuthIpDevTrackingGroup Implementation of this group is optional.
optional cpaeWebAuthUnAuthTimeoutGroup Implementation of this group is optional.
optional cpaeGlobalAuthFailVlanGroup Implementation of this group is optional.
optional cpaeGlobalSecViolationGroup Implementation of this group is optional.
optional cpaeCriticalEapolConfigGroup This group is mandatory in devices running software
which provides EAPOL configuration for 802.1x
Critical Authentication.
optional cpaeMacAuthBypassPortEnableGroup Implementation of this group is optional.
optional cpaeMacAuthBypassGroup4 Implementation of this group is optional.
optional cpaeAuthIabConfigGroup Implementation of this group is optional.
optional cpaeAuthConfigGroup3 This group is mandatory in devices running software
which provides configuration and information related
to re-authentication of 802.1x ports in the system.
optional cpaeAuthConfigGroup4 Implementation of this group is optional.
optional cpaeHostSessionIdGroup Implementation of this group is optional.
optional cpaeHostAuthInfoGroup Implementation of this group is optional.
optional cpaePortCapabilitiesConfigGroup Implementation of this group is optional.
optional cpaeDot1xSuppToGuestVlanGroup Implementation of this group is optional.
optional cpaeGuestVlanNotifEnableGroup Implementation of this group is optional.
optional cpaeGuestVlanNotifGroup Implementation of this group is optional.
optional cpaeAuthFailVlanNotifEnableGrp Implementation of this group is optional.
optional cpaeAuthFailVlanNotifGroup Implementation of this group is optional.
optional cpaePortAuthFailVlanConfigGroup This group is mandatory in devices running software which
supports Auth-Fail Vlan configuration for 802.1x feature.
optional cpaePortAuthFailUserInfoGroup Implementation of this group is optional.
Object refinements
ObjectAccessSyntaxDescription
cpaePortEapolTestStatus
active(1), createAndGo(4), destroy(6)
Only 'active', 'createAndGo' and 'destroy' are
needed to be supported.

OID .1.3.6.1.4.1.9.9.220.2.1.10
The compliance statement for devices that implement
the CISCO-PAE-MIB.
Required groups
mandatory cpaePortEntryGroup
optional cpaeGuestVlanGroup3 This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeShutdownTimeoutGroup This group is mandatory in devices running software
which support Shutdown Timeout for 802.1x.
optional cpaeRadiusConfigGroup This group is mandatory in devices running software
which support RADIUS accounting configuration for 802.1x.
optional cpaeUserGroupGroup This group is mandatory in devices running software
which support Group Manager for 802.1x.
optional cpaePortOperVlanGroup This group is mandatory for the devices which assign
interfaces to specific VLANs based on 802.1x authentication.
optional cpaeNoGuestVlanNotifEnableGrp This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeNoGuestVlanNotifGroup This group is mandatory in devices running software
which supports per-interface Guest Vlan feature.
optional cpaeNoAuthFailVlanNotifGroup This group is mandatory in devices running software
which supports Auth-Fail Vlan configuration for
802.1x feature.
optional cpaeMacAuthBypassGroup2 This group is mandatory in devices running software
which provides information about termination action and
session time left for Mac Authentication Bypass via
802.1x feature.
optional cpaeMacAuthBypassGroup3 This group is mandatory in devices running software
which provides configuration of authentication method
for Mac Authentication Bypass via 802.1x feature.
optional cpaeWebAuthGroup This group is mandatory in devices running software
which provides configuration for Web Proxy Authentication
via 802.1x feature.
optional cpaeWebAuthAaaFailGroup This group is mandatory in devices running software
which provides configuration of Inaccessible Authentication
Bypass for Web Proxy Authentication via 802.1x feature.
optional cpaeHostInfoGroup2 This group is mandatory in devices running software
which provides MAC address information of hosts connecting
to PAE ports in the system.
optional cpaeHostInfoGroup3 This group is mandatory in devices running software
which provides user and IP address information for 802.1x
authenticated host in the system.
optional cpaePortEapolTestGroup This group is mandatory in devices running software
which provides EAPOL capable information of hosts connecting
to PAE ports in the system.
optional cpaePortAuthFailVlanGroup2 This group is mandatory in devices running software
which provides configuration for maximum authentication
attempts for Auth-Fail Vlan feature.
optional cpaeAuthConfigGroup2 This group is mandatory in devices running software
which provides additional states in the PAE state machine.
optional cpaeCriticalRecoveryDelayGroup This group is mandatory in devices running software
which provides recovery delay configuration for 802.1x
Critical Authentication in the system.
optional cpaeMacAuthBypassCriticalGroup This group is mandatory in devices running software
which provides control over critical configuration for Mac
Authentication Bypass via 802.1x feature.
optional cpaeWebAuthCriticalGroup This group is mandatory in devices running software
which provides control over critical configuration for Web
Proxy Authentication via 802.1x feature.
optional cpaeHostPostureTokenGroup This group is mandatory in devices running software
which provides information about Posture Token of hosts
connecting to PAE ports.
optional cpaeMabAuditInfoGroup This group is mandatory in devices running software
which provides information about MAC Auth-Bypass Audit
sessions via 802.1x feature.
optional cpaeMabPortIpDevTrackConfGroup This group is mandatory in devices running software
which provides configuration and information about MAC
Auth-Bypass IP Device Tracking via 802.1x feature.
optional cpaePortIpDevTrackConfGroup This group is mandatory in devices running software
which provides configuration and information about
802.1x IP Device Tracking feature.
optional cpaeHostUrlRedirectGroup This group is mandatory in devices running software
which provides information about URL-redirection of 802.1x
authenticated hosts.
optional cpaeWebAuthIpDevTrackingGroup This group is mandatory in devices running software
which provides configuration and information about Web
Proxy Authentication IP Device Tracking via 802.1x feature.
optional cpaeWebAuthUnAuthTimeoutGroup This group is mandatory in devices running software
which provides configuration and information about Init State
Timeout of Web Proxy Authentication via 802.1x feature.
optional cpaeGlobalAuthFailVlanGroup This group is mandatory in devices running software
which provides global configuration and information about
maximum authentication attempts for Auth-Fail Vlan feature
in the system.
optional cpaeGlobalSecViolationGroup This group is mandatory in devices running software
which provides global configuration and information about
security violation action on PAE ports in the system.
optional cpaeCriticalEapolConfigGroup This group is mandatory in devices running software
which provides EAPOL configuration for 802.1x
Critical Authentication.
optional cpaeMacAuthBypassPortEnableGroup This group is mandatory in devices running software
which provides configuration to enable or disable MAC
Auth-Bypass on capable ports via 802.1x feature.
optional cpaeMacAuthBypassGroup4 This group is mandatory in devices running software
which provides configuration and information of MAC
Auth-Bypass parameters via 802.1x feature.
optional cpaeAuthIabConfigGroup This group is mandatory in devices running software
which provides configuration to enable or disable IAB
feature on capable ports in the system.
optional cpaeAuthConfigGroup3 This group is mandatory in devices running software
which provides configuration and information related
to re-authentication of 802.1x ports in the system.
optional cpaeAuthConfigGroup4 This group is mandatory in devices running software
which provides configuration of maximum reauthentication
attempts of 802.1x ports in the system.
optional cpaeHostSessionIdGroup This group is mandatory in devices running software
which provides session identification information for 802.1x
hosts in the system.
optional cpaeHostAuthInfoGroup This group is mandatory in devices running software
which provides information about state machines and
authentication information for 802.1x authenticated hosts in
the system.
optional cpaePortCapabilitiesConfigGroup This group is mandatory in devices running software
which provides configuration and information about PAE
functionalities of ports in the systems.
optional cpaeDot1xSuppToGuestVlanGroup This group is mandatory in devices running software
which provides configuration that allows moving ports with
802.1x supplicants to Guest Vlan.
optional cpaeGuestVlanNotifEnableGroup This group is mandatory in devices running software
which provides control over Guest Vlan related notification(s).
optional cpaeGuestVlanNotifGroup This group is mandatory in devices running software
which provides Guest-Vlan notification.
optional cpaeAuthFailVlanNotifEnableGrp This group is mandatory in devices running software
which provides control over Auth-Fail Vlan related
notification(s).
optional cpaeAuthFailVlanNotifGroup This group is mandatory in devices running software
which provides Auth-Fail Vlan notification.
optional cpaePortAuthFailVlanConfigGroup This group is mandatory in devices running software which
supports Auth-Fail Vlan configuration for 802.1x feature.
optional cpaePortAuthFailUserInfoGroup This group is mandatory in devices running software
which provides the Auth-Fail user information in the system.
optional cpaeSuppPortProfileGroup This group is mandatory in devices running software which
supports PAE supplicant credential and EAP profiles feature.
optional cpaeSuppHostInfoGroup This group is mandatory in devices running software which
supports per-host supplicant feature.
Object refinements
ObjectAccessSyntaxDescription
cpaePortMode readonly
Write access is not required.
cpaeGuestVlanNumber readonly
Write access is not required.
cpaeShutdownTimeoutEnabled readonly
Write access is not required.
cpaePortAuthFailVlan readonly
Write access is not required.
cpaeAuthFailVlanMaxAttempts readonly
Write access is not required.
cpaePortCapabilitiesEnabled readonly
Write access is not required.
cpaeShutdownTimeout readonly
Write access is not required.
cpaeRadiusAccountingEnabled readonly
Write access is not required.
cpaeNoGuestVlanNotifEnable readonly
Write access is not required.
cpaeNoAuthFailVlanNotifEnable readonly
Write access is not required.
cpaeGuestVlanNotifEnable readonly
Write access is not required.
cpaeAuthFailVlanNotifEnable readonly
Write access is not required.
cpaeMacAuthBypassReAuthTimeout readonly
Write access is not required.
cpaeMacAuthBypassReAuthEnabled readonly
Write access is not required.
cpaeMacAuthBypassViolation readonly
Write access is not required.
cpaeMacAuthBypassShutdownTimeout readonly
Write access is not required.
cpaeMacAuthBypassAuthFailTimeout readonly
Write access is not required.
cpaeMacAuthBypassPortEnabled readonly
Write access is not required.
cpaeMacAuthBypassPortInitialize readonly
Write access is not required.
cpaeMacAuthBypassPortReAuth readonly
Write access is not required.
cpaeMacAuthBypassPortAuthMethod readonly
Write access is not required.
cpaeMacAuthBypassAcctEnable readonly
Write access is not required.
cpaeMabCriticalRecoveryDelay readonly
Write access is not required.
cpaeMabPortIpDevTrackEnabled readonly
Write access is not required.
cpaeWebAuthEnabled readonly
Write access is not required.
cpaeWebAuthSessionPeriod readonly
Write access is not required.
cpaeWebAuthLoginPage readonly
Write access is not required.
cpaeWebAuthLoginFailedPage readonly
Write access is not required.
cpaeWebAuthQuietPeriod readonly
Write access is not required.
cpaeWebAuthMaxRetries readonly
Write access is not required.
cpaeWebAuthPortEnabled readonly
Write access is not required.
cpaeWebAuthPortInitialize readonly
Write access is not required.
cpaeWebAuthPortAaaFailPolicy readonly
Write access is not required.
cpaeWebAuthPortIpDevTrackEnabled readonly
Write access is not required.
cpaeWebAuthHostInitialize readonly
Write access is not required.
cpaeWebAuthCriticalRecoveryDelay readonly
Write access is not required.
cpaeWebAuthUnAuthStateTimeout readonly
Write access is not required.
cpaeAuthReAuthPeriodSrcAdmin readonly
Write access is not required.
cpaeAuthReAuthMax readonly
Write access is not required.
cpaeAuthIabEnabled readonly
Write access is not required.
cpaeCriticalEapolEnabled readonly
Write access is not required.
cpaeCriticalRecoveryDelay readonly
Write access is not required.
cpaePortIpDevTrackEnabled readonly
Write access is not required.
cpaeGlobalAuthFailMaxAttempts readonly
Write access is not required.
cpaeGlobalSecViolationAction readonly
Write access is not required.
cpaeDot1xSuppToGuestVlanAllowed readonly
Write access is not required.
cpaeSuppPortCredentialProfileName readonly
Write access is not required.
cpaeSuppPortEapProfileName readonly
Write access is not required.
cpaePortEapolTestStatus readonly
active(1)
Write access is not required.

Support for createAndWait and notInService is not required.
Notifications / Traps (4)
NameOIDDescription
.1.3.6.1.4.1.9.9.220.0.1
A cpaeNoGuestVlanNotif is sent if a non-802.1x
supplicant is detected on a PAE port for which the
value of corresponding instance of
dot1xAuthAuthControlledPortControl is 'auto' and the
value of corresponding instance of cpaeGuestVlanNumber
is zero.
.1.3.6.1.4.1.9.9.220.0.2
A cpaeNoAuthFailVlanNotif is sent if a 802.1x
supplicant fails to authenticate on a PAE port for
which the value of corresponding instance of
dot1xAuthAuthControlledPortControl is 'auto' and the
value of corresponding instance of cpaePortAuthFailVlan
is zero.
.1.3.6.1.4.1.9.9.220.0.3
A cpaeGuestVlanNotif is sent if value of the instance
of cpaeGuestVlanNotifEnable is set to 'true', and a PAE
port is being moved to the VLAN specified by value of
the corresponding instance of cpaeGuestVlanNumber.
.1.3.6.1.4.1.9.9.220.0.4
A cpaeAuthFailVlanNotif is sent if value of the instance
of cpaeAuthFailVlanNotifEnable is set to 'true', and a PAE
port is being moved to the VLAN specified by value of
the corresponding instance of cpaePortAuthFailVlan.