CISCO-PORT-SECURITY-MIB

        The MIB module for managing Cisco Port Security.
    
Source file
CISCO-PORT-SECURITY-MIB
Last revised
Identity
ciscoPortSecurityMIB
Base OID
1.3.6.1.4.1.9.9.315
Imported Objects
CISCO-SMI ciscoMgmt
CISCO-VTP-MIB vtpVlanName
IF-MIB ifIndex ifName
Q-BRIDGE-MIB VlanIndex
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC MacAddress RowStatus TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-PORT-SECURITY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-PORT-SECURITY-MIB::ciscoPortSecurityMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-PORT-SECURITY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-PORT-SECURITY-MIB::ciscoPortSecurityMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (60)
.1.3.6.1.4.1.9.9.315
.1.3.6.1.4.1.9.9.315.0
.1.3.6.1.4.1.9.9.315.0.0
.1.3.6.1.4.1.9.9.315.1
.1.3.6.1.4.1.9.9.315.1.1
Integer32
.1.3.6.1.4.1.9.9.315.1.1.1
Integer32
.1.3.6.1.4.1.9.9.315.1.1.2
.1.3.6.1.4.1.9.9.315.1.1.3
notifs per secondInteger32
.1.3.6.1.4.1.9.9.315.1.1.4
.1.3.6.1.4.1.9.9.315.1.1.5
.1.3.6.1.4.1.9.9.315.1.1.6
.1.3.6.1.4.1.9.9.315.1.2
.1.3.6.1.4.1.9.9.315.1.2.1
.1.3.6.1.4.1.9.9.315.1.2.1.1
.1.3.6.1.4.1.9.9.315.1.2.1.1.1
.1.3.6.1.4.1.9.9.315.1.2.1.1.10
cpsIfClearSecureAddresses deprecated r/w
.1.3.6.1.4.1.9.9.315.1.2.1.1.11
.1.3.6.1.4.1.9.9.315.1.2.1.1.12
.1.3.6.1.4.1.9.9.315.1.2.1.1.13
.1.3.6.1.4.1.9.9.315.1.2.1.1.14
.1.3.6.1.4.1.9.9.315.1.2.1.1.15
.1.3.6.1.4.1.9.9.315.1.2.1.1.16
Packets per secondInteger32
.1.3.6.1.4.1.9.9.315.1.2.1.1.17
.1.3.6.1.4.1.9.9.315.1.2.1.1.18
Enumeration
.1.3.6.1.4.1.9.9.315.1.2.1.1.2
Integer32
.1.3.6.1.4.1.9.9.315.1.2.1.1.3
Integer32
.1.3.6.1.4.1.9.9.315.1.2.1.1.4
minutesInteger32
.1.3.6.1.4.1.9.9.315.1.2.1.1.5
Enumeration
.1.3.6.1.4.1.9.9.315.1.2.1.1.6
.1.3.6.1.4.1.9.9.315.1.2.1.1.7
Enumeration
.1.3.6.1.4.1.9.9.315.1.2.1.1.8
.1.3.6.1.4.1.9.9.315.1.2.1.1.9
.1.3.6.1.4.1.9.9.315.1.2.2
.1.3.6.1.4.1.9.9.315.1.2.2.1
cpsSecureMacAddress deprecated
.1.3.6.1.4.1.9.9.315.1.2.2.1.1
Enumeration
.1.3.6.1.4.1.9.9.315.1.2.2.1.2
minutesInteger32
.1.3.6.1.4.1.9.9.315.1.2.2.1.3
cpsSecureMacAddrRowStatus deprecated r/w
.1.3.6.1.4.1.9.9.315.1.2.2.1.4
.1.3.6.1.4.1.9.9.315.1.2.3
.1.3.6.1.4.1.9.9.315.1.2.3.1
.1.3.6.1.4.1.9.9.315.1.2.3.1.1
.1.3.6.1.4.1.9.9.315.1.2.3.1.2
Enumeration
.1.3.6.1.4.1.9.9.315.1.2.3.1.3
.1.3.6.1.4.1.9.9.315.1.2.3.1.4
.1.3.6.1.4.1.9.9.315.1.2.3.1.5
cpsIfVlanTable obsolete
.1.3.6.1.4.1.9.9.315.1.2.4
cpsIfVlanEntry obsolete
.1.3.6.1.4.1.9.9.315.1.2.4.1
cpsIfVlanIndex obsolete
.1.3.6.1.4.1.9.9.315.1.2.4.1.1
Unsigned32
.1.3.6.1.4.1.9.9.315.1.2.4.1.2
Unsigned32
.1.3.6.1.4.1.9.9.315.1.2.4.1.3
.1.3.6.1.4.1.9.9.315.1.2.5
.1.3.6.1.4.1.9.9.315.1.2.5.1
.1.3.6.1.4.1.9.9.315.1.2.5.1.1
.1.3.6.1.4.1.9.9.315.1.2.5.1.2
.1.3.6.1.4.1.9.9.315.1.2.5.1.3
.1.3.6.1.4.1.9.9.315.1.2.5.1.4
.1.3.6.1.4.1.9.9.315.1.2.5.1.5
.1.3.6.1.4.1.9.9.315.2
.1.3.6.1.4.1.9.9.315.2.1
.1.3.6.1.4.1.9.9.315.2.2
Dependencies (21) 7 direct · 14 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (1)
Enumeration
done(0)
dynamic(1)
static(2)
sticky(3)
all(4)
Conformance Groups (16)
A collection of objects for use with the Port
Security feature.
.1.3.6.1.4.1.9.9.315.2.2.1
********* THIS GROUP IS DEPRECATED **********
A collection of objects for use with the Port
Security feature.
.1.3.6.1.4.1.9.9.315.2.2.2
A collection of objects providing the additional
information for the Port Security feature.
.1.3.6.1.4.1.9.9.315.2.2.3
A collection of notifications for use
with the Port Security feature.
.1.3.6.1.4.1.9.9.315.2.2.4
A collection of objects providing the
unicast flooding information for the
Port Security feature.
.1.3.6.1.4.1.9.9.315.2.2.5
A collection of objects providing the
shutdown timeout information for the
Port Security feature.
.1.3.6.1.4.1.9.9.315.2.2.6
A collection of objects for use with the Port
Security feature.
.1.3.6.1.4.1.9.9.315.2.2.8
********* THIS GROUP IS DEPRECATED **********
A collection of objects for use with the Port
Security configuration.
.1.3.6.1.4.1.9.9.315.2.2.9
********* THIS GROUP IS DEPRECATED **********
A collection of objects providing the additional
information for the Port Security feature.
.1.3.6.1.4.1.9.9.315.2.2.10
A collection of objects providing additional trunk
VLAN information for the Port Security feature on a
given interface.
.1.3.6.1.4.1.9.9.315.2.2.11
A collection of objects for clearing addresses
on the device.
.1.3.6.1.4.1.9.9.315.2.2.12
A collection of objects for use with the Port
Security configuration.
.1.3.6.1.4.1.9.9.315.2.2.13
A collection of trunk or multi-vlan port related
notifications for use with the port-security feature.
.1.3.6.1.4.1.9.9.315.2.2.14
A collection of objects providing additional per
interface per VLAN port security feature information
on a multi-vlan interface.
.1.3.6.1.4.1.9.9.315.2.2.15
A collection of trunk or multi-vlan port related
notifications for use with the port-security feature.
.1.3.6.1.4.1.9.9.315.2.2.16
A collection of objects providing the information of
the VLAN-id for the last MAC address seen on the
interface.
.1.3.6.1.4.1.9.9.315.2.2.17
Compliance Statements (5)

OID .1.3.6.1.4.1.9.9.315.2.1.1
The compliance statement for the Port Security MIB.
Required groups
mandatory cpsGlobalGroup
mandatory cpsInterfaceGroup
optional cpsExtInterfaceGroup This group is mandatory only for the device that
is capable of keeping track of the last secure MAC
address learned or configured on the interface.
optional cpsNotificationGroup This is mandatory only for the device that supports
'dropNotify' of cpsIfViolationAction.
optional cpsExtConfigInterfaceGroup This group is a optional.
Object refinements
ObjectAccessSyntaxDescription
cpsGlobalPortSecurityEnable readonly
read-write access is not required. This may be
read-only.
cpsGlobalSNMPNotifRate readonly
read-write access is not required.
cpsGlobalSNMPNotifControl readonly
read-write access is not required.
cpsIfSecureMacAddrAgingType readonly
read-write is not required if the device only support
one aging type.
cpsIfViolationAction
Enumeration
shutdown(1)
The support of the values 'dropNotify' and/or 'drop'
is not required if the device does not support the
configuration of 'dropNotify' and/or 'drop'.
cpsIfViolationCount
An implementation of violation count is
required only if the device can provide the
number of the violations occurred on the device.
cpsIfStaticMacAddrAgingEnable readonly
read-write access is not required.
cpsIfSecureLastMacAddress
An implementation of this object is not mandatory.
cpsIfClearSecureAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.

OID .1.3.6.1.4.1.9.9.315.2.1.2
The compliance statement for the Port Security MIB.
Required groups
mandatory cpsGlobalGroup
mandatory cpsInterfaceGroup1
mandatory cpsIfVlanSecureMacAddrGroup
optional cpsExtInterfaceGroup This group is mandatory only for the device that
is capable of keeping track of the last secure MAC
address learned or configured on the interface.
optional cpsNotificationGroup This is mandatory only for the device that supports
'dropNotify' of cpsIfViolationAction.
optional cpsUnicastFloodingInterfaceGroup This group is mandatory only for the device that
is capable of blocking unicast flooded traffic when
the secure address count reaches the threshold on
the interface.
optional cpsShutdownTimeoutInterfaceGroup This group is mandatory only for the device that
is capable to support shutdown timeout on the
interface.
Object refinements
ObjectAccessSyntaxDescription
cpsGlobalPortSecurityEnable readonly
read-write access is not required. This may be
read-only.
cpsGlobalSNMPNotifRate readonly
read-write access is not required.
cpsGlobalSNMPNotifControl readonly
read-write access is not required.
cpsIfSecureMacAddrAgingType readonly
read-write is not required if the device only support
one aging type.
cpsIfViolationAction
Enumeration
shutdown(1)
The support of the values 'dropNotify' and/or 'drop'
is not required if the device does not support the
configuration of 'dropNotify' and/or 'drop'.
cpsIfViolationCount
An implementation of violation count is
required only if the device can provide the
number of the violations occurred on the device.
cpsIfStaticMacAddrAgingEnable readonly
read-write access is not required.
cpsIfSecureLastMacAddress
An implementation of this object is not mandatory.
cpsIfClearSecureAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.

OID .1.3.6.1.4.1.9.9.315.2.1.3
The compliance statement for the Port Security MIB.
Required groups
mandatory cpsGlobalGroup
mandatory cpsInterfaceGroup2
mandatory cpsIfVlanSecureMacAddrGroup
optional cpsExtInterfaceGroup This group is mandatory only for the device that
is capable of keeping track of the last secure MAC
address learned or configured on the interface.
optional cpsNotificationGroup This is mandatory only for the device that supports
'dropNotify' of cpsIfViolationAction.
optional cpsUnicastFloodingInterfaceGroup This group is mandatory only for the device that
is capable of blocking unicast flooded traffic when
the secure address count reaches the threshold on
the interface.
optional cpsShutdownTimeoutInterfaceGroup This group is mandatory only for the device that
is capable to support shutdown timeout on the
interface.
optional cpsIfVlanGroup This group is mandatory only for the device that
is capable to support trunk port security on the
interfaces.
optional cpsGlobalClearAddressGroup This group is mandatory only for the device that
is capable of clearing secure addresses from
the system.
Object refinements
ObjectAccessSyntaxDescription
cpsGlobalPortSecurityEnable readonly
read-write access is not required. This may be
read-only.
cpsGlobalSNMPNotifRate readonly
read-write access is not required.
cpsGlobalSNMPNotifControl readonly
read-write access is not required.
cpsIfSecureMacAddrAgingType readonly
read-write is not required if the device only support
one aging type.
cpsIfViolationAction
Enumeration
shutdown(1)
The support of the values 'dropNotify' and/or 'drop'
is not required if the device does not support the
configuration of 'dropNotify' and/or 'drop'.
cpsIfViolationCount
An implementation of violation count is
required only if the device can provide the
number of the violations occurred on the device.
cpsIfStaticMacAddrAgingEnable readonly
read-write access is not required.
cpsIfSecureLastMacAddress
An implementation of this object is not mandatory.
cpsGlobalClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.
cpsIfClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.

OID .1.3.6.1.4.1.9.9.315.2.1.4
The compliance statement for the Port Security MIB.
Required groups
mandatory cpsGlobalGroup
mandatory cpsInterfaceGroup2
mandatory cpsIfVlanSecureMacAddrGroup
optional cpsExtInterfaceGroup This group is mandatory only for the device that
is capable of keeping track of the last secure MAC
address learned or configured on the interface.
optional cpsNotificationGroup This is mandatory only for the device that supports
'dropNotify' of cpsIfViolationAction.
optional cpsUnicastFloodingInterfaceGroup This group is mandatory only for the device that
is capable of blocking unicast flooded traffic when
the secure address count reaches the threshold on
the interface.
optional cpsShutdownTimeoutInterfaceGroup This group is mandatory only for the device that
is capable to support shutdown timeout on the
interface.
optional cpsIfVlanGroup This group is mandatory only for the device that
is capable to support trunk port security on the
interfaces.
optional cpsGlobalClearAddressGroup This group is mandatory only for the device that
is capable of clearing secure addresses from
the system.
optional cpsTrunkSecureNotificationGroup This group is mandatory only if the device supports
port-security feature on a trunk or multi-vlan port and
also supports the 'dropNotify' option for the object
cpsIfViolationAction.
Object refinements
ObjectAccessSyntaxDescription
cpsGlobalPortSecurityEnable readonly
read-write access is not required. This may be
read-only.
cpsGlobalSNMPNotifRate readonly
read-write access is not required.
cpsGlobalSNMPNotifControl readonly
read-write access is not required.
cpsIfSecureMacAddrAgingType readonly
read-write is not required if the device only support
one aging type.
cpsIfViolationAction
Enumeration
shutdown(1)
The support of the values 'dropNotify' and/or 'drop'
is not required if the device does not support the
configuration of 'dropNotify' and/or 'drop'.
cpsIfViolationCount
An implementation of violation count is
required only if the device can provide the
number of the violations occurred on the device.
cpsIfStaticMacAddrAgingEnable readonly
read-write access is not required.
cpsIfSecureLastMacAddress
An implementation of this object is not mandatory.
cpsGlobalClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.
cpsIfClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.

OID .1.3.6.1.4.1.9.9.315.2.1.5
The compliance statement for the Port Security MIB.
Required groups
mandatory cpsGlobalGroup
mandatory cpsInterfaceGroup2
mandatory cpsIfVlanSecureMacAddrGroup
optional cpsExtInterfaceGroup This group is mandatory only for the device that
is capable of keeping track of the last secure MAC
address learned or configured on the interface.
optional cpsNotificationGroup This is mandatory only for the device that supports
'dropNotify' of cpsIfViolationAction.
optional cpsUnicastFloodingInterfaceGroup This group is mandatory only for the device that
is capable of blocking unicast flooded traffic when
the secure address count reaches the threshold on
the interface.
optional cpsShutdownTimeoutInterfaceGroup This group is mandatory only for the device that
is capable to support shutdown timeout on the
interface.
optional cpsIfMultiVlanGroup This group is mandatory only for the device that
is capable to support port security on the multi-vlan
interfaces as well as capable to support the maximum
number of secure mac address specified on per interface
per VLAN.
optional cpsGlobalClearAddressGroup This group is mandatory only for the device that
is capable of clearing secure addresses from
the system.
optional cpsIfVlanSecureNotificationGroup This group is mandatory only if the device supports
port-security feature on a multi-vlan port and
also supports the 'dropNotify' option for the object
cpsIfViolationAction.
optional cpsExtInterfaceGroup1 This group is mandatory only for the device that
is capable of keeping track of the VLAN-id where last
MAC address that is seen on the interface.
Object refinements
ObjectAccessSyntaxDescription
cpsGlobalPortSecurityEnable readonly
read-write access is not required. This may be
read-only.
cpsGlobalSNMPNotifRate readonly
read-write access is not required.
cpsGlobalSNMPNotifControl readonly
read-write access is not required.
cpsIfSecureMacAddrAgingType readonly
read-write is not required if the device only support
one aging type.
cpsIfViolationAction
Enumeration
shutdown(1)
The support of the values 'dropNotify' and/or 'drop'
is not required if the device does not support the
configuration of 'dropNotify' and/or 'drop'.
cpsIfViolationCount
An implementation of violation count is
required only if the device can provide the
number of the violations occurred on the device.
cpsIfStaticMacAddrAgingEnable readonly
read-write access is not required.
cpsIfSecureLastMacAddress
An implementation of this object is not mandatory.
cpsGlobalClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.
cpsIfClearSecureMacAddresses readonly
read-write access is not required if the device
does not support the command to clear all secure
address on the interface.
Notifications / Traps (3)
NameOIDDescription
.1.3.6.1.4.1.9.9.315.0.0.1
The address violation notification is generated
when port security address violation is detected
on a secure non-trunk, access interface (that carries
a single vlan) and the cpsIfViolationAction is set to
'dropNotify'.
.1.3.6.1.4.1.9.9.315.0.0.2
The address violation notification is generated when port
security address violation is detected on a secure trunk
or a multi-vlan interface and the cpsIfViolationAction is
set to 'dropNotify'.
.1.3.6.1.4.1.9.9.315.0.0.3
The address violation notification is generated
when port security address violation is detected
on a multi-vlan interface and the cpsIfViolationAction
is set to 'dropNotify'.