CISCO-REMOTE-ACCESS-MONITOR-MIB

Monitored by Observium
        Acronyms and        Definitions
The        following acronyms and terms are used in this
document:
        
  IPSec: Secure IP Protocol
        
  VPN:   Virtual Private Network
        
  RAS:   Remote Access Service
        
  ISP:   Internet Service Provider.
        
  LAN:   Local Area        Network
        
  Group: A collection of remote access users grouped
         and managed together as a single entity for
         administrative convenience.
        
  Session: A Remote        Access Session.
        
  SVC:    SSL VPN Client
  Webvpn: VPN connection established using web browser.
        
Overview of the MIB
        
This is a MIB Module for monitoring        the structures in Virtual
Private Networks based remote access networks. The MIB seeks
to create a        common model of        Remote Access across implementations
of the service on layer 2 (PPTP, L2TP, L2F), layer 3 (IPsec) and
layer 4 (SSL) virtual private networks. The        MIB defines counters
and        objects        of interest to performance/fault monitoring in a
way        which is independent of        the technology of the remote access
implementation.
        
MIB        contains eight major groups of objects which are used
to manage Remote Access connections:
 a)        Remote Access capacity group
      This section defines metrics to gauge        the limits of
      resources on this device which are critical to RAS
      service.
        
 b)        Remote Access resource usage group
      This section defines metrics to gauge        the usage of
      resources on this device which are critical to RAS
      service service.
        
 c)        Current        activity and performance of RAS        service
      This section defines metrics to gauge        the current
      remote access        activity.
        
 d)        Remote Access Service failures
      This section defines metrics to monitor session
      failures and failures        of the service itself, measured
      at aggregate level, session level and        group level.
        
 e)        Security violations in the Remote Access service
      This section defines metrics which reflect the state
      of remote access service of interest to Security
      Operations staff in an enterprise.
        
 f)        Threshold group        (allows        definition of high water marks)
      This section allows the management entity to define
      thresholds to        set high water marks on        critical metrics.
        
 g)        Notifications
      This section defines notifications to        signal
      significant events pertaining        to the Remote Access
      Service.
    
Observium actively monitors this MIB
Observium uses this MIB in discovery or polling workflows on applicable devices.
Polling
Explore Observium network monitoring
Source file
CISCO-REMOTE-ACCESS-MONITOR-MIB
Last revised
Identity
ciscoRemoteAccessMonitorMIB
Base OID
1.3.6.1.4.1.9.9.392
Imported Objects
CISCO-SMI ciscoMgmt
INET-ADDRESS-MIB InetAddress InetAddressType
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Counter64 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 zeroDotZero
SNMPv2-TC TEXTUAL-CONVENTION (no object page) TimeStamp TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-REMOTE-ACCESS-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-REMOTE-ACCESS-MONITOR-MIB::ciscoRemoteAccessMonitorMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-REMOTE-ACCESS-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-REMOTE-ACCESS-MONITOR-MIB::ciscoRemoteAccessMonitorMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (137)
6 directly used by Observium
.1.3.6.1.4.1.9.9.392
.1.3.6.1.4.1.9.9.392.0
.1.3.6.1.4.1.9.9.392.1
.1.3.6.1.4.1.9.9.392.1.1
SessionsInteger32
.1.3.6.1.4.1.9.9.392.1.1.1
UsersInteger32
.1.3.6.1.4.1.9.9.392.1.1.2
GroupsInteger32
.1.3.6.1.4.1.9.9.392.1.1.3
UsersInteger32
.1.3.6.1.4.1.9.9.392.1.1.4
.1.3.6.1.4.1.9.9.392.1.2
MBytes/secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.392.1.2.1
.1.3.6.1.4.1.9.9.392.1.3
.1.3.6.1.4.1.9.9.392.1.3.1
.1.3.6.1.4.1.9.9.392.1.3.10
.1.3.6.1.4.1.9.9.392.1.3.11
.1.3.6.1.4.1.9.9.392.1.3.12
.1.3.6.1.4.1.9.9.392.1.3.2
.1.3.6.1.4.1.9.9.392.1.3.21
.1.3.6.1.4.1.9.9.392.1.3.21.1
OctetString
.1.3.6.1.4.1.9.9.392.1.3.21.1.1
.1.3.6.1.4.1.9.9.392.1.3.21.1.10
.1.3.6.1.4.1.9.9.392.1.3.21.1.11
ObjectIdentifier
.1.3.6.1.4.1.9.9.392.1.3.21.1.12
.1.3.6.1.4.1.9.9.392.1.3.21.1.13
.1.3.6.1.4.1.9.9.392.1.3.21.1.14
.1.3.6.1.4.1.9.9.392.1.3.21.1.15
SecondsUnsigned32
.1.3.6.1.4.1.9.9.392.1.3.21.1.16
.1.3.6.1.4.1.9.9.392.1.3.21.1.17
.1.3.6.1.4.1.9.9.392.1.3.21.1.18
.1.3.6.1.4.1.9.9.392.1.3.21.1.19
.1.3.6.1.4.1.9.9.392.1.3.21.1.2
.1.3.6.1.4.1.9.9.392.1.3.21.1.20
.1.3.6.1.4.1.9.9.392.1.3.21.1.21
.1.3.6.1.4.1.9.9.392.1.3.21.1.22
.1.3.6.1.4.1.9.9.392.1.3.21.1.23
.1.3.6.1.4.1.9.9.392.1.3.21.1.24
.1.3.6.1.4.1.9.9.392.1.3.21.1.25
.1.3.6.1.4.1.9.9.392.1.3.21.1.26
.1.3.6.1.4.1.9.9.392.1.3.21.1.27
.1.3.6.1.4.1.9.9.392.1.3.21.1.28
.1.3.6.1.4.1.9.9.392.1.3.21.1.29
.1.3.6.1.4.1.9.9.392.1.3.21.1.3
.1.3.6.1.4.1.9.9.392.1.3.21.1.30
.1.3.6.1.4.1.9.9.392.1.3.21.1.31
.1.3.6.1.4.1.9.9.392.1.3.21.1.32
.1.3.6.1.4.1.9.9.392.1.3.21.1.33
.1.3.6.1.4.1.9.9.392.1.3.21.1.34
.1.3.6.1.4.1.9.9.392.1.3.21.1.35
.1.3.6.1.4.1.9.9.392.1.3.21.1.36
.1.3.6.1.4.1.9.9.392.1.3.21.1.37
.1.3.6.1.4.1.9.9.392.1.3.21.1.4
.1.3.6.1.4.1.9.9.392.1.3.21.1.5
.1.3.6.1.4.1.9.9.392.1.3.21.1.6
.1.3.6.1.4.1.9.9.392.1.3.21.1.7
.1.3.6.1.4.1.9.9.392.1.3.21.1.8
.1.3.6.1.4.1.9.9.392.1.3.21.1.9
.1.3.6.1.4.1.9.9.392.1.3.22
.1.3.6.1.4.1.9.9.392.1.3.22.1
OctetString
.1.3.6.1.4.1.9.9.392.1.3.22.1.1
Integer32
.1.3.6.1.4.1.9.9.392.1.3.22.1.2
.1.3.6.1.4.1.9.9.392.1.3.22.1.3
.1.3.6.1.4.1.9.9.392.1.3.22.1.4
.1.3.6.1.4.1.9.9.392.1.3.22.1.5
.1.3.6.1.4.1.9.9.392.1.3.22.1.6
.1.3.6.1.4.1.9.9.392.1.3.22.1.7
.1.3.6.1.4.1.9.9.392.1.3.22.1.8
.1.3.6.1.4.1.9.9.392.1.3.23
.1.3.6.1.4.1.9.9.392.1.3.24
.1.3.6.1.4.1.9.9.392.1.3.25
.1.3.6.1.4.1.9.9.392.1.3.26
.1.3.6.1.4.1.9.9.392.1.3.27
.1.3.6.1.4.1.9.9.392.1.3.28
.1.3.6.1.4.1.9.9.392.1.3.29
.1.3.6.1.4.1.9.9.392.1.3.3
.1.3.6.1.4.1.9.9.392.1.3.30
.1.3.6.1.4.1.9.9.392.1.3.31
.1.3.6.1.4.1.9.9.392.1.3.32
.1.3.6.1.4.1.9.9.392.1.3.33
.1.3.6.1.4.1.9.9.392.1.3.34
.1.3.6.1.4.1.9.9.392.1.3.35
.1.3.6.1.4.1.9.9.392.1.3.36
.1.3.6.1.4.1.9.9.392.1.3.37
.1.3.6.1.4.1.9.9.392.1.3.38
.1.3.6.1.4.1.9.9.392.1.3.39
.1.3.6.1.4.1.9.9.392.1.3.4
.1.3.6.1.4.1.9.9.392.1.3.40
.1.3.6.1.4.1.9.9.392.1.3.41
.1.3.6.1.4.1.9.9.392.1.3.5
.1.3.6.1.4.1.9.9.392.1.3.6
.1.3.6.1.4.1.9.9.392.1.3.7
.1.3.6.1.4.1.9.9.392.1.3.8
.1.3.6.1.4.1.9.9.392.1.3.9
.1.3.6.1.4.1.9.9.392.1.4
.1.3.6.1.4.1.9.9.392.1.4.1
.1.3.6.1.4.1.9.9.392.1.4.1.1
SessionsUnsigned32
.1.3.6.1.4.1.9.9.392.1.4.1.2
.1.3.6.1.4.1.9.9.392.1.4.1.3
.1.3.6.1.4.1.9.9.392.1.4.1.4
.1.3.6.1.4.1.9.9.392.1.4.2
Unsigned32
.1.3.6.1.4.1.9.9.392.1.4.2.1
.1.3.6.1.4.1.9.9.392.1.4.3
.1.3.6.1.4.1.9.9.392.1.4.3.1
.1.3.6.1.4.1.9.9.392.1.4.3.1.1
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.1
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.10
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.11
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.2
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.3
Enumeration
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.4
Enumeration
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.5
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.6
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.7
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.8
.1.3.6.1.4.1.9.9.392.1.4.3.1.1.9
.1.3.6.1.4.1.9.9.392.1.4.3.2
.1.3.6.1.4.1.9.9.392.1.4.4
.1.3.6.1.4.1.9.9.392.1.4.4.1
.1.3.6.1.4.1.9.9.392.1.4.4.1.1
OctetString
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.1
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.2
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.3
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.4
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.5
.1.3.6.1.4.1.9.9.392.1.4.4.1.1.6
.1.3.6.1.4.1.9.9.392.1.5
.1.3.6.1.4.1.9.9.392.1.5.1
.1.3.6.1.4.1.9.9.392.1.5.1.1
.1.3.6.1.4.1.9.9.392.1.6
SessionsInteger32
.1.3.6.1.4.1.9.9.392.1.6.1
Unsigned32
.1.3.6.1.4.1.9.9.392.1.6.2
Octets Per SecondInteger32
.1.3.6.1.4.1.9.9.392.1.6.3
.1.3.6.1.4.1.9.9.392.1.7
.1.3.6.1.4.1.9.9.392.1.7.1
.1.3.6.1.4.1.9.9.392.1.7.2
.1.3.6.1.4.1.9.9.392.1.7.3
.1.3.6.1.4.1.9.9.392.2
.1.3.6.1.4.1.9.9.392.2.1
.1.3.6.1.4.1.9.9.392.2.2
Dependencies (6) 6 direct Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (9)
Unsigned32 range: 1..4294967295
Enumeration
other(1)
ipsec(2)
l2tp(3)
l2tpoveripsec(4)
pptp(5)
l2f(6)
ssl(7)
Enumeration
none(1)
other(2)
hmacMd5(3)
hmacSha(4)
Enumeration
none(1)
other(2)
lzs(3)
Enumeration
none(1)
des(2)
des3(3)
rc4(4)
rc5(5)
idea(6)
cast(7)
blowfish(8)
aes(9)
Integer32 range: 1..2147483647
Enumeration
initializing(1)
established(2)
terminating(3)
Enumeration
none(1)
other(2)
radius(3)
tacacsplus(4)
kerberos(5)
local(6)
ldap(7)
ntlm(8)
sdi(9)
Enumeration
none(1)
other(2)
radius(3)
tacacsplus(4)
kerberos(5)
local(6)
ldap(7)
Conformance Groups (11)
This group consists of the MIB objects pertaining
to Remote Access Service capacity parameters defined
in the Cisco Remote Access MIB.
.1.3.6.1.4.1.9.9.392.2.2.1
This group consists of the MIB objects pertaining
to Remote Access Service resource usage parameters
defined in the Cisco Remote Access MIB.
.1.3.6.1.4.1.9.9.392.2.2.2
This group consists of the MIB objects pertaining
to the Cisco Remote Access MIB Activity group.

Following are definitions of some terms used in
this compliance group:

User:
A remote access user.

Group:
A collection of remote access users grouped
and managed together as a single entity for
administrative convenience.

ISP:
Internet Service Provider.

Crypto Accelerator
'Crypto Accelerator' denotes a device which
the managed entity uses to offload some or all
computations pertaining to cryptographic
operations.

Session
A connection terminating on the managed device
which has been established to provide remote access
connectivity to a user.
.1.3.6.1.4.1.9.9.392.2.2.3
This group consists of the MIB objects pertaining
to activity of user groups.
.1.3.6.1.4.1.9.9.392.2.2.4
This group categorizes objects pertaining to
failures in the Remote Access Service which are
essential for successful monitoring of the
service.
.1.3.6.1.4.1.9.9.392.2.2.5
This group categorizes optional objects pertaining
to failures in the Remote Access Service.
.1.3.6.1.4.1.9.9.392.2.2.6
This group categorizes objects pertaining to the
monitoring state of security in the Remote Access
Service.
.1.3.6.1.4.1.9.9.392.2.2.7
This group categorizes objects which are used to
establish baseline values of metrics instrumenting
the Remote Access Service.
.1.3.6.1.4.1.9.9.392.2.2.8
This group of objects controls the sending of
notifications defined in this MIB module.
.1.3.6.1.4.1.9.9.392.2.2.9
This group contains the notifications for the
Remote Access MIB.
.1.3.6.1.4.1.9.9.392.2.2.10
This group contains activity information related
to sessions.
.1.3.6.1.4.1.9.9.392.2.2.11
Compliance Statements (2)

OID .1.3.6.1.4.1.9.9.392.2.1.1
The compliance statement for SNMP entities
the Cisco Remote Access Monitoring MIB.
Required groups
mandatory ciscoRasCapacityGroup
mandatory ciscoRasResourceUsageGroup
mandatory ciscoRasActivityGroup
mandatory ciscoRasMandatoryFailureGroup
optional ciscoRasGrpActivityGroup This group is optional.
optional ciscoRasOptionalFailureGroup This group is optional.
optional ciscoRasSecurityGroup This group is optional.
optional ciscoRasThresholdsGroup This group is optional.
optional ciscoRasNotificationsGroup This group is mandatory if and only if
the SNMP agent on the managed entity
implements the group
'ciscoRasThresholdsGroup'.
optional ciscoRasNotificationCntlGroup This group is mandatory if and only if
the SNMP agent on the managed entity
implements the group
'ciscoRasNotificationsGroup'.
Object refinements
ObjectAccessSyntaxDescription
crasSessionState readonly
Write access is not required.
crasCntlTooManySessions readonly
Write access is not required.
crasCntlTooManyFailedAuths readonly
Write access is not required.
crasCntlTooHighThroughput readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.392.2.1.2
The compliance statement for SNMP entities
the Cisco Remote Access Monitoring MIB.
Required groups
mandatory ciscoRasCapacityGroup
mandatory ciscoRasResourceUsageGroup
mandatory ciscoRasActivityGroup
mandatory ciscoRasActivityGroupRev1
mandatory ciscoRasMandatoryFailureGroup
optional ciscoRasGrpActivityGroup This group is optional.
optional ciscoRasOptionalFailureGroup This group is optional.
optional ciscoRasSecurityGroup This group is optional.
optional ciscoRasThresholdsGroup This group is optional.
optional ciscoRasNotificationsGroup This group is mandatory if and only if
the SNMP agent on the managed entity
implements the group
'ciscoRasThresholdsGroup'.
optional ciscoRasNotificationCntlGroup This group is mandatory if and only if
the SNMP agent on the managed entity
implements the group
'ciscoRasNotificationsGroup'.
Object refinements
ObjectAccessSyntaxDescription
crasSessionState readonly
Write access is not required.
crasCntlTooManySessions readonly
Write access is not required.
crasCntlTooManyFailedAuths readonly
Write access is not required.
crasCntlTooHighThroughput readonly
Write access is not required.
Notifications / Traps (3)
NameOIDDescription
.1.3.6.1.4.1.9.9.392.0.1
This notification is generated when the managed entity
detects that the number of sessions established exceeds
the set threshold crasThrMaxSessions.

Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold.
.1.3.6.1.4.1.9.9.392.0.2
This notification is generated when the managed entity
detects that the number of login attempts (over all
users) exceeds the set threshold for throughput
(crasThrMaxFailedAuths).

Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold.
.1.3.6.1.4.1.9.9.392.0.3
This notification is generated when the managed entity
detects that the current throughput of the device exceeds
the set threshold for throughput (crasThrMaxThroughput).

Once the notification has been issued, further
notiifcations are suppressed till the value returns
below the specified threshold.