CISCO-TAP-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
4
Rows
4
Columns
46
.1.3.6.1.4.1.9.9.252.1.1.2 · 1 row entry · 13 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cTapMediationTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TAP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TAP-MIB::cTapMediationTable'
This table lists the Mediation Devices with which the
intercepting device communicates. These may be on the same or
different Mediation Devices.
          
This table is written by the Mediation Device, and is always
volatile. This is because intercepts may disappear during a
restart of the intercepting equipment.
cTapMediationEntry row .1.3.6.1.4.1.9.9.252.1.1.2.1
The entry describes a single session maintained with an
application on a Mediation Device.
Column Syntax OID
cTapMediationContentId is a session identifier, from the
intercept application's perspective, and a content identifier
from the Mediation Device's perspective. The Mediation Device
is responsible for making sure these a…
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.252.1.1.2.1.1
The type of cTapMediationDestAddress.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.252.1.1.2.1.2
The IP Address of the Mediation Device's network interface
to which to direct intercepted traffic.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.252.1.1.2.1.3
The port number on the Mediation Device's network interface
to which to direct intercepted traffic.
INET-ADDRESS-MIBInetPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.1.2.1.4
The interface on the intercepting device from which to
transmit intercepted data. If zero, any interface may be used
according to normal IP practice.
IF-MIBInterfaceIndexOrZeror/w
Type Constraints:
range: 0..2147483647
Description:
This textual convention is an extension of the
InterfaceIndex convention. The latter defines a greater
than zero value used to identify an interface or interface
sub-layer in the managed system. This extension permits…
.1.3.6.1.4.1.9.9.252.1.1.2.1.5
The port number on the intercepting device to which the
Mediation Devices directs RTCP Receiver Reports and Nacks.
This object is only relevant when the value of
cTapMediationTransport is 'rtpNack'.

This …
INET-ADDRESS-MIBInetPortNumber
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.1.2.1.6
The Differentiated Services Code Point the intercepting
device applies to the IP packets encapsulating the
intercepted traffic.
CISCO-QOS-PIB-MIBDscpr/w
Type Constraints:
range: 0..63
.1.3.6.1.4.1.9.9.252.1.1.2.1.7
If RTP with Ack/Nack resilience is selected as a transport,
the mediation process requires an RTP payload type for data
transmissions, and a second RTP payload type for
retransmissions. This is the RTP payload type for…
Integer32r/w
Constraints:
range: 0-127
.1.3.6.1.4.1.9.9.252.1.1.2.1.8
If RTP with Ack/Nack resilience is selected as a transport,
the mediation process requires an RTP payload type for data
transmissions, and a second RTP payload type for
retransmissions. This is the RTP payload type for…
Integer32r/w
Constraints:
range: 0-127
.1.3.6.1.4.1.9.9.252.1.1.2.1.9
The time at which this row and all related Stream Table rows
should be automatically removed, and the intercept function
cease. Since the initiating network manager may be the only
device able to manage a specific inter…
SNMPv2-TCDateAndTimer/w
Type Constraints:
range: 8
range: 11
Description:
A date-time specification.

field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month …
.1.3.6.1.4.1.9.9.252.1.1.2.1.10
The protocol used in transferring intercepted data to the
Mediation Device. The following protocols may be supported:
udp: PacketCable udp format
rtpNack: RTP with Nack resilience
tc…
Enumerationr/w
Enumerated Values:
1udp
2rtpNack
3tcp
4sctp
.1.3.6.1.4.1.9.9.252.1.1.2.1.11
This variable controls the generation of any notifications or
informs by the MIB agent for this table entry.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.252.1.1.2.1.12
The status of this conceptual row. This object is used to
manage creation, modification and deletion of rows in this
table.

cTapMediationTimeout may be modified at any time (even while the
row is active).…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.252.1.1.2.1.13
.1.3.6.1.4.1.9.9.252.1.2.2 · 1 row entry · 19 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cTapStreamIpTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TAP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TAP-MIB::cTapStreamIpTable'
The Intercept Stream IP Table lists the IPv4 and IPv6 streams
to be intercepted.  The same data stream may be required by
multiple taps, and one might assume that often the intercepted
stream is a small subset of the traffic that could be
intercepted.
          
This essentially provides options for packet selection, only
some of which might be used. For example, if all traffic to or
from a given interface is to be intercepted, one would
configure an entry which lists the interface, and wild-card
everything else.  If all traffic to or from a given IP Address
is to be intercepted, one would configure two such entries
listing the IP Address as source and destination respectively,
and wild-card everything else.  If a particular voice on a
teleconference is to be intercepted, on the other hand, one
would extract the multicast (destination) IP address, the
source IP Address, the protocol (UDP), and the source and
destination ports from the call control exchange and list all
necessary information.
          
The first index indicates which Mediation Device the
intercepted traffic will be diverted to. The second index
permits multiple classifiers to be used together, such as
having an IP address as source or destination.
cTapStreamIpEntry row .1.3.6.1.4.1.9.9.252.1.2.2.1
A stream entry indicates a single data stream to be
intercepted to a Mediation Device. Many selected data
streams may go to the same application interface, and many
application interfaces are supported.
Column Syntax OID
The index of the stream itself.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.252.1.2.2.1.1
The ifIndex value of the interface over which traffic to be
intercepted is received or transmitted. The interface may be
physical or virtual. If this is the only parameter specified,
and it is other than -1 or 0, all tr…
Integer32r/w
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.252.1.2.2.1.2
The type of address, used in packet selection.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.252.1.2.2.1.3
The Destination address or prefix used in packet selection.
This address will be of the type specified in
cTapStreamIpAddrType.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.252.1.2.2.1.4
The length of the Destination Prefix. A value of zero causes
all addresses to match. This prefix length will be consistent
with the type specified in cTapStreamIpAddrType.
INET-ADDRESS-MIBInetAddressPrefixLengthr/w
Type Constraints:
range: 0..2040
.1.3.6.1.4.1.9.9.252.1.2.2.1.5
The Source Address used in packet selection. This address will
be of the type specified in cTapStreamIpAddrType.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.252.1.2.2.1.6
The length of the Source Prefix. A value of zero causes all
addresses to match. This prefix length will be consistent with
the type specified in cTapStreamIpAddrType.
INET-ADDRESS-MIBInetAddressPrefixLengthr/w
Type Constraints:
range: 0..2040
.1.3.6.1.4.1.9.9.252.1.2.2.1.7
The value of the TOS byte, when masked with
cTapStreamIpTosByteMask, of traffic to be intercepted.
If cTapStreamIpTosByte & (~cTapStreamIpTosByteMask) != 0,
configuration is rejected.
Integer32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.252.1.2.2.1.8
The value of the TOS byte in an IPv4 or IPv6 header is ANDed
with cTapStreamIpTosByteMask and compared with
cTapStreamIpTosByte.

If the values are equal, the comparison is equal. If the mask
is zero and t…
Integer32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.252.1.2.2.1.9
The flow identifier in an IPv6 header. -1 indicates that the
Flow Id is unused.
Integer32r/w
Constraints:
range: -1-1048575
.1.3.6.1.4.1.9.9.252.1.2.2.1.10
The IP protocol to match against the IPv4 protocol number or
the IPv6 Next- Header number in the packet. -1 means 'any IP
protocol'.
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.9.9.252.1.2.2.1.11
The minimum value that the layer-4 destination port number in
the packet must have in order to match. This value must be
equal to or less than the value specified for this entry in
cTapStreamIpDestL4PortMax.
INET-ADDRESS-MIBInetPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.2.2.1.12
The maximum value that the layer-4 destination port number in
the packet must have in order to match this classifier entry.
This value must be equal to or greater than the value specified
for this entry in cTapStreamIpD…
INET-ADDRESS-MIBInetPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.2.2.1.13
The minimum value that the layer-4 destination port number in
the packet must have in order to match. This value must be
equal to or less than the value specified for this entry in
cTapStreamIpSourceL4PortMax.
INET-ADDRESS-MIBInetPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.2.2.1.14
The maximum value that the layer-4 destination port number in
the packet must have in order to match this classifier entry.
This value must be equal to or greater than the value specified
for this entry in cTapStreamIpS…
INET-ADDRESS-MIBInetPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.252.1.2.2.1.15
If 'true', the tap should intercept matching traffic.
If 'false', this entry is used to pre-screen packets for
intercept.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.252.1.2.2.1.16
The number of packets matching this data stream specification
that have been intercepted.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.252.1.2.2.1.17
The number of packets matching this data stream specification
that, having been intercepted, were dropped in the lawful
intercept process.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.252.1.2.2.1.18
The status of this conceptual row. This object manages
creation, modification, and deletion of rows in this table.
cTapStreamIpInterceptEnable may be modified any time even the
value of this entry rowStatus object is 'a…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.252.1.2.2.1.19
.1.3.6.1.4.1.9.9.252.1.2.3 · 1 row entry · 12 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cTapStream802Table
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TAP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TAP-MIB::cTapStream802Table'
The Intercept Stream 802 Table lists the IEEE 802 data streams
to be intercepted.  The same data stream may be required by
multiple taps, and one might assume that often the intercepted
stream is a small subset of the traffic that could be
intercepted.
          
This essentially provides options for packet selection, only
some of which might be used. For example, if all traffic to or
from a given interface is to be intercepted, one would
configure an entry which lists the interface, and wild-card
everything else.  If all traffic to or from a given MAC Address
is to be intercepted, one would configure two such entries
listing the MAC Address as source and destination respectively,
and wild-card everything else.
          
The first index indicates which Mediation Device the
intercepted traffic will be diverted to. The second index
permits multiple classifiers to be used together, such as
having a MAC address as source or destination.
cTapStream802Entry row .1.3.6.1.4.1.9.9.252.1.2.3.1
A stream entry indicates a single data stream to be
intercepted to a Mediation Device. Many selected data
streams may go to the same application interface, and many
application interfaces are supported.
Column Syntax OID
The index of the stream itself.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.252.1.2.3.1.1
This object displays what attributes must be tested to
identify traffic which requires interception. The packet
matches if all flagged fields match.

interface: indicates that traffic on the state…
Bitsr/w
Enumerated Values:
0interface
1dstMacAddress
2srcMacAddress
3ethernetPid
4dstLlcSap
5srcLlcSap
.1.3.6.1.4.1.9.9.252.1.2.3.1.2
The ifIndex value of the interface over which traffic to be
intercepted is received or transmitted. The interface may be
physical or virtual. If this is the only parameter specified,
and it is other than -1 or 0, all tr…
Integer32r/w
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.252.1.2.3.1.3
The Destination address used in packet selection.
SNMPv2-TCMacAddressr/w
Type Constraints:
range: 6
Description:
Represents an 802 MAC address represented in the
`canonical' order defined by IEEE 802.1a, i.e., as if it
were transmitted least significant bit first, even though
802.5 (in contrast to other 802.x protocols) requires M…
.1.3.6.1.4.1.9.9.252.1.2.3.1.4
The Source Address used in packet selection.
SNMPv2-TCMacAddressr/w
Type Constraints:
range: 6
Description:
Represents an 802 MAC address represented in the
`canonical' order defined by IEEE 802.1a, i.e., as if it
were transmitted least significant bit first, even though
802.5 (in contrast to other 802.x protocols) requires M…
.1.3.6.1.4.1.9.9.252.1.2.3.1.5
The value of the Ethernet Protocol Identifier, which may be
found on Ethernet traffic or IEEE 802.2 SNAP traffic.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.252.1.2.3.1.6
The value of the IEEE 802.2 Destination SAP.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.252.1.2.3.1.7
The value of the IEEE 802.2 Source SAP.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.252.1.2.3.1.8
If 'true', the tap enables interception of matching traffic.
If cTapStreamCapabilities flag tapEnable is zero, this may not
be set to 'false'.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.252.1.2.3.1.9
The number of packets matching this data stream specification
that have been intercepted.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.252.1.2.3.1.10
The number of packets matching this data stream specification
that, having been intercepted, were dropped in the lawful
intercept process.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.252.1.2.3.1.11
The status of this conceptual row. This object manages
creation, modification, and deletion of rows in this table.
cTapStream802InterceptEnable can be modified any time even the
value of this entry rowStatus object is a…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.252.1.2.3.1.12
.1.3.6.1.4.1.9.9.252.1.3.1 · 1 row entry · 2 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cTapDebugTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TAP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TAP-MIB::cTapDebugTable'
A table that contains Lawful Intercept debug information
available on this device. This table is used to map an error
code to a text message for further information.
cTapDebugEntry row .1.3.6.1.4.1.9.9.252.1.3.1.1
A list of the debug messages.
Indexes
Column Syntax OID
Indicates an error code.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.252.1.3.1.1.1
A text string contains the description of an error code.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.252.1.3.1.1.2