CISCO-THREAT-MITIGATION-SERVICE-MIB
This MIB provides management information about the Threat
Mitigation Service(TMS) entity named 'Consumer'. TMS is part
of Cisco's Network Infection Containment (NIC) security
framework. The MIB is expected to be implemented on all
entities that act as TMS consumers.
The NIC framework deals with threat mitigation. The NIC
architecture consists of controllers and one or more consumers
registered with these controllers. The controller is
responsible for detecting threats and conveying the
information about the same to one or more consumers that
could be the potential targets of the detected threat.
Upon receiving the information about the threat from
the controller, the consumer responds with appropriate
mitigation actions according to the policies configured
on it and as indicated in the threat notification message.
TMS protocol is used for distribution and management of threat
related information from the controller to consumers.
TMS runs over TIDP layer which is used as distribution layer.
TIDP layer provides a secured connection between the
controller and the consumers. TIDP also provides group
management services.
Each consumer needs to participate in a TIDP group in order
to receive threat notification message from controller
in that TIDP group. To participate in a TIDP group consumer
needs to register with the controller of that group,
from which it intends to receive threat messages.
When the controller needs to distribute the information
about a threat to one or more target TIDP groups or to
one particular consumer in a TIDP group, it delivers
the information to the respective entities through
TMS protocol messages. Upon receiving the threat
notification message, consumer determines the appropriate
mitigation action to be executed, with the corresponding
action parameters, based on the configuration and information
available in threat message. The respective action is then
executed.
The state of threat is set according to the result of
enforcement action, e.g., upon successful application of
enforcement action it is marked as Active. The consumer then
responds to the controller with the results of the
mitigation action carried out for the threat.
GLOSSARY
--------
Active Threat : A threat is active on a consumer if mitigation
action corresponding to the threat has been enforced
successfully.
Inactive Threat : A threat is inactive on a consumer if
mitigation action corresponding to the threat has been
undone successfully.
ACL : Access Control List is the list of rules which are
used to filter or classify packets based on protocol
parameters.
ACL drop : ACL drop action refers to the drop action taken
on packets matching any of the filters in the access list.
DSCP : Differentiated Service Code Point is same as 'Type of
Service' field in IP header, used in reference to quality
of service.
FPM : Flexible Packet Matching is a framework which provides
packet filtering based on pattern at any offset in the packet.
FPM drop : FPM drop action refers to the drop action taken on
packet filtered by FPM.
TCDF : Traffic Classification Definition File gives
the XML description of traffic class.
TIDP : Threat Information Distribution Protocol is a
distribution protocol, which provides a secured connectivity
between network devices. It also provides a group management
function.
TIDP group : A closed group of network devices which share
authentication and encryption keys for message exchange.
TMS : TMS protocol provides information about threats and the
mitigation action required for the threats in a TIDP network.
TIDP network : TIDP network comprises of one or more
TIDP groups.
- Source file
CISCO-THREAT-MITIGATION-SERVICE-MIB- Last revised
- Identity
ciscoThreatMitigationServiceMIB- Base OID
1.3.6.1.4.1.9.9.603
Imported Objects
| CISCO-SMI | ciscoMgmt |
| IF-MIB | ifIndex |
| INET-ADDRESS-MIB | InetAddress InetAddressType |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | DateAndTime RowStatus StorageType TEXTUAL-CONVENTION (no object page) TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-THREAT-MITIGATION-SERVICE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-THREAT-MITIGATION-SERVICE-MIB::ciscoThreatMitigationServiceMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-THREAT-MITIGATION-SERVICE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-THREAT-MITIGATION-SERVICE-MIB::ciscoThreatMitigationServiceMIB'
Objects (50)
Showing 50 of 50 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.603 |
||
.1.3.6.1.4.1.9.9.603.0 |
||
.1.3.6.1.4.1.9.9.603.1 |
||
.1.3.6.1.4.1.9.9.603.1.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.1 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.2 |
|
.1.3.6.1.4.1.9.9.603.1.1.3 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.4 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.5 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.6 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.1.7 |
|
.1.3.6.1.4.1.9.9.603.1.1.8 |
||
.1.3.6.1.4.1.9.9.603.1.2 |
||
.1.3.6.1.4.1.9.9.603.1.2.1 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.2.1.1.1 |
|
.1.3.6.1.4.1.9.9.603.1.2.1.1.2 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1.4 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1.5 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1.6 |
||
.1.3.6.1.4.1.9.9.603.1.2.1.1.7 |
||
.1.3.6.1.4.1.9.9.603.1.3 |
||
.1.3.6.1.4.1.9.9.603.1.3.1 |
||
.1.3.6.1.4.1.9.9.603.1.3.1.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.1 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.2 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.3 |
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.4 |
||
.1.3.6.1.4.1.9.9.603.1.3.1.1.5 |
||
.1.3.6.1.4.1.9.9.603.1.3.1.1.6 |
||
.1.3.6.1.4.1.9.9.603.1.3.1.1.7 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.8 |
|
.1.3.6.1.4.1.9.9.603.1.3.1.1.9 |
||
.1.3.6.1.4.1.9.9.603.1.3.2 |
||
.1.3.6.1.4.1.9.9.603.1.3.2.1 |
||
.1.3.6.1.4.1.9.9.603.1.3.2.1.1 |
||
.1.3.6.1.4.1.9.9.603.1.3.2.1.2 |
||
.1.3.6.1.4.1.9.9.603.1.3.2.1.3 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.603.1.3.2.1.4 |
|
.1.3.6.1.4.1.9.9.603.1.3.2.1.5 |
||
.1.3.6.1.4.1.9.9.603.1.3.2.1.6 |
||
.1.3.6.1.4.1.9.9.603.1.3.3 |
||
.1.3.6.1.4.1.9.9.603.1.3.3.1 |
||
.1.3.6.1.4.1.9.9.603.1.3.3.1.1 |
||
.1.3.6.1.4.1.9.9.603.1.4 |
||
.1.3.6.1.4.1.9.9.603.1.4.1 |
||
.1.3.6.1.4.1.9.9.603.2 |
||
.1.3.6.1.4.1.9.9.603.2.1 |
||
.1.3.6.1.4.1.9.9.603.2.2 |
Dependencies (9) 7 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- INET-ADDRESS-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-THREAT-MITIGATION-SERVICE-MIBciscoselected
Type Definitions (6)
| Enumeration |
noParams(1)cir(2)bir(3)be(4)nexthop(5)dscpVal(6)vlanId(7) |
|
| Enumeration |
unsigned(1)networkAddress(2)string(3) |
|
| Enumeration |
ignore(1)aclDrop(2)fpmDrop(3)redirect(4)police(5)setIPDscp(6)localException(7)quarantine(8) |
|
| Enumeration |
notRegistered(1)registrationRequestSent(2)registered(3)registrationFailed(4) |
|
| Enumeration |
disabled(1)enabled(2) |
|
| Enumeration |
unknown(1)active(2)inactive(3)created(4)pending(5)activationFailed(6)inactivationFailed(7)deleted(8) |
Conformance Groups (5)
|
ciTmsConsumerDeviceId ciTmsGroupsMaxEntries ciTmsThreatsMaxEntries ciTmsThreatActionMaxEntries ciTmsInterfaceMaxEntries ciTmsConsumerState ciTmsConsStateChangeNotifEnable ciTmsGroupConsumerRegStatus ciTmsGroupNotifEnable ciTmsGroupStorageType ciTmsGroupRowStatus
This collection of objects represent the information about
the TIDP groups, the controller(s) in a TIDP group and the status of a consumer's registration with the controller in the TIDP group. |
.1.3.6.1.4.1.9.9.603.2.2.1
|
|
|
ciTmsActiveThreats ciTmsInActiveThreats ciTmsThreatVer ciTmsThreatStatus ciTmsThreatClass ciTmsThreatName ciTmsThreatActiveTimeDuration ciTmsThreatPriority ciTmsThreatTcdf
This collection of objects represents the information
about the threats detected, as being targeted towards a consumer, by a controller in a TIDP group. |
.1.3.6.1.4.1.9.9.603.2.2.2
|
|
|
ciTmsThreatActionParamType ciTmsThreatActionParamLength ciTmsThreatActionParamValue ciTmsThreatActionFailReason
This collection of objects represent the information about
the mitigation actions taken for the respective threats by the consumer. |
.1.3.6.1.4.1.9.9.603.2.2.3
|
|
|
This collection of objects represent the information about
the interfaces on which the mitigation action for a particular threat is applied. |
.1.3.6.1.4.1.9.9.603.2.2.4
|
|
|
ciscoTmsConsStateChange ciscoTmsControllerUnreachable ciscoTmsThreatStatusChange ciscoTmsMitigationActionFailed
This collection of objects represent the notifications
generated by the consumer. |
.1.3.6.1.4.1.9.9.603.2.2.5
|
Compliance Statements (1)
OID
.1.3.6.1.4.1.9.9.603.2.1.1The compliance statement for the SNMP entities that
implement the ciscoThreatMitigationServiceMIB module.
implement the ciscoThreatMitigationServiceMIB module.
Required groups
| mandatory | ciscoTmsConsumerGroup | |
| mandatory | ciscoTmsThreatGroup | |
| mandatory | ciscoTmsThreatActionGroup | |
| mandatory | ciscoTmsThreatInterfaceGroup | |
| mandatory | ciscoTmsNotificationGroup |
Notifications / Traps (4)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.603.0.1 |
This notification is generated to indicate the current
operational state of the consumer, when the consumer undergoes a state change. |
|
.1.3.6.1.4.1.9.9.603.0.2 |
This notification is generated by the consumer when the
controller it has registered with becomes unreachable. This notification will be generated only when notification generation is enabled for the corresponding TIDP group through ciTmsGroupNotifEnable. |
|
.1.3.6.1.4.1.9.9.603.0.3 |
This notification is generated by the consumer when
consumer acts upon a particular threat and changes the state of the threat. This notification will be generated only when notification generation is enabled for the corresponding TIDP group through ciTmsGroupNotifEnable. |
|
.1.3.6.1.4.1.9.9.603.0.4 |
This notification is generated by the consumer when the
mitigation action enforced for a particular threat fails. The notification contains the information about the failed mitigation action and the reason for the failure indicated by ciTmsThreatActionFailReason. This notification will be generated only when notification generation is enabled for the corresponding TIDP group through ciTmsGroupNotifEnable. |