CISCO-TRUSTSEC-INTERFACE-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
55
.1.3.6.1.4.1.9.9.740.1.1.1 · 1 row entry · 4 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfConfigTable'
A list of the TrustSec capable interfaces.
ctsiIfConfigEntry row .1.3.6.1.4.1.9.9.740.1.1.1.1
An entry contains the configuration information for a
particular TrustSec interface.
Indexes
Column Syntax OID
This object indicates the supported TrustSec mode on
this interface.
Bits
Enumerated Values:
0dot1x
1manual
2l3Forward
.1.3.6.1.4.1.9.9.740.1.1.1.1.1
This object indicates the TrustSec mode currently configured
on the interface. Each mode may have a corresponding
entry in its corresponding configuration table.

unknown - The configured TrustSec m…
Enumeration
Enumerated Values:
1unknown
2none
3dot1x
4manual
5l3Forward
.1.3.6.1.4.1.9.9.740.1.1.1.1.2
This object allows user to clear the cache for the specific
TrustSec interface by setting the value to 'true'.
Setting the value to 'false' has no effect.

When read, this object always returns 'false'.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.1.1.1.3
This object allows user to re-generate the SAP key for the
specific TrustSec interface by setting the value to 'true'.
Setting the value to 'false' has no effect.

When read, this object always returns 'fa…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.1.1.1.4
.1.3.6.1.4.1.9.9.740.1.2.1 · 1 row entry · 8 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfDot1xTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfDot1xTable'
A list of the interfaces which have TrustSec dot1x mode
configuration information.
ctsiIfDot1xEntry row .1.3.6.1.4.1.9.9.740.1.2.1.1
An entry containing the TrustSec dot1x configuration
for a particular interface.

An entry can be created or deleted by using
ctsiIfDot1xRowStatus.

An entry can only be created if the value of c…
Indexes
Column Syntax OID
This object specifies whether the SGT propagation is
enabled on this interface.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.2.1.1.1
This object specifies the re-authentication interval
applied to this interface when it is not provided from
the ACS.
secondsSNMPv2-SMIInteger32r/w
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.2
This object specifies the advertised modes for the SAP
negotiation on this interface. Modes are executed in
the order as specified in the mode list.

Mode which is at the beginning of the method list will…
CtsSapNegModeListr/w .1.3.6.1.4.1.9.9.740.1.2.1.1.3
This object indicates the re-authentication interval which
is downloaded from ACS.

A value of zero indicates no re-authentication interval is
downloaded from ACS.

A value of -1 indicates th…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.4
This object indicates the operational re-authentication
interval of the interface.

A value of zero indicates that dot1x re-authentication is
disabled on this interface.

A value of -1 indica…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.5
This object indicates the leftover time of the current
authentication session.

A value of zero indicates the re-authentication is in
progress.

A value of -1 indicates that this object is no…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.6
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
Description:
Describes the memory realization of a conceptual row. A
row which is volatile(2) is lost upon reboot. A row which
is either nonVolatile(3), permanent(4) or readOnly(5), is
backed up by stable storage. A row which is …
.1.3.6.1.4.1.9.9.740.1.2.1.1.7
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.740.1.2.1.1.8
.1.3.6.1.4.1.9.9.740.1.3.1 · 1 row entry · 8 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfManualTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfManualTable'
A list of the interfaces which have TrustSec manual mode
configuration information.
ctsiIfManualEntry row .1.3.6.1.4.1.9.9.740.1.3.1.1
An entry containing the TrustSec manual configuration
information for a particular interface.

An entry can be created or deleted by using
ctsiIfManualRowStatus.

An entry can only be created if …
Indexes
Column Syntax OID
This object specifies the peer's device identity which is
used to obtain the desired policy for authorization request.

Setting a none-zero value on this object is not allowed if
the value of ctsiIfManualS…
SNMP-FRAMEWORK-MIBSnmpAdminStringr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.740.1.3.1.1.1
This object specifies the statically configured SGT for
tagging the ingress traffic from the peer.

Setting a none-zero value on this object is not allowed if
the value of ctsiIfManualDynamicPeerId is not …
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTagr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.3.1.1.2
This object specifies the peer's SGT assignment trust
state.

This object only can be set when ctsiIfManualStaticSgt
is none-zero.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.3.1.1.3
This object specifies whether the SGT propagation is
enabled on this interface.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.3.1.1.4
This object specifies the PMK used by SAP.

A zero length string for this object indicates the SAP
negotiation is disabled on this interface.
OctetStringr/w
Constraints:
range: 0-0
range: 32-32
.1.3.6.1.4.1.9.9.740.1.3.1.1.5
This object specified the advertised modes for the SAP
negotiation on this interface. Modes are executed in
the order as specified in the mode list.

Mode which is at the beginning of the mode list will b…
CtsSapNegModeListr/w .1.3.6.1.4.1.9.9.740.1.3.1.1.6
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
Description:
Describes the memory realization of a conceptual row. A
row which is volatile(2) is lost upon reboot. A row which
is either nonVolatile(3), permanent(4) or readOnly(5), is
backed up by stable storage. A row which is …
.1.3.6.1.4.1.9.9.740.1.3.1.1.7
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.740.1.3.1.1.8
.1.3.6.1.4.1.9.9.740.1.4.1 · 1 row entry · 3 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfL3ForwardTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfL3ForwardTable'
A list of the interfaces which have TrustSec L3 forwarding
configuration information.
ctsiIfL3ForwardEntry row .1.3.6.1.4.1.9.9.740.1.4.1.1
An entry containing the TrustSec L3 forwarding configuration
information for a particular interface.

An entry can be created or deleted by using
ctsiIfL3ForwardRowStatus.

An entry can only be c…
Indexes
Column Syntax OID
This object specifies the type of L3 forwarding for
the interface.

l3Ipv4Forward - TrustSec L3 IPv4 forwarding.

l3Ipv6Forward - TrustSec L3 IPv6 forwarding.

l3IpForward - …
Enumerationr/w
Enumerated Values:
1l3Ipv4Forward
2l3Ipv6Forward
3l3IpForward
.1.3.6.1.4.1.9.9.740.1.4.1.1.1
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
Description:
Describes the memory realization of a conceptual row. A
row which is volatile(2) is lost upon reboot. A row which
is either nonVolatile(3), permanent(4) or readOnly(5), is
backed up by stable storage. A row which is …
.1.3.6.1.4.1.9.9.740.1.4.1.1.2
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.740.1.4.1.1.3
.1.3.6.1.4.1.9.9.740.1.5.1 · 1 row entry · 12 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfStatusTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfStatusTable'
A list of TrustSec enabled interfaces.
ctsiIfStatusEntry row .1.3.6.1.4.1.9.9.740.1.5.1.1
An entry contains the information of the specific TrustSec
interface.

A entry is created by system when TrustSec is enabled for
an interface. An entry is deleted by system if TrustSec
is disabled for an in…
Indexes
Column Syntax OID
This object indicates the current IFC state of this
interface.
CtsiInterfaceControllerState
Type Values:
1unknown
2initialize
3authenticating
4authorizing
5sapNegotiating
6open
7held
8disconnecting
9invalid
10licenseError
.1.3.6.1.4.1.9.9.740.1.5.1.1.1
This object indicates the current TrustSec authentication
status of this interface.

unknown - status not covered by any of
the follow enumerations.

succeeded …
Enumeration
Enumerated Values:
1unknown
2succeeded
3rejected
4logOff
5noRespond
6notApplicable
7incomplete
8failed
.1.3.6.1.4.1.9.9.740.1.5.1.1.2
This object indicates the device identity or symbolic
group name of the remote peer.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.740.1.5.1.1.3
This object indicates the advertised capabilities of the
remote peer associated with this interface.
Bits
Enumerated Values:
0sap
.1.3.6.1.4.1.9.9.740.1.5.1.1.4
This object indicates the current TrustSec authorization
status of the interface.

unknown - status not covered by any of
the follow enumerations.

i…
Enumeration
Enumerated Values:
1unknown
2inProgress
3succeeded
4failed
5fallBackPolicy
6incomplete
7peerSucceeded
8rbaclSucceeded
9policySucceeded
.1.3.6.1.4.1.9.9.740.1.5.1.1.5
This object indicates the SGT value of the remote peer.
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.5.1.1.6
This object indicates whether the SGT of the remote peer
is trusted.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.740.1.5.1.1.7
This object indicates the SAP negotiation status on
this interface.

notApplicable - SAP disabled on local or remote peer
is not SAP capable.

unknown - s…
Enumeration
Enumerated Values:
1notApplicable
2unknown
3inProgress
4succeeded
5failed
6licenseError
.1.3.6.1.4.1.9.9.740.1.5.1.1.8
This object indicates the operational SAP negotiation
mode list on this interface.
CtsSapNegModeList .1.3.6.1.4.1.9.9.740.1.5.1.1.9
This object indicates the time when the current cached data
applied on the interface will be expired.

A value of zero indicates that the cached data will never be
expired.
SNMPv2-TCDateAndTime
Type Constraints:
range: 8
range: 11
Description:
A date-time specification.

field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month …
.1.3.6.1.4.1.9.9.740.1.5.1.1.10
This object indicates the source of cached data applied to the
interface.
CtsiCasheDataSource
Type Values:
1unknown
2acs
3dram
4nvram
5all
.1.3.6.1.4.1.9.9.740.1.5.1.1.11
This object indicates the CTS Critical-Auth status
of interface.

disable - link is not in Critical-Auth mode.

cache - link is in Critical-Auth cached mode.

default - link i…
Enumeration
Enumerated Values:
1disable
2cache
3default
.1.3.6.1.4.1.9.9.740.1.5.1.1.12
.1.3.6.1.4.1.9.9.740.1.6.1 · 1 row entry · 10 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfStatsTable'
A list of Cisco Trusted Security capable interface.
ctsiIfStatsEntry row .1.3.6.1.4.1.9.9.740.1.6.1.1
An entry contains the statistics information of a
particular TrustSec interface.

An entry created by system for each interface is TrustSec
enabled. An entry deleted by system for each interface is
TrustSec…
Indexes
Column Syntax OID
The number of times that peer has been successfully
authenticated on this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.1
The number of times that peer has been rejected
in authentication on this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.2
The number of times that peer has been failed in
authentication on this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.3
The number of times that no authentication respond
received from the remote peer associated with this
interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.4
The number of times that received authentication log
off from the peer associated with this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.5
The number of times that the peer entity successfully
passed the TrustSec authorization challenge on this
interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.6
The number of time that fail to access policy or refresh
the policy for TrustSec authorization on this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.7
The number of times that peer has been failed in TrustSec
authorization on this interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.8
The number of times that SAP negotiation is succeed on this
interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.9
The number of times that SAP negotiation has failed on this
interface.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.10
.1.3.6.1.4.1.9.9.740.1.7.1 · 1 row entry · 8 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiAuthorizationTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiAuthorizationTable'
A list of authorized remote peers on this device.
ctsiAuthorizationEntry row .1.3.6.1.4.1.9.9.740.1.7.1.1
An entry containing the management information for a
particular authorized peer.

An entry is created when the policy acquired from the ACS
for a new peer.

An entry is deleted when the authoriza…
Column Syntax OID
This object indicates the device identity or symbolic group
name of the remote peer.
OctetString
Constraints:
range: 1-64
.1.3.6.1.4.1.9.9.740.1.7.1.1.1
This object indicates the SGT of the remote peer.
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.7.1.1.2
This object indicates the current state of the
authorization entity.

unknown - none of the following states.

start - authorization entity created and
Enumeration
Enumerated Values:
1unknown
2start
3waitingRespond
4assessing
5complete
6failure
.1.3.6.1.4.1.9.9.740.1.7.1.1.3
The object indicates the date and time when the authorized
peer was last refreshed.
SNMPv2-TCDateAndTime
Type Constraints:
range: 8
range: 11
Description:
A date-time specification.

field octets contents range
----- ------ -------- -----
1 1-2 year* 0..65536
2 3 month …
.1.3.6.1.4.1.9.9.740.1.7.1.1.4
This object indicates the leftover time for the current
policy.

A value of zero indicates that policy refresh is in progress.

A value of -1 indicates that this object is not applicable
on t…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.7.1.1.5
This object indicates the time left to start the policy
refresh.

A value of zero indicates that policy refresh is in progress.

A value of -1 indicates that this object is not applicable
on …
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.7.1.1.6
This object indicates the source of cached data.
CtsiCasheDataSource
Type Values:
1unknown
2acs
3dram
4nvram
5all
.1.3.6.1.4.1.9.9.740.1.7.1.1.7
This object indicates the status of this authorization peer.
unknown - status not covered by any of
the follow enumerations.

inProgress - new authorization link create…
Enumeration
Enumerated Values:
1unknown
2inProgress
3succeeded
4failed
5fallbackPolicy
6incomplete
.1.3.6.1.4.1.9.9.740.1.7.1.1.8
.1.3.6.1.4.1.9.9.740.1.8.1 · 1 row entry · 2 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ctsiIfcStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-INTERFACE-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-INTERFACE-MIB::ctsiIfcStatsTable'
A list of IFC state statistic on this device.
ctsiIfcStatsEntry row .1.3.6.1.4.1.9.9.740.1.8.1.1
An entry containing the total number of interfaces which
are currently belong to a particular IFC state.
Indexes
Column Syntax OID
This object indicates the IFC state.
CtsiInterfaceControllerState
Type Values:
1unknown
2initialize
3authenticating
4authorizing
5sapNegotiating
6open
7held
8disconnecting
9invalid
10licenseError
.1.3.6.1.4.1.9.9.740.1.8.1.1.1
The total number of interfaces on the device which is
currently in the IFC state.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.8.1.1.2