CISCO-TRUSTSEC-INTERFACE-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
55
.1.3.6.1.4.1.9.9.740.1.1.1 · 1 row entry · 4 columns
A list of the TrustSec capable interfaces.
ctsiIfConfigEntry entry .1.3.6.1.4.1.9.9.740.1.1.1.1
An entry contains the configuration information for a
particular TrustSec interface.
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfModeCapability
This object indicates the supported TrustSec mode on
this interface.
Bits
Enumerated Values:
0dot1x
1manual
2l3Forward
.1.3.6.1.4.1.9.9.740.1.1.1.1.1
ctsiIfConfiguredMode
This object indicates the TrustSec mode currently configured
on the interface. Each mode may have a corresponding
entry in its corresponding configuration table.

unknown - The configured TrustSec m…
Enumeration
Enumerated Values:
1unknown
2none
3dot1x
4manual
5l3Forward
.1.3.6.1.4.1.9.9.740.1.1.1.1.2
ctsiIfCacheClear
This object allows user to clear the cache for the specific
TrustSec interface by setting the value to 'true'.
Setting the value to 'false' has no effect.

When read, this object always returns 'false'.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.1.1.1.3
ctsiIfRekey
This object allows user to re-generate the SAP key for the
specific TrustSec interface by setting the value to 'true'.
Setting the value to 'false' has no effect.

When read, this object always returns 'fa…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.1.1.1.4
.1.3.6.1.4.1.9.9.740.1.2.1 · 1 row entry · 8 columns
A list of the interfaces which have TrustSec dot1x mode
configuration information.
ctsiIfDot1xEntry entry .1.3.6.1.4.1.9.9.740.1.2.1.1
An entry containing the TrustSec dot1x configuration
for a particular interface.

An entry can be created or deleted by using
ctsiIfDot1xRowStatus.

An entry can only be created if the value of c…
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfDot1xSgtPropagateEnabled
This object specifies whether the SGT propagation is
enabled on this interface.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.2.1.1.1
ctsiIfDot1xReauthInterval
This object specifies the re-authentication interval
applied to this interface when it is not provided from
the ACS.
secondsSNMPv2-SMIInteger32r/w
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.2
ctsiIfDot1xSapModeList
This object specifies the advertised modes for the SAP
negotiation on this interface. Modes are executed in
the order as specified in the mode list.

Mode which is at the beginning of the method list will…
CtsSapNegModeListr/w
Textual Convention: CtsSapNegModeList OctetString
.1.3.6.1.4.1.9.9.740.1.2.1.1.3
ctsiIfDot1xDownloadReauthInterval
This object indicates the re-authentication interval which
is downloaded from ACS.

A value of zero indicates no re-authentication interval is
downloaded from ACS.

A value of -1 indicates th…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.4
ctsiIfDot1xOperReauthInterval
This object indicates the operational re-authentication
interval of the interface.

A value of zero indicates that dot1x re-authentication is
disabled on this interface.

A value of -1 indica…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.5
ctsiIfDot1xReauthTimeLeft
This object indicates the leftover time of the current
authentication session.

A value of zero indicates the re-authentication is in
progress.

A value of -1 indicates that this object is no…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.2.1.1.6
ctsiIfDot1xStorageType
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Textual Convention: SNMPv2-TCStorageType Enumeration
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
.1.3.6.1.4.1.9.9.740.1.2.1.1.7
ctsiIfDot1xRowStatus
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.740.1.2.1.1.8
.1.3.6.1.4.1.9.9.740.1.3.1 · 1 row entry · 8 columns
A list of the interfaces which have TrustSec manual mode
configuration information.
ctsiIfManualEntry entry .1.3.6.1.4.1.9.9.740.1.3.1.1
An entry containing the TrustSec manual configuration
information for a particular interface.

An entry can be created or deleted by using
ctsiIfManualRowStatus.

An entry can only be created if …
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfManualDynamicPeerId
This object specifies the peer's device identity which is
used to obtain the desired policy for authorization request.

Setting a none-zero value on this object is not allowed if
the value of ctsiIfManualS…
SNMP-FRAMEWORK-MIBSnmpAdminStringr/w
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.740.1.3.1.1.1
ctsiIfManualStaticSgt
This object specifies the statically configured SGT for
tagging the ingress traffic from the peer.

Setting a none-zero value on this object is not allowed if
the value of ctsiIfManualDynamicPeerId is not …
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTagr/w
Textual Convention: CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.3.1.1.2
ctsiIfManualStaticSgtTrusted
This object specifies the peer's SGT assignment trust
state.

This object only can be set when ctsiIfManualStaticSgt
is none-zero.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.3.1.1.3
ctsiIfManualSgtPropagateEnabled
This object specifies whether the SGT propagation is
enabled on this interface.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.3.1.1.4
ctsiIfManualSapPmk
This object specifies the PMK used by SAP.

A zero length string for this object indicates the SAP
negotiation is disabled on this interface.
OctetStringr/w
Constraints:
range: 0-0
range: 32-32
.1.3.6.1.4.1.9.9.740.1.3.1.1.5
ctsiIfManualSapModeList
This object specified the advertised modes for the SAP
negotiation on this interface. Modes are executed in
the order as specified in the mode list.

Mode which is at the beginning of the mode list will b…
CtsSapNegModeListr/w
Textual Convention: CtsSapNegModeList OctetString
.1.3.6.1.4.1.9.9.740.1.3.1.1.6
ctsiIfManualStorageType
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Textual Convention: SNMPv2-TCStorageType Enumeration
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
.1.3.6.1.4.1.9.9.740.1.3.1.1.7
ctsiIfManualRowStatus
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.740.1.3.1.1.8
.1.3.6.1.4.1.9.9.740.1.4.1 · 1 row entry · 3 columns
A list of the interfaces which have TrustSec L3 forwarding
configuration information.
ctsiIfL3ForwardEntry entry .1.3.6.1.4.1.9.9.740.1.4.1.1
An entry containing the TrustSec L3 forwarding configuration
information for a particular interface.

An entry can be created or deleted by using
ctsiIfL3ForwardRowStatus.

An entry can only be c…
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfL3ForwardMode
This object specifies the type of L3 forwarding for
the interface.

l3Ipv4Forward - TrustSec L3 IPv4 forwarding.

l3Ipv6Forward - TrustSec L3 IPv6 forwarding.

l3IpForward - …
Enumerationr/w
Enumerated Values:
1l3Ipv4Forward
2l3Ipv6Forward
3l3IpForward
.1.3.6.1.4.1.9.9.740.1.4.1.1.1
ctsiIfL3ForwardStorageType
The storage type for this conceptual row.
SNMPv2-TCStorageTyper/w
Textual Convention: SNMPv2-TCStorageType Enumeration
Type Values:
1other
2volatile
3nonVolatile
4permanent
5readOnly
.1.3.6.1.4.1.9.9.740.1.4.1.1.2
ctsiIfL3ForwardRowStatus
The status of this conceptual row.

All writable objects in this row may be modified at any time.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.740.1.4.1.1.3
.1.3.6.1.4.1.9.9.740.1.5.1 · 1 row entry · 12 columns
A list of TrustSec enabled interfaces.
ctsiIfStatusEntry entry .1.3.6.1.4.1.9.9.740.1.5.1.1
An entry contains the information of the specific TrustSec
interface.

A entry is created by system when TrustSec is enabled for
an interface. An entry is deleted by system if TrustSec
is disabled for an in…
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfControllerState
This object indicates the current IFC state of this
interface.
CtsiInterfaceControllerState
Textual Convention: CtsiInterfaceControllerState Enumeration
Type Values:
1unknown
2initialize
3authenticating
4authorizing
5sapNegotiating
6open
7held
8disconnecting
9invalid
10licenseError
.1.3.6.1.4.1.9.9.740.1.5.1.1.1
ctsiIfAuthenticationStatus
This object indicates the current TrustSec authentication
status of this interface.

unknown - status not covered by any of
the follow enumerations.

succeeded …
Enumeration
Enumerated Values:
1unknown
2succeeded
3rejected
4logOff
5noRespond
6notApplicable
7incomplete
8failed
.1.3.6.1.4.1.9.9.740.1.5.1.1.2
ctsiIfPeerId
This object indicates the device identity or symbolic
group name of the remote peer.
SNMP-FRAMEWORK-MIBSnmpAdminString
Textual Convention: SNMP-FRAMEWORK-MIBSnmpAdminString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.740.1.5.1.1.3
ctsiIfPeerAdvCapability
This object indicates the advertised capabilities of the
remote peer associated with this interface.
Bits
Enumerated Values:
0sap
.1.3.6.1.4.1.9.9.740.1.5.1.1.4
ctsiIfAuthorizationStatus
This object indicates the current TrustSec authorization
status of the interface.

unknown - status not covered by any of
the follow enumerations.

i…
Enumeration
Enumerated Values:
1unknown
2inProgress
3succeeded
4failed
5fallBackPolicy
6incomplete
7peerSucceeded
8rbaclSucceeded
9policySucceeded
.1.3.6.1.4.1.9.9.740.1.5.1.1.5
ctsiIfPeerSgt
This object indicates the SGT value of the remote peer.
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag
Textual Convention: CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.5.1.1.6
ctsiIfPeerSgtTrusted
This object indicates whether the SGT of the remote peer
is trusted.
SNMPv2-TCTruthValue
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.740.1.5.1.1.7
ctsiIfSapNegotiationStatus
This object indicates the SAP negotiation status on
this interface.

notApplicable - SAP disabled on local or remote peer
is not SAP capable.

unknown - s…
Enumeration
Enumerated Values:
1notApplicable
2unknown
3inProgress
4succeeded
5failed
6licenseError
.1.3.6.1.4.1.9.9.740.1.5.1.1.8
ctsiIfSapNegModeList
This object indicates the operational SAP negotiation
mode list on this interface.
CtsSapNegModeList
Textual Convention: CtsSapNegModeList OctetString
.1.3.6.1.4.1.9.9.740.1.5.1.1.9
ctsiIfCacheExpirationTime
This object indicates the time when the current cached data
applied on the interface will be expired.

A value of zero indicates that the cached data will never be
expired.
SNMPv2-TCDateAndTime
Textual Convention: SNMPv2-TCDateAndTime OctetString
Type Constraints:
range: 8
range: 11
.1.3.6.1.4.1.9.9.740.1.5.1.1.10
ctsiIfCacheDataSource
This object indicates the source of cached data applied to the
interface.
CtsiCasheDataSource
Textual Convention: CtsiCasheDataSource Enumeration
Type Values:
1unknown
2acs
3dram
4nvram
5all
.1.3.6.1.4.1.9.9.740.1.5.1.1.11
ctsiIfCriticalAuthStatus
This object indicates the CTS Critical-Auth status
of interface.

disable - link is not in Critical-Auth mode.

cache - link is in Critical-Auth cached mode.

default - link i…
Enumeration
Enumerated Values:
1disable
2cache
3default
.1.3.6.1.4.1.9.9.740.1.5.1.1.12
.1.3.6.1.4.1.9.9.740.1.6.1 · 1 row entry · 10 columns
A list of Cisco Trusted Security capable interface.
ctsiIfStatsEntry entry .1.3.6.1.4.1.9.9.740.1.6.1.1
An entry contains the statistics information of a
particular TrustSec interface.

An entry created by system for each interface is TrustSec
enabled. An entry deleted by system for each interface is
TrustSec…
Indexes
IF-MIBifIndex
Column Syntax OID
ctsiIfAuthenticationSuccess
The number of times that peer has been successfully
authenticated on this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.1
ctsiIfAuthenticationReject
The number of times that peer has been rejected
in authentication on this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.2
ctsiIfAuthenticationFailure
The number of times that peer has been failed in
authentication on this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.3
ctsiIfAuthenticationNoResponse
The number of times that no authentication respond
received from the remote peer associated with this
interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.4
ctsiIfAuthenticationLogoff
The number of times that received authentication log
off from the peer associated with this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.5
ctsiIfAuthorizationSuccess
The number of times that the peer entity successfully
passed the TrustSec authorization challenge on this
interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.6
ctsiIfAuthorizationPolicyFail
The number of time that fail to access policy or refresh
the policy for TrustSec authorization on this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.7
ctsiIfAuthorizationFail
The number of times that peer has been failed in TrustSec
authorization on this interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.8
ctsiIfSapSuccess
The number of times that SAP negotiation is succeed on this
interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.9
ctsiIfSapFail
The number of times that SAP negotiation has failed on this
interface.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.6.1.1.10
.1.3.6.1.4.1.9.9.740.1.7.1 · 1 row entry · 8 columns
A list of authorized remote peers on this device.
ctsiAuthorizationEntry entry .1.3.6.1.4.1.9.9.740.1.7.1.1
An entry containing the management information for a
particular authorized peer.

An entry is created when the policy acquired from the ACS
for a new peer.

An entry is deleted when the authoriza…
Indexes
ctsiAuthorizationPeerId
Column Syntax OID
ctsiAuthorizationPeerId
This object indicates the device identity or symbolic group
name of the remote peer.
OctetString
Constraints:
range: 1-64
.1.3.6.1.4.1.9.9.740.1.7.1.1.1
ctsiAuthorizationPeerSgt
This object indicates the SGT of the remote peer.
CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag
Textual Convention: CISCO-TRUSTSEC-TC-MIBCtsSecurityGroupTag Unsigned32
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.740.1.7.1.1.2
ctsiAuthorizationState
This object indicates the current state of the
authorization entity.

unknown - none of the following states.

start - authorization entity created and
Enumeration
Enumerated Values:
1unknown
2start
3waitingRespond
4assessing
5complete
6failure
.1.3.6.1.4.1.9.9.740.1.7.1.1.3
ctsiAuthorizationLastRefresh
The object indicates the date and time when the authorized
peer was last refreshed.
SNMPv2-TCDateAndTime
Textual Convention: SNMPv2-TCDateAndTime OctetString
Type Constraints:
range: 8
range: 11
.1.3.6.1.4.1.9.9.740.1.7.1.1.4
ctsiAuthorizationTimeLeft
This object indicates the leftover time for the current
policy.

A value of zero indicates that policy refresh is in progress.

A value of -1 indicates that this object is not applicable
on t…
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.7.1.1.5
ctsiAuthorizationTimeToRefresh
This object indicates the time left to start the policy
refresh.

A value of zero indicates that policy refresh is in progress.

A value of -1 indicates that this object is not applicable
on …
secondsInteger32
Constraints:
range: -1-2147483647
.1.3.6.1.4.1.9.9.740.1.7.1.1.6
ctsiAuthorizationCacheDataSource
This object indicates the source of cached data.
CtsiCasheDataSource
Textual Convention: CtsiCasheDataSource Enumeration
Type Values:
1unknown
2acs
3dram
4nvram
5all
.1.3.6.1.4.1.9.9.740.1.7.1.1.7
ctsiAuthorizationStatus
This object indicates the status of this authorization peer.
unknown - status not covered by any of
the follow enumerations.

inProgress - new authorization link create…
Enumeration
Enumerated Values:
1unknown
2inProgress
3succeeded
4failed
5fallbackPolicy
6incomplete
.1.3.6.1.4.1.9.9.740.1.7.1.1.8
.1.3.6.1.4.1.9.9.740.1.8.1 · 1 row entry · 2 columns
A list of IFC state statistic on this device.
ctsiIfcStatsEntry entry .1.3.6.1.4.1.9.9.740.1.8.1.1
An entry containing the total number of interfaces which
are currently belong to a particular IFC state.
Indexes
ctsiIfcState
Column Syntax OID
ctsiIfcState
This object indicates the IFC state.
CtsiInterfaceControllerState
Textual Convention: CtsiInterfaceControllerState Enumeration
Type Values:
1unknown
2initialize
3authenticating
4authorizing
5sapNegotiating
6open
7held
8disconnecting
9invalid
10licenseError
.1.3.6.1.4.1.9.9.740.1.8.1.1.1
ctsiIfcStatsIfCount
The total number of interfaces on the device which is
currently in the IFC state.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.740.1.8.1.1.2