CISCO-TRUSTSEC-MIB

        This MIB module is for the configuration of a network
device on the Cisco Trusted Security (TrustSec) system.
        
TrustSec secures a network fabric by authenticating and
authorizing each device connecting to the network, allowing for
the encryption, authentication and replay protection of data
traffic on a hop by hop basis.
        
Glossary :
        
TrustSec - Cisco Trusted Security
        
EAP-FAST - Extensible Authentication Protocol-Flexible
           Authentication via Secure Tunneling (RFC 4851)
        
PAC - Protected Access Credential
      A credential dynamically downloaded from the
      Access Control Server.
        
ACS - Access Control Server
        
SGT - Security Group Tag
      A tag identifying its source, assigned to a packet on
      ingress to a TrustSec cloud, and used to determine
      security and other policy to be applied to it along
      its path through the cloud.
    
Source file
CISCO-TRUSTSEC-MIB
Last revised
Identity
ciscoTrustSecMIB
Base OID
1.3.6.1.4.1.9.9.730
Imported Objects
CISCO-SMI ciscoMgmt
CISCO-TRUSTSEC-TC-MIB CtsAcsAuthorityIdentity CtsCredentialRecordType CtsGenerationId CtsPasswordEncryptionType CtsSecurityGroupTag
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC DateAndTime RowStatus TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-TRUSTSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-TRUSTSEC-MIB::ciscoTrustSecMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-MIB::ciscoTrustSecMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (76)
.1.3.6.1.4.1.9.9.730
.1.3.6.1.4.1.9.9.730.0
.1.3.6.1.4.1.9.9.730.1
.1.3.6.1.4.1.9.9.730.1.1
.1.3.6.1.4.1.9.9.730.1.1.1
.1.3.6.1.4.1.9.9.730.1.1.2
Enumeration
.1.3.6.1.4.1.9.9.730.1.1.3
.1.3.6.1.4.1.9.9.730.1.2
.1.3.6.1.4.1.9.9.730.1.2.1
Enumeration
.1.3.6.1.4.1.9.9.730.1.2.2
.1.3.6.1.4.1.9.9.730.1.3
.1.3.6.1.4.1.9.9.730.1.3.1
.1.3.6.1.4.1.9.9.730.1.3.10
.1.3.6.1.4.1.9.9.730.1.3.11
.1.3.6.1.4.1.9.9.730.1.3.13
.1.3.6.1.4.1.9.9.730.1.3.13.1
OctetString
.1.3.6.1.4.1.9.9.730.1.3.13.1.1
.1.3.6.1.4.1.9.9.730.1.3.13.1.2
.1.3.6.1.4.1.9.9.730.1.3.14
.1.3.6.1.4.1.9.9.730.1.3.14.1
OctetString
.1.3.6.1.4.1.9.9.730.1.3.14.1.1
.1.3.6.1.4.1.9.9.730.1.3.14.1.2
.1.3.6.1.4.1.9.9.730.1.3.15
.1.3.6.1.4.1.9.9.730.1.3.15.1
OctetString
.1.3.6.1.4.1.9.9.730.1.3.15.1.1
.1.3.6.1.4.1.9.9.730.1.3.15.1.2
Enumeration
.1.3.6.1.4.1.9.9.730.1.3.15.1.3
.1.3.6.1.4.1.9.9.730.1.3.15.1.4
.1.3.6.1.4.1.9.9.730.1.3.15.1.5
.1.3.6.1.4.1.9.9.730.1.3.15.1.6
.1.3.6.1.4.1.9.9.730.1.3.16
.1.3.6.1.4.1.9.9.730.1.3.2
.1.3.6.1.4.1.9.9.730.1.3.3
Enumeration
.1.3.6.1.4.1.9.9.730.1.3.4
.1.3.6.1.4.1.9.9.730.1.3.5
.1.3.6.1.4.1.9.9.730.1.3.6
.1.3.6.1.4.1.9.9.730.1.3.7
.1.3.6.1.4.1.9.9.730.1.3.8
.1.3.6.1.4.1.9.9.730.1.3.9
.1.3.6.1.4.1.9.9.730.1.4
Enumeration
.1.3.6.1.4.1.9.9.730.1.4.1
.1.3.6.1.4.1.9.9.730.1.4.16
.1.3.6.1.4.1.9.9.730.1.4.16.1
Unsigned32
.1.3.6.1.4.1.9.9.730.1.4.16.1.1
.1.3.6.1.4.1.9.9.730.1.4.16.1.2
Bits
.1.3.6.1.4.1.9.9.730.1.4.16.1.3
.1.3.6.1.4.1.9.9.730.1.4.16.1.4
.1.3.6.1.4.1.9.9.730.1.4.2
.1.3.6.1.4.1.9.9.730.1.4.3
.1.3.6.1.4.1.9.9.730.1.4.4
.1.3.6.1.4.1.9.9.730.1.4.5
.1.3.6.1.4.1.9.9.730.1.4.6
.1.3.6.1.4.1.9.9.730.1.4.7
Enumeration
.1.3.6.1.4.1.9.9.730.1.4.8
Enumeration
.1.3.6.1.4.1.9.9.730.1.4.9
.1.3.6.1.4.1.9.9.730.1.5
.1.3.6.1.4.1.9.9.730.1.5.1
.1.3.6.1.4.1.9.9.730.1.5.2
.1.3.6.1.4.1.9.9.730.1.5.3
.1.3.6.1.4.1.9.9.730.1.5.4
.1.3.6.1.4.1.9.9.730.1.5.5
.1.3.6.1.4.1.9.9.730.1.5.6
.1.3.6.1.4.1.9.9.730.1.6
Enumeration
.1.3.6.1.4.1.9.9.730.1.6.1
Enumeration
.1.3.6.1.4.1.9.9.730.1.6.2
.1.3.6.1.4.1.9.9.730.1.6.3
.1.3.6.1.4.1.9.9.730.1.7
.1.3.6.1.4.1.9.9.730.1.7.1
Enumeration
.1.3.6.1.4.1.9.9.730.1.7.2
.1.3.6.1.4.1.9.9.730.1.7.3
.1.3.6.1.4.1.9.9.730.1.7.4
OctetString
.1.3.6.1.4.1.9.9.730.1.7.5
OctetString
.1.3.6.1.4.1.9.9.730.1.7.6
.1.3.6.1.4.1.9.9.730.2
.1.3.6.1.4.1.9.9.730.2.1
.1.3.6.1.4.1.9.9.730.2.2
Dependencies (6) 6 direct Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. CISCO-TRUSTSEC-TC-MIBcisco
  5. SNMPv2-CONFrfc
  6. SNMP-FRAMEWORK-MIBrfc
  7. CISCO-TRUSTSEC-MIBciscoselected
Conformance Groups (17)
A collection of objects that provides the cache configuration
for TrustSec in the system.
.1.3.6.1.4.1.9.9.730.2.2.1
A collection of objects to manage SGT for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.2
A collection of objects to manage credentials parameters for
TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.3
A collection of objects to manage hardware keystore for
TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.4
A collection of objects to manage Environment Data for
TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.5
A collection of objects to manage assignment of TrustSec SGT.
.1.3.6.1.4.1.9.9.730.2.2.6
A collection of object(s) to manage Security Group Name
information for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.7
A collection of object(s) to provide information
regarding software keystore notifications for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.8
A collection of object(s) to control software keystore
notifications for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.9
A collection of software keystore related notifications for
TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.10
A collection of object(s) to provide information
regarding file error related notifications for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.11
A collection of object(s) to provide information
regarding TrustSec notification.
.1.3.6.1.4.1.9.9.730.2.2.12
A collection of object(s) to control cache file
related notifications for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.13
A collection of TrustSec cache file related notifications.
.1.3.6.1.4.1.9.9.730.2.2.14
A collection of object(s) to control CTR-DRBG related
notifications for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.15
A collection of CTR-DRBG related notifications
for TrustSec.
.1.3.6.1.4.1.9.9.730.2.2.16
A collection of CTS Critical Auth Config
objects
.1.3.6.1.4.1.9.9.730.2.2.17
Compliance Statements (4)

OID .1.3.6.1.4.1.9.9.730.2.1.1
The compliance statement for the CISCO-TRUSTSEC-MIB.
Required groups
mandatory ciscoTrustSecCacheGroup
mandatory ciscoTrustSecSgtGroup
mandatory ciscoTrustSecCredentialsGroup
mandatory ciscoTrustSecHwKeystoreInfoGroup
mandatory ciscoTrustSecEnvDataGroup
optional ciscoTrustSecSgtAssignmentGroup Implementation of this group is mandatory for the
devices that support mechanism to assign SGT for
line cards without TrustSec tagging capability.
Object refinements
ObjectAccessSyntaxDescription
ctsCacheEnabled readonly
Write access is not required.
ctsCacheNvStorage readonly
Write access is not required.
ctsCacheClear readonly
Write access is not required.
ctsSecurityGroupTagId readonly
Write access is not required.
ctsSgtAssignmentMethod readonly
Write access is not required.
ctsDeviceId readonly
Write access is not required.
ctsDevicePasswordType readonly
Write access is not required.
ctsDevicePassword readonly
Write access is not required.
ctsPacStatus readonly
active(1)
Write access is not required.
ctsCredentialsClearAll readonly
Write access is not required.
ctsEnvDataAction readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.730.2.1.2
The compliance statement for the CISCO-TRUSTSEC-MIB.
Required groups
mandatory ciscoTrustSecCacheGroup
mandatory ciscoTrustSecSgtGroup
mandatory ciscoTrustSecCredentialsGroup
mandatory ciscoTrustSecHwKeystoreInfoGroup
mandatory ciscoTrustSecEnvDataGroup
optional ciscoTrustSecSgtAssignmentGroup Implementation of this group is mandatory for the
devices that support mechanism to assign SGT for
line cards without TrustSec tagging capability.
optional ciscoTrustSecEnvSecGroupNameGroup Implementation of this group is mandatory for the
devices that support Security Group Name functionality.
Object refinements
ObjectAccessSyntaxDescription
ctsCacheEnabled readonly
Write access is not required.
ctsCacheNvStorage readonly
Write access is not required.
ctsCacheClear readonly
Write access is not required.
ctsSecurityGroupTagId readonly
Write access is not required.
ctsSgtAssignmentMethod readonly
Write access is not required.
ctsDeviceId readonly
Write access is not required.
ctsDevicePasswordType readonly
Write access is not required.
ctsDevicePassword readonly
Write access is not required.
ctsPacStatus readonly
active(1)
Write access is not required.
ctsCredentialsClearAll readonly
Write access is not required.
ctsEnvDataAction readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.730.2.1.3
The compliance statement for the CISCO-TRUSTSEC-MIB.
Required groups
mandatory ciscoTrustSecCacheGroup
mandatory ciscoTrustSecSgtGroup
mandatory ciscoTrustSecCredentialsGroup
mandatory ciscoTrustSecHwKeystoreInfoGroup
mandatory ciscoTrustSecEnvDataGroup
optional ciscoTrustSecSgtAssignmentGroup Implementation of this group is mandatory for the
devices that support mechanism to assign SGT for
line cards without TrustSec tagging capability.
optional ciscoTrustSecEnvSecGroupNameGroup Implementation of this group is mandatory for the
devices that support Security Group Name functionality.
optional ciscoTrustSecSwKeystoreNotifsInfoGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecSwKeystoreNotifsControlGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecSwKeystoreNotifsGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecFileErrNotifsInfoGroup Implementation of this group is mandatory for the
devices that support TrustSec keystore or cache file
error related notifications.
optional ciscoTrustSecNotifsMessageStringInfoGroup Implementation of this group is mandatory for the
devices that provide additional information for
TrustSec notifications.
optional ciscoTrustSecCacheFileNotifsControlGroup Implementation of this group is mandatory for the
devices that support TrustSec cache file error
notifications.
optional ciscoTrustSecCacheFileNotifsGroup Implementation of this group is mandatory for the
devices that support TrustSec cache file error
notifications.
optional ciscoTrustSecCtrDrbgNotifsControlGroup Implementation of this group is mandatory for the
devices that support CTR-DRBG error notifications.
optional ciscoTrustSecCtrDrbgNotifsGroup Implementation of this group is mandatory for the
devices that support CTR-DRBG error notifications.
Object refinements
ObjectAccessSyntaxDescription
ctsCacheEnabled readonly
Write access is not required.
ctsCacheNvStorage readonly
Write access is not required.
ctsCacheClear readonly
Write access is not required.
ctsSecurityGroupTagId readonly
Write access is not required.
ctsSgtAssignmentMethod readonly
Write access is not required.
ctsDeviceId readonly
Write access is not required.
ctsDevicePasswordType readonly
Write access is not required.
ctsDevicePassword readonly
Write access is not required.
ctsPacStatus readonly
active(1)
Write access is not required.
ctsCredentialsClearAll readonly
Write access is not required.
ctsEnvDataAction readonly
Write access is not required.
ctsSwKeystoreFileErrNotifEnable readonly
Write access is not required.
ctsSwKeystoreSyncFailNotifEnable readonly
Write access is not required.
ctsAuthzCacheFileErrNotifEnable readonly
Write access is not required.
ctsCacheFileAccessErrNotifEnable readonly
Write access is not required.
ctsSrcEntropyFailNotifEnable readonly
Write access is not required.
ctsSapRandomNumberFailNotifEnable readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.730.2.1.4
The compliance statement for the CISCO-TRUSTSEC-MIB.
Required groups
mandatory ciscoTrustSecCacheGroup
mandatory ciscoTrustSecSgtGroup
mandatory ciscoTrustSecCredentialsGroup
mandatory ciscoTrustSecHwKeystoreInfoGroup
mandatory ciscoTrustSecEnvDataGroup
optional ciscoTrustSecSgtAssignmentGroup Implementation of this group is mandatory for the
devices that support mechanism to assign SGT for
line cards without TrustSec tagging capability.
optional ciscoTrustSecEnvSecGroupNameGroup Implementation of this group is mandatory for the
devices that support Security Group Name functionality.
optional ciscoTrustSecSwKeystoreNotifsInfoGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecSwKeystoreNotifsControlGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecSwKeystoreNotifsGroup Implementation of this group is mandatory for the
devices that support software keystore notifications.
optional ciscoTrustSecFileErrNotifsInfoGroup Implementation of this group is mandatory for the
devices that support TrustSec keystore or cache file
error related notifications.
optional ciscoTrustSecNotifsMessageStringInfoGroup Implementation of this group is mandatory for the
devices that provide additional information for
TrustSec notifications.
optional ciscoTrustSecCacheFileNotifsControlGroup Implementation of this group is mandatory for the
devices that support TrustSec cache file error
notifications.
optional ciscoTrustSecCacheFileNotifsGroup Implementation of this group is mandatory for the
devices that support TrustSec cache file error
notifications.
optional ciscoTrustSecCtrDrbgNotifsControlGroup Implementation of this group is mandatory for the
devices that support CTR-DRBG error notifications.
optional ciscoTrustSecCtrDrbgNotifsGroup Implementation of this group is mandatory for the
devices that support CTR-DRBG error notifications.
optional ciscoTrustSecCrtclAuthGroup Implementation of this group is mandatory for the
devices that support CTS Critical-Auth
Object refinements
ObjectAccessSyntaxDescription
ctsCacheEnabled readonly
Write access is not required.
ctsCacheNvStorage readonly
Write access is not required.
ctsCacheClear readonly
Write access is not required.
ctsSecurityGroupTagId readonly
Write access is not required.
ctsSgtAssignmentMethod readonly
Write access is not required.
ctsDeviceId readonly
Write access is not required.
ctsDevicePasswordType readonly
Write access is not required.
ctsDevicePassword readonly
Write access is not required.
ctsPacStatus readonly
active(1)
Write access is not required.
ctsCredentialsClearAll readonly
Write access is not required.
ctsEnvDataAction readonly
Write access is not required.
ctsSwKeystoreFileErrNotifEnable readonly
Write access is not required.
ctsSwKeystoreSyncFailNotifEnable readonly
Write access is not required.
ctsAuthzCacheFileErrNotifEnable readonly
Write access is not required.
ctsCacheFileAccessErrNotifEnable readonly
Write access is not required.
ctsSrcEntropyFailNotifEnable readonly
Write access is not required.
ctsSapRandomNumberFailNotifEnable readonly
Write access is not required.
ctsCriticalAuthEnabled readonly
Write access is not required.
ctsCriticalAuthFallback readonly
Write access is not required.
ctsCriticalAuthPeerSgt readonly
Write access is not required.
ctsCriticalAuthPeerSgtTrust readonly
Write access is not required.
ctsCriticalAuthDefaultPmk readonly
Write access is not required.
Notifications / Traps (6)
NameOIDDescription
.1.3.6.1.4.1.9.9.730.0.1
A ctsSwKeystoreFileErrNotif is generated when system
encounters an error while performing operation on the
software keystore file.
.1.3.6.1.4.1.9.9.730.0.2
A ctsSwKeystoreSyncFailNotifReason is generated when system
fails to sync software keystore information from the active
supervisor to the standby supervisor.
.1.3.6.1.4.1.9.9.730.0.3
A ctsAuthzCacheFileErrNotif is generated when the system
encounters error downloading TrustSec authorization
related environment data to a cache file.
.1.3.6.1.4.1.9.9.730.0.4
A ctsCacheFileAccessErrNotif is generated when the
system fails to perform open/read/write operation
for a TrustSec cache file.
.1.3.6.1.4.1.9.9.730.0.5
A ctsSrcEntropyFailNotif is generated when
the periodic health tests for the CTR-DRBG (Counter-
Deterministic Random Bit Generator) implementation
fails due to issues with the source entropy.
.1.3.6.1.4.1.9.9.730.0.6
A ctsSapRandomNumberFailNotif is generated when the
the system fails to obtain a random number from
CTR-DRBG block for SAP (Security Association Protocol)
key-counter.