CISCO-TRUSTSEC-POLICY-MIB

        This MIB module defines managed objects that facilitate the
management of various policies within the Cisco Trusted Security
(TrustSec) infrastructure. 
        
The information available through this MIB includes:
        
o Device and interface level configuration for enabling
  SGACL (Security Group Access Control List) enforcement
  on Layer2/3 traffic. 
        
o Administrative and operational SGACL mapping to Security
  Group Tag (SGT). 
        
o Various statistics counters for traffic subject to SGACL
  enforcement. 
        
o TrustSec policies with respect to peer device. 
        
o Interface level configuration for enabling the propagation
  of SGT along with the Layer 3 traffic in portions of network
  which does not have the capability to support TrustSec 
  feature. 
          
o TrustSec policies with respect to SGT propagation with
  Layer 3 traffic. 
        
The following terms are used throughout this MIB:
        
VRF:   Virtual Routing and Forwarding.
        
SGACL: Security Group Access Control List.
        
ACE: Access Control Entries.
        
SXP: SGT Propagation Protocol.
        
SVI: Switch Virtual Interface.
        
IPM: Identity Port Mapping.
        
SGT (Security Group Tag) is a unique 16 bits value assigned
to every security group and used by network devices to
enforce SGACL.
        
Peer is another device connected to the local device on the
other side of a TrustSec link.
        
Default Policy:  Policy applied to traffic when there is 
no explicit policy between the SGT associated with the 
originator of the traffic and the SGT associated with 
the destination of the traffic.
    
Source file
CISCO-TRUSTSEC-POLICY-MIB
Last revised
Identity
ciscoTrustSecPolicyMIB
Base OID
1.3.6.1.4.1.9.9.713
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-TRUSTSEC-POLICY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-TRUSTSEC-POLICY-MIB::ciscoTrustSecPolicyMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-POLICY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-POLICY-MIB::ciscoTrustSecPolicyMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (169)
.1.3.6.1.4.1.9.9.713
.1.3.6.1.4.1.9.9.713.0
.1.3.6.1.4.1.9.9.713.1
.1.3.6.1.4.1.9.9.713.1.1
.1.3.6.1.4.1.9.9.713.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.1.1
.1.3.6.1.4.1.9.9.713.1.1.1.2
.1.3.6.1.4.1.9.9.713.1.1.1.3
.1.3.6.1.4.1.9.9.713.1.1.1.4
.1.3.6.1.4.1.9.9.713.1.1.1.4.1
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.1
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.2
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.3
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.4
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.5
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.6
.1.3.6.1.4.1.9.9.713.1.1.2
.1.3.6.1.4.1.9.9.713.1.1.2.1
.1.3.6.1.4.1.9.9.713.1.1.2.1.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.1
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.2
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.3
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.4
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.5
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.6
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.7
.1.3.6.1.4.1.9.9.713.1.1.2.10
.1.3.6.1.4.1.9.9.713.1.1.2.2
.1.3.6.1.4.1.9.9.713.1.1.2.3
.1.3.6.1.4.1.9.9.713.1.1.2.4
.1.3.6.1.4.1.9.9.713.1.1.2.4.1
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.1
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.2
Unsigned32
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.3
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.4
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.5
Bits
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.6
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.7
.1.3.6.1.4.1.9.9.713.1.1.2.5
.1.3.6.1.4.1.9.9.713.1.1.2.5.1
Unsigned32
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.1
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.2
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.3
Bits
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.4
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.5
.1.3.6.1.4.1.9.9.713.1.1.2.6
.1.3.6.1.4.1.9.9.713.1.1.2.6.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.1
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.2
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.3
Unsigned32
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.4
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.5
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.6
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.7
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.8
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.9
.1.3.6.1.4.1.9.9.713.1.1.2.7
.1.3.6.1.4.1.9.9.713.1.1.2.7.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.1
Unsigned32
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.2
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.3
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.4
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.5
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.6
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.7
.1.3.6.1.4.1.9.9.713.1.1.2.8
.1.3.6.1.4.1.9.9.713.1.1.2.9
.1.3.6.1.4.1.9.9.713.1.1.3
.1.3.6.1.4.1.9.9.713.1.1.3.1
.1.3.6.1.4.1.9.9.713.1.1.3.1.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.1
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.2
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.3
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.4
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.5
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.6
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.7
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.8
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.9
.1.3.6.1.4.1.9.9.713.1.1.3.2
.1.3.6.1.4.1.9.9.713.1.1.3.2.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.1
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.2
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.3
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.4
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.5
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.6
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.7
.1.3.6.1.4.1.9.9.713.1.10
.1.3.6.1.4.1.9.9.713.1.10.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.10.2
.1.3.6.1.4.1.9.9.713.1.10.3
.1.3.6.1.4.1.9.9.713.1.2
Enumeration
.1.3.6.1.4.1.9.9.713.1.2.1
.1.3.6.1.4.1.9.9.713.1.2.2
.1.3.6.1.4.1.9.9.713.1.2.2.1
OctetString
.1.3.6.1.4.1.9.9.713.1.2.2.1.1
.1.3.6.1.4.1.9.9.713.1.2.2.1.2
.1.3.6.1.4.1.9.9.713.1.2.2.1.3
Enumeration
.1.3.6.1.4.1.9.9.713.1.2.2.1.4
.1.3.6.1.4.1.9.9.713.1.2.2.1.5
.1.3.6.1.4.1.9.9.713.1.2.2.1.6
Enumeration
.1.3.6.1.4.1.9.9.713.1.2.2.1.7
.1.3.6.1.4.1.9.9.713.1.3
.1.3.6.1.4.1.9.9.713.1.3.1
.1.3.6.1.4.1.9.9.713.1.3.1.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.3.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.3.1.1.2
.1.3.6.1.4.1.9.9.713.1.3.1.1.3
.1.3.6.1.4.1.9.9.713.1.3.1.1.4
.1.3.6.1.4.1.9.9.713.1.3.1.1.5
.1.3.6.1.4.1.9.9.713.1.3.2
.1.3.6.1.4.1.9.9.713.1.3.2.1
.1.3.6.1.4.1.9.9.713.1.3.2.1.1
.1.3.6.1.4.1.9.9.713.1.3.2.1.2
.1.3.6.1.4.1.9.9.713.1.4
.1.3.6.1.4.1.9.9.713.1.4.1
.1.3.6.1.4.1.9.9.713.1.4.1.1
.1.3.6.1.4.1.9.9.713.1.4.1.1.1
.1.3.6.1.4.1.9.9.713.1.4.1.1.2
.1.3.6.1.4.1.9.9.713.1.4.1.1.3
.1.3.6.1.4.1.9.9.713.1.4.1.1.4
.1.3.6.1.4.1.9.9.713.1.4.1.1.5
Enumeration
.1.3.6.1.4.1.9.9.713.1.4.1.1.6
.1.3.6.1.4.1.9.9.713.1.4.1.1.7
.1.3.6.1.4.1.9.9.713.1.4.1.1.8
.1.3.6.1.4.1.9.9.713.1.5
Enumeration
.1.3.6.1.4.1.9.9.713.1.5.1
.1.3.6.1.4.1.9.9.713.1.5.2
.1.3.6.1.4.1.9.9.713.1.5.2.1
.1.3.6.1.4.1.9.9.713.1.5.2.1.1
.1.3.6.1.4.1.9.9.713.1.5.2.1.2
.1.3.6.1.4.1.9.9.713.1.5.2.1.3
.1.3.6.1.4.1.9.9.713.1.5.2.1.4
Enumeration
.1.3.6.1.4.1.9.9.713.1.5.2.1.5
.1.3.6.1.4.1.9.9.713.1.5.3
.1.3.6.1.4.1.9.9.713.1.5.3.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.5.3.1.1
.1.3.6.1.4.1.9.9.713.1.5.3.1.2
.1.3.6.1.4.1.9.9.713.1.5.3.1.3
.1.3.6.1.4.1.9.9.713.1.5.3.1.4
Enumeration
.1.3.6.1.4.1.9.9.713.1.5.3.1.5
.1.3.6.1.4.1.9.9.713.1.6
.1.3.6.1.4.1.9.9.713.1.6.1
.1.3.6.1.4.1.9.9.713.1.6.1.1
.1.3.6.1.4.1.9.9.713.1.6.1.1.1
.1.3.6.1.4.1.9.9.713.1.6.1.1.2
.1.3.6.1.4.1.9.9.713.1.6.1.1.3
.1.3.6.1.4.1.9.9.713.1.6.1.1.4
.1.3.6.1.4.1.9.9.713.1.6.2
.1.3.6.1.4.1.9.9.713.1.6.2.1
Enumeration
.1.3.6.1.4.1.9.9.713.1.6.2.1.1
.1.3.6.1.4.1.9.9.713.1.7
.1.3.6.1.4.1.9.9.713.1.7.1
.1.3.6.1.4.1.9.9.713.1.7.1.1
.1.3.6.1.4.1.9.9.713.1.7.1.1.1
.1.3.6.1.4.1.9.9.713.1.7.1.1.2
.1.3.6.1.4.1.9.9.713.1.7.1.1.3
.1.3.6.1.4.1.9.9.713.1.7.1.1.4
.1.3.6.1.4.1.9.9.713.1.8
Enumeration
.1.3.6.1.4.1.9.9.713.1.8.1
.1.3.6.1.4.1.9.9.713.1.8.2
.1.3.6.1.4.1.9.9.713.1.8.3
.1.3.6.1.4.1.9.9.713.1.9
.1.3.6.1.4.1.9.9.713.1.9.1
.1.3.6.1.4.1.9.9.713.1.9.2
.1.3.6.1.4.1.9.9.713.2
.1.3.6.1.4.1.9.9.713.2.1
.1.3.6.1.4.1.9.9.713.2.2
Dependencies (21) 10 direct · 11 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Conformance Groups (25)
A collection of object which provides the SGACL enforcement
information for all TrustSec capable Layer 3 interfaces
(excluding SVIs) at the device level.
.1.3.6.1.4.1.9.9.713.2.2.1
A collection of object which provides netflow monitor
information for IPv4 traffic drop packet due to SGACL
enforcement in the device.
.1.3.6.1.4.1.9.9.713.2.2.2
A collection of object which provides netflow monitor
information for IPv6 traffic drop packet due to SGACL
enforcement in the device.
.1.3.6.1.4.1.9.9.713.2.2.3
A collection of object which provides the SGACL enforcement
and VRF information for each VLAN.
.1.3.6.1.4.1.9.9.713.2.2.4
A collection of objects which provides the administratively
configured SGACL mapping information in the device.
.1.3.6.1.4.1.9.9.713.2.2.5
A collection of objects which provides the downloaded
SGACL mapping information in the device.
.1.3.6.1.4.1.9.9.713.2.2.6
A collection of objects which provides the operational
SGACL mapping information in the device.
.1.3.6.1.4.1.9.9.713.2.2.7
A collection of objects which provides software
statistics counters for unicast IP traffic subjected
to SGACL enforcement.
.1.3.6.1.4.1.9.9.713.2.2.8
A collection of objects which provides hardware
statistics counters for unicast IP traffic subjected
to SGACL enforcement.
.1.3.6.1.4.1.9.9.713.2.2.9
A collection of objects which provides software
statistics counters for unicast IP traffic subjected
to unicast default policy enforcement.
.1.3.6.1.4.1.9.9.713.2.2.10
A collection of objects which provides hardware
statistics counters for unicast IP traffic subjected to
unicast default policy enforcement.
.1.3.6.1.4.1.9.9.713.2.2.11
A collection of object which provides refreshing
of all peer policies in the device.
.1.3.6.1.4.1.9.9.713.2.2.12
A collection of object which provides peer policy
information in the device.
.1.3.6.1.4.1.9.9.713.2.2.13
A collection of objects which provides managed
information regarding the SGT propagation along with
Layer 3 traffic in the device.
.1.3.6.1.4.1.9.9.713.2.2.14
A collection of objects which provides managed
information for Layer3 Tranport policy enforcement on
capable interface in the device.
.1.3.6.1.4.1.9.9.713.2.2.15
A collection of objects which provides managed
information regarding IP-to-Sgt mapping in the device.
.1.3.6.1.4.1.9.9.713.2.2.16
A collection of object which provides SGT policy
information in the device.
.1.3.6.1.4.1.9.9.713.2.2.17
A collection of objects which provides managed
information regarding Interface-to-Sgt mapping in
the device.
.1.3.6.1.4.1.9.9.713.2.2.18
A collection of objects which provides sgt mapping
information for the IP traffic in the specified Vlan.
.1.3.6.1.4.1.9.9.713.2.2.19
A collection of objects which provides sgt Caching
information.
.1.3.6.1.4.1.9.9.713.2.2.20
A collection of objects which provides SGACL monitor
information.
.1.3.6.1.4.1.9.9.713.2.2.21
A collection of objects which provides monitor statistics
counters for unicast IP traffic subjected to SGACL
enforcement.
.1.3.6.1.4.1.9.9.713.2.2.22
A collection of objects providing notification control
for TrustSec policy notifications.
.1.3.6.1.4.1.9.9.713.2.2.23
A collection of notifications for TrustSec policy.
.1.3.6.1.4.1.9.9.713.2.2.24
A collection of objects providing the variable binding for
TrustSec policy notifications.
.1.3.6.1.4.1.9.9.713.2.2.25
Compliance Statements (2)

OID .1.3.6.1.4.1.9.9.713.2.1.1
The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
Required groups
mandatory ctspGlobalSgaclEnforcementGroup
mandatory ctspOperSgaclMappingGroup
mandatory ctspDownloadedSgaclMappingGroup
mandatory ctspIpSwStatisticsGroup
mandatory ctspDefSwStatisticsGroup
optional ctspVlanConfigGroup This group is mandatory only for platforms which support
SGACL enforcement for VLAN.
optional ctspConfigSgaclMappingGroup This group is mandatory only for platforms which support
statically configured SGACLs in the device.
optional ctspIpHwStatisticsGroup This group is mandatory only for platforms which support
hardware statistics counters for unicast IP traffic
subjected to SGACL enforcement.
optional ctspDefHwStatisticsGroup This group is mandatory only for platforms which support
hardware statistics counters for unicast IP traffic
subjected to default unicast policy enforcement.
optional ctspSgaclIpv4DropNetflowMonitorGroup This group is mandatory only for platforms which support
netflow monitor for IPv4 traffic drop packet due to SGACL
enforcement information in the device.
optional ctspSgaclIpv6DropNetflowMonitorGroup This group is mandatory only for platforms which support
netflow monitor for IPv6 traffic drop packet due to SGACL
enforcement information in the device.
optional ctspPeerPolicyGroup This group is mandatory only for platforms which support
peer policies information in the device.
optional ctspPeerPolicyActionGroup This group is mandatory only for platforms which support
refresh of all peer policies information in the device.
optional ctspLayer3TransportGroup This group is mandatory only for platforms which support
SGT propagation along Layer 3 traffic to network that is
not capable of TrustSec feature.
optional ctspIpSgtMappingGroup This group is mandatory only for platforms which support
IP-to-SGT mapping information.
optional ctspIfL3PolicyConfigGroup This group is mandatory only for platforms which support
Layer3 Transport policy enforcement on capable interface.
optional ctspSgtPolicyGroup This group is mandatory only for platforms which support
SGT policies information in the device.
Object refinements
ObjectAccessSyntaxDescription
ctspVlanConfigSgaclEnforcement readonly
Support for read-create access is not required.
ctspVlanConfigVrfName readonly
Support for read-create access is not required.
ctspVlanConfigStorageType readonly
Support for read-create access is not required.
ctspVlanConfigRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspConfigSgaclMappingStorageType readonly
Support for read-create access is not required.
ctspConfigSgaclMappingRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspSgaclEnforcementEnable readonly
Write access is not required.
ctspSgaclIpv4DropNetflowMonitor readonly
Write access is not required.
ctspSgaclIpv6DropNetflowMonitor readonly
Write access is not required.
ctspConfigSgaclMappingSgaclName readonly
Write access is not required.
ctspDefConfigIpv4Sgacls readonly
Write access is not required.
ctspDefConfigIpv6Sgacls readonly
Write access is not required.
ctspLayer3PolicyLocalConfig readonly
Write access is not required.
ctspIpSgtStorageType readonly
Support for read-create access is not required.
ctspIpSgtRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspIpSgtValue readonly
Write access is not required.
ctspIpSgtSource readonly
Write access is not required.
ctspIfL3Ipv4PolicyEnabled readonly
Write access is not required.
ctspIfL3Ipv6PolicyEnabled readonly
Write access is not required.
ctspAllPeerPolicyAction readonly
Write access is not required.
ctspPeerPolicyAction readonly
Write access is not required.
ctspAllSgtPolicyAction readonly
Write access is not required.
ctspDownloadedSgtPolicyAction readonly
Write access is not required.
ctspDownloadedDefSgtPolicyAction readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.713.2.1.2
The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
Required groups
mandatory ctspGlobalSgaclEnforcementGroup
mandatory ctspOperSgaclMappingGroup
mandatory ctspDownloadedSgaclMappingGroup
mandatory ctspIpSwStatisticsGroup
mandatory ctspDefSwStatisticsGroup
optional ctspVlanConfigGroup This group is mandatory only for platforms which support
SGACL enforcement for VLAN.
optional ctspConfigSgaclMappingGroup This group is mandatory only for platforms which support
statically configured SGACLs in the device.
optional ctspIpHwStatisticsGroup This group is mandatory only for platforms which support
hardware statistics counters for unicast IP traffic
subjected to SGACL enforcement.
optional ctspDefHwStatisticsGroup This group is mandatory only for platforms which support
hardware statistics counters for unicast IP traffic
subjected to default unicast policy enforcement.
optional ctspSgaclIpv4DropNetflowMonitorGroup This group is mandatory only for platforms which support
netflow monitor for IPv4 traffic drop packet due to SGACL
enforcement information in the device.
optional ctspSgaclIpv6DropNetflowMonitorGroup This group is mandatory only for platforms which support
netflow monitor for IPv6 traffic drop packet due to SGACL
enforcement information in the device.
optional ctspPeerPolicyGroup This group is mandatory only for platforms which support
peer policies information in the device.
optional ctspPeerPolicyActionGroup This group is mandatory only for platforms which support
refresh of all peer policies information in the device.
optional ctspLayer3TransportGroup This group is mandatory only for platforms which support
SGT propagation along Layer 3 traffic to network that is
not capable of TrustSec feature.
optional ctspIpSgtMappingGroup This group is mandatory only for platforms which support
IP-to-SGT mapping information.
optional ctspIfL3PolicyConfigGroup This group is mandatory only for platforms which support
Layer3 Transport policy enforcement on capable interface.
optional ctspSgtPolicyGroup This group is mandatory only for platforms which support
SGT policies information in the device.
optional ctspIfSgtMappingGroup This group is mandatory only for platforms which support
Interface-to-SGT mapping information.
optional ctspVlanSgtMappingGroup This group is mandatory only for platforms which support
Vlan-to-SGT mapping information.
optional ctspSgtCachingGroup This group is mandatory only for platforms which support
SGT-Caching feature.
optional ctspSgaclMonitorGroup This group is mandatory only for platforms which support
SGACL monitor feature.
optional ctspSgaclMonitorStatisticGroup This group is mandatory only for platforms which support
SGACL monitor statistic.
optional ctspNotifCtrlGroup This group is mandatory only for platforms which support
cisco TrustSec policy notifications.
optional ctspNotifGroup This group is mandatory only for platforms which support
cisco TrustSec policy notifications.
optional ctspNotifInfoGroup This group is mandatory only for platforms which support
cisco TrustSec policy notifications.
Object refinements
ObjectAccessSyntaxDescription
ctspVlanConfigSgaclEnforcement readonly
Support for read-create access is not required.
ctspVlanConfigVrfName readonly
Support for read-create access is not required.
ctspVlanConfigStorageType readonly
Support for read-create access is not required.
ctspVlanConfigRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspConfigSgaclMappingStorageType readonly
Support for read-create access is not required.
ctspConfigSgaclMappingRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspSgaclEnforcementEnable readonly
Write access is not required.
ctspSgaclIpv4DropNetflowMonitor readonly
Write access is not required.
ctspSgaclIpv6DropNetflowMonitor readonly
Write access is not required.
ctspConfigSgaclMappingSgaclName readonly
Write access is not required.
ctspDefConfigIpv4Sgacls readonly
Write access is not required.
ctspDefConfigIpv6Sgacls readonly
Write access is not required.
ctspLayer3PolicyLocalConfig readonly
Write access is not required.
ctspIpSgtStorageType readonly
Support for read-create access is not required.
ctspIpSgtRowStatus readonly
active(1)
Support for 'createAndWait' is not required.
ctspIpSgtValue readonly
Write access is not required.
ctspIpSgtSource readonly
Write access is not required.
ctspIfL3Ipv4PolicyEnabled readonly
Write access is not required.
ctspIfL3Ipv6PolicyEnabled readonly
Write access is not required.
ctspAllPeerPolicyAction readonly
Write access is not required.
ctspPeerPolicyAction readonly
Write access is not required.
ctspAllSgtPolicyAction readonly
Write access is not required.
ctspDownloadedSgtPolicyAction readonly
Write access is not required.
ctspDownloadedDefSgtPolicyAction readonly
Write access is not required.
ctspDefConfigIpv4SgaclsMonitor readonly
Write access is not required.
ctspDefConfigIpv6SgaclsMonitor readonly
Write access is not required.
ctspSgaclMonitorEnable readonly
Write access is not required.
ctspIfSgtValue readonly
Write access is not required.
ctspIfSgName readonly
Write access is not required.
ctspIfSgtStorageType readonly
Read-create access is not required.
ctspIfSgtRowStatus readonly
active(1)
Read-create access is not required.
ctspVlanSgtMapValue readonly
Write access is not required.
ctspVlanSgtStorageType readonly
Read-create access is not required.
ctspVlanSgtRowStatus readonly
active(1)
Read-create access is not required.
ctspConfigSgaclMonitor readonly
Write access is not required.
ctspSgtCachingMode readonly
Write access is not required.
ctspSgtCachingVlansFirst2K readonly
Write access is not required.
ctspSgtCachingVlansSecond2K readonly
Write access is not required.
ctspPeerPolicyUpdatedNotifEnable readonly
Write access is not required.
ctspAuthorizationSgaclFailNotifEnable readonly
Write access is not required.
Notifications / Traps (2)
NameOIDDescription
.1.3.6.1.4.1.9.9.713.0.1
A ctspPeerPolicyUpdatedNotif is generated when
the SGT value of a peer device has been updated.
.1.3.6.1.4.1.9.9.713.0.2
A ctspAuthorizationSgaclFailNotif is generated
when the authorization of SGACL fails.