CISCO-TRUSTSEC-POLICY-MIB
This MIB module defines managed objects that facilitate the
management of various policies within the Cisco Trusted Security
(TrustSec) infrastructure.
The information available through this MIB includes:
o Device and interface level configuration for enabling
SGACL (Security Group Access Control List) enforcement
on Layer2/3 traffic.
o Administrative and operational SGACL mapping to Security
Group Tag (SGT).
o Various statistics counters for traffic subject to SGACL
enforcement.
o TrustSec policies with respect to peer device.
o Interface level configuration for enabling the propagation
of SGT along with the Layer 3 traffic in portions of network
which does not have the capability to support TrustSec
feature.
o TrustSec policies with respect to SGT propagation with
Layer 3 traffic.
The following terms are used throughout this MIB:
VRF: Virtual Routing and Forwarding.
SGACL: Security Group Access Control List.
ACE: Access Control Entries.
SXP: SGT Propagation Protocol.
SVI: Switch Virtual Interface.
IPM: Identity Port Mapping.
SGT (Security Group Tag) is a unique 16 bits value assigned
to every security group and used by network devices to
enforce SGACL.
Peer is another device connected to the local device on the
other side of a TrustSec link.
Default Policy: Policy applied to traffic when there is
no explicit policy between the SGT associated with the
originator of the traffic and the SGT associated with
the destination of the traffic.
- Source file
CISCO-TRUSTSEC-POLICY-MIB- Last revised
- Identity
ciscoTrustSecPolicyMIB- Base OID
1.3.6.1.4.1.9.9.713
Imported Objects
| CISCO-SMI | ciscoMgmt |
| CISCO-TC | Cisco2KVlanList CiscoVrfName |
| CISCO-TRUSTSEC-TC-MIB | CtsAclList CtsAclListOrEmpty CtsAclName CtsAclNameOrEmpty CtsGenerationId CtsSecurityGroupTag CtsSgaclMonitorMode |
| IF-MIB | ifIndex |
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType |
| Q-BRIDGE-MIB | VlanIndex |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter64 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | DateAndTime RowStatus StorageType TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-TRUSTSEC-POLICY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-TRUSTSEC-POLICY-MIB::ciscoTrustSecPolicyMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-POLICY-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-POLICY-MIB::ciscoTrustSecPolicyMIB'
Objects (169)
Showing 169 of 169 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.713 |
||
.1.3.6.1.4.1.9.9.713.0 |
||
.1.3.6.1.4.1.9.9.713.1 |
||
.1.3.6.1.4.1.9.9.713.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.1.4.1.6 |
||
.1.3.6.1.4.1.9.9.713.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.6 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.1.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.10 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.4.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.2 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.3 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.5 |
||
|
Bits
|
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.6 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.4.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.5.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.3 |
||
|
Bits
|
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.4 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.5.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.6 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.6.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.3 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.4 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.6 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.7 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.8 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.6.1.9 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.7 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.7.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.1 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.2 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.5 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.6 |
|
.1.3.6.1.4.1.9.9.713.1.1.2.7.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.8 |
||
.1.3.6.1.4.1.9.9.713.1.1.2.9 |
||
.1.3.6.1.4.1.9.9.713.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.6 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.8 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.1.1.9 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.6 |
||
.1.3.6.1.4.1.9.9.713.1.1.3.2.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.10 |
||
.1.3.6.1.4.1.9.9.713.1.10.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.10.2 |
|
.1.3.6.1.4.1.9.9.713.1.10.3 |
||
.1.3.6.1.4.1.9.9.713.1.2 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.2.1 |
|
.1.3.6.1.4.1.9.9.713.1.2.2 |
||
.1.3.6.1.4.1.9.9.713.1.2.2.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.2.2.1.3 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.4 |
|
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.5 |
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.6 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.2.2.1.7 |
|
.1.3.6.1.4.1.9.9.713.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.3.1 |
||
.1.3.6.1.4.1.9.9.713.1.3.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.3.1.1.1 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.3.1.1.2 |
|
.1.3.6.1.4.1.9.9.713.1.3.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.3.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.3.1.1.5 |
||
.1.3.6.1.4.1.9.9.713.1.3.2 |
||
.1.3.6.1.4.1.9.9.713.1.3.2.1 |
||
.1.3.6.1.4.1.9.9.713.1.3.2.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.3.2.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.4.1 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1.4 |
||
|
|
.1.3.6.1.4.1.9.9.713.1.4.1.1.5 |
|
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.4.1.1.6 |
.1.3.6.1.4.1.9.9.713.1.4.1.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.4.1.1.8 |
||
.1.3.6.1.4.1.9.9.713.1.5 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.5.1 |
|
.1.3.6.1.4.1.9.9.713.1.5.2 |
||
.1.3.6.1.4.1.9.9.713.1.5.2.1 |
||
.1.3.6.1.4.1.9.9.713.1.5.2.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.5.2.1.2 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.713.1.5.2.1.3 |
|
.1.3.6.1.4.1.9.9.713.1.5.2.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.5.2.1.5 |
|
.1.3.6.1.4.1.9.9.713.1.5.3 |
||
.1.3.6.1.4.1.9.9.713.1.5.3.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.5.3.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.5.3.1.2 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.713.1.5.3.1.3 |
|
.1.3.6.1.4.1.9.9.713.1.5.3.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.5.3.1.5 |
|
.1.3.6.1.4.1.9.9.713.1.6 |
||
.1.3.6.1.4.1.9.9.713.1.6.1 |
||
.1.3.6.1.4.1.9.9.713.1.6.1.1 |
||
|
|
.1.3.6.1.4.1.9.9.713.1.6.1.1.1 |
|
|
|
.1.3.6.1.4.1.9.9.713.1.6.1.1.2 |
|
.1.3.6.1.4.1.9.9.713.1.6.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.6.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.6.2 |
||
.1.3.6.1.4.1.9.9.713.1.6.2.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.6.2.1.1 |
|
.1.3.6.1.4.1.9.9.713.1.7 |
||
.1.3.6.1.4.1.9.9.713.1.7.1 |
||
.1.3.6.1.4.1.9.9.713.1.7.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.7.1.1.1 |
||
.1.3.6.1.4.1.9.9.713.1.7.1.1.2 |
||
.1.3.6.1.4.1.9.9.713.1.7.1.1.3 |
||
.1.3.6.1.4.1.9.9.713.1.7.1.1.4 |
||
.1.3.6.1.4.1.9.9.713.1.8 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.713.1.8.1 |
|
.1.3.6.1.4.1.9.9.713.1.8.2 |
||
.1.3.6.1.4.1.9.9.713.1.8.3 |
||
.1.3.6.1.4.1.9.9.713.1.9 |
||
.1.3.6.1.4.1.9.9.713.1.9.1 |
||
.1.3.6.1.4.1.9.9.713.1.9.2 |
||
.1.3.6.1.4.1.9.9.713.2 |
||
.1.3.6.1.4.1.9.9.713.2.1 |
||
.1.3.6.1.4.1.9.9.713.2.2 |
Dependencies (21) 10 direct · 11 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-TCcisco
- CISCO-TRUSTSEC-TC-MIBcisco
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- INET-ADDRESS-MIBrfc
- BRIDGE-MIBrfc
- P-BRIDGE-MIBrfc
- RMON-MIBrfc
- RFC-1212rfc
- RFC1155-SMIrfc
- RFC1213-MIBrfc
- RFC1271-MIBrfc
- TOKEN-RING-RMON-MIBrfc
- RMON2-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- Q-BRIDGE-MIBrfc
- CISCO-TRUSTSEC-POLICY-MIBciscoselected
Conformance Groups (25)
|
A collection of object which provides the SGACL enforcement
information for all TrustSec capable Layer 3 interfaces (excluding SVIs) at the device level. |
.1.3.6.1.4.1.9.9.713.2.2.1
|
|
|
A collection of object which provides netflow monitor
information for IPv4 traffic drop packet due to SGACL enforcement in the device. |
.1.3.6.1.4.1.9.9.713.2.2.2
|
|
|
A collection of object which provides netflow monitor
information for IPv6 traffic drop packet due to SGACL enforcement in the device. |
.1.3.6.1.4.1.9.9.713.2.2.3
|
|
|
ctspVlanConfigSgaclEnforcement ctspVlanSviActive ctspVlanConfigVrfName ctspVlanConfigStorageType ctspVlanConfigRowStatus
A collection of object which provides the SGACL enforcement
and VRF information for each VLAN. |
.1.3.6.1.4.1.9.9.713.2.2.4
|
|
|
ctspConfigSgaclMappingSgaclName ctspConfigSgaclMappingStorageType ctspConfigSgaclMappingRowStatus ctspDefConfigIpv4Sgacls ctspDefConfigIpv6Sgacls
A collection of objects which provides the administratively
configured SGACL mapping information in the device. |
.1.3.6.1.4.1.9.9.713.2.2.5
|
|
|
ctspDownloadedSgaclName ctspDownloadedSgaclGenId ctspDownloadedIpTrafficType ctspDefDownloadedSgaclName ctspDefDownloadedSgaclGenId ctspDefDownloadedIpTrafficType
A collection of objects which provides the downloaded
SGACL mapping information in the device. |
.1.3.6.1.4.1.9.9.713.2.2.6
|
|
|
ctspOperationalSgaclName ctspOperationalSgaclGenId ctspOperSgaclMappingSource ctspOperSgaclConfigSource ctspDefOperationalSgaclName ctspDefOperationalSgaclGenId ctspDefOperSgaclMappingSource ctspDefOperSgaclConfigSource
A collection of objects which provides the operational
SGACL mapping information in the device. |
.1.3.6.1.4.1.9.9.713.2.2.7
|
|
|
A collection of objects which provides software
statistics counters for unicast IP traffic subjected to SGACL enforcement. |
.1.3.6.1.4.1.9.9.713.2.2.8
|
|
|
A collection of objects which provides hardware
statistics counters for unicast IP traffic subjected to SGACL enforcement. |
.1.3.6.1.4.1.9.9.713.2.2.9
|
|
|
A collection of objects which provides software
statistics counters for unicast IP traffic subjected to unicast default policy enforcement. |
.1.3.6.1.4.1.9.9.713.2.2.10
|
|
|
A collection of objects which provides hardware
statistics counters for unicast IP traffic subjected to unicast default policy enforcement. |
.1.3.6.1.4.1.9.9.713.2.2.11
|
|
|
A collection of object which provides refreshing
of all peer policies in the device. |
.1.3.6.1.4.1.9.9.713.2.2.12
|
|
|
ctspPeerSgt ctspPeerSgtGenId ctspPeerTrustState ctspPeerPolicyLifeTime ctspPeerPolicyLastUpdate ctspPeerPolicyAction
A collection of object which provides peer policy
information in the device. |
.1.3.6.1.4.1.9.9.713.2.2.13
|
|
|
A collection of objects which provides managed
information regarding the SGT propagation along with Layer 3 traffic in the device. |
.1.3.6.1.4.1.9.9.713.2.2.14
|
|
|
A collection of objects which provides managed
information for Layer3 Tranport policy enforcement on capable interface in the device. |
.1.3.6.1.4.1.9.9.713.2.2.15
|
|
|
A collection of objects which provides managed
information regarding IP-to-Sgt mapping in the device. |
.1.3.6.1.4.1.9.9.713.2.2.16
|
|
|
ctspAllSgtPolicyAction ctspDownloadedSgtPolicySgtGenId ctspDownloadedSgtPolicyLifeTime ctspDownloadedSgtPolicyLastUpdate ctspDownloadedSgtPolicyAction ctspDownloadedDefSgtPolicySgtGenId ctspDownloadedDefSgtPolicyLifeTime ctspDownloadedDefSgtPolicyLastUpdate ctspDownloadedDefSgtPolicyAction
A collection of object which provides SGT policy
information in the device. |
.1.3.6.1.4.1.9.9.713.2.2.17
|
|
|
A collection of objects which provides managed
information regarding Interface-to-Sgt mapping in the device. |
.1.3.6.1.4.1.9.9.713.2.2.18
|
|
|
A collection of objects which provides sgt mapping
information for the IP traffic in the specified Vlan. |
.1.3.6.1.4.1.9.9.713.2.2.19
|
|
|
A collection of objects which provides sgt Caching
information. |
.1.3.6.1.4.1.9.9.713.2.2.20
|
|
|
ctspSgaclMonitorEnable ctspConfigSgaclMonitor ctspDefConfigIpv4SgaclsMonitor ctspDefConfigIpv6SgaclsMonitor ctspDownloadedSgaclMonitor ctspDefDownloadedSgaclMonitor ctspOperSgaclMonitor ctspDefOperSgaclMonitor
A collection of objects which provides SGACL monitor
information. |
.1.3.6.1.4.1.9.9.713.2.2.21
|
|
|
A collection of objects which provides monitor statistics
counters for unicast IP traffic subjected to SGACL enforcement. |
.1.3.6.1.4.1.9.9.713.2.2.22
|
|
|
A collection of objects providing notification control
for TrustSec policy notifications. |
.1.3.6.1.4.1.9.9.713.2.2.23
|
|
|
A collection of notifications for TrustSec policy.
|
.1.3.6.1.4.1.9.9.713.2.2.24
|
|
|
A collection of objects providing the variable binding for
TrustSec policy notifications. |
.1.3.6.1.4.1.9.9.713.2.2.25
|
Compliance Statements (2)
OID
.1.3.6.1.4.1.9.9.713.2.1.1The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
Required groups
| mandatory | ctspGlobalSgaclEnforcementGroup | |
| mandatory | ctspOperSgaclMappingGroup | |
| mandatory | ctspDownloadedSgaclMappingGroup | |
| mandatory | ctspIpSwStatisticsGroup | |
| mandatory | ctspDefSwStatisticsGroup | |
| optional | ctspVlanConfigGroup |
This group is mandatory only for platforms which support SGACL enforcement for VLAN. |
| optional | ctspConfigSgaclMappingGroup |
This group is mandatory only for platforms which support statically configured SGACLs in the device. |
| optional | ctspIpHwStatisticsGroup |
This group is mandatory only for platforms which support hardware statistics counters for unicast IP traffic subjected to SGACL enforcement. |
| optional | ctspDefHwStatisticsGroup |
This group is mandatory only for platforms which support hardware statistics counters for unicast IP traffic subjected to default unicast policy enforcement. |
| optional | ctspSgaclIpv4DropNetflowMonitorGroup |
This group is mandatory only for platforms which support netflow monitor for IPv4 traffic drop packet due to SGACL enforcement information in the device. |
| optional | ctspSgaclIpv6DropNetflowMonitorGroup |
This group is mandatory only for platforms which support netflow monitor for IPv6 traffic drop packet due to SGACL enforcement information in the device. |
| optional | ctspPeerPolicyGroup |
This group is mandatory only for platforms which support peer policies information in the device. |
| optional | ctspPeerPolicyActionGroup |
This group is mandatory only for platforms which support refresh of all peer policies information in the device. |
| optional | ctspLayer3TransportGroup |
This group is mandatory only for platforms which support SGT propagation along Layer 3 traffic to network that is not capable of TrustSec feature. |
| optional | ctspIpSgtMappingGroup |
This group is mandatory only for platforms which support IP-to-SGT mapping information. |
| optional | ctspIfL3PolicyConfigGroup |
This group is mandatory only for platforms which support Layer3 Transport policy enforcement on capable interface. |
| optional | ctspSgtPolicyGroup |
This group is mandatory only for platforms which support SGT policies information in the device. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| ctspVlanConfigSgaclEnforcement | readonly | Support for read-create access is not required. | |
| ctspVlanConfigVrfName | readonly | Support for read-create access is not required. | |
| ctspVlanConfigStorageType | readonly | Support for read-create access is not required. | |
| ctspVlanConfigRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspConfigSgaclMappingStorageType | readonly | Support for read-create access is not required. | |
| ctspConfigSgaclMappingRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspSgaclEnforcementEnable | readonly | Write access is not required. | |
| ctspSgaclIpv4DropNetflowMonitor | readonly | Write access is not required. | |
| ctspSgaclIpv6DropNetflowMonitor | readonly | Write access is not required. | |
| ctspConfigSgaclMappingSgaclName | readonly | Write access is not required. | |
| ctspDefConfigIpv4Sgacls | readonly | Write access is not required. | |
| ctspDefConfigIpv6Sgacls | readonly | Write access is not required. | |
| ctspLayer3PolicyLocalConfig | readonly | Write access is not required. | |
| ctspIpSgtStorageType | readonly | Support for read-create access is not required. | |
| ctspIpSgtRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspIpSgtValue | readonly | Write access is not required. | |
| ctspIpSgtSource | readonly | Write access is not required. | |
| ctspIfL3Ipv4PolicyEnabled | readonly | Write access is not required. | |
| ctspIfL3Ipv6PolicyEnabled | readonly | Write access is not required. | |
| ctspAllPeerPolicyAction | readonly | Write access is not required. | |
| ctspPeerPolicyAction | readonly | Write access is not required. | |
| ctspAllSgtPolicyAction | readonly | Write access is not required. | |
| ctspDownloadedSgtPolicyAction | readonly | Write access is not required. | |
| ctspDownloadedDefSgtPolicyAction | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.713.2.1.2The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
Required groups
| mandatory | ctspGlobalSgaclEnforcementGroup | |
| mandatory | ctspOperSgaclMappingGroup | |
| mandatory | ctspDownloadedSgaclMappingGroup | |
| mandatory | ctspIpSwStatisticsGroup | |
| mandatory | ctspDefSwStatisticsGroup | |
| optional | ctspVlanConfigGroup |
This group is mandatory only for platforms which support SGACL enforcement for VLAN. |
| optional | ctspConfigSgaclMappingGroup |
This group is mandatory only for platforms which support statically configured SGACLs in the device. |
| optional | ctspIpHwStatisticsGroup |
This group is mandatory only for platforms which support hardware statistics counters for unicast IP traffic subjected to SGACL enforcement. |
| optional | ctspDefHwStatisticsGroup |
This group is mandatory only for platforms which support hardware statistics counters for unicast IP traffic subjected to default unicast policy enforcement. |
| optional | ctspSgaclIpv4DropNetflowMonitorGroup |
This group is mandatory only for platforms which support netflow monitor for IPv4 traffic drop packet due to SGACL enforcement information in the device. |
| optional | ctspSgaclIpv6DropNetflowMonitorGroup |
This group is mandatory only for platforms which support netflow monitor for IPv6 traffic drop packet due to SGACL enforcement information in the device. |
| optional | ctspPeerPolicyGroup |
This group is mandatory only for platforms which support peer policies information in the device. |
| optional | ctspPeerPolicyActionGroup |
This group is mandatory only for platforms which support refresh of all peer policies information in the device. |
| optional | ctspLayer3TransportGroup |
This group is mandatory only for platforms which support SGT propagation along Layer 3 traffic to network that is not capable of TrustSec feature. |
| optional | ctspIpSgtMappingGroup |
This group is mandatory only for platforms which support IP-to-SGT mapping information. |
| optional | ctspIfL3PolicyConfigGroup |
This group is mandatory only for platforms which support Layer3 Transport policy enforcement on capable interface. |
| optional | ctspSgtPolicyGroup |
This group is mandatory only for platforms which support SGT policies information in the device. |
| optional | ctspIfSgtMappingGroup |
This group is mandatory only for platforms which support Interface-to-SGT mapping information. |
| optional | ctspVlanSgtMappingGroup |
This group is mandatory only for platforms which support Vlan-to-SGT mapping information. |
| optional | ctspSgtCachingGroup |
This group is mandatory only for platforms which support SGT-Caching feature. |
| optional | ctspSgaclMonitorGroup |
This group is mandatory only for platforms which support SGACL monitor feature. |
| optional | ctspSgaclMonitorStatisticGroup |
This group is mandatory only for platforms which support SGACL monitor statistic. |
| optional | ctspNotifCtrlGroup |
This group is mandatory only for platforms which support cisco TrustSec policy notifications. |
| optional | ctspNotifGroup |
This group is mandatory only for platforms which support cisco TrustSec policy notifications. |
| optional | ctspNotifInfoGroup |
This group is mandatory only for platforms which support cisco TrustSec policy notifications. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| ctspVlanConfigSgaclEnforcement | readonly | Support for read-create access is not required. | |
| ctspVlanConfigVrfName | readonly | Support for read-create access is not required. | |
| ctspVlanConfigStorageType | readonly | Support for read-create access is not required. | |
| ctspVlanConfigRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspConfigSgaclMappingStorageType | readonly | Support for read-create access is not required. | |
| ctspConfigSgaclMappingRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspSgaclEnforcementEnable | readonly | Write access is not required. | |
| ctspSgaclIpv4DropNetflowMonitor | readonly | Write access is not required. | |
| ctspSgaclIpv6DropNetflowMonitor | readonly | Write access is not required. | |
| ctspConfigSgaclMappingSgaclName | readonly | Write access is not required. | |
| ctspDefConfigIpv4Sgacls | readonly | Write access is not required. | |
| ctspDefConfigIpv6Sgacls | readonly | Write access is not required. | |
| ctspLayer3PolicyLocalConfig | readonly | Write access is not required. | |
| ctspIpSgtStorageType | readonly | Support for read-create access is not required. | |
| ctspIpSgtRowStatus | readonly |
active(1)
|
Support for 'createAndWait' is not required. |
| ctspIpSgtValue | readonly | Write access is not required. | |
| ctspIpSgtSource | readonly | Write access is not required. | |
| ctspIfL3Ipv4PolicyEnabled | readonly | Write access is not required. | |
| ctspIfL3Ipv6PolicyEnabled | readonly | Write access is not required. | |
| ctspAllPeerPolicyAction | readonly | Write access is not required. | |
| ctspPeerPolicyAction | readonly | Write access is not required. | |
| ctspAllSgtPolicyAction | readonly | Write access is not required. | |
| ctspDownloadedSgtPolicyAction | readonly | Write access is not required. | |
| ctspDownloadedDefSgtPolicyAction | readonly | Write access is not required. | |
| ctspDefConfigIpv4SgaclsMonitor | readonly | Write access is not required. | |
| ctspDefConfigIpv6SgaclsMonitor | readonly | Write access is not required. | |
| ctspSgaclMonitorEnable | readonly | Write access is not required. | |
| ctspIfSgtValue | readonly | Write access is not required. | |
| ctspIfSgName | readonly | Write access is not required. | |
| ctspIfSgtStorageType | readonly | Read-create access is not required. | |
| ctspIfSgtRowStatus | readonly |
active(1)
|
Read-create access is not required. |
| ctspVlanSgtMapValue | readonly | Write access is not required. | |
| ctspVlanSgtStorageType | readonly | Read-create access is not required. | |
| ctspVlanSgtRowStatus | readonly |
active(1)
|
Read-create access is not required. |
| ctspConfigSgaclMonitor | readonly | Write access is not required. | |
| ctspSgtCachingMode | readonly | Write access is not required. | |
| ctspSgtCachingVlansFirst2K | readonly | Write access is not required. | |
| ctspSgtCachingVlansSecond2K | readonly | Write access is not required. | |
| ctspPeerPolicyUpdatedNotifEnable | readonly | Write access is not required. | |
| ctspAuthorizationSgaclFailNotifEnable | readonly | Write access is not required. |
Notifications / Traps (2)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.713.0.1 |
A ctspPeerPolicyUpdatedNotif is generated when
the SGT value of a peer device has been updated. |
|
.1.3.6.1.4.1.9.9.713.0.2 |
A ctspAuthorizationSgaclFailNotif is generated
when the authorization of SGACL fails. |