CISCO-TRUSTSEC-SXP-MIB

        This MIB module is for the configuration and status query
of SGT Exchange Protocol over TCP (SXPoTCP) feature of the
device on the Cisco's Trusted Security (TrustSec) system.
        
Security Group Tag (SGT) identifying its source, assigned to a
packet on ingress to a TrustSec cloud, and used to determine
security and other policy to be applied to it along its path
through the cloud.
        
SXPoTCP protocol extends the original SGT Exchange Protocol
(SXP) protocol to enable a much wider array of deployment
scenarios.  This MIB uses the term SXP to refer to SXPoTCP.
        
TrustSec secures a network fabric by authenticating and
authorizing each device connecting to the network, allowing
for the encryption, authentication and replay protection of data
traffic on a hop by hop basis.  SXP allows the deployment
of RBACL, a key component of the TrustSec architecture, in the
absence of TrustSec capable hardware.
    
Source file
CISCO-TRUSTSEC-SXP-MIB
Last revised
Identity
ciscoTrustSecSxpMIB
Base OID
1.3.6.1.4.1.9.9.720
Imported Objects
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-TRUSTSEC-SXP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-TRUSTSEC-SXP-MIB::ciscoTrustSecSxpMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-TRUSTSEC-SXP-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-TRUSTSEC-SXP-MIB::ciscoTrustSecSxpMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (106)
.1.3.6.1.4.1.9.9.720
.1.3.6.1.4.1.9.9.720.0
.1.3.6.1.4.1.9.9.720.1
.1.3.6.1.4.1.9.9.720.1.1
.1.3.6.1.4.1.9.9.720.1.1.1
.1.3.6.1.4.1.9.9.720.1.1.10
.1.3.6.1.4.1.9.9.720.1.1.11
.1.3.6.1.4.1.9.9.720.1.1.12
.1.3.6.1.4.1.9.9.720.1.1.13
.1.3.6.1.4.1.9.9.720.1.1.14
.1.3.6.1.4.1.9.9.720.1.1.15
.1.3.6.1.4.1.9.9.720.1.1.16
.1.3.6.1.4.1.9.9.720.1.1.17
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.1.18
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.1.19
.1.3.6.1.4.1.9.9.720.1.1.2
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.1.20
Enumeration
.1.3.6.1.4.1.9.9.720.1.1.21
.1.3.6.1.4.1.9.9.720.1.1.3
.1.3.6.1.4.1.9.9.720.1.1.4
.1.3.6.1.4.1.9.9.720.1.1.5
.1.3.6.1.4.1.9.9.720.1.1.6
.1.3.6.1.4.1.9.9.720.1.1.7
.1.3.6.1.4.1.9.9.720.1.1.8
.1.3.6.1.4.1.9.9.720.1.1.9
.1.3.6.1.4.1.9.9.720.1.2
.1.3.6.1.4.1.9.9.720.1.2.1
.1.3.6.1.4.1.9.9.720.1.2.1.1
.1.3.6.1.4.1.9.9.720.1.2.1.1.1
.1.3.6.1.4.1.9.9.720.1.2.1.1.10
.1.3.6.1.4.1.9.9.720.1.2.1.1.11
.1.3.6.1.4.1.9.9.720.1.2.1.1.12
Enumeration
.1.3.6.1.4.1.9.9.720.1.2.1.1.13
Enumeration
.1.3.6.1.4.1.9.9.720.1.2.1.1.14
.1.3.6.1.4.1.9.9.720.1.2.1.1.15
.1.3.6.1.4.1.9.9.720.1.2.1.1.16
.1.3.6.1.4.1.9.9.720.1.2.1.1.17
.1.3.6.1.4.1.9.9.720.1.2.1.1.18
.1.3.6.1.4.1.9.9.720.1.2.1.1.19
.1.3.6.1.4.1.9.9.720.1.2.1.1.2
.1.3.6.1.4.1.9.9.720.1.2.1.1.20
Enumeration
.1.3.6.1.4.1.9.9.720.1.2.1.1.21
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.2.1.1.22
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.2.1.1.23
secondsUnsigned32
.1.3.6.1.4.1.9.9.720.1.2.1.1.24
.1.3.6.1.4.1.9.9.720.1.2.1.1.25
Bits
.1.3.6.1.4.1.9.9.720.1.2.1.1.26
.1.3.6.1.4.1.9.9.720.1.2.1.1.27
.1.3.6.1.4.1.9.9.720.1.2.1.1.28
OctetString
.1.3.6.1.4.1.9.9.720.1.2.1.1.3
.1.3.6.1.4.1.9.9.720.1.2.1.1.4
.1.3.6.1.4.1.9.9.720.1.2.1.1.5
.1.3.6.1.4.1.9.9.720.1.2.1.1.6
.1.3.6.1.4.1.9.9.720.1.2.1.1.7
Enumeration
.1.3.6.1.4.1.9.9.720.1.2.1.1.8
.1.3.6.1.4.1.9.9.720.1.2.1.1.9
.1.3.6.1.4.1.9.9.720.1.3
.1.3.6.1.4.1.9.9.720.1.3.1
.1.3.6.1.4.1.9.9.720.1.3.1.1
.1.3.6.1.4.1.9.9.720.1.3.1.1.1
.1.3.6.1.4.1.9.9.720.1.3.1.1.2
OctetString
.1.3.6.1.4.1.9.9.720.1.3.1.1.3
.1.3.6.1.4.1.9.9.720.1.3.1.1.4
OctetString
.1.3.6.1.4.1.9.9.720.1.3.1.1.5
.1.3.6.1.4.1.9.9.720.1.3.1.1.6
.1.3.6.1.4.1.9.9.720.1.3.1.1.7
.1.3.6.1.4.1.9.9.720.1.3.1.1.8
Enumeration
.1.3.6.1.4.1.9.9.720.1.3.1.1.9
.1.3.6.1.4.1.9.9.720.1.3.2
.1.3.6.1.4.1.9.9.720.1.3.2.1
.1.3.6.1.4.1.9.9.720.1.3.2.1.1
OctetString
.1.3.6.1.4.1.9.9.720.1.3.2.1.10
Enumeration
.1.3.6.1.4.1.9.9.720.1.3.2.1.11
.1.3.6.1.4.1.9.9.720.1.3.2.1.2
OctetString
.1.3.6.1.4.1.9.9.720.1.3.2.1.3
.1.3.6.1.4.1.9.9.720.1.3.2.1.4
.1.3.6.1.4.1.9.9.720.1.3.2.1.5
OctetString
.1.3.6.1.4.1.9.9.720.1.3.2.1.6
.1.3.6.1.4.1.9.9.720.1.3.2.1.7
.1.3.6.1.4.1.9.9.720.1.3.2.1.8
.1.3.6.1.4.1.9.9.720.1.3.2.1.9
.1.3.6.1.4.1.9.9.720.1.4
.1.3.6.1.4.1.9.9.720.1.4.1
.1.3.6.1.4.1.9.9.720.1.4.2
.1.3.6.1.4.1.9.9.720.1.4.3
.1.3.6.1.4.1.9.9.720.1.4.4
.1.3.6.1.4.1.9.9.720.1.4.5
.1.3.6.1.4.1.9.9.720.1.4.6
.1.3.6.1.4.1.9.9.720.1.4.7
.1.3.6.1.4.1.9.9.720.1.4.8
.1.3.6.1.4.1.9.9.720.1.4.9
.1.3.6.1.4.1.9.9.720.1.5
.1.3.6.1.4.1.9.9.720.1.5.1
.1.3.6.1.4.1.9.9.720.1.5.10
.1.3.6.1.4.1.9.9.720.1.5.11
.1.3.6.1.4.1.9.9.720.1.5.2
.1.3.6.1.4.1.9.9.720.1.5.3
.1.3.6.1.4.1.9.9.720.1.5.4
.1.3.6.1.4.1.9.9.720.1.5.5
.1.3.6.1.4.1.9.9.720.1.5.6
.1.3.6.1.4.1.9.9.720.1.5.7
.1.3.6.1.4.1.9.9.720.1.5.8
.1.3.6.1.4.1.9.9.720.1.5.9
.1.3.6.1.4.1.9.9.720.2
.1.3.6.1.4.1.9.9.720.2.1
.1.3.6.1.4.1.9.9.720.2.2
Dependencies (11) 9 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Conformance Groups (17)
A collection of objects providing management functionality
of global SXP configuration.
.1.3.6.1.4.1.9.9.720.2.2.1
A collection of objects providing management functionality
of SXP connections.
.1.3.6.1.4.1.9.9.720.2.2.2
A collection of objects providing management functionality
of SGT mapping for SXP.
.1.3.6.1.4.1.9.9.720.2.2.3
A collection of object(s) providing version information
for SXP.
.1.3.6.1.4.1.9.9.720.2.2.4
A collection of object(s) providing logging control
for SXP binding.
.1.3.6.1.4.1.9.9.720.2.2.5
A collection of object(s) providing variable binding
information for SXP notifications.
.1.3.6.1.4.1.9.9.720.2.2.6
A collection of object(s) providing detailed error messages
for SXP notifications.
.1.3.6.1.4.1.9.9.720.2.2.7
A collection of object(s) providing SXP node ID information
for the system.
.1.3.6.1.4.1.9.9.720.2.2.8
A collection of objects providing management functionality
of SGT mapping and expansion for SXP.
.1.3.6.1.4.1.9.9.720.2.2.9
A collection of objects providing notification control
for SXP.
.1.3.6.1.4.1.9.9.720.2.2.10
A collection of notifications for SXP.
.1.3.6.1.4.1.9.9.720.2.2.11
A collection of objects providing global
hold-time information for SXP connections.
.1.3.6.1.4.1.9.9.720.2.2.12
A collection of objects providing hold-time
information for each SXP connection.
.1.3.6.1.4.1.9.9.720.2.2.13
A collection of object(s) providing capability
information for each SXP connection.
.1.3.6.1.4.1.9.9.720.2.2.14
A collection of object(s) providing SXP version
capability information.
.1.3.6.1.4.1.9.9.720.2.2.15
A collection of object(s) providing Peer Sequence
information.
.1.3.6.1.4.1.9.9.720.2.2.16
A collection of object(s) providing Bi-directional
SXP information.
.1.3.6.1.4.1.9.9.720.2.2.17
Compliance Statements (4)

OID .1.3.6.1.4.1.9.9.720.2.1.1
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
Required groups
Object refinements
ObjectAccessSyntaxDescription
ctsxSxpEnable readonly
Write access is not required.
ctsxSxpConfigDefaultPasswordType readonly
Write access is not required.
ctsxSxpConfigDefaultPassword readonly
Write access is not required.
ctsxSxpDefaultSourceAddrType readonly
Write access is not required.
ctsxSxpDefaultSourceAddr readonly
Write access is not required.
ctsxSxpRetryPeriod readonly
Write access is not required.
ctsxSxpReconPeriod readonly
Write access is not required.
ctsxSxpConnSourceAddrType readonly
Write access is not required.
ctsxSxpConnSourceAddr readonly
Write access is not required.
ctsxSxpConnPasswordUsed readonly
Write access is not required.
ctsxSxpConnConfigPasswordType readonly
Write access is not required.
ctsxSxpConnConfigPassword readonly
Write access is not required.
ctsxSxpConnModeLocation readonly
Write access is not required.
ctsxSxpConnMode readonly
Write access is not required.
ctsxSxpConnStorageType readonly
Write access is not required.
ctsxSxpConnRowStatus readonly
active(1)
Write access is not required.
Support for createAndWait and notInService is not required.

OID .1.3.6.1.4.1.9.9.720.2.1.2
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
Required groups
mandatory ctsxSxpGlobalGroup
mandatory ctsxSxpConnectionGroup
mandatory ctsxIpSgtMappingGroup
optional ctsxSxpVersionGroup This group is mandatory for platforms which support
displaying SXP protocol version.
Object refinements
ObjectAccessSyntaxDescription
ctsxSxpEnable readonly
Write access is not required.
ctsxSxpConfigDefaultPasswordType readonly
Write access is not required.
ctsxSxpConfigDefaultPassword readonly
Write access is not required.
ctsxSxpDefaultSourceAddrType readonly
Write access is not required.
ctsxSxpDefaultSourceAddr readonly
Write access is not required.
ctsxSxpRetryPeriod readonly
Write access is not required.
ctsxSxpReconPeriod readonly
Write access is not required.
ctsxSxpConnSourceAddrType readonly
Write access is not required.
ctsxSxpConnSourceAddr readonly
Write access is not required.
ctsxSxpConnPasswordUsed readonly
Write access is not required.
ctsxSxpConnConfigPasswordType readonly
Write access is not required.
ctsxSxpConnConfigPassword readonly
Write access is not required.
ctsxSxpConnModeLocation readonly
Write access is not required.
ctsxSxpConnMode readonly
Write access is not required.
ctsxSxpConnStorageType readonly
Write access is not required.
ctsxSxpConnRowStatus readonly
active(1)
Write access is not required.
Support for createAndWait and notInService is not required.

OID .1.3.6.1.4.1.9.9.720.2.1.3
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
Required groups
mandatory ctsxSxpGlobalGroup
mandatory ctsxSxpConnectionGroup
optional ctsxSxpVersionGroup This group is mandatory for platforms which support
displaying SXP protocol version.
optional ctsxSxpBindingLogGroup This group is mandatory for platforms which support
controlling logging functionality for SXP bindings.
optional ctsxSxpBindingNotifInfoGroup This group is mandatory for platforms which support
binding expansion functionality in SXP.
optional ctsxSxpNodeIdInfoGroup This group is mandatory for platforms which support
loop detection functionality for SXP.
optional ctsxIpSgtMappingGroup This group is mandatory for platforms which support
SGT mapping functionality but do not support
SGT mapping expansion functionality .
optional ctsxSxpSgtMapGroup This group is mandatory for platforms which support
SGT mapping and SGT mapping expansion functionality in SXP.
optional ctsxNotifsControlGroup This group is mandatory for platforms which support
SXP notifications.
optional ctsxNotifsGroup This group is mandatory for platforms which support
SXP notifications.
optional ctsxSxpNotifErrMsgGroup This group is mandatory for platforms which support
ctsxNotifsGroup.
optional ctsxSxpGlobalHoldTimeGroup This group is mandatory for platforms which support
global hold-time configuration for SXP connections.
optional ctsxSxpConnHoldTimeGroup This group is mandatory for platforms which support
hold-time configuration for individual SXP connections.
optional ctsxSxpConnCapbilityGroup This group is mandatory for platforms which provide
capability information for SXP connections.
optional ctsxSxpVersionSupportGroup This group is mandatory for platforms which provide
version support information for SXP protocol.
optional ctsxSgtMapPeerSeqGroup This group is mandatory for platforms which provide
Peer Sequence information for the SGT mapping.
Object refinements
ObjectAccessSyntaxDescription
ctsxSxpEnable readonly
Write access is not required.
ctsxSxpConfigDefaultPasswordType readonly
Write access is not required.
ctsxSxpConfigDefaultPassword readonly
Write access is not required.
ctsxSxpDefaultSourceAddrType readonly
Write access is not required.
ctsxSxpDefaultSourceAddr readonly
Write access is not required.
ctsxSxpRetryPeriod readonly
Write access is not required.
ctsxSxpReconPeriod readonly
Write access is not required.
ctsxSxpConnSourceAddrType readonly
Write access is not required.
ctsxSxpConnSourceAddr readonly
Write access is not required.
ctsxSxpConnPasswordUsed readonly
Write access is not required.
ctsxSxpConnConfigPasswordType readonly
Write access is not required.
ctsxSxpConnConfigPassword readonly
Write access is not required.
ctsxSxpConnModeLocation readonly
Write access is not required.
ctsxSxpConnMode readonly
Write access is not required.
ctsxSxpConnStorageType readonly
Write access is not required.
ctsxSxpConnRowStatus readonly
active(1)
Write access is not required.
Support for createAndWait and notInService is not required.
ctsxSxpBindingChangesLogEnable readonly
Write access is not required.
ctsxSgtMapExpansionLimit readonly
Write access is not required.
ctsxSxpAdminNodeId readonly
Write access is not required.
ctsxSxpNodeIdInterface readonly
Write access is not required.
ctsxSxpNodeIdIpAddrType readonly
Write access is not required.
ctsxSxpNodeIdIpAddr readonly
Write access is not required.
ctsxSxpConnSourceAddrErrNotifEnable readonly
Write access is not required.
ctsxSxpMsgParseErrNotifEnable readonly
Write access is not required.
ctsxSxpConnConfigErrNotifEnable readonly
Write access is not required.
ctsxSxpBindingErrNotifEnable readonly
Write access is not required.
ctsxSxpConnUpNotifEnable readonly
Write access is not required.
ctsxSxpConnDownNotifEnable readonly
Write access is not required.
ctsxSxpExpansionFailNotifEnable readonly
Write access is not required.
ctsxSxpOperNodeIdChangeNotifEnable readonly
Write access is not required.
ctsxSxpBindingConflictNotifEnable readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.720.2.1.4
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
Required groups
mandatory ctsxSxpGlobalGroup
mandatory ctsxSxpConnectionGroup
optional ctsxSxpVersionGroup This group is mandatory for platforms which support
displaying SXP protocol version.
optional ctsxSxpBindingLogGroup This group is mandatory for platforms which support
controlling logging functionality for SXP bindings.
optional ctsxSxpBindingNotifInfoGroup This group is mandatory for platforms which support
binding expansion functionality in SXP.
optional ctsxSxpNodeIdInfoGroup This group is mandatory for platforms which support
loop detection functionality for SXP.
optional ctsxIpSgtMappingGroup This group is mandatory for platforms which support
SGT mapping functionality but do not support
SGT mapping expansion functionality .
optional ctsxSxpSgtMapGroup This group is mandatory for platforms which support
SGT mapping and SGT mapping expansion functionality in SXP.
optional ctsxNotifsControlGroup This group is mandatory for platforms which support
SXP notifications.
optional ctsxNotifsGroup This group is mandatory for platforms which support
SXP notifications.
optional ctsxSxpNotifErrMsgGroup This group is mandatory for platforms which support
ctsxNotifsGroup.
optional ctsxSxpGlobalHoldTimeGroup This group is mandatory for platforms which support
global hold-time configuration for SXP connections.
optional ctsxSxpConnHoldTimeGroup This group is mandatory for platforms which support
hold-time configuration for individual SXP connections.
optional ctsxSxpConnCapbilityGroup This group is mandatory for platforms which provide
capability information for SXP connections.
optional ctsxSxpVersionSupportGroup This group is mandatory for platforms which provide
version support information for SXP protocol.
optional ctsxSgtMapPeerSeqGroup This group is mandatory for platforms which provide
Peer Sequence information for the SGT mapping.
optional ctsxBiDirectionalSxpGroup This group is mandatory for platforms which provide
Bi-directional SXP.
Object refinements
ObjectAccessSyntaxDescription
ctsxSxpEnable readonly
Write access is not required.
ctsxSxpConfigDefaultPasswordType readonly
Write access is not required.
ctsxSxpConfigDefaultPassword readonly
Write access is not required.
ctsxSxpDefaultSourceAddrType readonly
Write access is not required.
ctsxSxpDefaultSourceAddr readonly
Write access is not required.
ctsxSxpRetryPeriod readonly
Write access is not required.
ctsxSxpReconPeriod readonly
Write access is not required.
ctsxSxpConnSourceAddrType readonly
Write access is not required.
ctsxSxpConnSourceAddr readonly
Write access is not required.
ctsxSxpConnPasswordUsed readonly
Write access is not required.
ctsxSxpConnConfigPasswordType readonly
Write access is not required.
ctsxSxpConnConfigPassword readonly
Write access is not required.
ctsxSxpConnModeLocation readonly
Write access is not required.
ctsxSxpConnMode readonly
Write access is not required.
ctsxSxpConnStorageType readonly
Write access is not required.
ctsxSxpConnRowStatus readonly
active(1)
Write access is not required.
Support for createAndWait and notInService is not required.
ctsxSxpBindingChangesLogEnable readonly
Write access is not required.
ctsxSgtMapExpansionLimit readonly
Write access is not required.
ctsxSxpAdminNodeId readonly
Write access is not required.
ctsxSxpNodeIdInterface readonly
Write access is not required.
ctsxSxpNodeIdIpAddrType readonly
Write access is not required.
ctsxSxpNodeIdIpAddr readonly
Write access is not required.
ctsxSxpConnSourceAddrErrNotifEnable readonly
Write access is not required.
ctsxSxpMsgParseErrNotifEnable readonly
Write access is not required.
ctsxSxpConnConfigErrNotifEnable readonly
Write access is not required.
ctsxSxpBindingErrNotifEnable readonly
Write access is not required.
ctsxSxpConnUpNotifEnable readonly
Write access is not required.
ctsxSxpConnDownNotifEnable readonly
Write access is not required.
ctsxSxpExpansionFailNotifEnable readonly
Write access is not required.
ctsxSxpOperNodeIdChangeNotifEnable readonly
Write access is not required.
ctsxSxpBindingConflictNotifEnable readonly
Write access is not required.
Notifications / Traps (9)
NameOIDDescription
.1.3.6.1.4.1.9.9.720.0.1
A ctsxSxpConnSourceAddrErrNotif is generated if the
system is not able to establish SXP connection using
ctsxSxpConnOperSourceAddr.
.1.3.6.1.4.1.9.9.720.0.2
A ctsxSxpMsgParseErrNotif is generated if the system is
not able to parse a received SXP message.
.1.3.6.1.4.1.9.9.720.0.3
A ctsxSxpConnConfigErrNotif is generated if the system
detects a configuration error for an SXP connection.
.1.3.6.1.4.1.9.9.720.0.4
A ctsxSxpBindingErrNotif is generated if the address in the
SGT mapping is not found in routing and forwarding table of
the system.
.1.3.6.1.4.1.9.9.720.0.5
A ctsxSxpConnUpNotif is generated if the ctsxSxpConnStatus
for an SXP connection transitioned into 'on' state.
.1.3.6.1.4.1.9.9.720.0.6
A ctsxSxpConnDownNotif is generated if ctsxSxpConnStatus
for an SXP connection left the 'on' state and transitioned
into some other state.
.1.3.6.1.4.1.9.9.720.0.7
A ctsxSxpExpansionFailNotif is generated if the number of
expanded SGT maps reaches the configured limit and the received
SGT mapping can not be expanded.
.1.3.6.1.4.1.9.9.720.0.8
A ctsxSxpOperNodeIdChangeNotif is generated if the value of
ctsxSxpOperNodeId changes.
.1.3.6.1.4.1.9.9.720.0.9
A ctsxSxpBindingConflictNotif is generated if the
device receives conflicting SGT mapping information.