IEEE8021-SECY-MIB
The MAC security entity (SecY) MIB module. A SecY is a protocol
shim providing MAC Security (MACsec) in an interface stack.
Each SecY transmits MACsec protected frames on one or more
Secure Channels (SCs) to each of the other SecYs attached to the
same LAN and participating in the same Secure Connectivity
Association (CA). The CA is a security relationship, that is
established and maintained by key agreement protocols and supported
by MACsec to provide full connectivity between its participants.
Each SC provides unidirectional point to multipoint connectivity
from one participant to all the others and is supported by a
succession of similarly point to multipoint Secure Associations
(SAs). The Secure Association Key (SAK) used to protect frames is
changed as an SA is replaced by its (overlapping) successor so
fresh keys can be used without disrupting a long lived SC and CA.
Two different upper interfaces, a Controlled Port (for frames
protected by MACsec, providing an instance of the secure MAC
service) and an Uncontrolled Port (for frames not requiring
protection, like the key agreement frames used to establish the
CA and distribute keys) are associated with a SecY shim. For each
instance of a SecY two ifTable rows (one for each interface) run on
top of an ifTable row representing the 'Common Port' interface,
such as a row with ifType ='ethernetCsmacd(6)'.
___________________________________________________________________
| | |
| Controlled Port Interface | Uncontrolled Port Interface |
| (ifEntry = j,ifType = | (ifEntry = k, ifType = |
| macSecControlledIF(231)) | macSecUncontrolledIF(232)) |
|________________________________________________________________|
| |
| Physical Interface |
| (ifEntry = i) |
| (ifType = ethernetCsmacd(6)) |
|________________________________________________________________|
Example MACsec Interface Stack. i, j, k are ifIndexes each
indicating a row in the ifTable.
- Source file
IEEE8021-SECY-MIB- Last revised
- Identity
ieee8021SecyMIB- Base OID
1.0.8802.1.1.3
Imported Objects
| IF-MIB | ifCounterDiscontinuityGroup (no object page) InterfaceIndex |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Counter64 Integer32 MODULE-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | RowPointer RowStatus TEXTUAL-CONVENTION (no object page) TimeStamp TruthValue |
Net-SNMP examples using the rfc MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'IEEE8021-SECY-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'IEEE8021-SECY-MIB::ieee8021SecyMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IEEE8021-SECY-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IEEE8021-SECY-MIB::ieee8021SecyMIB'
Objects (159)
Showing 159 of 159 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.0.8802.1.1.3 |
||
.1.0.8802.1.1.3.0 |
||
.1.0.8802.1.1.3.1 |
||
.1.0.8802.1.1.3.1.1 |
||
.1.0.8802.1.1.3.1.1.1 |
||
.1.0.8802.1.1.3.1.1.1.1 |
||
.1.0.8802.1.1.3.1.1.1.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.1.1.10 |
|
.1.0.8802.1.1.3.1.1.1.1.11 |
||
.1.0.8802.1.1.3.1.1.1.1.12 |
||
.1.0.8802.1.1.3.1.1.1.1.13 |
||
.1.0.8802.1.1.3.1.1.1.1.14 |
||
.1.0.8802.1.1.3.1.1.1.1.15 |
||
.1.0.8802.1.1.3.1.1.1.1.16 |
||
|
security connectionsSNMPv2-SMIUnsigned32
|
.1.0.8802.1.1.3.1.1.1.1.17 |
|
|
security connectionsSNMPv2-SMIUnsigned32
|
.1.0.8802.1.1.3.1.1.1.1.2 |
|
.1.0.8802.1.1.3.1.1.1.1.3 |
||
.1.0.8802.1.1.3.1.1.1.1.4 |
||
.1.0.8802.1.1.3.1.1.1.1.5 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.1.1.6 |
|
.1.0.8802.1.1.3.1.1.1.1.7 |
||
|
PacketsSNMPv2-SMIUnsigned32
|
.1.0.8802.1.1.3.1.1.1.1.8 |
|
.1.0.8802.1.1.3.1.1.1.1.9 |
||
.1.0.8802.1.1.3.1.1.10 |
||
.1.0.8802.1.1.3.1.1.10.1 |
||
.1.0.8802.1.1.3.1.1.10.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.10.1.2 |
|
.1.0.8802.1.1.3.1.1.10.1.3 |
||
.1.0.8802.1.1.3.1.1.10.1.4 |
||
.1.0.8802.1.1.3.1.1.10.1.5 |
||
.1.0.8802.1.1.3.1.1.10.1.6 |
||
.1.0.8802.1.1.3.1.1.11 |
||
.1.0.8802.1.1.3.1.1.11.1 |
||
.1.0.8802.1.1.3.1.1.11.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.11.1.2 |
|
.1.0.8802.1.1.3.1.1.11.1.3 |
||
.1.0.8802.1.1.3.1.1.11.1.4 |
||
|
OctetString
|
.1.0.8802.1.1.3.1.1.11.1.5 |
|
.1.0.8802.1.1.3.1.1.11.1.6 |
||
.1.0.8802.1.1.3.1.1.11.1.7 |
||
.1.0.8802.1.1.3.1.1.11.1.8 |
||
.1.0.8802.1.1.3.1.1.11.1.9 |
||
.1.0.8802.1.1.3.1.1.2 |
||
.1.0.8802.1.1.3.1.1.2.1 |
||
.1.0.8802.1.1.3.1.1.2.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.2.1.2 |
|
.1.0.8802.1.1.3.1.1.2.1.3 |
||
|
|
.1.0.8802.1.1.3.1.1.2.1.4 |
|
.1.0.8802.1.1.3.1.1.2.1.5 |
||
.1.0.8802.1.1.3.1.1.2.1.6 |
||
.1.0.8802.1.1.3.1.1.2.1.7 |
||
.1.0.8802.1.1.3.1.1.3 |
||
.1.0.8802.1.1.3.1.1.3.1 |
||
.1.0.8802.1.1.3.1.1.3.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.3.1.2 |
|
.1.0.8802.1.1.3.1.1.3.1.3 |
||
.1.0.8802.1.1.3.1.1.3.1.4 |
||
|
|
.1.0.8802.1.1.3.1.1.3.1.5 |
|
.1.0.8802.1.1.3.1.1.3.1.6 |
||
.1.0.8802.1.1.3.1.1.3.1.7 |
||
.1.0.8802.1.1.3.1.1.3.1.8 |
||
.1.0.8802.1.1.3.1.1.4 |
||
.1.0.8802.1.1.3.1.1.4.1 |
||
.1.0.8802.1.1.3.1.1.4.1.1 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.4.1.2 |
|
|
|
.1.0.8802.1.1.3.1.1.4.1.3 |
|
.1.0.8802.1.1.3.1.1.4.1.4 |
||
.1.0.8802.1.1.3.1.1.4.1.5 |
||
.1.0.8802.1.1.3.1.1.4.1.6 |
||
.1.0.8802.1.1.3.1.1.5 |
||
.1.0.8802.1.1.3.1.1.5.1 |
||
.1.0.8802.1.1.3.1.1.5.1.1 |
||
|
OctetString
|
.1.0.8802.1.1.3.1.1.5.1.10 |
|
.1.0.8802.1.1.3.1.1.5.1.11 |
||
|
Enumeration
|
.1.0.8802.1.1.3.1.1.5.1.2 |
|
|
|
.1.0.8802.1.1.3.1.1.5.1.3 |
|
|
|
.1.0.8802.1.1.3.1.1.5.1.4 |
|
.1.0.8802.1.1.3.1.1.5.1.5 |
||
.1.0.8802.1.1.3.1.1.5.1.6 |
||
.1.0.8802.1.1.3.1.1.5.1.7 |
||
.1.0.8802.1.1.3.1.1.5.1.8 |
||
.1.0.8802.1.1.3.1.1.5.1.9 |
||
.1.0.8802.1.1.3.1.1.6 |
||
.1.0.8802.1.1.3.1.1.6.1 |
||
|
Unsigned32
|
.1.0.8802.1.1.3.1.1.6.1.1 |
|
|
OctetString
|
.1.0.8802.1.1.3.1.1.6.1.2 |
|
|
OctetString
|
.1.0.8802.1.1.3.1.1.6.1.3 |
|
|
Bits
|
.1.0.8802.1.1.3.1.1.6.1.4 |
|
|
|
Bits
|
.1.0.8802.1.1.3.1.1.6.1.5 |
|
|
bytesInteger32
|
.1.0.8802.1.1.3.1.1.6.1.6 |
.1.0.8802.1.1.3.1.1.6.1.7 |
||
|
octetsUnsigned32
|
.1.0.8802.1.1.3.1.1.6.1.8 |
|
.1.0.8802.1.1.3.1.1.6.1.9 |
||
.1.0.8802.1.1.3.1.1.7 |
||
.1.0.8802.1.1.3.1.1.7.1 |
||
.1.0.8802.1.1.3.1.1.7.1.1 |
||
.1.0.8802.1.1.3.1.1.7.1.2 |
||
.1.0.8802.1.1.3.1.1.7.1.3 |
||
.1.0.8802.1.1.3.1.1.8 |
||
.1.0.8802.1.1.3.1.1.8.1 |
||
|
Integer32
|
.1.0.8802.1.1.3.1.1.8.1.1 |
|
|
Integer32
|
.1.0.8802.1.1.3.1.1.8.1.2 |
|
.1.0.8802.1.1.3.1.1.9 |
||
.1.0.8802.1.1.3.1.1.9.1 |
||
|
Integer32
|
.1.0.8802.1.1.3.1.1.9.1.1 |
|
|
Integer32
|
.1.0.8802.1.1.3.1.1.9.1.2 |
|
.1.0.8802.1.1.3.1.2 |
||
|
|
.1.0.8802.1.1.3.1.2.1 |
|
|
|
.1.0.8802.1.1.3.1.2.1.1 |
|
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.1.1.1 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.1.1.2 |
.1.0.8802.1.1.3.1.2.12 |
||
.1.0.8802.1.1.3.1.2.12.1 |
||
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.12.1.1 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.12.1.2 |
|
.1.0.8802.1.1.3.1.2.2 |
||
.1.0.8802.1.1.3.1.2.2.1 |
||
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.2.1.1 |
|
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.2.1.10 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.2.1.11 |
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.2.1.4 |
|
|
|
.1.0.8802.1.1.3.1.2.3 |
|
|
|
.1.0.8802.1.1.3.1.2.3.1 |
|
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.3.1.1 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.3.1.13 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.3.1.16 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.3.1.25 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.0.8802.1.1.3.1.2.3.1.4 |
.1.0.8802.1.1.3.1.2.4 |
||
.1.0.8802.1.1.3.1.2.4.1 |
||
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.1 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.10 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.2 |
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.3 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.4 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.5 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.6 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.7 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.8 |
|
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.4.1.9 |
.1.0.8802.1.1.3.1.2.5 |
||
.1.0.8802.1.1.3.1.2.5.1 |
||
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.1 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.10 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.11 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.12 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.13 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.14 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.2 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.3 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.4 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.5 |
|
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.6 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.7 |
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.8 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.0.8802.1.1.3.1.2.5.1.9 |
|
.1.0.8802.1.1.3.2 |
||
.1.0.8802.1.1.3.2.1 |
||
.1.0.8802.1.1.3.2.2 |
Dependencies (7) 5 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- SNMPv2-TCrfc
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- IEEE8021-SECY-MIBrfcselected
Conformance Groups (24)
Compliance Statements (2)
OID
.1.0.8802.1.1.3.2.1.1The compliance statement for the IEEE8021-SECY-MIB as specified in
IEEE Std 802.1AE-2006.
IEEE Std 802.1AE-2006.
Required groups
| mandatory | secyIfCtrlGroup | |
| mandatory | secyTxSCGroup | |
| mandatory | secyTxSAGroup | |
| mandatory | secyRxSCGroup | |
| mandatory | secyRxSAGroup | |
| mandatory | secyCipherSuiteGroup | |
| mandatory | secyTxSAStatsGroup | |
| mandatory | secyTxSCStatsGroup | |
| mandatory | secyRxSAStatsGroup | |
| mandatory | secyRxSCStatsGroup | |
| mandatory | secyStatsGroup |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| secyIfCurrentCipherSuite | readonly | write access not required, may be read-only. | |
| secyCipherSuiteId | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteName | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteCapability | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteProtection | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteProtectionOffset | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteDataLengthChange | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteICVLength | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteRowStatus | readonly | read-create not required, may be read-only. |
OID
.1.0.8802.1.1.3.2.1.2The compliance statement for an IEEE8021-SECY-MIB supporting
traffic class transmit SCs, added by IEEE 802.1AEcg.
traffic class transmit SCs, added by IEEE 802.1AEcg.
Required groups
| mandatory | IF-MIB::ifCounterDiscontinuityGroup | |
| mandatory | secyIfGroup | |
| mandatory | secyIfCipherGroup | |
| mandatory | secyIfTCGroup | |
| mandatory | secyIfAPGroup | |
| mandatory | secyTSCGroup | |
| mandatory | secyTSAGroup | |
| mandatory | secyRSCGroup | |
| mandatory | secyRSAGroup | |
| mandatory | secyCipherInfoGroup | |
| mandatory | secyCipherStatsGroup | |
| mandatory | secyTSCStatsGroup | |
| mandatory | secyRSCStatsGroup | |
| mandatory | secyIfStatsGroup |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| secyIfCurrentCipherSuite | readonly | should be read-only, use the secyIfCipherTable to control ciper suite use. |
|
| secyCipherSuiteId | readonly | read-create not required, may be read-only. | |
| secyCipherSuiteName | readonly | read-create not required, should be read-only. | |
| secyCipherSuiteCapability | readonly | read-create not required, should be read-only. | |
| secyCipherSuiteDataLengthChange | readonly | read-create not required, should be read-only. | |
| secyCipherSuiteICVLength | readonly | read-create not required, should be read-only. |