IEEE8021-SECY-MIB

        The MAC security entity (SecY) MIB module. A SecY is a protocol
shim providing MAC Security (MACsec) in an interface stack.
        
Each SecY transmits MACsec protected frames on one or more
Secure Channels (SCs) to each of the other SecYs attached to the 
same LAN and participating in the same Secure Connectivity
Association (CA). The CA is a security relationship, that is
established and maintained by key agreement protocols and supported 
by MACsec to provide full connectivity between its participants.
Each SC provides unidirectional point to multipoint connectivity 
from one participant to all the others and is supported by a 
succession of similarly point to multipoint Secure Associations 
(SAs). The Secure Association  Key (SAK) used to protect frames is 
changed as an SA is replaced by its (overlapping) successor so
fresh keys can be used without disrupting a long lived SC and CA.
        
Two different upper interfaces, a Controlled Port (for frames
protected by MACsec, providing an instance of the secure MAC
service) and an Uncontrolled Port (for frames not requiring 
protection, like the key agreement frames used to establish the 
CA and distribute keys) are associated with a SecY  shim. For each
instance of a SecY two ifTable rows (one for each interface) run on 
top of an ifTable row representing the 'Common Port' interface,
such as a row with ifType ='ethernetCsmacd(6)'.
        
___________________________________________________________________
|                               |                                |
|  Controlled Port Interface    |   Uncontrolled Port Interface  |
|  (ifEntry = j,ifType =        |   (ifEntry = k, ifType =       |
|   macSecControlledIF(231))    |    macSecUncontrolledIF(232))  |
|________________________________________________________________|
|                                                                |
|                    Physical Interface                          |
|                      (ifEntry = i)                             |
|                (ifType = ethernetCsmacd(6))                    |
|________________________________________________________________|
   Example MACsec Interface Stack. i, j, k are ifIndexes each
   indicating a row in the ifTable.
    
Source file
IEEE8021-SECY-MIB
Last revised
Identity
ieee8021SecyMIB
Base OID
1.0.8802.1.1.3
Imported Objects
IF-MIB ifCounterDiscontinuityGroup (no object page) InterfaceIndex
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Counter64 Integer32 MODULE-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowPointer RowStatus TEXTUAL-CONVENTION (no object page) TimeStamp TruthValue
Net-SNMP examples using the rfc MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'IEEE8021-SECY-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'IEEE8021-SECY-MIB::ieee8021SecyMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IEEE8021-SECY-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IEEE8021-SECY-MIB::ieee8021SecyMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (159)
.1.0.8802.1.1.3
.1.0.8802.1.1.3.0
.1.0.8802.1.1.3.1
.1.0.8802.1.1.3.1.1
.1.0.8802.1.1.3.1.1.1
.1.0.8802.1.1.3.1.1.1.1
.1.0.8802.1.1.3.1.1.1.1.1
Enumeration
.1.0.8802.1.1.3.1.1.1.1.10
.1.0.8802.1.1.3.1.1.1.1.11
.1.0.8802.1.1.3.1.1.1.1.12
.1.0.8802.1.1.3.1.1.1.1.13
.1.0.8802.1.1.3.1.1.1.1.14
.1.0.8802.1.1.3.1.1.1.1.15
.1.0.8802.1.1.3.1.1.1.1.16
security connectionsSNMPv2-SMIUnsigned32
.1.0.8802.1.1.3.1.1.1.1.17
security connectionsSNMPv2-SMIUnsigned32
.1.0.8802.1.1.3.1.1.1.1.2
.1.0.8802.1.1.3.1.1.1.1.3
.1.0.8802.1.1.3.1.1.1.1.4
.1.0.8802.1.1.3.1.1.1.1.5
Enumeration
.1.0.8802.1.1.3.1.1.1.1.6
.1.0.8802.1.1.3.1.1.1.1.7
.1.0.8802.1.1.3.1.1.1.1.8
.1.0.8802.1.1.3.1.1.1.1.9
.1.0.8802.1.1.3.1.1.10
.1.0.8802.1.1.3.1.1.10.1
.1.0.8802.1.1.3.1.1.10.1.1
Enumeration
.1.0.8802.1.1.3.1.1.10.1.2
.1.0.8802.1.1.3.1.1.10.1.3
.1.0.8802.1.1.3.1.1.10.1.4
.1.0.8802.1.1.3.1.1.10.1.5
.1.0.8802.1.1.3.1.1.10.1.6
.1.0.8802.1.1.3.1.1.11
.1.0.8802.1.1.3.1.1.11.1
.1.0.8802.1.1.3.1.1.11.1.1
Enumeration
.1.0.8802.1.1.3.1.1.11.1.2
.1.0.8802.1.1.3.1.1.11.1.3
.1.0.8802.1.1.3.1.1.11.1.4
OctetString
.1.0.8802.1.1.3.1.1.11.1.5
.1.0.8802.1.1.3.1.1.11.1.6
.1.0.8802.1.1.3.1.1.11.1.7
.1.0.8802.1.1.3.1.1.11.1.8
.1.0.8802.1.1.3.1.1.11.1.9
.1.0.8802.1.1.3.1.1.2
.1.0.8802.1.1.3.1.1.2.1
.1.0.8802.1.1.3.1.1.2.1.1
Enumeration
.1.0.8802.1.1.3.1.1.2.1.2
.1.0.8802.1.1.3.1.1.2.1.3
.1.0.8802.1.1.3.1.1.2.1.4
.1.0.8802.1.1.3.1.1.2.1.5
.1.0.8802.1.1.3.1.1.2.1.6
.1.0.8802.1.1.3.1.1.2.1.7
.1.0.8802.1.1.3.1.1.3
.1.0.8802.1.1.3.1.1.3.1
.1.0.8802.1.1.3.1.1.3.1.1
Enumeration
.1.0.8802.1.1.3.1.1.3.1.2
.1.0.8802.1.1.3.1.1.3.1.3
.1.0.8802.1.1.3.1.1.3.1.4
.1.0.8802.1.1.3.1.1.3.1.5
.1.0.8802.1.1.3.1.1.3.1.6
.1.0.8802.1.1.3.1.1.3.1.7
.1.0.8802.1.1.3.1.1.3.1.8
.1.0.8802.1.1.3.1.1.4
.1.0.8802.1.1.3.1.1.4.1
.1.0.8802.1.1.3.1.1.4.1.1
Enumeration
.1.0.8802.1.1.3.1.1.4.1.2
secyRxSCCurrentSA deprecated
.1.0.8802.1.1.3.1.1.4.1.3
.1.0.8802.1.1.3.1.1.4.1.4
.1.0.8802.1.1.3.1.1.4.1.5
.1.0.8802.1.1.3.1.1.4.1.6
.1.0.8802.1.1.3.1.1.5
.1.0.8802.1.1.3.1.1.5.1
.1.0.8802.1.1.3.1.1.5.1.1
OctetString
.1.0.8802.1.1.3.1.1.5.1.10
.1.0.8802.1.1.3.1.1.5.1.11
Enumeration
.1.0.8802.1.1.3.1.1.5.1.2
secyRxSANextPN deprecated r/w
.1.0.8802.1.1.3.1.1.5.1.3
.1.0.8802.1.1.3.1.1.5.1.4
.1.0.8802.1.1.3.1.1.5.1.5
.1.0.8802.1.1.3.1.1.5.1.6
.1.0.8802.1.1.3.1.1.5.1.7
.1.0.8802.1.1.3.1.1.5.1.8
.1.0.8802.1.1.3.1.1.5.1.9
.1.0.8802.1.1.3.1.1.6
.1.0.8802.1.1.3.1.1.6.1
Unsigned32
.1.0.8802.1.1.3.1.1.6.1.1
OctetString
.1.0.8802.1.1.3.1.1.6.1.2
OctetString
.1.0.8802.1.1.3.1.1.6.1.3
Bits
.1.0.8802.1.1.3.1.1.6.1.4
secyCipherSuiteProtection deprecated r/w
Bits
.1.0.8802.1.1.3.1.1.6.1.5
bytesInteger32
.1.0.8802.1.1.3.1.1.6.1.6
.1.0.8802.1.1.3.1.1.6.1.7
octetsUnsigned32
.1.0.8802.1.1.3.1.1.6.1.8
.1.0.8802.1.1.3.1.1.6.1.9
.1.0.8802.1.1.3.1.1.7
.1.0.8802.1.1.3.1.1.7.1
.1.0.8802.1.1.3.1.1.7.1.1
.1.0.8802.1.1.3.1.1.7.1.2
.1.0.8802.1.1.3.1.1.7.1.3
.1.0.8802.1.1.3.1.1.8
.1.0.8802.1.1.3.1.1.8.1
Integer32
.1.0.8802.1.1.3.1.1.8.1.1
Integer32
.1.0.8802.1.1.3.1.1.8.1.2
.1.0.8802.1.1.3.1.1.9
.1.0.8802.1.1.3.1.1.9.1
Integer32
.1.0.8802.1.1.3.1.1.9.1.1
Integer32
.1.0.8802.1.1.3.1.1.9.1.2
.1.0.8802.1.1.3.1.2
secyTxSAStatsTable deprecated
.1.0.8802.1.1.3.1.2.1
secyTxSAStatsEntry deprecated
.1.0.8802.1.1.3.1.2.1.1
.1.0.8802.1.1.3.1.2.1.1.1
.1.0.8802.1.1.3.1.2.1.1.2
.1.0.8802.1.1.3.1.2.12
.1.0.8802.1.1.3.1.2.12.1
.1.0.8802.1.1.3.1.2.12.1.1
.1.0.8802.1.1.3.1.2.12.1.2
.1.0.8802.1.1.3.1.2.2
.1.0.8802.1.1.3.1.2.2.1
.1.0.8802.1.1.3.1.2.2.1.1
.1.0.8802.1.1.3.1.2.2.1.10
.1.0.8802.1.1.3.1.2.2.1.11
.1.0.8802.1.1.3.1.2.2.1.4
secyRxSAStatsTable deprecated
.1.0.8802.1.1.3.1.2.3
secyRxSAStatsEntry deprecated
.1.0.8802.1.1.3.1.2.3.1
.1.0.8802.1.1.3.1.2.3.1.1
.1.0.8802.1.1.3.1.2.3.1.13
.1.0.8802.1.1.3.1.2.3.1.16
secyRxSAStatsOKPkts deprecated
.1.0.8802.1.1.3.1.2.3.1.25
.1.0.8802.1.1.3.1.2.3.1.4
.1.0.8802.1.1.3.1.2.4
.1.0.8802.1.1.3.1.2.4.1
.1.0.8802.1.1.3.1.2.4.1.1
.1.0.8802.1.1.3.1.2.4.1.10
.1.0.8802.1.1.3.1.2.4.1.2
.1.0.8802.1.1.3.1.2.4.1.3
.1.0.8802.1.1.3.1.2.4.1.4
.1.0.8802.1.1.3.1.2.4.1.5
.1.0.8802.1.1.3.1.2.4.1.6
.1.0.8802.1.1.3.1.2.4.1.7
.1.0.8802.1.1.3.1.2.4.1.8
.1.0.8802.1.1.3.1.2.4.1.9
.1.0.8802.1.1.3.1.2.5
.1.0.8802.1.1.3.1.2.5.1
.1.0.8802.1.1.3.1.2.5.1.1
.1.0.8802.1.1.3.1.2.5.1.10
.1.0.8802.1.1.3.1.2.5.1.11
.1.0.8802.1.1.3.1.2.5.1.12
.1.0.8802.1.1.3.1.2.5.1.13
.1.0.8802.1.1.3.1.2.5.1.14
.1.0.8802.1.1.3.1.2.5.1.2
.1.0.8802.1.1.3.1.2.5.1.3
.1.0.8802.1.1.3.1.2.5.1.4
.1.0.8802.1.1.3.1.2.5.1.5
.1.0.8802.1.1.3.1.2.5.1.6
.1.0.8802.1.1.3.1.2.5.1.7
.1.0.8802.1.1.3.1.2.5.1.8
.1.0.8802.1.1.3.1.2.5.1.9
.1.0.8802.1.1.3.2
.1.0.8802.1.1.3.2.1
.1.0.8802.1.1.3.2.2
Dependencies (7) 5 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. SNMPv2-TCrfc
  3. IANAifType-MIBrfc
  4. SNMPv2-CONFrfc
  5. SNMPv2-MIBrfc
  6. IF-MIBrfc
  7. SNMP-FRAMEWORK-MIBrfc
  8. IEEE8021-SECY-MIBrfcselected
Type Definitions (2)
Unsigned32 range: 0..3
OctetString range: 8
Conformance Groups (24)
SecY service management (secyIfTable) objects.
.1.0.8802.1.1.3.2.2.1
secyTxSCGroup deprecated
Transmit SC management objects (for systems without
traffic class SC capabilities).
.1.0.8802.1.1.3.2.2.2
secyTxSAGroup deprecated
Transmit SA management objects (for systems without
traffic class SC capabilities).
.1.0.8802.1.1.3.2.2.3
secyRxSCGroup deprecated
Receive SC management objects.
.1.0.8802.1.1.3.2.2.4
secyRxSAGroup deprecated
Receive SA management objects.
.1.0.8802.1.1.3.2.2.5
Cipher Suite information objects.
.1.0.8802.1.1.3.2.2.6
Transmit SA statistics objects.
.1.0.8802.1.1.3.2.2.7
Receive SA statistics objects.
.1.0.8802.1.1.3.2.2.8
Transmit SC statistics objects.
.1.0.8802.1.1.3.2.2.9
Receive SC statistics objects.
.1.0.8802.1.1.3.2.2.10
secyStatsGroup deprecated
SecY statistics objects.
.1.0.8802.1.1.3.2.2.11
SecY service management (secyIfTable objects) for
systems supporting traffic class SCs.
.1.0.8802.1.1.3.2.2.12
Cipher Suite use control (secyIfCipherTable objects).
.1.0.8802.1.1.3.2.2.13
Traffic class control (secyIfTCTable).
.1.0.8802.1.1.3.2.2.14
Access Priority Code Point control (secyIfAPTable).
.1.0.8802.1.1.3.2.2.15
Transmit SC management (secyTSCTable objects) for
systems supporting traffic class SCs.
.1.0.8802.1.1.3.2.2.16
Transmit SA management (secyTSATable objects) for
systems supporting traffic class SCs.
.1.0.8802.1.1.3.2.2.17
Receive SC management (secyRxSCTable objects).
.1.0.8802.1.1.3.2.2.18
Receive SA (secyRxSATable objects).
.1.0.8802.1.1.3.2.2.19
SecY statistics (secyStatsTable objects).
.1.0.8802.1.1.3.2.2.20
Cipher Suite implementation information
(secyCipherSuiteTable objects).
.1.0.8802.1.1.3.2.2.21
Transmit SC statistics (secyTSCStatsTable objects).
.1.0.8802.1.1.3.2.2.22
Receive SC statistics (secyRxSCStatsTable objects).
.1.0.8802.1.1.3.2.2.23
Cipher Suite performance statistics (from secyStatsTable).
.1.0.8802.1.1.3.2.2.24
Compliance Statements (2)

OID .1.0.8802.1.1.3.2.1.1
The compliance statement for the IEEE8021-SECY-MIB as specified in
IEEE Std 802.1AE-2006.
Required groups
Object refinements
ObjectAccessSyntaxDescription
secyIfCurrentCipherSuite readonly
write access not required, may be read-only.
secyCipherSuiteId readonly
read-create not required, may be read-only.
secyCipherSuiteName readonly
read-create not required, may be read-only.
secyCipherSuiteCapability readonly
read-create not required, may be read-only.
secyCipherSuiteProtection readonly
read-create not required, may be read-only.
secyCipherSuiteProtectionOffset readonly
read-create not required, may be read-only.
secyCipherSuiteDataLengthChange readonly
read-create not required, may be read-only.
secyCipherSuiteICVLength readonly
read-create not required, may be read-only.
secyCipherSuiteRowStatus readonly
read-create not required, may be read-only.

OID .1.0.8802.1.1.3.2.1.2
The compliance statement for an IEEE8021-SECY-MIB supporting
traffic class transmit SCs, added by IEEE 802.1AEcg.
Required groups
Object refinements
ObjectAccessSyntaxDescription
secyIfCurrentCipherSuite readonly
should be read-only, use the secyIfCipherTable
to control ciper suite use.
secyCipherSuiteId readonly
read-create not required, may be read-only.
secyCipherSuiteName readonly
read-create not required, should be read-only.
secyCipherSuiteCapability readonly
read-create not required, should be read-only.
secyCipherSuiteDataLengthChange readonly
read-create not required, should be read-only.
secyCipherSuiteICVLength readonly
read-create not required, should be read-only.