T11-FC-SP-SA-MIB
This MIB module specifies the management information
required to manage Security Associations established via
Fibre Channel's FC-SP specification.
The MIB module consists of six parts:
- a per-Fabric table, t11FcSpSaIfTable, of capabilities,
parameters, status information, and counters; the counters
include non-transient aggregates of per-SA transient
counters;
- three tables, t11FcSpSaPropTable, t11FcSpSaTSelPropTable,
and t11FcSpSaTransTable, specifying the proposals for an
FC-SP entity acting as an SA_Initiator to present to the
SA_Responder during the negotiation of Security
Associations. The same information is also used by an
FC-SP entity acting as an SA_Responder to decide what to
accept during the negotiation of Security Associations.
One of these tables, t11FcSpSaTransTable, is used not only
for information about security transforms to propose and
to accept, but also as agreed upon during the negotiation
of Security Associations;
- a table, t11FcSpSaTSelDrByTable, of Traffic Selectors
having the security action of 'drop' or 'bypass' to be
applied either to ingress traffic that is unprotected by
FC-SP, or to all egress traffic;
- four tables, t11FcSpSaPairTable, t11FcSpSaTSelNegInTable,
t11FcSpSaTSelNegOutTable, and t11FcSpSaTSelSpiTable,
containing information about active bidirectional pairs of
Security Associations; in particular, t11FcSpSaPairTable
has one row per active bidirectional SA pair,
t11FcSpSaTSelNegInTable and t11FcSpSaTSelNegOutTable
contain information on the Traffic Selectors negotiated on
the SAs, and the t11FcSpSaTSelSpiTable is an alternate
lookup table such that the Traffic Selector(s) in use on a
particular Security Association can be quickly determined
based on the (ingress) SPI value;
- a table, t11FcSpSaControlTable, of control and other
information concerning the generation of notifications for
events related to FC-SP Security Associations;
- one notification, t11FcSpSaNotifyAuthFailure, generated on
the occurrence of an Authentication failure for a received
FC-2 or CT_IU frame.
Copyright (C) The IETF Trust (2008). This version
of this MIB module is part of RFC 5324; see the RFC
itself for full legal notices.
- Source file
T11-FC-SP-SA-MIB- Last revised
- Identity
t11FcSpSaMIB- Base OID
1.3.6.1.2.1.179
Imported Objects
| FC-MGMT-MIB | FcAddressIdOrZero fcmInstanceIndex |
| IF-MIB | InterfaceIndex InterfaceIndexOrZero |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Counter64 Gauge32 mib-2 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) TimeTicks Unsigned32 |
| SNMPv2-TC | AutonomousType RowStatus StorageType TimeStamp TruthValue |
| T11-FC-SP-TC-MIB | T11FcRoutingControl T11FcSaDirection T11FcSpiIndex T11FcSpLifetimeLeft T11FcSpLifetimeLeftUnits T11FcSpPrecedence T11FcSpSecurityProtocolId T11FcSpTransforms T11FcSpType |
| T11-TC-MIB | T11FabricIndex |
Net-SNMP examples using the rfc MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'T11-FC-SP-SA-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'T11-FC-SP-SA-MIB::t11FcSpSaMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'T11-FC-SP-SA-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'T11-FC-SP-SA-MIB::t11FcSpSaMIB'
Objects (142)
Showing 142 of 142 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.2.1.179 |
||
.1.3.6.1.2.1.179.0 |
||
.1.3.6.1.2.1.179.1 |
||
.1.3.6.1.2.1.179.1.1 |
||
.1.3.6.1.2.1.179.1.1.1 |
||
.1.3.6.1.2.1.179.1.1.1.1 |
||
.1.3.6.1.2.1.179.1.1.1.1.1 |
||
.1.3.6.1.2.1.179.1.1.1.1.10 |
||
|
Enumeration
|
.1.3.6.1.2.1.179.1.1.1.1.11 |
|
.1.3.6.1.2.1.179.1.1.1.1.12 |
||
.1.3.6.1.2.1.179.1.1.1.1.13 |
||
.1.3.6.1.2.1.179.1.1.1.1.14 |
||
.1.3.6.1.2.1.179.1.1.1.1.15 |
||
.1.3.6.1.2.1.179.1.1.1.1.16 |
||
.1.3.6.1.2.1.179.1.1.1.1.17 |
||
.1.3.6.1.2.1.179.1.1.1.1.18 |
||
.1.3.6.1.2.1.179.1.1.1.1.19 |
||
.1.3.6.1.2.1.179.1.1.1.1.2 |
||
.1.3.6.1.2.1.179.1.1.1.1.20 |
||
.1.3.6.1.2.1.179.1.1.1.1.21 |
||
.1.3.6.1.2.1.179.1.1.1.1.3 |
||
.1.3.6.1.2.1.179.1.1.1.1.4 |
||
.1.3.6.1.2.1.179.1.1.1.1.5 |
||
.1.3.6.1.2.1.179.1.1.1.1.6 |
||
.1.3.6.1.2.1.179.1.1.1.1.7 |
||
.1.3.6.1.2.1.179.1.1.1.1.8 |
||
.1.3.6.1.2.1.179.1.1.1.1.9 |
||
.1.3.6.1.2.1.179.1.2 |
||
.1.3.6.1.2.1.179.1.2.1 |
||
.1.3.6.1.2.1.179.1.2.1.1 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.2.1.1.1 |
|
.1.3.6.1.2.1.179.1.2.1.1.2 |
||
.1.3.6.1.2.1.179.1.2.1.1.3 |
||
.1.3.6.1.2.1.179.1.2.1.1.4 |
||
|
Enumeration
|
.1.3.6.1.2.1.179.1.2.1.1.5 |
|
.1.3.6.1.2.1.179.1.2.1.1.6 |
||
.1.3.6.1.2.1.179.1.2.1.1.7 |
||
.1.3.6.1.2.1.179.1.2.2 |
||
.1.3.6.1.2.1.179.1.2.2.1 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.2.2.1.1 |
|
.1.3.6.1.2.1.179.1.2.2.1.10 |
||
.1.3.6.1.2.1.179.1.2.2.1.11 |
||
.1.3.6.1.2.1.179.1.2.2.1.12 |
||
.1.3.6.1.2.1.179.1.2.2.1.13 |
||
.1.3.6.1.2.1.179.1.2.2.1.2 |
||
.1.3.6.1.2.1.179.1.2.2.1.3 |
||
|
OctetString
|
.1.3.6.1.2.1.179.1.2.2.1.4 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.2.1.5 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.2.1.6 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.2.1.7 |
|
.1.3.6.1.2.1.179.1.2.2.1.8 |
||
.1.3.6.1.2.1.179.1.2.2.1.9 |
||
.1.3.6.1.2.1.179.1.2.3 |
||
.1.3.6.1.2.1.179.1.2.3.1 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.2.3.1.1 |
|
|
Unsigned32
|
.1.3.6.1.2.1.179.1.2.3.1.2 |
|
.1.3.6.1.2.1.179.1.2.3.1.3 |
||
.1.3.6.1.2.1.179.1.2.3.1.4 |
||
.1.3.6.1.2.1.179.1.2.3.1.5 |
||
.1.3.6.1.2.1.179.1.2.3.1.6 |
||
.1.3.6.1.2.1.179.1.2.3.1.7 |
||
.1.3.6.1.2.1.179.1.2.3.1.8 |
||
.1.3.6.1.2.1.179.1.2.4 |
||
.1.3.6.1.2.1.179.1.2.4.1 |
||
.1.3.6.1.2.1.179.1.2.4.1.1 |
||
.1.3.6.1.2.1.179.1.2.4.1.10 |
||
.1.3.6.1.2.1.179.1.2.4.1.11 |
||
.1.3.6.1.2.1.179.1.2.4.1.12 |
||
.1.3.6.1.2.1.179.1.2.4.1.13 |
||
.1.3.6.1.2.1.179.1.2.4.1.2 |
||
|
Enumeration
|
.1.3.6.1.2.1.179.1.2.4.1.3 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.4.1.4 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.4.1.5 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.4.1.6 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.2.4.1.7 |
|
.1.3.6.1.2.1.179.1.2.4.1.8 |
||
.1.3.6.1.2.1.179.1.2.4.1.9 |
||
.1.3.6.1.2.1.179.1.3 |
||
.1.3.6.1.2.1.179.1.3.1 |
||
.1.3.6.1.2.1.179.1.3.1.1 |
||
.1.3.6.1.2.1.179.1.3.1.1.1 |
||
.1.3.6.1.2.1.179.1.3.1.1.10 |
||
.1.3.6.1.2.1.179.1.3.1.1.11 |
||
.1.3.6.1.2.1.179.1.3.1.1.12 |
||
.1.3.6.1.2.1.179.1.3.1.1.2 |
||
.1.3.6.1.2.1.179.1.3.1.1.3 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.3.1.1.4 |
|
|
Unsigned32
|
.1.3.6.1.2.1.179.1.3.1.1.5 |
|
.1.3.6.1.2.1.179.1.3.1.1.6 |
||
.1.3.6.1.2.1.179.1.3.1.1.7 |
||
|
Enumeration
|
.1.3.6.1.2.1.179.1.3.1.1.8 |
|
.1.3.6.1.2.1.179.1.3.1.1.9 |
||
.1.3.6.1.2.1.179.1.3.2 |
||
.1.3.6.1.2.1.179.1.3.2.1 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.3.2.1.1 |
|
.1.3.6.1.2.1.179.1.3.2.1.10 |
||
.1.3.6.1.2.1.179.1.3.2.1.11 |
||
.1.3.6.1.2.1.179.1.3.2.1.2 |
||
|
OctetString
|
.1.3.6.1.2.1.179.1.3.2.1.3 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.2.1.4 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.2.1.5 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.2.1.6 |
|
.1.3.6.1.2.1.179.1.3.2.1.7 |
||
.1.3.6.1.2.1.179.1.3.2.1.8 |
||
.1.3.6.1.2.1.179.1.3.2.1.9 |
||
.1.3.6.1.2.1.179.1.3.3 |
||
.1.3.6.1.2.1.179.1.3.3.1 |
||
.1.3.6.1.2.1.179.1.3.3.1.1 |
||
.1.3.6.1.2.1.179.1.3.3.1.10 |
||
.1.3.6.1.2.1.179.1.3.3.1.2 |
||
|
OctetString
|
.1.3.6.1.2.1.179.1.3.3.1.3 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.3.1.4 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.3.1.5 |
|
|
OctetString
|
.1.3.6.1.2.1.179.1.3.3.1.6 |
|
.1.3.6.1.2.1.179.1.3.3.1.7 |
||
.1.3.6.1.2.1.179.1.3.3.1.8 |
||
.1.3.6.1.2.1.179.1.3.3.1.9 |
||
.1.3.6.1.2.1.179.1.3.4 |
||
.1.3.6.1.2.1.179.1.3.4.1 |
||
.1.3.6.1.2.1.179.1.3.4.1.1 |
||
|
Unsigned32
|
.1.3.6.1.2.1.179.1.3.4.1.2 |
|
.1.3.6.1.2.1.179.1.3.4.1.3 |
||
.1.3.6.1.2.1.179.1.3.4.1.4 |
||
.1.3.6.1.2.1.179.1.4 |
||
.1.3.6.1.2.1.179.1.4.1 |
||
.1.3.6.1.2.1.179.1.4.1.1 |
||
.1.3.6.1.2.1.179.1.4.1.1.1 |
||
.1.3.6.1.2.1.179.1.4.1.1.10 |
||
.1.3.6.1.2.1.179.1.4.1.1.11 |
||
.1.3.6.1.2.1.179.1.4.1.1.12 |
||
.1.3.6.1.2.1.179.1.4.1.1.13 |
||
.1.3.6.1.2.1.179.1.4.1.1.2 |
||
.1.3.6.1.2.1.179.1.4.1.1.3 |
||
.1.3.6.1.2.1.179.1.4.1.1.4 |
||
|
OctetString
|
.1.3.6.1.2.1.179.1.4.1.1.5 |
|
.1.3.6.1.2.1.179.1.4.1.1.6 |
||
.1.3.6.1.2.1.179.1.4.1.1.7 |
||
|
secondsUnsigned32
|
.1.3.6.1.2.1.179.1.4.1.1.8 |
|
.1.3.6.1.2.1.179.1.4.1.1.9 |
||
.1.3.6.1.2.1.179.2 |
||
.1.3.6.1.2.1.179.2.1 |
||
.1.3.6.1.2.1.179.2.2 |
Dependencies (10) 7 direct · 3 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- SNMPv2-TCrfc
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- FC-MGMT-MIBrfc
- T11-FC-SP-TC-MIBrfc
- T11-TC-MIBrfc
- T11-FC-SP-SA-MIBrfcselected
Conformance Groups (8)
Compliance Statements (1)
OID
.1.3.6.1.2.1.179.2.1.1The compliance statement for entities that implement
FC-SP Security Associations.
FC-SP Security Associations.
Required groups
| mandatory | t11FcSpSaCapabilityGroup | |
| mandatory | t11FcSpSaParamStatusGroup | |
| mandatory | t11FcSpSaSummaryCountGroup | |
| mandatory | t11FcSpSaProposalGroup | |
| mandatory | t11FcSpSaDropBypassGroup | |
| mandatory | t11FcSpSaActiveGroup | |
| mandatory | t11FcSpSaNotifInfoGroup | |
| mandatory | t11FcSpSaNotificationGroup |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| t11FcSpSaIfStorageType | readonly | Write access is not required. | |
| t11FcSpSaTSelPropStorageType | readonly | Write access is not required. | |
| t11FcSpSaTransStorageType | readonly | Write access is not required. | |
| t11FcSpSaIfReplayPrevention | readonly | Write access is not required. | |
| t11FcSpSaIfReplayWindowSize | readonly | Write access is not required. | |
| t11FcSpSaIfTerminateAllSas | readonly | Write access is not required. | |
| t11FcSpSaPropSecurityProt | readonly | Write access is not required. | |
| t11FcSpSaPropTSelListIndex | readonly | Write access is not required. | |
| t11FcSpSaPropTransListIndex | readonly | Write access is not required. | |
| t11FcSpSaPropAcceptAlgorithm | readonly | Write access is not required. | |
| t11FcSpSaPropRowStatus | readonly | Write access is not required. | |
| t11FcSpSaTSelPropDirection | readonly | Write access is not required. | |
| t11FcSpSaTSelPropStartSrcAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelPropEndSrcAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelPropStartDstAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelPropEndDstAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelPropStartRCtl | readonly | Write access is not required. | |
| t11FcSpSaTSelPropEndRCtl | readonly | Write access is not required. | |
| t11FcSpSaTSelPropStartType | readonly | Write access is not required. | |
| t11FcSpSaTSelPropEndType | readonly | Write access is not required. | |
| t11FcSpSaTSelPropRowStatus | readonly | Write access is not required. | |
| t11FcSpSaTransSecurityProt | readonly | Write access is not required. | |
| t11FcSpSaTransEncryptAlg | readonly | Write access is not required. | |
| t11FcSpSaTransEncryptKeyLen | readonly | Write access is not required. | |
| t11FcSpSaTransIntegrityAlg | readonly | Write access is not required. | |
| t11FcSpSaTransRowStatus | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByAction | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByStartSrcAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByEndSrcAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByStartDstAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByEndDstAddr | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByStartRCtl | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByEndRCtl | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByStartType | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByEndType | readonly | Write access is not required. | |
| t11FcSpSaTSelDrByRowStatus | readonly | Write access is not required. | |
| t11FcSpSaPairTerminate | readonly | Write access is not required. | |
| t11FcSpSaControlAuthFailEnable | readonly | Write access is not required. | |
| t11FcSpSaControlWindow | readonly | Write access is not required. | |
| t11FcSpSaControlMaxNotifs | readonly | Write access is not required. | |
| t11FcSpSaControlLifeExcdEnable | readonly | Write access is not required. |
Notifications / Traps (2)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.2.1.179.0.1 |
When this notification is generated, it indicates the
occurrence of an Authentication failure for a received FC-2 or CT_IU frame. The t11FcSpSaControlInboundSpi, t11FcSpSaControlSource, and t11FcSpSaControlDestination objects in the varbindlist are the frame's SPI, source and destination addresses, respectively. t11FcSpSaControlFrame provides the (beginning of the) frame's content if such is available. This notification is generated only for the first occurrence of an Authentication failure on a Fabric within a time window. Subsequent occurrences of an Authentication Failure on the same Fabric within the same time window are counted but suppressed. The value of t11FcSpSaControlElapsed contains (a lower bound on) the elapsed time since the last generation of this notification for the same Fabric. The value of t11FcSpSaControlSuppressed contains the number of generations which were suppressed in the time window after that last generation, or zero if unknown. |
|
.1.3.6.1.2.1.179.0.2 |
This notification is generated when the lifetime (in
seconds or in passed bytes) of an SA is exceeded, and the SA is either immediately terminated or is terminated because an attempt to renew the SA fails. The values of t11FcSpSaControlLifeExcdSpi and t11FcSpSaControlLifeExcdDir contain the SPI and direction of the terminated SA. |