T11-FC-SP-SA-MIB

        This MIB module specifies the management information
required to manage Security Associations established via
Fibre Channel's FC-SP specification.
        
The MIB module consists of six parts:
        
- a per-Fabric table, t11FcSpSaIfTable, of capabilities,
  parameters, status information, and counters; the counters
  include non-transient aggregates of per-SA transient
  counters;
        
- three tables, t11FcSpSaPropTable, t11FcSpSaTSelPropTable,
  and t11FcSpSaTransTable, specifying the proposals for an
  FC-SP entity acting as an SA_Initiator to present to the
  SA_Responder during the negotiation of Security
        
  Associations.  The same information is also used by an
  FC-SP entity acting as an SA_Responder to decide what to
  accept during the negotiation of Security Associations.
  One of these tables, t11FcSpSaTransTable, is used not only
  for information about security transforms to propose and
  to accept, but also as agreed upon during the negotiation
  of Security Associations;
        
- a table, t11FcSpSaTSelDrByTable, of Traffic Selectors
  having the security action of 'drop' or 'bypass' to be
  applied either to ingress traffic that is unprotected by
  FC-SP, or to all egress traffic;
        
- four tables, t11FcSpSaPairTable, t11FcSpSaTSelNegInTable,
  t11FcSpSaTSelNegOutTable, and t11FcSpSaTSelSpiTable,
  containing information about active bidirectional pairs of
  Security Associations; in particular, t11FcSpSaPairTable
  has one row per active bidirectional SA pair,
  t11FcSpSaTSelNegInTable and t11FcSpSaTSelNegOutTable
  contain information on the Traffic Selectors negotiated on
  the SAs, and the t11FcSpSaTSelSpiTable is an alternate
  lookup table such that the Traffic Selector(s) in use on a
  particular Security Association can be quickly determined
  based on the (ingress) SPI value;
        
- a table, t11FcSpSaControlTable, of control and other
  information concerning the generation of notifications for
  events related to FC-SP Security Associations;
        
- one notification, t11FcSpSaNotifyAuthFailure, generated on
  the occurrence of an Authentication failure for a received
  FC-2 or CT_IU frame.
        
Copyright (C) The IETF Trust (2008).  This version
of this MIB module is part of RFC 5324;  see the RFC
itself for full legal notices.
    
Source file
T11-FC-SP-SA-MIB
Last revised
Identity
t11FcSpSaMIB
Base OID
1.3.6.1.2.1.179
Net-SNMP examples using the rfc MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'T11-FC-SP-SA-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'T11-FC-SP-SA-MIB::t11FcSpSaMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'T11-FC-SP-SA-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'T11-FC-SP-SA-MIB::t11FcSpSaMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (142)
.1.3.6.1.2.1.179
.1.3.6.1.2.1.179.0
.1.3.6.1.2.1.179.1
.1.3.6.1.2.1.179.1.1
.1.3.6.1.2.1.179.1.1.1
.1.3.6.1.2.1.179.1.1.1.1
.1.3.6.1.2.1.179.1.1.1.1.1
.1.3.6.1.2.1.179.1.1.1.1.10
Enumeration
.1.3.6.1.2.1.179.1.1.1.1.11
.1.3.6.1.2.1.179.1.1.1.1.12
.1.3.6.1.2.1.179.1.1.1.1.13
.1.3.6.1.2.1.179.1.1.1.1.14
.1.3.6.1.2.1.179.1.1.1.1.15
.1.3.6.1.2.1.179.1.1.1.1.16
.1.3.6.1.2.1.179.1.1.1.1.17
.1.3.6.1.2.1.179.1.1.1.1.18
.1.3.6.1.2.1.179.1.1.1.1.19
.1.3.6.1.2.1.179.1.1.1.1.2
.1.3.6.1.2.1.179.1.1.1.1.20
.1.3.6.1.2.1.179.1.1.1.1.21
.1.3.6.1.2.1.179.1.1.1.1.3
.1.3.6.1.2.1.179.1.1.1.1.4
.1.3.6.1.2.1.179.1.1.1.1.5
.1.3.6.1.2.1.179.1.1.1.1.6
.1.3.6.1.2.1.179.1.1.1.1.7
.1.3.6.1.2.1.179.1.1.1.1.8
.1.3.6.1.2.1.179.1.1.1.1.9
.1.3.6.1.2.1.179.1.2
.1.3.6.1.2.1.179.1.2.1
.1.3.6.1.2.1.179.1.2.1.1
Unsigned32
.1.3.6.1.2.1.179.1.2.1.1.1
.1.3.6.1.2.1.179.1.2.1.1.2
.1.3.6.1.2.1.179.1.2.1.1.3
.1.3.6.1.2.1.179.1.2.1.1.4
Enumeration
.1.3.6.1.2.1.179.1.2.1.1.5
.1.3.6.1.2.1.179.1.2.1.1.6
.1.3.6.1.2.1.179.1.2.1.1.7
.1.3.6.1.2.1.179.1.2.2
.1.3.6.1.2.1.179.1.2.2.1
Unsigned32
.1.3.6.1.2.1.179.1.2.2.1.1
.1.3.6.1.2.1.179.1.2.2.1.10
.1.3.6.1.2.1.179.1.2.2.1.11
.1.3.6.1.2.1.179.1.2.2.1.12
.1.3.6.1.2.1.179.1.2.2.1.13
.1.3.6.1.2.1.179.1.2.2.1.2
.1.3.6.1.2.1.179.1.2.2.1.3
OctetString
.1.3.6.1.2.1.179.1.2.2.1.4
OctetString
.1.3.6.1.2.1.179.1.2.2.1.5
OctetString
.1.3.6.1.2.1.179.1.2.2.1.6
OctetString
.1.3.6.1.2.1.179.1.2.2.1.7
.1.3.6.1.2.1.179.1.2.2.1.8
.1.3.6.1.2.1.179.1.2.2.1.9
.1.3.6.1.2.1.179.1.2.3
.1.3.6.1.2.1.179.1.2.3.1
Unsigned32
.1.3.6.1.2.1.179.1.2.3.1.1
Unsigned32
.1.3.6.1.2.1.179.1.2.3.1.2
.1.3.6.1.2.1.179.1.2.3.1.3
.1.3.6.1.2.1.179.1.2.3.1.4
.1.3.6.1.2.1.179.1.2.3.1.5
.1.3.6.1.2.1.179.1.2.3.1.6
.1.3.6.1.2.1.179.1.2.3.1.7
.1.3.6.1.2.1.179.1.2.3.1.8
.1.3.6.1.2.1.179.1.2.4
.1.3.6.1.2.1.179.1.2.4.1
.1.3.6.1.2.1.179.1.2.4.1.1
.1.3.6.1.2.1.179.1.2.4.1.10
.1.3.6.1.2.1.179.1.2.4.1.11
.1.3.6.1.2.1.179.1.2.4.1.12
.1.3.6.1.2.1.179.1.2.4.1.13
.1.3.6.1.2.1.179.1.2.4.1.2
Enumeration
.1.3.6.1.2.1.179.1.2.4.1.3
OctetString
.1.3.6.1.2.1.179.1.2.4.1.4
OctetString
.1.3.6.1.2.1.179.1.2.4.1.5
OctetString
.1.3.6.1.2.1.179.1.2.4.1.6
OctetString
.1.3.6.1.2.1.179.1.2.4.1.7
.1.3.6.1.2.1.179.1.2.4.1.8
.1.3.6.1.2.1.179.1.2.4.1.9
.1.3.6.1.2.1.179.1.3
.1.3.6.1.2.1.179.1.3.1
.1.3.6.1.2.1.179.1.3.1.1
.1.3.6.1.2.1.179.1.3.1.1.1
.1.3.6.1.2.1.179.1.3.1.1.10
.1.3.6.1.2.1.179.1.3.1.1.11
.1.3.6.1.2.1.179.1.3.1.1.12
.1.3.6.1.2.1.179.1.3.1.1.2
.1.3.6.1.2.1.179.1.3.1.1.3
Unsigned32
.1.3.6.1.2.1.179.1.3.1.1.4
Unsigned32
.1.3.6.1.2.1.179.1.3.1.1.5
.1.3.6.1.2.1.179.1.3.1.1.6
.1.3.6.1.2.1.179.1.3.1.1.7
Enumeration
.1.3.6.1.2.1.179.1.3.1.1.8
.1.3.6.1.2.1.179.1.3.1.1.9
.1.3.6.1.2.1.179.1.3.2
.1.3.6.1.2.1.179.1.3.2.1
Unsigned32
.1.3.6.1.2.1.179.1.3.2.1.1
.1.3.6.1.2.1.179.1.3.2.1.10
.1.3.6.1.2.1.179.1.3.2.1.11
.1.3.6.1.2.1.179.1.3.2.1.2
OctetString
.1.3.6.1.2.1.179.1.3.2.1.3
OctetString
.1.3.6.1.2.1.179.1.3.2.1.4
OctetString
.1.3.6.1.2.1.179.1.3.2.1.5
OctetString
.1.3.6.1.2.1.179.1.3.2.1.6
.1.3.6.1.2.1.179.1.3.2.1.7
.1.3.6.1.2.1.179.1.3.2.1.8
.1.3.6.1.2.1.179.1.3.2.1.9
.1.3.6.1.2.1.179.1.3.3
.1.3.6.1.2.1.179.1.3.3.1
.1.3.6.1.2.1.179.1.3.3.1.1
.1.3.6.1.2.1.179.1.3.3.1.10
.1.3.6.1.2.1.179.1.3.3.1.2
OctetString
.1.3.6.1.2.1.179.1.3.3.1.3
OctetString
.1.3.6.1.2.1.179.1.3.3.1.4
OctetString
.1.3.6.1.2.1.179.1.3.3.1.5
OctetString
.1.3.6.1.2.1.179.1.3.3.1.6
.1.3.6.1.2.1.179.1.3.3.1.7
.1.3.6.1.2.1.179.1.3.3.1.8
.1.3.6.1.2.1.179.1.3.3.1.9
.1.3.6.1.2.1.179.1.3.4
.1.3.6.1.2.1.179.1.3.4.1
.1.3.6.1.2.1.179.1.3.4.1.1
Unsigned32
.1.3.6.1.2.1.179.1.3.4.1.2
.1.3.6.1.2.1.179.1.3.4.1.3
.1.3.6.1.2.1.179.1.3.4.1.4
.1.3.6.1.2.1.179.1.4
.1.3.6.1.2.1.179.1.4.1
.1.3.6.1.2.1.179.1.4.1.1
.1.3.6.1.2.1.179.1.4.1.1.1
.1.3.6.1.2.1.179.1.4.1.1.10
.1.3.6.1.2.1.179.1.4.1.1.11
.1.3.6.1.2.1.179.1.4.1.1.12
.1.3.6.1.2.1.179.1.4.1.1.13
.1.3.6.1.2.1.179.1.4.1.1.2
.1.3.6.1.2.1.179.1.4.1.1.3
.1.3.6.1.2.1.179.1.4.1.1.4
OctetString
.1.3.6.1.2.1.179.1.4.1.1.5
.1.3.6.1.2.1.179.1.4.1.1.6
.1.3.6.1.2.1.179.1.4.1.1.7
secondsUnsigned32
.1.3.6.1.2.1.179.1.4.1.1.8
.1.3.6.1.2.1.179.1.4.1.1.9
.1.3.6.1.2.1.179.2
.1.3.6.1.2.1.179.2.1
.1.3.6.1.2.1.179.2.2
Dependencies (10) 7 direct · 3 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Conformance Groups (8)
A collection of objects containing information
related to capabilities of FC-SP entities.
.1.3.6.1.2.1.179.2.2.1
A collection of objects containing parameters
and status information related to FC-SP entities.
.1.3.6.1.2.1.179.2.2.2
A collection of objects containing summary
counters for FC-SP Security Associations.
.1.3.6.1.2.1.179.2.2.3
A collection of objects containing information
related to making and accepting proposals for
FC-SP Security Associations.
.1.3.6.1.2.1.179.2.2.4
A collection of objects containing information
about Traffic Selectors of traffic to drop or bypass
for FC-SP Security.
.1.3.6.1.2.1.179.2.2.5
A collection of objects containing information related
to currently active FC-SP Security Associations.
.1.3.6.1.2.1.179.2.2.6
A collection of objects containing information
related to notifications of events concerning
FC-SP Security Associations.
.1.3.6.1.2.1.179.2.2.7
A collection of notifications of events concerning
FC-SP Security Associations.
.1.3.6.1.2.1.179.2.2.8
Compliance Statements (1)

OID .1.3.6.1.2.1.179.2.1.1
The compliance statement for entities that implement
FC-SP Security Associations.
Required groups
Object refinements
ObjectAccessSyntaxDescription
t11FcSpSaIfStorageType readonly
Write access is not required.
t11FcSpSaTSelPropStorageType readonly
Write access is not required.
t11FcSpSaTransStorageType readonly
Write access is not required.
t11FcSpSaIfReplayPrevention readonly
Write access is not required.
t11FcSpSaIfReplayWindowSize readonly
Write access is not required.
t11FcSpSaIfTerminateAllSas readonly
Write access is not required.
t11FcSpSaPropSecurityProt readonly
Write access is not required.
t11FcSpSaPropTSelListIndex readonly
Write access is not required.
t11FcSpSaPropTransListIndex readonly
Write access is not required.
t11FcSpSaPropAcceptAlgorithm readonly
Write access is not required.
t11FcSpSaPropRowStatus readonly
Write access is not required.
t11FcSpSaTSelPropDirection readonly
Write access is not required.
t11FcSpSaTSelPropStartSrcAddr readonly
Write access is not required.
t11FcSpSaTSelPropEndSrcAddr readonly
Write access is not required.
t11FcSpSaTSelPropStartDstAddr readonly
Write access is not required.
t11FcSpSaTSelPropEndDstAddr readonly
Write access is not required.
t11FcSpSaTSelPropStartRCtl readonly
Write access is not required.
t11FcSpSaTSelPropEndRCtl readonly
Write access is not required.
t11FcSpSaTSelPropStartType readonly
Write access is not required.
t11FcSpSaTSelPropEndType readonly
Write access is not required.
t11FcSpSaTSelPropRowStatus readonly
Write access is not required.
t11FcSpSaTransSecurityProt readonly
Write access is not required.
t11FcSpSaTransEncryptAlg readonly
Write access is not required.
t11FcSpSaTransEncryptKeyLen readonly
Write access is not required.
t11FcSpSaTransIntegrityAlg readonly
Write access is not required.
t11FcSpSaTransRowStatus readonly
Write access is not required.
t11FcSpSaTSelDrByAction readonly
Write access is not required.
t11FcSpSaTSelDrByStartSrcAddr readonly
Write access is not required.
t11FcSpSaTSelDrByEndSrcAddr readonly
Write access is not required.
t11FcSpSaTSelDrByStartDstAddr readonly
Write access is not required.
t11FcSpSaTSelDrByEndDstAddr readonly
Write access is not required.
t11FcSpSaTSelDrByStartRCtl readonly
Write access is not required.
t11FcSpSaTSelDrByEndRCtl readonly
Write access is not required.
t11FcSpSaTSelDrByStartType readonly
Write access is not required.
t11FcSpSaTSelDrByEndType readonly
Write access is not required.
t11FcSpSaTSelDrByRowStatus readonly
Write access is not required.
t11FcSpSaPairTerminate readonly
Write access is not required.
t11FcSpSaControlAuthFailEnable readonly
Write access is not required.
t11FcSpSaControlWindow readonly
Write access is not required.
t11FcSpSaControlMaxNotifs readonly
Write access is not required.
t11FcSpSaControlLifeExcdEnable readonly
Write access is not required.
Notifications / Traps (2)
NameOIDDescription
.1.3.6.1.2.1.179.0.1
When this notification is generated, it indicates the
occurrence of an Authentication failure for a received
FC-2 or CT_IU frame. The t11FcSpSaControlInboundSpi,
t11FcSpSaControlSource, and t11FcSpSaControlDestination
objects in the varbindlist are the frame's SPI, source and
destination addresses, respectively. t11FcSpSaControlFrame
provides the (beginning of the) frame's content if such is
available.

This notification is generated only for the first
occurrence of an Authentication failure on a Fabric within
a time window. Subsequent occurrences of an Authentication
Failure on the same Fabric within the same time window
are counted but suppressed.

The value of t11FcSpSaControlElapsed contains (a lower bound
on) the elapsed time since the last generation of this
notification for the same Fabric. The value of
t11FcSpSaControlSuppressed contains the number of
generations which were suppressed in the time window after
that last generation, or zero if unknown.
.1.3.6.1.2.1.179.0.2
This notification is generated when the lifetime (in
seconds or in passed bytes) of an SA is exceeded, and the
SA is either immediately terminated or is terminated
because an attempt to renew the SA fails. The values of
t11FcSpSaControlLifeExcdSpi and t11FcSpSaControlLifeExcdDir
contain the SPI and direction of the terminated SA.