ALCATEL-IND1-AAA-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
30
Rows
30
Columns
210
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1 · 1 row entry · 42 columns
This table shows current configuration for each AAA server.
aaaServerEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1
An AAA server configuration identified by its protocol
and its index. An entry is created/removed when a server
is defined or undefined with IOS configuration commands
via CLI or by issuing appropriate sets to this tabl…
Indexes
aaasName
Column Syntax OID
aaasName
Name of the server.
This name is given by the operator to refer the server.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.1
aaasProtocol
Protocol used with the server:
radius(1) - RADIUS
ldap(2) - LDAP
ace(3) - ACE
tacacs(4) - TACACS+
Enumerationr/w
Enumerated Values:
1radius
2ldap
3ace
4tacacs
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.2
aaasHostName
DNS name of the server host.
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.3
aaasIpAddress
IP address of the server host.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.4
aaasHostName2
DNS name of the backup server host.
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.5
aaasIpAddress2
IP address of the backup server host.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.6
aaasRetries
Number of retries the switch makes to the server to
authenticate a user before trying the next backup server.
The default value is 3.
Integer32r/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.7
aaasTimout
Time-out for server replies to authentication requests.
The default value is 2.
Integer32r/w
Constraints:
range: 0-30
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.8
aaasRadKey
The shared secret is a string of characters known to the switch
and to the RADIUS server, but it is not sent out over the network.
The secret can be any text string and must be configured here as
well as on the server. …
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.9
aaasRadAuthPort
For RADIUS server only.
Port number for authentication request;
the host is not used for authentication if set to 0.
The default value is 1645.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.10
aaasRadAcctPort
For RADIUS server only.
Port number for accounting request;
the host is not used for authentication if set to 0.
The default value is 1646.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.11
aaasLdapPort
For LDAP server only.
Port number for LDAP server host.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.12
aaasLdapDn
For LDAP server only.
the super user dn, i.e., the administrative distinguished name
recognized by the LDAP-enabled directory servers
(e.g., cn=manager)
OctetStringr/w
Constraints:
range: 0-255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.13
aaasLdapPasswd
For LDAP server only.
the super user password, i.e., the administrative password
recognized by LDAP-enabled directory servers (e.g., secret).
The secret is stored encrypted using a two way algorithm.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.14
aaasLdapSearchBase
For LDAP server only.
Search base recognized by LDAP-enabled
directory servers (e.g.,o=company, c=US).
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.15
aaasLdapServType
For LDAP server only.
Directory server type used in LDAP Authentication:
ns(0) - non significant value
generic(1) - Generic Schema
netscape(2) - Netscape Directory Server
novell(3) - Novell …
Enumerationr/w
Enumerated Values:
0ns
1generic
2netscape
3novell
4sun
5microsoft
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.16
aaasLdapEnableSsl
Only for LDAP server.
Specify if the connection between the swtich and the LDAP server
use a SSL session.
Enumerationr/w
Enumerated Values:
0ns
1true
2false
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.17
aaasAceClear
Only for ACE server.
The ACE/Server generates a secrets that it sends to clients
for authentication. While you cannot configure the secret on
the switch, you can clear it.
To clear the current ACE/Server secret, set thi…
Enumerationr/w
Enumerated Values:
0ns
1true
2false
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.18
aaasRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.19
aaasTacacsKey
The shared secret is a string of characters known to the switch
and to the TACACS+ server, but it is not sent out over the network.
The secret can be any text string and must be configured here as
well as on the server.…
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.20
aaasTacacsPort
For TACACS+ server only.
Port number for LDAP server host.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.21
aaasHttpPort
For HTTP server only.
Port number for LDAP server host.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.22
aaasHttpDirectory
For HTTP server only.
A combination of directory tree and filename where the CRL can be found.
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.23
aaasHttpProxyHostName
For HTTP server only.
DNS name of the proxy server.
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.24
aaasHttpProxyIpAddress
For HTTP server only.
IP address of the proxy server.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.25
aaasHttpProxyPort
For HTTP server only.
Port number for HTTP proxy server.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.26
aaasVrfName
Name of the VRF that the server is on.
This VRF name is valid only when the server type is RADIUS.
(aaasProtocol = 1 (Radius).
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.27
aaasRadMacAddrCase
Only for Radius Server.
This Attribute contains a text string which identifies the case of the Mac Address Authentication.
Enumerationr/w
Enumerated Values:
0uppercase
1lowercase
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.28
aaasRadNasPort
Only for Radius Server.
This Attribute contains a text string which identifies the port of
the NAS which is authenticating the user.
Enumerationr/w
Enumerated Values:
0default
1ifindex
2not-applicable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.29
aaasRadNasPortId
Only for Radius Server.
This Attribute contains a text string which identifies the port of
the NAS which is authenticating the user.
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.30
aaasRadNasPortType
Only for Radius Server.
It indicates the type of the physical port of the NAS
which is authenticating the user.
AaasRadNasPortTypeConventionr/w
Textual Convention: AaasRadNasPortTypeConvention Enumeration
Type Values:
0async
1sync
2isdn-sync
3isdn-async-v120
4isdn-async-v110
5virtual
6piafs
7hdlc-clear-channel
8x25
9x75
10g3-fax
11sdsl-symmetric-dsl
12adsl-cap-asymmetric-dsl
13adsl-dmt
14idsl
15ethernet
16xdsl
17cable
18wireless-other
19wireless-ieee-802-11
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.31
aaasRadMacAddrFormat
This Attribute shall set Mac-address-format to uppercase or lowercase.
By default the format will be uppercase.
Enumerationr/w
Enumerated Values:
0uppercase
1lowercase
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.32
aaasRadUniqueAcctSessionId
Getting command based Accounting Session_ID
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.33
aaasRadMacAddrCaseStatus
To enable/disable mac-address case feature
Enumerationr/w
Enumerated Values:
0disable
1enable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.34
aaasRadServerStatus
The current status of the configured server
Enumeration
Enumerated Values:
0down
1up
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.35
aaasRadHealthstatus
To Enable/Disable Radius-Health-Check feature
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.36
aaasRadPollInterval
To set polling value for each radius server
SNMPv2-SMIInteger32r/w
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.37
aaasRadFailoverStatus
To enable/disable failover for radius server
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.38
aaasRadUser
Username for Radius server
SNMPv2-TCDisplayStringr/w
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.39
aaasRadPasswd
Password for radius server
SNMPv2-TCDisplayStringr/w
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.40
aaaRadServerPrimaryStatus
The status of primary server
Enumeration
Enumerated Values:
0down
1up
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.41
aaaRadServerBackupStatus
The status of backup server
Enumeration
Enumerated Values:
0down
1up
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.1.1.1.42
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1 · 1 row entry · 7 columns
This table allow to display and modify the configuration of the
authentication servers for the authenticated vlans.
aaaAuthVlanEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1
There can be one or several entries in this table. In case of
single authority, all vlan are authenticated by the same set of
servers, the aaatvVlan index is then equal to 0. In case of multiple
authorities, each authen…
Indexes
aaatvVlan
Column Syntax OID
aaatvVlan
It indicate the vlan number authenticated by the servers.
The value (0) means that all vlan are authenticated by the same
servers (single mode configuration).
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.1
aaatvName1
Name of the server.
It corresponds to an index value of the aaaServerTable
An Ace server can not be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.2
aaatvName2
Name of the server.
It corresponds to an index value of the aaaServerTable
An Ace server can not be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.3
aaatvName3
Name of the server.
It corresponds to an index value of the aaaServerTable
An Ace server can not be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.4
aaatvName4
Name of the server.
It corresponds to an index value of the aaaServerTable
An Ace server can not be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.5
aaatvRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.6
aaatvCertificate
use of x509 user certificate during the HTTPs session establisment.
noCertificate(0)- no user certificate is required,
certificateOnly(1) - the DN from the certifiicate is used to access to the authorization
data of the…
Enumerationr/w
Enumerated Values:
0noCertificate
1certificateOnly
2certificateWithPassword
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.1.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2 · 1 row entry · 8 columns
This table allow to display and modify the configuration of the
authentication servers for the switch accesses.
aaaAuthSAEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1
A switch access authentication entry is specified by the type
of access.
Indexes
aaatsInterface
Column Syntax OID
aaatsInterface
Type of connection that must be authenticated
default(1) -define the default authentication method for console,
telnet, ftp, snmp , http and ssh. If the operator
interface is not especially configured the default value
Enumerationr/w
Enumerated Values:
1default
2console
3telnet
4ftp
5http
6snmp
7ssh
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.1
aaatsName1
Name of the server.
Special value 'local' correspond to the local database.
Other name correspond to an index value of the aaaServerTable
snmp entry can only use ldap server and local database.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.2
aaatsName2
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local database.
Other name correspond to an index value of the aaaServerTable
snmp entry can only use ldap server and loc…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.3
aaatsName3
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local database.
Other name correspond to an index value of the aaaServerTable
snmp entry can only use ldap server and loc…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.4
aaatsName4
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local database.
Other name correspond to an index value of the aaaServerTable
snmp entry can only use ldap server and loc…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.5
aaatsName5
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local database.
Other name correspond to an index value of the aaaServerTable
snmp entry can only use ldap server and loc…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.6
aaatsRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.7
aaatsCertificate
use of x509 user certificate during the HTTPs session establisment.
noCertificate(0)- no user certificate is required,
certificateOnly(1) - the DN from the certifiicate is used to access to the authorization
data of the…
Enumerationr/w
Enumerated Values:
0noCertificate
1certificateOnly
2certificateWithPassword
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.2.1.8
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3 · 1 row entry · 6 columns
This table allows to display and configure the accounting
servers for authenticated Vlans.
aaaAcctVlanEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1
There can be one or several entries in this table. In case of
single authority, accounting information for all vlans are sent
to the same set of servers, the aaatVlan index is then equal to 0. In case of multiple
author…
Indexes
aaacvVlan
Column Syntax OID
aaacvVlan
Current vlan number.
The value (0) for avlan interface means that all authenticated
vlans use the same servers for authentication.
Integer32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.1
aaacvName1
Name of the server.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.2
aaacvName2
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.3
aaacvName3
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.4
aaacvName4
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.5
aaacvRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.3.1.6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4 · 1 row entry · 8 columns
This table shows current configuration for Switch access accounting.
aaaAcctSAEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1
Accounting configuration for switch access.
Indexes
aaacsInterface
Column Syntax OID
aaacsInterface
For now, accounting for console, telnet, ftp, http, snmp, ssh are stored
in the same set of servers, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.1
aaacsName1
Name of the server.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.2
aaacsName2
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.3
aaacsName3
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.4
aaacsName4
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.5
aaacsRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.6
aaaAccountingSessionIdStatus
Getting command based Accounting Session_ID
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.7
aaacsName5
Name of a server used if the precedent is not accessible.
Special value 'local' correspond to the local log.
Other name correspond to an index value of the aaaServerTable
An Ace server can not be used for accounting.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.4.1.8
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5 · 1 row entry · 8 columns
This table shows current configuration for 802.1X authentication.
aaaAuth8021xEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1
configuration for 802.1X authentication.
Indexes
aaatxInterface
Column Syntax OID
aaatxInterface
For now, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.1
aaatxName1
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.2
aaatxName2
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.3
aaatxName3
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.4
aaatxName4
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.5
aaatxOpen
Type of port openning after authentication. If open-global(1) the port treats packet with unknown MAC addresses like an un-authenticated port. If open-unique(2), the port drops incomming packet with unknown MAC addresse…
Enumerationr/w
Enumerated Values:
1global
2unique
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.6
aaatxRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.7
aaatxName5
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.5.1.8
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6 · 1 row entry · 7 columns
This table shows current configuration for 802.1X accounting.
aaaAcct8021xEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1
Configuration for 802.1X accounting.
Indexes
aaacxInterface
Column Syntax OID
aaacxInterface
For now, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.1
aaacxName1
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.2
aaacxName2
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.3
aaacxName3
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.4
aaacxName4
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.5
aaacxRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.6
aaacxName5
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.6.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7 · 1 row entry · 7 columns
This table shows current configuration for PKI.
aaaPkiEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1
Configuration for PKI.
Indexes
aaatpInterface
Column Syntax OID
aaatpInterface
For now, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.1
aaatpName1
Name of the server contening the CRL.
It corresponds to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.2
aaatpName2
Name of the server contening the CRL.
It corresponds to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.3
aaatpName3
Name of the server contening the CRL.
It corresponds to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.4
aaatpName4
Name of the server contening the CRL.
It corresponds to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.5
aaatpLevel
level of control to do on the user certificate.
certificate means that there is a valid chain of certificate between the user certificate and a root certificate known by the switch. The root certificates are managed usi…
Enumerationr/w
Enumerated Values:
1certificate
2notRevoked
3repository
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.6
aaatpRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.7.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8 · 1 row entry · 7 columns
This table shows current configuration for non-suplicant ( MAC based ) authentication.
aaaAuthMACEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1
configuration for MAC based authentication.
Indexes
aaatxInterface
Column Syntax OID
aaaMacInterface
For now, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.1
aaaMacSrvrName1
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.2
aaaMacSrvrName2
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.3
aaaMacSrvrName3
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.4
aaaMacSrvrName4
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.5
aaaMacSrvrRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.6
aaaMacSrvrName5
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.8.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9 · 1 row entry · 7 columns
This table stores the commands that will be logged during an accounting session.
This feature is valid only for Tacacs+ accounting
aaaAcctCmdEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1
Tacacs+ Accounting configuration for executed commands.
Indexes
aaacmdInterface
Column Syntax OID
aaacmdInterface
For now, accounting for console, telnet, ftp, http, snmp, ssh are stored
in the same set of servers, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.1
aaacmdSrvName1
Name of the Tacacs+ server.
Other name correspond to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.2
aaacmdSrvName2
Name of the Tacacs+ server used if the precedent is not accessible.
Other name correspond to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.3
aaacmdSrvName3
Name of the Tacacs+ server used if the precedent is not accessible.
Other name correspond to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.4
aaacmdSrvName4
Name of the Tacacs+ server used if the precedent is not accessible.
Other name correspond to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.5
aaacmdRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.6
aaacmdSrvName5
Name of the Tacacs+ server used if the precedent is not accessible.
Other name correspond to an index value of the aaaServerTable
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.9.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10 · 1 row entry · 7 columns
This table shows current configuration for MAC accounting.
aaaAcctMACEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1
Configuration for MAC accounting.
Indexes
aaaAcctSvrInterface
Column Syntax OID
aaaAcctSvrInterface
For now, the index is always (1).
Integer32r/w
Constraints:
range: 1-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.1
aaaAcctSvr1
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.2
aaaAcctSvr2
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.3
aaaAcctSvr3
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.4
aaaAcctSvr4
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.5
aaaAcctSvrRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.6
aaaAcctSvr5
Name of the server.
It corresponds to an index value of the aaaServerTable
Only RADIUS server can be used in front hand.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.2.10.1.7
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1 · 1 row entry · 19 columns
This table shows current configuration for the local user database.
aaaUserEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1
An user configuration identified by its user name.
Indexes
aaauUserName
Column Syntax OID
aaauUserName
Name of the user.
OctetStringr/w
Constraints:
range: 0-63
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.1
aaauPassword
Password of the user. For get response the password in encoded in a
one way method. This makes the password readable by noone.
OctetStringr/w
Constraints:
range: 0-47
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.2
aaauReadRight1
Specifies the families that the user can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, the user is allowed to run
commands of this family.…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.3
aaauReadRight2
Specifies the families that the user can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, the user is allowed to run
commands of this family.…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.4
aaauWriteRight1
Specifies the families that the user can execute with write right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, the user is allowed to run commands of
this family…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.5
aaauWriteRight2
Specifies the families that the user can execute with write right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, the user is allowed to run commands of
this family…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.6
aaauProfile obsolete
Specifies the profile number.
A profile number in the user account database represents the geographic
privilege. This number points to an entry in the table of the user profiles.
Integer32r/w
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.7
aaauSnmpLevel
Specifies if the user is authorized to use SNMP and if yes its security level.
no(1) - Not authorized to use SNMP.
noauth(2) - SNMPv1,SNMPv2c or SNMPv3 without authentication.
sha(3) - SNMPv3 with SHA authentication and…
Enumerationr/w
Enumerated Values:
1no
2noauth
3sha
4md5
5shaDes
6md5Des
7shaAes
8shaAes192
9shaAes256
10sha3Des
11sha224
12sha256
13sha224Aes
14sha224Aes192
15sha224Aes256
16sha2243Des
17sha256Aes
18sha256Aes192
19sha256Aes256
20sha2563Des
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.8
aaauSnmpAuthKey
Authentication key of the user. The key is encoded in a two way method.
The encryption key is deducted from this key.
OctetString
Constraints:
range: 0-255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.9
aaauRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.10
aaauOldPassword
Internal use
OctetStringr/w
Constraints:
range: 0-47
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.11
aaauEndUserProfile
Specifies the END user profile name.
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.12
aaauPasswordExpirationDate
The local time of when the password would be expired.
This date will be reset once the value of
aaaAsaDefaultPasswordExpirationInDays is updated.

Only the following format is valid:

mm/dd/y…
OctetStringr/w
Constraints:
range: 0-16
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.13
aaauPasswordExpirationInMinute
Number of minutes from now till the password expiration time.
Setting this object will update aaauPasswordExpirationDate.
If -1, password will not be expired.
If 0, password has been expired.
Integer32r/w
Constraints:
range: -1-216000
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.14
aaauPasswordAllowModifyDate
The local time of when the password can be start to be modified.
This date will be reset once the value of
aaauPasswordAllowModifyDate is updated.

Only the following format is valid:

mm/dd/…
OctetString
Constraints:
range: 0-16
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.15
aaauPasswordLockoutEnable
Indicate whether this account is locked out.
Enumerationr/w
Enumerated Values:
1lockout
2unlock
3expired
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.16
aaauBadAtempts
Number bad password attempts in the observation window.
Integer32
Constraints:
range: 0-999
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.17
aaauSnmpOnly
Enable or disable User SNMP only restriction
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.18
aaauSnmpPrivPassword
Privacy Password of the user. For get response the password in encoded in a
one way method. This makes the password readable by none.
OctetStringr/w
Constraints:
range: 8-30
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.3.1.1.19
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4 · 1 row entry · 6 columns
Provide the list of users currently authenticated into the
switch for bridging purpose.
aaaAuthenticatedUserEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1
An entry in the AaaAuthenticatedUserTable.
Indexes
aaaaMacAddress
Column Syntax OID
aaaaMacAddress
Mac address of the user's device.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.1
aaaaUserName
Login name of the user.
OctetString
Constraints:
range: 0-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.2
aaaaSlot
Slot number on which user is connected.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.3
aaaaPort
Port number on which the user is connected.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.4
aaaaVlan
Vlan number on which the user is authenticated.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.5
aaaaDrop
Allow to remove a Mac address from a Vlan.
The corresponding user is logged out of the network.
Enumerationr/w
Enumerated Values:
1true
2false
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.4.1.6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.7 · 1 row entry · 2 columns
Vlan authenticated IP address Table
aaaAvlanAddressEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.7.1
Vlan authenticated IP address entry
Indexes
aaaAvlanId
Column Syntax OID
aaaAvlanId
Vlan Id corresponding to the authenticated IP address
Integer32
Constraints:
range: 1-4094
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.7.1.1
aaaAvlanIpAddress
Authenticated IP address for this vlan id
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.7.1.2
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8 · 1 row entry · 9 columns
User Network Profile Table
aaaUserNetProfileEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1
User Network Profile entry
Indexes
aaaUserNetProfileName
Column Syntax OID
aaaUserNetProfileName
The name of this profile.
OctetString
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.1
aaaUserNetProfileVlanID
The VLAN id for this profile.
Integer32r/w
Constraints:
range: 1-4094
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.2
aaaUserNetProfileRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.3
aaaUserNetProfileHICflag
The flag to indicate if HIC is enabled (1) or disabled (2).
Integer32r/w
Constraints:
range: 1-2
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.4
aaaUserNetProfileQosPolicyListName
The name of the QoS Policy List name that will be used if this
User Network Profile is applied for a given device along with
aaaUserNetProfileVlanID.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.5
aaaUserNetProfileMaxIngressBw
Maximum Ingress Bandwidth (Kbits/sec) allowed for traffic associated to this profile.
If -1, specifies Not Applicable Bandwidth means Ingress Bw will not be applied.
Integer32r/w
Constraints:
range: -1-10000000
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.6
aaaUserNetProfileMaxEgressBw
Maximum Egress Bandwidth (Kbits/sec) allowed for traffic associated to this profile.
If -1, specifies Not Applicable Bandwidth means Egress Bw will not be applied.
Integer32r/w
Constraints:
range: -1-10000000
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.7
aaaUserNetProfileMaxDefaultDepth
Maximum Default Depth (Kbits/sec) associated to Bandwidth.
If -1, specifies Not Applicable Depth.For depth value of -1
and 0 default optimal depth will be applied, otherwise BW will
be applied with depth specified
Integer32r/w
Constraints:
range: -1-131072
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.8
aaaUserNetworkProfileRedirectUrl
The redirection url is used to re-direct to the Clearpass page for the BYOD feature.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.8.1.9
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1 · 1 row entry · 8 columns
This table shows current configuration for each HIC server.
aaaHicSvrEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1
A HIC server configuration.
Indexes
aaaHicSvrName
Column Syntax OID
aaaHicSvrName
Name of the server.
This name is given by the operator to refer the server.
OctetString
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.1
aaaHicSvrIpAddr
IP address of the server host.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.2
aaaHicSvrPort
For HIC server only. Port number for HIC request
Integer32r/w
Constraints:
range: 1025-65535
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.3
aaaHicSvrKey
The shared secret is a string of characters known to the switch
and to the HIC server. It is used to compute the digest to
preserve the integrity between the HIC server and the AoS Switch.
The secret is stored encryp…
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.4
aaaHicSvrRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.5
aaaHicSvrStatus
HIC server status.
Enumeration
Enumerated Values:
1down
2up
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.6
aaaHicSvrRole
Role of the server either primary or backup
Enumeration
Enumerated Values:
1primary
2backup
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.7
aaaHicSvrConnection
The server connection specifies the current mode of the server either active or inactive.
Enumeration
Enumerated Values:
1active
2inactive
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.1.1.8
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2 · 1 row entry · 4 columns
This table contains the list of allowed/exception IP Addresses the 
the HIC hosts allowed to access during HIC. Those are the IP addresses
of the Remediation/Patch servers, and the Web Agent Download server.
aaaHicAllowedEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2.1
A Remediation server configuration.
Indexes
aaaHicAllowedName
Column Syntax OID
aaaHicAllowedName
Name of the server.
This name is given by the operator to refer the server.
OctetString
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2.1.1
aaaHicAllowedIpAddr
IP address of the allowed entry.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2.1.2
aaaHicAllowedIpMask
IP Mask of the allowed entry.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2.1.3
aaaHicAllowedRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.2.1.4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.3 · 1 row entry · 3 columns
This table shows list of MAC addresses that overrides the
existing HIC status.
aaaHicOverrideEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.3.1
HIC MAC override list configuration.
Indexes
aaaHicOverrideMac
Column Syntax OID
aaaHicOverrideMac
Static MAC address index to each override entry.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.3.1.1
aaaHicOverrideStatus
Overriding status of each static MAC address.
Enumerationr/w
Enumerated Values:
1enforce
2bypass
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.3.1.2
aaaHicOverrideRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.3.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.4 · 1 row entry · 2 columns
This table shows list of HIC Hosts and their active HIC status.
aaaHicHostEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.4.1
HIC Host status information.
Indexes
aaaHicHostMac
Column Syntax OID
aaaHicHostMac
Static MAC address index to each override entry.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.4.1.1
aaaHicHostStatus
HIC status of each HIC Host.
Enumeration
Enumerated Values:
1inprogress
2success
3fail
4timeout
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.11.4.1.2
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12 · 1 row entry · 5 columns
A list of IP network address rules.  This is used to match 
the InetAddress of a packet to a User Network Profile entry.
aaaUNPIpNetRuleEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1
An IP network address rule entry.
Indexes
aaaUNPIpNetRuleAddrType aaaUNPIpNetRuleAddr aaaUNPIpNetRuleMask
Column Syntax OID
aaaUNPIpNetRuleAddrType
The IP network address type used for VLAN classification. For now
Only IPv4 is supported.
INET-ADDRESS-MIBInetAddressType
Textual Convention: INET-ADDRESS-MIBInetAddressType Enumeration
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1.1
aaaUNPIpNetRuleAddr
The IP network address used for VLAN classification. Only IPv4 is
supported.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1.2
aaaUNPIpNetRuleMask
The IP network mask applying to the IP network address.
INET-ADDRESS-MIBInetAddress
Textual Convention: INET-ADDRESS-MIBInetAddress OctetString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1.3
aaaUNPIpNetRuleProfileName
The profile name in the User Network Profile Table to be
applied.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1.4
aaaUNPIpNetRuleRowStatus
Row Status for creating/deleting rules.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.12.1.5
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.13 · 1 row entry · 3 columns
A list of MAC address rules.  This is used to match 
the MAC Address of a packet to a User Network Profile entry
aaaUNPMacRuleEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.13.1
A MAC rule entry.
Indexes
aaaUNPMacRuleAddr
Column Syntax OID
aaaUNPMacRuleAddr
The MAC address used for VLAN classification.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.13.1.1
aaaUNPMacRuleProfileName
The profile name in the User Network Profile Table to be
applied.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.13.1.2
aaaUNPMacRuleRowStatus
Row Status for creating/deleting rules.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.13.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14 · 1 row entry · 4 columns
A list of MAC range rules.  This is used to match 
the MAC Address Range of a packet to a User Network Profile entry.
aaaUNPMacRangeRuleEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14.1
A MAC range rule entry.
Indexes
aaaUNPMacRangeRuleLoAddr
Column Syntax OID
aaaUNPMacRangeRuleLoAddr
The lower bound of MAC address range used for VLAN classification.
SNMPv2-TCMacAddress
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14.1.1
aaaUNPMacRangeRuleHiAddr
The upper bound of MAC address range used for VLAN classification.
SNMPv2-TCMacAddressr/w
Textual Convention: SNMPv2-TCMacAddress OctetString
Type Constraints:
range: 6
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14.1.2
aaaUNPMacRangeRuleProfileName
The profile name in the User Network Profile Table to be
applied.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14.1.3
aaaUNPMacRangeRuleRowStatus
Row Status for creating/deleting rules.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.14.1.4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.15 · 1 row entry · 3 columns
This table shows current configuration for HIC server down UNP mapping.
aaaHicSvrDownUnpMapEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.15.1
A HIC server down UNP configuration.
Indexes
aaaHicSvrDownUnpName
Column Syntax OID
aaaHicSvrDownUnpName
The profile name which needs to be modified when the HIC server is down.
OctetString
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.15.1.1
aaaHicSvrDownMappedUnpName
The target UNP profile name to which the host needs to be moved when the HIC server is down.
OctetStringr/w
Constraints:
range: 1-32
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.15.1.2
aaaHicSvrDownUnpRowStatus
Row Status for creating/deleting UNP mapping.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.15.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1 · 1 row entry · 8 columns
This table is used to configure ClearPass redirect server name with its Ip address and url list.
aaaRedirectServerEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1
Redirect server configuration.
Indexes
aaaRedirectServerName
Column Syntax OID
aaaRedirectServerName
The name of the ClearPass redirect server name.
OctetString
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.1
aaaRedirectServerIpAddress
The Ip Address for the clearpass rediret server for BYOD feature.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.2
aaaRedirectServerUrl1
The redirect URL configured on the server. Maximum it can accept 5 URLs.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.3
aaaRedirectServerUrl2
The redirect URL configured on the server. Maximum it can accept 5 URLs.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.4
aaaRedirectServerUrl3
The redirect URL configured on the server. Maximum it can accept 5 URLs.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.5
aaaRedirectServerUrl4
The redirect URL configured on the server. Maximum it can accept 5 URLs.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.6
aaaRedirectServerUrl5
The redirect URL configured on the server. Maximum it can accept 5 URLs.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.7
aaaRedirectSvrConfigRowStatus
The Rowstatus of the Redirect Server Entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.1.1.8
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.2 · 1 row entry · 3 columns
This table is used to configure redirect URLs for the redirection to happen.
aaaRedirectURLEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.2.1
Redirect URL configuration.Maximum 5 entries can be allowed
Indexes
aaaRedirectServerUrlName
Column Syntax OID
aaaRedirectServerUrlName
The name of the redirect URL.At maximum 5 redirect URLS can be allowed per switch.
OctetString
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.2.1.1
aaaRedirectServerUrl
The URL where the redirect should happen. At maximum 5 URLS can be allowed per switch.
OctetStringr/w
Constraints:
range: 1-31
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.2.1.2
aaaRedirectServerRowStatus
The RowStatus of the table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.2.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.4 · 1 row entry · 3 columns
A table to list port bounce status in slot/port basis.
aaaPortBounceInterfaceEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.4.1
Entries for aaa port bounce slot/port status.
Indexes
IF-MIBifIndex
Column Syntax OID
aaaPortBouncePortSlot
The physical slot number to enable/disable port bounce.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.4.1.1
aaaPortBounceIF
The interface number of the switch.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.4.1.2
aaaPortBounceStatus
Enabling/Disabling Port bounce in slot/port basis.
Enumerationr/w
Enumerated Values:
1enable
2disable
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.4.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.5 · 1 row entry · 3 columns
This table is used to configure the BYOD white list IP address.
aaaBYODWhiteListEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.5.1
BYOD White List IP configuration.
Indexes
aaaBYODWhiteListIPAddress aaaBYODWhiteListIPMask
Column Syntax OID
aaaBYODWhiteListIPAddress
The Ip Address added as a whitelist entry.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.5.1.1
aaaBYODWhiteListIPMask
The IP network mask applying to the whitelist IP address.
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.5.1.2
aaaBYODWhiteListRowStatus
The RowStatus of the table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.16.5.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.1 · 1 row entry · 3 columns
This table is used to configure SwitchAccess management station's Ip address.
aaaSwitchAccessMgmtStationEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.1.1
SwitchAccessManagementStation configuration.
Indexes
aaaSwitchAccessMgmtStationIpAddress
Column Syntax OID
aaaSwitchAccessMgmtStationIpAddress
The Ip Address for the SwitchAccess management station
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.1.1.1
aaaSwitchAccessMgmtStationIpAddressMask
The Ip Address mask for the SwitchAccess management station
SNMPv2-SMIIpAddressr/w
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.1.1.2
aaaSwitchAccessMgmtStationRowStatus
The Rowstatus of the AaaSwitchAccessMgmtStationEntry. 0 (allowed) 1 (blocked).
Integer32r/w
Constraints:
range: 0-1
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.1.1.3
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.2 · 1 row entry · 2 columns
This table is used to retrieve the Banned Ip address.
aaaSwitchAccessBannedIpEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.2.1
SwitchAccessManagementStation configuration.
Indexes
aaaSwitchAccessBannedIpAddress
Column Syntax OID
aaaSwitchAccessBannedIpAddress
To see the list of ip addresses which are banned
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.2.1.1
aaaSwitchAccessBannedIpRowStatus
The Rowstatus of the AaaSwitchAccessBannedIpEntry. 1 - active. 0 - inactive.
Unsigned32
Constraints:
range: 0-4194967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.2.1.2
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3 · 1 row entry · 6 columns
This table is used to create the read write permissions for the each session.
aaaSwitchAccessPrivMaskEntry entry .1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1
Priv mask configuration identified by the access type
Indexes
aaaSwitchAccessType
Column Syntax OID
aaaSwitchAccessType
Name of the access type
OctetStringr/w
Constraints:
range: 0-63
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.1
aaaSwitchAccessReadRight1
Specifies the families through the access type can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, through the access type the user is allow…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.2
aaaSwitchAccessReadRight2
Specifies the families through the access type can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, through the access type the user is allow…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.3
aaaSwitchAccessWriteRight1
Specifies the families through the access type can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, through the access type the user is allow…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.4
aaaSwitchAccessWriteRight2
Specifies the families through the access type can execute with read right.
Each bit of the 32-bit integer mask represents a command's family
number. When the family bit is set, through the access type the user is allow…
Unsigned32r/w
Constraints:
range: 0-4294967295
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.5
aaaSwitchAccessPrivMaskRowStatus
The status of this table entry.
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.6486.800.1.2.1.15.1.1.17.3.1.6