CISCO-LWAPP-WLAN-SECURITY-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
4
Rows
4
Columns
42
.1.3.6.1.4.1.9.9.521.1.1.1 · 1 row entry · 29 columns
This table represents the CCKM configuration
for the WLANs configured on this controller.  
          
There exist a row in this table corresponding to each
row representing a WLAN in cLWlanConfigTable.  The
controller adds or deletes a row to this table
whenever a WLAN is added or deleted.
cLWSecDot11EssCckmEntry entry .1.3.6.1.4.1.9.9.521.1.1.1.1
Each entry represents a conceptual row in
cLWSecDot11EssCckmTable and uniquely identified
by cLWlanIndex.
Indexes
Column Syntax OID
cLWSecDot11EssCckmWpaSupport
This object specifies to enable or disable layer-2
security using WPA1 or WPA2. When this
object is set to 'true' layer-2 security is enabled.
When this object is set to 'false' layer-2 security
is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.1
cLWSecDot11EssCckmWpa1Security
This object specifies whether cckmwpa1 security
is enabled or not.
A value of 'true' indicates that WPA1 security
is enabled on the controller.
A value of 'false' indicates that WPA1 security
is disabled on …
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.2
cLWSecDot11EssCckmWpa1EncType
This object specifies the type of WPA1 encryption
configured on this WLAN.
The value populated by this object is applicable
only when cLWSecDot11EssCckmWpa1Security populates
a value of 'true'.
CISCO-LWAPP-TC-MIBCLSecEncryptTyper/w
Textual Convention: CISCO-LWAPP-TC-MIBCLSecEncryptType Bits
Type Values:
0tkip
1aes
.1.3.6.1.4.1.9.9.521.1.1.1.1.3
cLWSecDot11EssCckmWpa2Security
This object specifies whether
cckmwpa2 security is enabled or not.
A value of 'true' indicates that WPA2 security
is enabled on the controller.
A value of 'false' indicates that WPA2 security
is disabled on the …
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.4
cLWSecDot11EssCckmWpa2EncType
This object specifies the type of WPA2 encryption
configured on this WLAN.
The value populated by this object is applicable
only when cLWSecDot11EssCckmWpa2Security populates
a value of 'true'.
CISCO-LWAPP-TC-MIBCLSecEncryptTyper/w
Textual Convention: CISCO-LWAPP-TC-MIBCLSecEncryptType Bits
Type Values:
0tkip
1aes
.1.3.6.1.4.1.9.9.521.1.1.1.1.5
cLWSecDot11EssCckmKeyMgmtMode
This object specifies the type of authentication
key management that is applicable only when
cLWSecDot11EssCckmWpaSupport is set to a value of
'true'.

The following are the possible key management
configu…
Bitsr/w
Enumerated Values:
0dot1x
1cckm
2psk
3ftDot1x
4ftPsk
5pmfDot1x
6pmfPsk
7osenDot1x
8sae
9owe
10ftSae
11saeExtKey
12ftSaeExtKey
.1.3.6.1.4.1.9.9.521.1.1.1.1.6
cLWSecDot11EssPskFmt
This object specifies the type of the
authentication preshared key configured through
the object cLWSecDot11EssCckmPsk. Note
that the key configuration is applicable only
when psk is configured as the key management
me…
CISCO-LWAPP-TC-MIBCLSecKeyFormatr/w
Textual Convention: CISCO-LWAPP-TC-MIBCLSecKeyFormat Enumeration
Type Values:
1default
2hex
3ascii
.1.3.6.1.4.1.9.9.521.1.1.1.1.7
cLWSecDot11EssPsk
This object specifies the authentication pre-shared
key in the hex format that is applicable only when
the 'psk' bit is specified in the
cLWSecDot11EssCckmKeyMgmtMode object.

The length of the key that c…
OctetStringr/w
Constraints:
range: 8-64
.1.3.6.1.4.1.9.9.521.1.1.1.1.8
cLWSecDot11EssCckmGtkRandomize
This object represents the Group Temporal Key(GTK)
used for multicast and broadcast packet encryption
in wpa1 and wpa2 clients.

This object indicates the Group Temporal Key (GTK)
configured on this WLAN …
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.9
cLWSecDot11EssFtEnable deprecated
This object specifies whether fast transition is enabled
for particular WLAN.
A value of 'true' means that fast transition is enabled and
A value of 'false' means that fast transition is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.10
cLWSecDot11EssFtReassocTime
This object specifies the fast transition
re-association time.
SNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.521.1.1.1.1.11
cLWSecDot11EssFtOverDs
This object specifies whether fast transition over
distributed system is enabled.
A 'true' value means that fast transition over the
distributed system is enabled.
A 'false' value means fast transition over the
distr…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.12
cLWSecDot11Ess11wPfm
This object specifies the 802.11w PFM status for a
particular WLAN.
Enumerationr/w
Enumerated Values:
0disabled
1optional
2required
.1.3.6.1.4.1.9.9.521.1.1.1.1.13
cLWSecDot11EssRetryTime
This object specifies the 802.11w Security Association(SA)
query retry timeout.
millisecondsSNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.521.1.1.1.1.14
cLWSecDot11EssComebackTime
This object specifies the 802.11w association comeback time.
SNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.521.1.1.1.1.15
cLWSecDot11EssFtMode
This object indicates the 11r status for a wlan
cLWSecDot11EssFtMode is set to a value of
'adaptive'.
Enumerationr/w
Enumerated Values:
0disabled
1enabled
2adaptive
.1.3.6.1.4.1.9.9.521.1.1.1.1.16
cLWSecDot11EssWpa3Security
This object specifies whether
wpa3 security is enabled or not.
A value of 'true' indicates that WPA3 security
is enabled on the controller.
A value of 'false' indicates that WPA3 security
is disabled on the contr…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.17
cLWSecDot11EssMPskEnable
This object specifies whether
Multi-PSK security feature is enabled or not.
True: indicates Multi-PSK security feature
is enabled.
False: indicates Multi-PSK security feature is
disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.18
cLWSecDot11EssSaeAntiClogThreshold
This object specifies the threshold for number of
SAE open sessions beyond which Anti Clogging shall
be enforced for future associations.
Unsigned32r/w
Constraints:
range: 0-3000
.1.3.6.1.4.1.9.9.521.1.1.1.1.19
cLWSecDot11EssSaeRetransTimeout
This object specifies the SAE Retransmission
Timeout value.
millisecondsUnsigned32r/w
Constraints:
range: 1-10000
.1.3.6.1.4.1.9.9.521.1.1.1.1.20
cLWSecDot11EssSaeMaxRetry
This object specifies the SAE maximum number of
retry count
Integer32r/w
Constraints:
range: 1-10
.1.3.6.1.4.1.9.9.521.1.1.1.1.21
cLWSecDot11OsenEnable
This object specifies whether Hotspot 2.0
OSEN security feature is enabled or not.
True: indicates OSEN security feature
is enabled.
False: indicates OSEN security feature is
disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.22
cLWSecDot11TMWlanId
This object shall be used to configure OWE
Transition mode support on the corresponding
WLANs. Range: 0-4096. It enables OWE Transition
mode on the corresponding WLANs. If it is 0,
the transition mode is not enabled.
SNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.521.1.1.1.1.23
cLWSecDot11EssWpa3EncType
This object specifies the type of WPA3 encryption
configured on this WLAN.
The value populated by this object is applicable
only when cLWSecDot11EssWpa3Security populates
a value of 'true'.
Bitsr/w
Enumerated Values:
0aes
1ccmp256
2gcmp128
3gcmp256
.1.3.6.1.4.1.9.9.521.1.1.1.1.24
cLWSecDot11EssPskType
This object indicates the type of storage used
to store PSK.
clear: indicate PSK is stored as clear text'.
aes : indicate the PSK is stored encrypted using AES.
Enumerationr/w
Enumerated Values:
0clear
1aes
.1.3.6.1.4.1.9.9.521.1.1.1.1.25
cLWSecDot11EssEasyPskEnable
This object specifies whether Easy PSK security feature is
enabled or not.
True: indicates Easy PSK security feature is enabled.
False: indicates Easy PSK security feature is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.26
cLWSecDot11EssSaePweMode
This object specifies SAE Password Element Mode
0: Hunting And Pecking Only, disables Hash To Element
1: Hash To Element Only, disables Hunting and Pecking
2: Both Hash to element, Hunting and pecking support.
Enumerationr/w
Enumerated Values:
0hnp
1h2e
2h2e-hnp
.1.3.6.1.4.1.9.9.521.1.1.1.1.27
cLWSecDot11TransitionDisable
This object specifies whether Transition Disable feature is
enabled or not.
True: indicates Transition Disable feature is enabled.
False: indicates Transition Disable feature is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.28
cLWSecDot11BeaconProtectionEnable
This object specifies whether Beacon Protection feature is
enabled or not.
True: indicates Beacon Protection feature is enabled.
False: indicates Beacon Protection feature is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.1.1.29
.1.3.6.1.4.1.9.9.521.1.1.2 · 1 row entry · 7 columns
This table represents the CKIP parameters of a
WLAN.
          
This is a new layer-2 security policy similar to 
static WEP.  User can select this policy on a WLAN.  
This policy will be allowed to be configured only when 
Aironet Extensions are enabled on the WLAN.
          
Once user has selected CKIP he will be given an option 
to : 
    1> configure key 
    2> select  MMH 
          
There exist a row in this table corresponding to each
row representing a WLAN in cLWlanConfigTable.  The
controller adds or deletes a row to this table
whenever a WLAN is added or deleted.
cLWSecDot11EssCkipEntry entry .1.3.6.1.4.1.9.9.521.1.1.2.1
Each entry represents a conceptual row in
cLWSecDot11EssCkipTable and uniquely identified
by cLWlanIndex.
Indexes
Column Syntax OID
cLWSecDot11EssCkipSecurity
This object is used to enable to disable layer-2
CKIP as security policy for this WLAN. When this
object is set to 'true', layer-2 CKIP security is
enabled. When this object is set to 'false',
layer-2 CKIP security i…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.2.1.1
cLWSecDot11EssCkipKeyIndex
This object specifies the key index corresponding
to the key being configured. A value of 0 indicates
that the CKIP key hasn't been configured.
Unsigned32r/w
Constraints:
range: 0-4
.1.3.6.1.4.1.9.9.521.1.1.2.1.2
cLWSecDot11EssCkipKeyLength
This object specifies the length of CKIP key in bits
that is applicable only when cLWSecDot11EssCkipSecurity
is set as 'true'.
Enumerationr/w
Enumerated Values:
1none
2len40
3len104
.1.3.6.1.4.1.9.9.521.1.1.2.1.3
cLWSecDot11EssCkipKeyFmt
This object specifies the type of the key
configured through the object
cLWSecDot11EssCkipKey.
CISCO-LWAPP-TC-MIBCLSecKeyFormatr/w
Textual Convention: CISCO-LWAPP-TC-MIBCLSecKeyFormat Enumeration
Type Values:
1default
2hex
3ascii
.1.3.6.1.4.1.9.9.521.1.1.2.1.4
cLWSecDot11EssCkipKey
This object specifies the CKIP key that is
applicable only when cLWSecDot11EssCkipSecurity
is set as 'true'.

The number of characters to be configured depends
on the key length and the key type configured…
OctetStringr/w
Constraints:
range: 5-26
.1.3.6.1.4.1.9.9.521.1.1.2.1.5
cLWSecDot11EssCkipMMHMode
This object is used to enable or disable MMH MIC
mode for the CKIP for this WLAN.

'true' - MMH MIC mode is enabled
'false' - MMH MIC mode is disabled.
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.2.1.6
cLWSecDot11EssCkipKPEnable
This object specifies whether CKIP is enabled.
A value of 'true' indicates that the encryption
keys will be generated by permuting the static CKIP
key configured through cLWSecDot11EssCkipKey.
A value of 'false' indica…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.1.2.1.7
.1.3.6.1.4.1.9.9.521.1.1.5 · 1 row entry · 4 columns
This table represents the Multi-PSK configuration
for the WLANs configured on the controller.
Each row in this table corresponds to a
Multi-PSK priority and pre-shared key combination.
cLWSecMPskKeysEntry entry .1.3.6.1.4.1.9.9.521.1.1.5.1
Each entry represents a conceptual row in
cLWSecMPskKeysTable table and is uniquely identified
by cLWlanIndex and cLWSecMPskPriority
Indexes
CISCO-LWAPP-WLAN-MIBcLWlanIndex cLWSecMPskPriority
Column Syntax OID
cLWSecMPskPriority
This object specifies the priority for Multi-PSK value
Unsigned32
Constraints:
range: 1-256
.1.3.6.1.4.1.9.9.521.1.1.5.1.1
cLWSecMPskRowStatus
The status of this conceptual row:
To create a row in cLWSecMPskKeysTable table,
set this object to either createAndGo(4) or
createAndWait(5) and set cLWSecMPskPriority, cLWSecMPskKey and
cLWSecMPskKeyFormat objects in …
SNMPv2-TCRowStatusr/w
Textual Convention: SNMPv2-TCRowStatus Enumeration
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
.1.3.6.1.4.1.9.9.521.1.1.5.1.2
cLWSecMPskKeyFormat
This object specifies the type of the
authentication pre-shared key configured through
the object cLWSecMPskKey. This configuration
is applicable only when cLWSecDot11EssMPskEnable is enabled.
CISCO-LWAPP-TC-MIBCLSecKeyFormatr/w
Textual Convention: CISCO-LWAPP-TC-MIBCLSecKeyFormat Enumeration
Type Values:
1default
2hex
3ascii
.1.3.6.1.4.1.9.9.521.1.1.5.1.3
cLWSecMPskKey
This object specifies the authentication pre-shared
key that is applicable only when
cLWSecDot11EssMPskEnable is enabled.
The length of this attribute depends on the
value of the cLWSecMPskKeyFormat:
'ascii': 8-63 oc…
OctetStringr/w
Constraints:
range: 8-64
.1.3.6.1.4.1.9.9.521.1.1.5.1.4
.1.3.6.1.4.1.9.9.521.1.3.1 · 1 row entry · 2 columns
This table represents the conditional web-redirect
parameters for the WLANs configured on this controller.  
          
There exist a row in this table corresponding to each
row representing a WLAN in cLWlanConfigTable.  The
controller adds or deletes a row to this table
whenever a WLAN is added or deleted.
cLWSecDot11EssWebPolicyEntry entry .1.3.6.1.4.1.9.9.521.1.3.1.1
Each entry represents a conceptual row in
cLWSecDot11EssWebPolicyTable and uniquely identified
by cLWlanIndex.
Indexes
Column Syntax OID
cLWSecDot11EssWebPolicyCondRedirect
This object is used to enable or disable conditional redirect.

When this attribute is 'true', it signifies that conditional
redirect is enabled and redirection of the client is done
based on the url-redi…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.3.1.1.1
cLWSecDot11EssWebPolicySplashPageWebRedirect
This object is used to enable or disable splash page web
redirect.

When this attribute is 'true', it signifies that splash page
redirect is enabled and redirection of the client is done
based on the url-…
SNMPv2-TCTruthValuer/w
Textual Convention: SNMPv2-TCTruthValue Enumeration
Type Values:
1true
2false
.1.3.6.1.4.1.9.9.521.1.3.1.1.2