MIB Viewer

BAYSTACK-IPV6-FIRST-HOP-SEC-MIB

119 objects
This MIB module is used for IPv6 First Hop Security configuration. The purpose of First Hop Security feature is to take care of the treats caused by the immediate node to another immediate node attached to the same First Hop Security device.
Imported Objects
IF-MIBInterfaceIndex
IPV6-TCIpv6Address
SNMPv2-SMICounter32 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE
SNMPv2-TCDisplayString MacAddress RowStatus TEXTUAL-CONVENTION TruthValue
SYNOPTICS-ROOT-MIBbayStackMibs
OIDNameAccessStatusDescription
1.3.6.1.4.1.45.5.45IdentitybayStackIpv6FirstHopSecMibofThis MIB module is used for IPv6 First Hop Security configuration. The purpose of First Hop Security feature is to take care of the treats caused by the immedi…
1.3.6.1.4.1.45.5.45.0NodebsIpv6FirstHopSecNotifications
1.3.6.1.4.1.45.5.45.0.1NotificationbsIpv6NDSBTTableFullobsoleteThis notification is generated when an attempt is made to add a new SBT entry when the Secure Binding Table is full. The value of bsIpv6NDInspectionNotificatio…
1.3.6.1.4.1.45.5.45.0.2NotificationbsIpv6NDNotificationsUntrustedPortobsoleteThis notification is generated when an ND message is suspected to be generated by the untrusted system/host.
1.3.6.1.4.1.45.5.45.0.3NotificationbsIpv6NDNotificationSBTTableFullcurrentThis notification is generated when an attempt is made to add a new SBT entry when the Secure Binding Table is full. The value of bsIpv6NDInspectionNotificatio…
1.3.6.1.4.1.45.5.45.0.4NotificationbsIpv6NDNotificationUntrustedPortcurrentThis notification is generated when an ND message is suspected to be generated by the untrusted system/host.
1.3.6.1.4.1.45.5.45.0.5NotificationbsIpv6RAGuardNotificationcurrentThis notification is generated when an RA message comes in that does not match the RA Guard configuration
1.3.6.1.4.1.45.5.45.0.6NotificationbsIpv6DHCPGuardNotificationcurrentThis notification is generated when an DHCPv6 message comes in that does not match the DHCPv6 Guard configuration
1.3.6.1.4.1.45.5.45.1NodebsIpv6FirstHopSecObjects
1.3.6.1.4.1.45.5.45.1.1NodebsIpv6FHSScalVar
1.3.6.1.4.1.45.5.45.1.1.1ScalarbsIpv6FHSAdminread-writecurrentFirst Hop Security Global Admin status
1.3.6.1.4.1.45.5.45.1.1.2ScalarbsIpv6FHSRagAdminread-writecurrentRA guard Global Admin status
1.3.6.1.4.1.45.5.45.1.1.3ScalarbsIpv6FHSDhcpv6gAdminread-writecurrentDHCPv6 guard Global Admin status
1.3.6.1.4.1.45.5.45.1.1.4ScalarbsIpv6FHSNdInspectAdminread-writecurrentND Inspection Global Admin status
1.3.6.1.4.1.45.5.45.1.1.5ScalarbsIpv6FHSMaxDynSbtEntriesread-writecurrentMaximum Dynamic SBT entries allowed
1.3.6.1.4.1.45.5.45.1.1.6ScalarbsIpv6FHSSbtReachLifeTimeread-writecurrentSBT Reachable state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer
1.3.6.1.4.1.45.5.45.1.1.7ScalarbsIpv6FHSSbtStaleLifeTimeread-writecurrentSBT Stale state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer
1.3.6.1.4.1.45.5.45.1.1.8ScalarbsIpv6FHSSbtDownLifeTimeread-writecurrentSBT Down state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer
1.3.6.1.4.1.45.5.45.1.1.9ScalarbsIpv6FHSSbtTblOverFlowread-onlycurrentSBT Table Overflow due to the maximum SBT entry restriction
1.3.6.1.4.1.45.5.45.1.2TablebsIpv6FHSIpv6AccessListTablenot-accessiblecurrentTable contains the list of IPv6 Access List used for Frist Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.2.1RowbsIpv6FHSIpv6AccessListEntrynot-accessiblecurrentEntry contains the list of IPv6 Access List used for Frist Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.2.1.1ColumnbsIpv6FHSIpv6AccessListNamenot-accessiblecurrentIPv6 Access List Name
1.3.6.1.4.1.45.5.45.1.2.1.2ColumnbsIpv6FHSIpv6AccessListPrefixnot-accessiblecurrentIPv6 Prefix attached to this IPv6 access list Id
1.3.6.1.4.1.45.5.45.1.2.1.3ColumnbsIpv6FHSIpv6AccessListPrefixMaskLennot-accessiblecurrentIPv6 Prefix mask length attached to this IPv6 access list Id
1.3.6.1.4.1.45.5.45.1.2.1.4ColumnbsIpv6FHSIpv6AccessListMaskLenFromread-writecurrentIPv6 Prefix mask length range from
1.3.6.1.4.1.45.5.45.1.2.1.5ColumnbsIpv6FHSIpv6AccessListMaskLenToread-writecurrentIPv6 Prefix mask length range to
1.3.6.1.4.1.45.5.45.1.2.1.6ColumnbsIpv6FHSIpv6AccessListAccessTyperead-writecurrentIPv6 IP Access Type Allow or Deny
1.3.6.1.4.1.45.5.45.1.2.1.7ColumnbsIpv6FHSIpv6AccessListRowStatusread-writecurrentIPv6 IP Access List row status
1.3.6.1.4.1.45.5.45.1.3TablebsIpv6FHSMacAccessListTablenot-accessiblecurrentTable contains the list of MAC Access List used for Frist Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.3.3RowbsIpv6FHSMacAccessListEntrynot-accessiblecurrentEntry contains the list of MAC Access List used for Frist Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.3.3.1ColumnbsIpv6FHSMacAccessListNamenot-accessiblecurrentMAC Access List Name
1.3.6.1.4.1.45.5.45.1.3.3.2ColumnbsIpv6FHSMacAccessListMacnot-accessiblecurrentMAC address attached to this MAC access list Id
1.3.6.1.4.1.45.5.45.1.3.3.3ColumnbsIpv6FHSMacAccessListAccessTyperead-writecurrentMAC Access Type Allow or Deny
1.3.6.1.4.1.45.5.45.1.3.3.4ColumnbsIpv6FHSMacAccessListRowStatusread-writecurrentMAC Access List row status
1.3.6.1.4.1.45.5.45.1.4TablebsIpv6FHSPolicyPortMapTablenot-accessiblecurrentTable contains the list of First Hop security Policies attached to the interface.
1.3.6.1.4.1.45.5.45.1.4.1RowbsIpv6FHSPolicyPortMapEntrynot-accessiblecurrentEntry contains the list of First Hop security Policies attached to the interface.
1.3.6.1.4.1.45.5.45.1.4.1.1ColumnbsIpv6FHSPolicyPortMapIfIndexnot-accessiblecurrentInterface index number
1.3.6.1.4.1.45.5.45.1.4.1.2ColumnbsIpv6FHSPolicyPortMapDhcpv6gPolicyNameread-writecurrentDHCPv6 guard policy name
1.3.6.1.4.1.45.5.45.1.4.1.3ColumnbsIpv6FHSPolicyPortMapRagPolicyNameread-writecurrentRA guard policy name
1.3.6.1.4.1.45.5.45.1.4.1.4ColumnbsIpv6FHSPolicyPortMapNDAdminread-writecurrentEnable/Disable ND-inspection
1.3.6.1.4.1.45.5.45.1.4.1.5ColumnbsIpv6FHSPolicyPortMapSbtDynLearnAdminread-writecurrentEnable/Disable learning dynamic SBT entry
1.3.6.1.4.1.45.5.45.1.4.1.6ColumnbsIpv6FHSPolicyPortMapTotDhcpv6PktRcvread-onlycurrentTotal Number of Dhcpv6 packets Received
1.3.6.1.4.1.45.5.45.1.4.1.7ColumnbsIpv6FHSPolicyPortMapTotDhcpv6PktDroppedread-onlycurrentTotal Number of Dhcpv6 packets dropped
1.3.6.1.4.1.45.5.45.1.4.1.8ColumnbsIpv6FHSPolicyPortMapTotRaPktRcvread-onlycurrentTotal Number of RA packets Received
1.3.6.1.4.1.45.5.45.1.4.1.9ColumnbsIpv6FHSPolicyPortMapTotRaPktDroppedread-onlycurrentTotal Number of RA packets dropped
1.3.6.1.4.1.45.5.45.1.4.1.10ColumnbsIpv6FHSPolicyPortMapTotNdPktRcvread-onlycurrentTotal Number of ND Packets Received
1.3.6.1.4.1.45.5.45.1.4.1.11ColumnbsIpv6FHSPolicyPortMapTotNdPktDroppedread-onlycurrentTotal Number of ND Packets Dropped
1.3.6.1.4.1.45.5.45.1.4.1.12ColumnbsIpv6FHSPolicyPortMapClearDhcpGuardStatsread-writecurrentFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotDhcpv6PktRcv and bsIpv6FHSPolicyPortMapTotDhcpv6PktDropped
1.3.6.1.4.1.45.5.45.1.4.1.13ColumnbsIpv6FHSPolicyPortMapClearRaGuardStatsread-writecurrentFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotRaPktRcv and bsIpv6FHSPolicyPortMapTotRaPktDropped
1.3.6.1.4.1.45.5.45.1.4.1.14ColumnbsIpv6FHSPolicyPortMapClearNDInspectStatsread-writecurrentFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotNdPktRcv, bsIpv6FHSPolicyPortMapTotNdPktDropped and bsIpv6FHSPolicyPortMapTotSbtEntDropped
1.3.6.1.4.1.45.5.45.1.4.1.15ColumnbsIpv6FHSPolicyPortMapRowStatusread-writecurrentFirst Hop security row status
1.3.6.1.4.1.45.5.45.1.4.1.16ColumnbsIpv6FHSPolicyPortMapDhcpv6gDeviceRoleread-writecurrentThis is the device role of the received port. If the device role is client and if it receives DHCPv6 reply then those packets should be dropped. This object is…
1.3.6.1.4.1.45.5.45.1.4.1.17ColumnbsIpv6FHSPolicyPortMapRagDeviceRoleread-writecurrentThis is the device role to the received port. If the device role is host and if it receives RAs then those packets should be dropped. This object is currently …
1.3.6.1.4.1.45.5.45.1.5TablebsIpv6FHSDhcpv6gPolicyListTablenot-accessiblecurrentTable contains the list of DHCPv6 guard Policies used for Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.5.1RowbsIpv6FHSDhcpv6gPolicyListEntrynot-accessiblecurrentEntry contains the list of DHCPv6 guard Policies used for Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.5.1.1ColumnbsIpv6FHSDhcpv6gPolicyNamenot-accessiblecurrentThis is the DHCPv6 guard Policy Name
1.3.6.1.4.1.45.5.45.1.5.1.2ColumnbsIpv6FHSDhcpv6gDeviceRoleread-writecurrentThis is the device role of the received port. If the device role is client and if it receives DHCPv6 reply then those packets should be dropped
1.3.6.1.4.1.45.5.45.1.5.1.3ColumnbsIpv6FHSDhcpv6gServerAccessListNameread-writecurrentThis is the IPv6 access list which will be validating source IPv6 address of the DHCPv6 Reply packet from the server
1.3.6.1.4.1.45.5.45.1.5.1.4ColumnbsIpv6FHSDhcpv6gReplyPrefixListNameread-writecurrentValidate the prefix information in the DHCPv6 reply against the configured reply prefix list.
1.3.6.1.4.1.45.5.45.1.5.1.5ColumnbsIpv6FHSDhcpv6gPrefLimitMinread-writecurrentThis is check against the DHCPv6 server / relay router preference. If the received router preference is less than the configured router preference than drop th…
1.3.6.1.4.1.45.5.45.1.5.1.6ColumnbsIpv6FHSDhcpv6gPrefLimitMaxread-writecurrentThis is check against the DHCPv6 server / relay router preference. If the received router preference is greater than the configured router preference than drop…
1.3.6.1.4.1.45.5.45.1.5.1.7ColumnbsIpv6FHSDhcpv6gPolicyListRowStatusread-writecurrentDHCPv6 guard policy row status
1.3.6.1.4.1.45.5.45.1.6TablebsIpv6FHSRagPolicyListTablenot-accessiblecurrentTable contains the list of RA guard Policies used for Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.6.1RowbsIpv6FHSRagPolicyListEntrynot-accessiblecurrentEntry contains the list of RA guard Policies used for Hop Security Feature.
1.3.6.1.4.1.45.5.45.1.6.1.1ColumnbsIpv6FHSRagPolicyNamenot-accessiblecurrentRA guard policy Name
1.3.6.1.4.1.45.5.45.1.6.1.2ColumnbsIpv6FHSRagDeviceRoleread-writecurrentThis is the device role to be checked against
1.3.6.1.4.1.45.5.45.1.6.1.3ColumnbsIpv6FHSRagIpv6AccessListNameread-writecurrentThis is the IPv6 access list which will be validating the source IPv6 address of the RA packet
1.3.6.1.4.1.45.5.45.1.6.1.4ColumnbsIpv6FHSRagIpv6PrefixListNameread-writecurrentThis is the IPv6 access list which will be validating the Prefix present in the RA packet
1.3.6.1.4.1.45.5.45.1.6.1.5ColumnbsIpv6FHSRagMacListNameread-writecurrentThis is the MAC access list which will be validating the source MAC of the received RA packet
1.3.6.1.4.1.45.5.45.1.6.1.6ColumnbsIpv6FHSRagManagedConfigFlagread-writecurrentIn the RA packets, there is an M flag (Managed Address configuration Flag) which is set indicating that the address assignments are available via DHCPv6. This …
1.3.6.1.4.1.45.5.45.1.6.1.7ColumnbsIpv6FHSRagRouterPrefMaxread-writecurrentIn the RA packet there is router preference information is available in the Flags. This could be HIGH or LOW or MEDIUM. This filtering policy option would veri…
1.3.6.1.4.1.45.5.45.1.6.1.8ColumnbsIpv6FHSRagHopLimitMinread-writecurrentThis is the minimum value check for the hop limit value present in the RA packet. If the value is less than configured minimum value then drop the RA packet
1.3.6.1.4.1.45.5.45.1.6.1.9ColumnbsIpv6FHSRagHopLimitMaxread-writecurrentThis is the maximum value check for the hop limit value present in the RA packet. If the value is greater than configured maximum value then drop the RA packet
1.3.6.1.4.1.45.5.45.1.6.1.10ColumnbsIpv6FHSRagPolicyListRowStatusread-writecurrentRA guard policy row status
1.3.6.1.4.1.45.5.45.1.7TablebsIpv6FHSSbtTablenot-accessiblecurrentTable contains the list of SBT entries learnt Dynamically and statically configure.
1.3.6.1.4.1.45.5.45.1.7.1RowbsIpv6FHSSbtListEntrynot-accessiblecurrentEntry contains the list of SBT entries.
1.3.6.1.4.1.45.5.45.1.7.1.1ColumnbsIpv6FHSSbtInterfaceIndexnot-accessiblecurrentDerive unit and port number from this ifindex
1.3.6.1.4.1.45.5.45.1.7.1.2ColumnbsIpv6FHSSbtVlannot-accessiblecurrentVLAN
1.3.6.1.4.1.45.5.45.1.7.1.3ColumnbsIpv6FHSSbtSrcIpnot-accessiblecurrentSource IPv6 Address
1.3.6.1.4.1.45.5.45.1.7.1.4ColumnbsIpv6FHSSbtLinkLayerAddressread-writecurrentLink Layer MAC address
1.3.6.1.4.1.45.5.45.1.7.1.5ColumnbsIpv6FHSSbtLearnTyperead-onlycurrentSBT Entry Type
1.3.6.1.4.1.45.5.45.1.7.1.6ColumnbsIpv6FHSSbtLearnPriorityread-onlycurrentSBT Entry priority
1.3.6.1.4.1.45.5.45.1.7.1.7ColumnbsIpv6FHSSbtLearnStateread-onlycurrentSBT Entry state
1.3.6.1.4.1.45.5.45.1.7.1.8ColumnbsIpv6FHSSbtLearnAgeread-onlycurrentTime Elapsed after being in this state
1.3.6.1.4.1.45.5.45.1.7.1.9ColumnbsIpv6FHSSbtRowStatusread-writecurrentSBT entry row status
1.3.6.1.4.1.45.5.45.1.8NodebsIpv6NDTrapNotificationObjects
1.3.6.1.4.1.45.5.45.1.8.1ScalarbsIpv6NDInspectionNotificationClientMACAddraccessible-for-notifyobsoleteThis value indicates the source MAC Address of a dropped ND inspection packet.
1.3.6.1.4.1.45.5.45.1.8.2ScalarbsIpv6NDInspectionNotificationMsgTypeaccessible-for-notifyobsoleteThis value indicates the message type of a dropped ND packet.
1.3.6.1.4.1.45.5.45.1.8.3ScalarbsIpv6FHSNDInterfaceIndexaccessible-for-notifyobsoleteThis value indicates the unit and port number of a dropped ND inspection packet.
1.3.6.1.4.1.45.5.45.1.8.4ScalarbsIpv6FHSNDIpv6Addressaccessible-for-notifyobsoleteThis value indicates the Ipv6 source address of a dropped ND inspection packet.
1.3.6.1.4.1.45.5.45.1.8.5ScalarbsIpv6FHSNDVlanIDaccessible-for-notifyobsoleteThis value indicates the Vlan ID of a dropped ND inspection packet.
1.3.6.1.4.1.45.5.45.1.9TablebsIpv6FHSSourceGuardInterfaceConfigTablenot-accessiblecurrentIPv6 Source Guard Interface table.
1.3.6.1.4.1.45.5.45.1.9.1RowbsIpv6FHSSourceGuardInterfaceConfigEntrynot-accessiblecurrentAn entry of this table.
1.3.6.1.4.1.45.5.45.1.9.1.1ColumnbsIpv6FHSSourceGuardIfIndexnot-accessiblecurrentInterface index number.
1.3.6.1.4.1.45.5.45.1.9.1.2ColumnbsIpv6FHSSourceGuardInterfaceStateread-writecurrentIPv6 Source Guard Admin state of an interface.
1.3.6.1.4.1.45.5.45.1.9.1.3ColumnbsIpv6FHSSourceGuardMaxAddrread-writecurrentMaximum allowed IPv6 Source Addresses on an interface.
1.3.6.1.4.1.45.5.45.1.9.1.4ColumnbsIpv6FHSSourceGuardOverflowCountread-onlycurrentNumber of times the SBT entries could not be added to the allowed list.
1.3.6.1.4.1.45.5.45.1.9.1.5ColumnbsIpv6FHSSourceGuardClearOverflowCountread-writecurrentThis object clears counter object bsIpv6FHSSourceGuardOverflowCount.
1.3.6.1.4.1.45.5.45.1.9.1.6ColumnbsIpv6FHSSourceGuardDropCountread-onlycurrentNumber of dropped packets per port of source guard.
1.3.6.1.4.1.45.5.45.1.9.1.7ColumnbsIpv6FHSSourceGuardClearDropCountread-writecurrentThis object clears counter object: bsIpv6FHSSourceGuardDropCount.
1.3.6.1.4.1.45.5.45.1.10TablebsIpv6FHSSourceGuardBindingTablenot-accessiblecurrentList of IPv6 Source Guard binding entries for each Source Guard enabled interface.
1.3.6.1.4.1.45.5.45.1.10.1RowbsIpv6FHSSourceGuardBindingEntrynot-accessiblecurrentAn entry of this table.
1.3.6.1.4.1.45.5.45.1.10.1.1ColumnbsIpv6FHSSourceGuardEntryIfIndexnot-accessiblecurrentInterface index number.
1.3.6.1.4.1.45.5.45.1.10.1.2ColumnbsIpv6FHSSourceGuardEntryIpv6Addrread-onlycurrentIPv6 address allowed on the interface.
1.3.6.1.4.1.45.5.45.1.11NodebsIpv6FHSTrapNotificationObjects
1.3.6.1.4.1.45.5.45.1.11.1ScalarbsIpv6FHSTrapClientMACAddraccessible-for-notifycurrentThis value indicates the source MAC Address of a dropped ND/RS/RA/DHCP packet.
1.3.6.1.4.1.45.5.45.1.11.2ScalarbsIpv6FHSTrapInterfaceIndexaccessible-for-notifycurrentThis value indicates the unit and port number of a dropped ND/RS/RA/DHCP inspection packet.
1.3.6.1.4.1.45.5.45.1.11.3ScalarbsIpv6FHSTrapClientIpv6Addressaccessible-for-notifycurrentThis value indicates the Ipv6 source address of a dropped ND/RS/RA/DHCP inspection packet.
1.3.6.1.4.1.45.5.45.1.11.4ScalarbsIpv6FHSTrapVlanIDaccessible-for-notifycurrentThis value indicates the Vlan ID of a dropped ND/RS/RA/DHCP inspection packet.
1.3.6.1.4.1.45.5.45.1.11.5ScalarbsIpv6FHSTrapMsgTypeaccessible-for-notifycurrentThis value indicates the message type of a dropped ND/RS/RA/DHCP packet.
1.3.6.1.4.1.45.5.45.1.11.6ScalarbsIpv6FhsTrapPktDropReasonaccessible-for-notifycurrentThis value indicates reason for dropped packet in FHS.
Type Definitions
NameSyntaxStatusDescription
FhsAccessTypeINTEGER { allow(1), deny(2) }currentA value indicating an access-type.
FhsDhcpv6GuardDeviceRoleINTEGER { server(1), client(2), none(3) }currentA value indicating dhcp-guard device role.
FhsListNameDisplayString (SIZE(1..64))currentFirst Hop Security list name.
FhsRaGuardDeviceRoleINTEGER { router(1), host(2), none(3) }currentA value indicating a role of ra-guard device.
FhsRaManagedConfigFlagINTEGER { none(1), on(2), off(3) }currentA value indicating ra-guard managed config flag.
FhsRaRouterPrefMaxINTEGER { none(1), high(2), medium(3), low(4) }currentA value indicating ra-guard router max preference.
FhsSbtStateINTEGER { incomplete(1), reachable(2), stale(3), down(4) }currentA value indicating state of SBT entry
FhsSbtTypeINTEGER { static(1), nd(2), dhcp(3) }currentA value indicating SBT entry learn type