MIB Viewer

CISCO-AUTH-FRAMEWORK-MIB

117 objects
MIB module for Authentication Framework in the system. Authentication Framework provides generic configurations for authentication methods in the system and manage the failover sequence of these methods in a flexible manner.
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.656IdentityciscoAuthFrameworkMIBMIB module for Authentication Framework in the system. Authentication Framework provides generic configurations for authentication methods in the system and ma…
1.3.6.1.4.1.9.9.656.0NodeciscoAuthFrameworkMIBNotifs
1.3.6.1.4.1.9.9.656.0.1NotificationcafSecurityViolationNotifcurrentA cafSecurityViolationNotif is sent if a security violation is detected on a port, and the instance value of cafSecurityViolationNotifEnable is 'true'.
1.3.6.1.4.1.9.9.656.0.2NotificationcafAuthFailNotifcurrentA cafAuthFailNotif is sent if an authentication failure is detected on a port, and the instance value of cafAuthFailNotifEnable is 'true'. ifName contains the …
1.3.6.1.4.1.9.9.656.1NodeciscoAuthFrameworkMIBObjects
1.3.6.1.4.1.9.9.656.1.1NodeciscoAuthFrameworkSystem
1.3.6.1.4.1.9.9.656.1.1.1ScalarcafAaaNoRespRecoveryDelayread-writecurrentSpecifies the AAA recovery delay for authentication methods registered in Authentication Framework when AAA server becomes active again after being inactive. A…
1.3.6.1.4.1.9.9.656.1.1.2TablecafAuthMethodRegTablenot-accessiblecurrentA list of authentication methods which are currrently registered with Authentication Framework. An entry is created by the agent when an authentication method …
1.3.6.1.4.1.9.9.656.1.1.2.1RowcafAuthMethodRegEntrynot-accessiblecurrentAn entry containing registration information of a particular authentication method with Authentication Framework.
1.3.6.1.4.1.9.9.656.1.1.2.1.1ColumncafAuthMethodnot-accessiblecurrentThe authentication method registered with Authentication Framework.
1.3.6.1.4.1.9.9.656.1.1.2.1.2ColumncafAuthMethodDefaultPriorityread-onlycurrentA unique number which indicates the default priority of a authentication method. The default priority is assigned by Authentication Framework during method reg…
1.3.6.1.4.1.9.9.656.1.1.2.1.3ColumncafAuthMethodDefaultExecOrderread-onlycurrentA unique number which indicates the default execution order of a authentication method. The default execution order is assigned by Authentication Framework dur…
1.3.6.1.4.1.9.9.656.1.1.3ScalarcafMacMoveModeread-writecurrentThis object specifies the MAC Move configuration for Authentication Framework. deny : When a host is authenticated on one port, that address is not allowed on …
1.3.6.1.4.1.9.9.656.1.1.4ScalarcafCoABouncePortCommandIgnoreEnabledread-writecurrentThis object specifies whether the device ignores the bounce port command that sent from RADIUS via Change-of-Authorization (CoA) packets.
1.3.6.1.4.1.9.9.656.1.1.5ScalarcafCoADisablePortCommandIgnoreEnabledread-writecurrentThis object specifies whether the device ingores the disable port command that sent from RADIUS via Change-of-Authorization (CoA) packets.
1.3.6.1.4.1.9.9.656.1.2NodeciscoAuthFrwkAuthenticator
1.3.6.1.4.1.9.9.656.1.2.1TablecafPortConfigTablenot-accessiblecurrentA list of port entries. An entry will exist for each interface which support Authentication Framework feature.
1.3.6.1.4.1.9.9.656.1.2.1.1RowcafPortConfigEntrynot-accessiblecurrentAn entry containing management information of Authentication Framework applicable to a particular port.
1.3.6.1.4.1.9.9.656.1.2.1.1.1ColumncafPortControlledDirectionread-writecurrentSpecifies the controlled direction of this port.
1.3.6.1.4.1.9.9.656.1.2.1.1.2ColumncafPortFallBackProfileread-writecurrentSpecifies the name of the fallback profile to be used when failing over to Web Proxy Authentication. A zero length string indicates that fallback mechanism to …
1.3.6.1.4.1.9.9.656.1.2.1.1.3ColumncafPortAuthHostModeread-writecurrentSpecifies the authentication host mode for this port.
1.3.6.1.4.1.9.9.656.1.2.1.1.4ColumncafPortPreAuthOpenAccessread-writecurrentSpecifies if the Pre-Authentication Open Access feature allows clients/devices to gain network access before authentication is performed. A value of 'true' for…
1.3.6.1.4.1.9.9.656.1.2.1.1.5ColumncafPortAuthorizeControlread-writecurrentSpecifies the authorization control for this port.
1.3.6.1.4.1.9.9.656.1.2.1.1.6ColumncafPortReauthEnabledread-writecurrentSpecifies if reauthentication is enabled for this port.
1.3.6.1.4.1.9.9.656.1.2.1.1.7ColumncafPortReauthIntervalread-writecurrentSpecifies the reauthentication interval, after which the port will be reauthenticated if value of the corresponding instance of cafPortReauthEnabled is 'true'.…
1.3.6.1.4.1.9.9.656.1.2.1.1.8ColumncafPortRestartIntervalread-writecurrentSpecifies the interval after which a further authentication attempt should be made to this port if it is not authorized. A value of zero indicates that no furt…
1.3.6.1.4.1.9.9.656.1.2.1.1.9ColumncafPortInactivityTimeoutread-writecurrentSpecifies the period of time that a client associating with this port is allowed to be inactive before being terminated. A value of zero indicates that inactiv…
1.3.6.1.4.1.9.9.656.1.2.1.1.10ColumncafPortViolationActionread-writecurrentSpecifies the action to be taken due to a security violation occurs on this port. restrict: This port will be moved to restricted state. shutdown: This port wi…
1.3.6.1.4.1.9.9.656.1.2.2TablecafPortMethodTablenot-accessiblecurrentThe table contains a list of port entries. An entry will exist for each port which supports Authentication Framework feature.
1.3.6.1.4.1.9.9.656.1.2.2.1RowcafPortMethodEntrynot-accessiblecurrentEntry containing configuration and information of authentication methods for a particular port.
1.3.6.1.4.1.9.9.656.1.2.2.1.1ColumncafPortMethodAdminExecOrderread-writecurrentThis object specifies the administrative execution order of authentication methods on the port. Methods are executed in the order as specified in the method li…
1.3.6.1.4.1.9.9.656.1.2.2.1.2ColumncafPortMethodAdminPriorityread-writecurrentThis object specifies the administrative priority of authentication methods on the port. The priority of each method is assigned based on the method list. Meth…
1.3.6.1.4.1.9.9.656.1.2.2.1.3ColumncafPortMethodAvailableread-onlycurrentThis object indicates the authentication methods currently available on this port.
1.3.6.1.4.1.9.9.656.1.2.2.1.4ColumncafPortMethodOperExecOrderread-onlycurrentThis object indicates the operational execution order of authentication methods on this port. Methods are executed in the order as specified in the method list…
1.3.6.1.4.1.9.9.656.1.2.2.1.5ColumncafPortMethodOperPriorityread-onlycurrentThis object indicates the operational priority of authentication methods on this port. Methods have the priority as specified in the method list. Method which …
1.3.6.1.4.1.9.9.656.1.3NodeciscoAuthFrameworkEvent
1.3.6.1.4.1.9.9.656.1.3.1TablecafAuthFailedEventPortTablenot-accessiblecurrentThe table contains a list of port entries. An entry will exist for each port which supports Authentication Fail event within the Authentication Framework.
1.3.6.1.4.1.9.9.656.1.3.1.1RowcafAuthFailedEventPortEntrynot-accessiblecurrentEntry containing management information of Authentication Fail event for a particular port.
1.3.6.1.4.1.9.9.656.1.3.1.1.1ColumncafAuthFailedMaxRetryread-writecurrentThis object specifies the maximum number of retry should be performed before generating Authentication Fail event. A value of zero indicates that Authenticatio…
1.3.6.1.4.1.9.9.656.1.3.1.1.2ColumncafAuthFailedNoActionEnabledread-writecurrentThis object specifies whether no action will be performed when an Authentication Fail event occurs. Setting 'true' on this object indicates that no action will…
1.3.6.1.4.1.9.9.656.1.3.1.1.3ColumncafAuthFailedAuthorizedVlanread-writecurrentThis object specifies the Authentication Failed VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. The read-only…
1.3.6.1.4.1.9.9.656.1.3.1.1.4ColumncafAuthFailedNextMethodEnabledread-writecurrentThis object specifies whether the next authentication method will be used if an Authentication Fail event is generated by the current authentication method. Se…
1.3.6.1.4.1.9.9.656.1.3.2TablecafClientNoRespEventPortTablenot-accessiblecurrentThe table contains a list of port entries. An entry exists for each port which supports No Response event within the Authentication Framework.
1.3.6.1.4.1.9.9.656.1.3.2.1RowcafClientNoRespEventPortEntrynot-accessiblecurrentEntry containing management information of No Response event for a particular port.
1.3.6.1.4.1.9.9.656.1.3.2.1.1ColumncafClientNoRespNoActionEnabledread-writecurrentThis object specifies whether an action is performed when No Response event occurs. Setting 'true' on this object indicates that no action will be performed wh…
1.3.6.1.4.1.9.9.656.1.3.2.1.2ColumncafClientNoRespAuthorizedVlanread-writecurrentThis object specifies the No Response Authorized VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. The read-onl…
1.3.6.1.4.1.9.9.656.1.3.3TablecafServerEventPortTablenot-accessiblecurrentThe table contains a list of port entries. An entry exists for each port which supports AAA Server Reachability event within the Authentication Framework.
1.3.6.1.4.1.9.9.656.1.3.3.1RowcafServerEventPortEntrynot-accessiblecurrentEntry containing management information of AAA Server Reachability event for a particular port.
1.3.6.1.4.1.9.9.656.1.3.3.1.1ColumncafServerDeadNoActionEnabledread-writecurrentThis object indicates whether an action is performed if an AAA Server Reachability event occurs. Setting 'true' on this object indicates that no action will be…
1.3.6.1.4.1.9.9.656.1.3.3.1.2ColumncafServerDeadRemainAuthorizedread-writecurrentThis object specifies if current authorization will remain unchanged for the port when AAA Server Reachability event occurs. Setting 'true' on this object indi…
1.3.6.1.4.1.9.9.656.1.3.3.1.3ColumncafServerDeadAuthorizedVlanread-writecurrentThis object specifies the AAA Server Reachability Authorized VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. …
1.3.6.1.4.1.9.9.656.1.3.3.1.4ColumncafServerAliveActionread-writecurrentThis object specifies the action applied to the port upon AAA recovery. none : no action will be applied. reinitialize: the port will be reinitialized with the…
1.3.6.1.4.1.9.9.656.1.4NodeciscoAuthFrameworkSession
1.3.6.1.4.1.9.9.656.1.4.1TablecafSessionTablenot-accessiblecurrentThe table contains a list of authentication session. An entry is created when an authentication session has successfully created within Authentication Framewor…
1.3.6.1.4.1.9.9.656.1.4.1.1RowcafSessionEntrynot-accessiblecurrentEntry containing management information for a particular authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.1ColumncafSessionIdnot-accessiblecurrentA unique identifier of the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.2ColumncafSessionClientMacAddressread-onlycurrentIndicates the MAC address of the device associates with the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.3ColumncafSessionClientAddrTyperead-onlycurrentIndicates the type of Internet address of the client associates with the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.4ColumncafSessionClientAddressread-onlycurrentIndicates the Internet address of the client associates with the authentication session. The type of this address is determined by the value of cafSessionClien…
1.3.6.1.4.1.9.9.656.1.4.1.1.5ColumncafSessionStatusread-onlycurrentIndicates the current status of the authentication session. idle : the session has been initialized and no method has run yet. running : an authentication meth…
1.3.6.1.4.1.9.9.656.1.4.1.1.6ColumncafSessionDomainread-onlycurrentIndicates the type of domain that the authentication session belongs to. other : none of the below. data : indicates the data domain. voice: indicates the voic…
1.3.6.1.4.1.9.9.656.1.4.1.1.7ColumncafSessionAuthHostModeread-onlycurrentIndicates the authentication host mode of the port in the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.8ColumncafSessionControlledDirectionread-onlycurrentIndicates the operational controlled directions parameter for this port in the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.9ColumncafSessionPostureTokenread-onlycurrentIndicates the posture token associates with the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.10ColumncafSessionAuthUserNameread-onlycurrentIndicates the name of the authenticated user for the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.11ColumncafSessionClientFramedIpPoolread-onlycurrentIndicates the name of the address pool from which the session's client IP address is assigned.
1.3.6.1.4.1.9.9.656.1.4.1.1.12ColumncafSessionAuthorizedByread-onlycurrentIndicates the name of the feature which authorizes the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.13ColumncafSessionCriticalTimeLeftread-onlycurrentIndicates the leftover time before the next authentication attempt for the authentication session after Server Reachability event occurred. Value zero indicate…
1.3.6.1.4.1.9.9.656.1.4.1.1.14ColumncafSessionAuthVlanread-onlycurrentIndicates the authorized VLAN applied to the authentication session. Value zero indicates that no authorized VLAN has been applied, or it is not applicable.
1.3.6.1.4.1.9.9.656.1.4.1.1.15ColumncafSessionTimeoutread-onlycurrentIndicates the session timeout used by Authentication Framework in the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.16ColumncafSessionTimeLeftread-onlycurrentIndicates the leftover time of the current authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.17ColumncafSessionTimeoutActionread-onlycurrentIndicates the timeout action on the authentication session, when value of the corresponding instance of cafSessionTimeLeft reaches zero. unknown : None of the …
1.3.6.1.4.1.9.9.656.1.4.1.1.18ColumncafSessionInactivityTimeoutread-onlycurrentIndicates the inactivity timeout used by Authentication Framework in the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.19ColumncafSessionInactivityTimeLeftread-onlycurrentIndicates the leftover time of the inactivity timer of the authentication session.
1.3.6.1.4.1.9.9.656.1.4.1.1.20ColumncafSessionReauthread-writecurrentThe reauthentication control for the authentication session. Setting this object to 'true' cause the current authenticated session to reauthenticate the authen…
1.3.6.1.4.1.9.9.656.1.4.1.1.21ColumncafSessionTerminateread-writecurrentThe termination request control for the authentication session. Setting this object to 'true' terminates the current session. Setting this object to 'false' ha…
1.3.6.1.4.1.9.9.656.1.4.1.1.22ColumncafSessionVlanGroupNameread-onlycurrentThe name of the VLAN group that has been used during VLAN assignment for this session. A zero length string indicates that there is no VLAN group been used dur…
1.3.6.1.4.1.9.9.656.1.4.2TablecafSessionMethodsInfoTablenot-accessiblecurrentThe table contains a list of authentication method for every authentication session. An entry exists for each authentication method that can authenticate an au…
1.3.6.1.4.1.9.9.656.1.4.2.1RowcafSessionMethodsInfoEntrynot-accessiblecurrentEntry containing method information for a particular runnable authentication methods which is associated with a session for an Authentication Framework managed…
1.3.6.1.4.1.9.9.656.1.4.2.1.1ColumncafSessionMethodnot-accessiblecurrentIndicates this authentication method.
1.3.6.1.4.1.9.9.656.1.4.2.1.2ColumncafSessionMethodStateread-onlycurrentIndicates the state of this authentication method. notRun : The method has not run for this session. running : The method is running for this session. failedOv…
1.3.6.1.4.1.9.9.656.1.5NodeciscoAuthFrwkNotifControl
1.3.6.1.4.1.9.9.656.1.5.1ScalarcafSecurityViolationNotifEnableread-writecurrentThis variable indicates whether the system produces the cafSecurityViolationNotif. A 'false' value will prevent cafSecurityViolationNotif from being generated …
1.3.6.1.4.1.9.9.656.1.5.2ScalarcafAuthFailNotifEnableread-writecurrentThis object specifies whether the system produces the cafAuthFailNotif. A 'true' value will cause cafAuthFailNotif to be generated by this system when an authe…
1.3.6.1.4.1.9.9.656.1.6NodeciscoAuthFrwkNotifInfo
1.3.6.1.4.1.9.9.656.1.6.1ScalarcafSecurityViolationClientaccessible-for-notifycurrentThe MAC address included in the notification currently being sent, indicating the client who triggered the security violation notification.
1.3.6.1.4.1.9.9.656.1.6.2ScalarcafAuthFailClientaccessible-for-notifycurrentThe MAC address included in the cafAuthFailNotif being sent, indicating the client which failed to authenticate.
1.3.6.1.4.1.9.9.656.2NodeciscoAuthFrameworkMIBConform
1.3.6.1.4.1.9.9.656.2.1NodeciscoAuthFrameworkMIBCompliances
1.3.6.1.4.1.9.9.656.2.1.1ComplianceciscoAuthFrameworkMIBComplianceread-onlydeprecatedThe compliance statement for entities which implement CISCO-AUTH-FRAMEWORK-MIB.
1.3.6.1.4.1.9.9.656.2.1.2ComplianceciscoAuthFrameworkMIBCompliance2read-onlydeprecatedThe compliance statement for entities which implement CISCO-AUTH-FRAMEWORK-MIB.
1.3.6.1.4.1.9.9.656.2.1.3ComplianceciscoAuthFrameworkMIBCompliance3read-onlydeprecatedThe compliance statement for entities which implement CISCO-AUTH-FRAMEWORK-MIB.
1.3.6.1.4.1.9.9.656.2.1.4ComplianceciscoAuthFrameworkMIBCompliance4read-onlycurrentThe compliance statement for entities which implement CISCO-AUTH-FRAMEWORK-MIB.
1.3.6.1.4.1.9.9.656.2.2NodeciscoAuthFrameworkMIBGroups
1.3.6.1.4.1.9.9.656.2.2.1GroupcafAuthMethodRegGroupcurrentA collection of objects that provides registration information of authentication methods in Authentication Framework.
1.3.6.1.4.1.9.9.656.2.2.2GroupcafAaaNoRespRecoveryDelayGroupcurrentA collection of objects that provides AAA recovery delay configuration for Authentication Framework in the system.
1.3.6.1.4.1.9.9.656.2.2.3GroupcafAuthPortConfigGroupcurrentA collection of objects that provides configuration of Authentication Framework for capable ports in the system.
1.3.6.1.4.1.9.9.656.2.2.4GroupcafPortMethodGroupcurrentA collection of objects that provides configuration and information of authentication methods within Authentication Framework for capable ports in the system.
1.3.6.1.4.1.9.9.656.2.2.5GroupcafAuthFailedEventGroupcurrentA collection of objects that provides configuration of Auth-Failed behaviour of Authentication Framework for ports in the system.
1.3.6.1.4.1.9.9.656.2.2.6GroupcafClientNoRespEventGroupcurrentA collection of objects that provides configuration of Authentication Framework when no-responsive client is detected on a port in the system.
1.3.6.1.4.1.9.9.656.2.2.7GroupcafServerEventGroupcurrentA collection of objects that provides configuration of Authentication Framework when AAA Server Reachability event occurs.
1.3.6.1.4.1.9.9.656.2.2.8GroupcafSessionGroupcurrentA collection of objects that provides authentication session management information for Authentication Framework.
1.3.6.1.4.1.9.9.656.2.2.9GroupcafSessionMethodInfoGroupcurrentA collection of objects that provides information about authentication methods associate with Authentication Framework 's authentication sessions in the system.
1.3.6.1.4.1.9.9.656.2.2.10GroupcafSecViolationNotifEnableGroupcurrentA collection of objects that provides control over security violation notification for Authentication Framework in the system.
1.3.6.1.4.1.9.9.656.2.2.11GroupcafSecurityViolationNotifGroupcurrentA collection of notification providing information about port's security violation in Authentication Framework.
1.3.6.1.4.1.9.9.656.2.2.12GroupcafSecurityViolationClientGroupcurrentA collection of objects providing MAC address of the offending client in the security violation notification.
1.3.6.1.4.1.9.9.656.2.2.13GroupcafSessionVlanGroupNameGroupcurrentA collection of objects providing VLAN group information of authenticated session in Authentication Framework.
1.3.6.1.4.1.9.9.656.2.2.14GroupcafMacMoveConfigGroupcurrentA collection of objects providing MAC move cofiguration information for Authentication Framework on the device.
1.3.6.1.4.1.9.9.656.2.2.15GroupcafCoACommandConfigGroupcurrentA collection of objects providing configuration information for the device's behaviour on CoA commands.
1.3.6.1.4.1.9.9.656.2.2.16GroupcafAuthFailNotifGroupcurrentA collection of notification providing information about port's authentication failure in Authentication Framework.
1.3.6.1.4.1.9.9.656.2.2.17GroupcafAuthFailNotifEnableGroupcurrentA collection of objects that provides control over authentication failure notification for Authentication Framework in the system.
1.3.6.1.4.1.9.9.656.2.2.18GroupcafAuthFailClientGroupcurrentA collection of objects providing MAC address of the failed client in the authentication failure notification.
Type Definitions
NameSyntaxStatusDescription
CiscoAuthControlledDirectionsINTEGER { both(0), in(1) }currentThe controlled direction values for capable ports in Authentication Framework. both: control is required to be exerted over both incoming and outgoing traffic through the controlled port. in : control is required to be …
CiscoAuthControlledPortControlINTEGER { forceUnauthorized(1), auto(2), forceAuthorized(3) }currentThe authorization control values of Authentication Framework on a controlled port. forceUnauthorized: the controlled port is forced to be unauthorized unconditionally. auto : authorization of the controlled port will be…
CiscoAuthHostModeINTEGER { singleHost(1), multiHost(2), multiAuth(3), multiDomain(4) }currentThe authentication mode of a controlled port. singleHost: port allows one host to connect and authenticate in a single domain. multiHost : port allows multiple hosts to connect. Once a host is authenticated, all remaini…
CiscoAuthMethodINTEGER { other(1), dot1x(2), macAuthBypass(3), webAuth(4) }currentThe authentication methods and protocols supported in Authentication Framework. other : none of the below. dot1x : 802.1x Protocol. macAuthBypass: MAC Authentication Bypass. webAuth : Web-Proxy Authentication. 'other' i…
CiscoAuthMethodListOCTET STRINGcurrentThe list of authentication methods provided within Authentication Framework. Each octet represents an authentication method which is defined in CiscoAuthMethod. The DESCRIPTION clause of CiscoAuthMethodList objects must…