CISCO-COMMON-ROLES-EXT-MIB
40 objects
A MIB Module for managing the roles that are common between access methods like Command Line Interface (CLI), SNMP and XML interface. This MIB is an extension to the CISCO-COMMON-ROLES-MIB, which is for managing Common Roles on a device with fixed feature. Terminology: Commands are the basic operations that can be performed on a device. For example 'show aaa *', 'clear aaa *', 'config t; ip arp *'. Commands can be organized into groups called Features. Features can be organized into groups called Feature Groups. The constituents of a Feature (i.e. Commands) and the constituents of a Feature Group (i.e. Features) are collectively referred to as Feature Elements. This MIB extends the CISCO-COMMON-ROLES-MIB by adding the following. Features can be organized into groups called feature groups. Access privileges can be assigned to feature group(s) associated with a Role. The five access privileges (clear, config, debug, show & exec) are replaced by two access privileges ('read' and 'readWrite'). These two privileges have no relation to the replaced five privileges. The types of objects to which access can be restricted is extended to include VLANs and Interfaces. A device implementing this MIB need not implement CISCO-COMMON-ROLES-MIB.
Imported Objects
| CISCO-COMMON-ROLES-MIB | ccrmConfigurationExtGroup |
| CISCO-SMI | ciscoMgmt |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE OBJECT-GROUP |
| SNMPv2-SMI | Integer32 MODULE-IDENTITY OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | RowStatus TEXTUAL-CONVENTION TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.9.9.651 | IdentityciscoCommonRolesExtMIB | A MIB Module for managing the roles that are common between access methods like Command Line Interface (CLI), SNMP and XML interface. This MIB is an extension … | ||
| 1.3.6.1.4.1.9.9.651.0 | NodeciscoCommonRolesExtNotifications | |||
| 1.3.6.1.4.1.9.9.651.1 | NodeciscoCommonRolesExtMIBObjects | |||
| 1.3.6.1.4.1.9.9.651.1.1 | NodeccreInfo | |||
| 1.3.6.1.4.1.9.9.651.1.1.1 | TableccreFeatureElementTable | not-accessible | current | This table lists all the features and feature groups configured on a device. For each feature it lists all the command(s) contained in the feature. For each fe… |
| 1.3.6.1.4.1.9.9.651.1.1.1.1 | RowccreFeatureElementEntry | not-accessible | current | An entry (conceptual row) in the ccreFeatureElementTable. Each row in this table represents an element (command or a feature) contained in a feature or a featu… |
| 1.3.6.1.4.1.9.9.651.1.1.1.1.1 | ColumnccreFeatureName | not-accessible | current | Identifies the feature or the feature group for which this entry represents an element. This object is the same as the commonRoleFeatureName. |
| 1.3.6.1.4.1.9.9.651.1.1.1.1.2 | ColumnccreFeatureElementIndex | not-accessible | current | An index value for this element which uniquely distinguishes it from all other elements of same feature. |
| 1.3.6.1.4.1.9.9.651.1.1.1.1.3 | ColumnccreFeatureElementName | read-create | current | Name of the feature element represented by this row. |
| 1.3.6.1.4.1.9.9.651.1.1.1.1.4 | ColumnccreFeatureElementType | read-create | current | An indication of the type of element represented by this row. When this field has the value 'command', this row represents a command name. When this field has … |
| 1.3.6.1.4.1.9.9.651.1.1.1.1.5 | ColumnccreFeatureRowStatus | read-create | current | Status of this row. |
| 1.3.6.1.4.1.9.9.651.1.2 | NodeccreRoleConfig | |||
| 1.3.6.1.4.1.9.9.651.1.2.2 | TableccreRoleTable | not-accessible | current | This table lists all the common roles configured on this device. Common roles are the user roles which are common across SNMP and CLI. A device implementing th… |
| 1.3.6.1.4.1.9.9.651.1.2.2.1 | RowccreRoleEntry | not-accessible | current | An entry (conceptual row) in the ccreRoleTable. One entry per role defined on the device. |
| 1.3.6.1.4.1.9.9.651.1.2.2.1.1 | ColumnccreRoleName | not-accessible | current | Name of the common role. This is same as commonRoleName. |
| 1.3.6.1.4.1.9.9.651.1.2.2.1.2 | ColumnccreRoleDescription | read-create | current | Description of the common role. This is same as commonRoleDescription. |
| 1.3.6.1.4.1.9.9.651.1.2.2.1.3 | ColumnccreRoleResourceAccess | read-create | current | Defines the default access to the resources to which access can be controlled. vsan(0) Bit value of 0 indicates that the user has access to no VSANs. However a… |
| 1.3.6.1.4.1.9.9.651.1.2.2.1.4 | ColumnccreRoleRowStatus | read-create | current | Status of this role. |
| 1.3.6.1.4.1.9.9.651.1.2.3 | TableccreRoleScopeTable | not-accessible | current | This table lists the resources to which a user belonging to a role can access. A role may be restricted from accessing various resources of a device. This tabl… |
| 1.3.6.1.4.1.9.9.651.1.2.3.1 | RowccreRoleScopeEntry | not-accessible | current | An entry (conceptual row) in the ccreRoleScopeTable. There is one entry for each different scope value of a Role. If a Role 'R1' is defined to have scope on VS… |
| 1.3.6.1.4.1.9.9.651.1.2.3.1.1 | ColumnccreRoleScopeIndex | not-accessible | current | An index value for this entry which uniquely distinguishes it from all other entries for same Role. |
| 1.3.6.1.4.1.9.9.651.1.2.3.1.2 | ColumnccreRoleScopeRestriction | read-create | current | This object indicates the type of the scope restriction about which the information is provided by row. |
| 1.3.6.1.4.1.9.9.651.1.2.3.1.3 | ColumnccreRoleScopeValue | read-create | current | This object identifies the resource this role can access. If the value of 'ccreRoleScopeRestriction' is 'vsan' or 'vlan', this object specifies the Id (which i… |
| 1.3.6.1.4.1.9.9.651.1.2.3.1.4 | ColumnccreRoleScopeRowStatus | read-create | current | Status of this scope restriction entry. |
| 1.3.6.1.4.1.9.9.651.1.3 | NodeccreRuleConfig | |||
| 1.3.6.1.4.1.9.9.651.1.3.2 | TableccreRuleTable | not-accessible | current | This table lists all the rules configured for roles defined in the ccreRoleTable. Each rule defines the access (permit/deny) allowed to a particular command, f… |
| 1.3.6.1.4.1.9.9.651.1.3.2.1 | RowccreRuleEntry | not-accessible | current | An entry (conceptual row) in the ccreRuleRuleTable. There is one entry for each Rule contained in a Role. For eg. if a Role 'R1' has 6 rules, there will be six… |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.1 | ColumnccreRuleNumber | not-accessible | current | A unique index for a rule in a particular role. The rule are applied according to their rule number, i.e. Rule 1 will be the first rule applied followed by Rul… |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.2 | ColumnccreRuleFeatureElementName | read-create | current | Name of the command or feature or feature group. If this is a zero-length string, then this rule applies to all the features supported on the device as enumera… |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.3 | ColumnccreRuleFeatureElementType | read-create | current | Specifies the type of entry (command or feature or feature group) as specified by the object ccreRuleFeatureElementName |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.4 | ColumnccreRuleOperation | read-create | current | The operation for this rule. |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.5 | ColumnccreRuleOperationPermitted | read-create | current | This object tells if the operation `ccreRuleOperation' is permitted or denied. The operation is permitted if the value of this object is `true'. If the value o… |
| 1.3.6.1.4.1.9.9.651.1.3.2.1.6 | ColumnccreRuleRowStatus | read-create | current | Status of this rule. |
| 1.3.6.1.4.1.9.9.651.2 | NodeciscoCommonRolesExtMIBConformance | |||
| 1.3.6.1.4.1.9.9.651.2.1 | NodeccreMIBCompliances | |||
| 1.3.6.1.4.1.9.9.651.2.1.1 | ComplianceccreMIBCompliance | read-only | current | The compliance statement for entities which implement the CISCO-COMMON-ROLES-EXT-MIB. |
| 1.3.6.1.4.1.9.9.651.2.2 | NodeccreMIBGroups | |||
| 1.3.6.1.4.1.9.9.651.2.2.1 | GroupccreConfigurationGroup | current | A collection of objects for Common Roles Extention configuration. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| CcreOperation | INTEGER { read(1), readWrite(2) } | current | Privileges allowed for a common role. read - Read opeation readWrite - Read-Write operation Note that if a privilege is not supported by an access method, then it does not apply to that access method. There privileges a… |
| CcreResourceAccess | BITS { vsan(0), vlan(1), interface(2) } | current | A User can be restricted from accessing resources, in addition to being restricted from performing certain operations. For e.g. a user assigned a role can be restricted from accessing all VLANs configured on the device … |