MIB Viewer

CISCO-DOT11-SSID-SECURITY-MIB

75 objects
This MIB module provides network management support for Cisco IEEE 802.11 Wireless LAN devices association and authentication. ACRONYMS AES Advanced Encryption Standard. AP Access point. AID Association IDentifier for wireless stations. BSS IEEE 802.11 Basic Service Set. BSSID Basic SSID, a MAC address. CCKM Cisco Central Key Management. CCMP Code Mode/CBC Mac Protocol. CKIP Cisco per packet key hashing. CMIC Cisco MMH MIC. CRC Cyclic Redundancy Check. DTIM Data Traffic Indication Map EAP Extensible Authentication Protocol. GRE Generic Routing Encapsulation IAPP Inter-Access-Point Protocol. ICV Integrity Check Value. MBSSID Multiple Basic SSID. MIC Message Integrity Check. MMH Multi-Modal Hashing. MMIC Michael MIC. RF Radio Frequency. SSID Radio Service Set Id. SSIDL IE SSID List Information Element STA IEEE 802.11 wireless station. TKIP WPA Temporal Key encryption. VLAN Virtual LAN. WEP Wired Equivalent Privacy. WPA Wi-Fi Protected Access. WPS Wireless Provisioning System. GLOSSARY Access point Transmitter/receiver (transceiver) device that commonly connects and transports data between a wireless network and a wired network. Association The service used to establish access point or station mapping and enable STA invocation of the distribution system services. (Wireless clients attempt to connect to access points.) Basic Service Set The IEEE 802.11 BSS of an AP comprises of the stations directly associating with the AP. Backup VLAN Wireless clients found to be running outdated/ unsupported virus software and not compliant to network admission control guidelines need to be placed on different VLANs than the intended normal VLAN. These VLANs on which the non-compliant clients are placed are termed as Backup VLANs. Backup VLANs are used to quarantine the non-compliant clients running incorrect software till they upgrade their software to the correct version. Bridge Device that connects two or more segments and reduces traffic by analyzing the destination address, filtering the frame, and forwarding the frame to all connected segments. Bridge AP It is an AP that functions as a transparent bridge between 2 wired LAN segments. Broadcast SSID Clients can send out Broadcast SSID Probe Requests to a nearby AP, and the AP will broadcast its own SSID within its beacons to response to clients. Clients can use this Broadcast SSID to associate and communicate with the AP. Extensible Authentication Protocol EAP acts as the interface between a wireless client and an authentication server, such as a RADIUS server, to which the access point communicates over the wired network. IEEE 802.11 Standard to encourage interoperability among wireless networking equipment. IEEE 802.11b High-rate wireless LAN standard for wireless data transfer at up to 11 Mbps. IEEE P802.11g Higher Speed Physical Layer (PHY) Extension to IEEE 802.11b, will boost wireless LAN speed to 54 Mbps by using OFDM (orthogonal frequency division multiplexing). The IEEE 802.11g specification is backward compatible with the widely deployed IEEE 802.11b standard. Inter-Access-Point Protocol The IEEE 802.11 standard does not define how access points track moving users or how to negotiate a handoff from one access point to the next, a process referred to as roaming. IAPP is a Cisco proprietary protocol to support roaming. However, IAPP does not address how the wireless system tracks users moving from one subnet to another. Independent network Network that provides peer-to-peer connectivity without relying on a complete network infrastructure. Information Element Optional wireless network management data element in the beacons and probe responses generated by wireless stations. These elements identify the extended capabilities supported by the stations. Integrity Check Value The WEP ICV shall be a 32-bit value containing the 32-bit cyclic redundancy code designed for verifying wireless data frame integrity. Message Integrity Check A MIC can, optionally, be added to WEP-encrypted 802.11 frames. MIC prevents attacks on encrypted packets. MIC, implemented on both the access point and all associated client devices, adds a few bytes to each packet to make the packets tamper-proof. Multiple BSS-ID An access point radio broadcasts and advertises multiple SSIDs in the beacons. For clients' prospective, it is like there are multiple access points existing in the wireless network. Native VLAN ID A switch port and/or AP can be configured with a 'native VLAN ID'. Untagged or priority-tagged frames are implicitly associated with the native VLAN ID. The default native VLAN ID is '1' if VLAN tagging is enabled. The native VLAN ID is '0' or 'no VLAN ID' if VLAN tagging is not enabled. Non-Root Bridge This wireless bridge does not connect to the main wired LAN segment. It connects to a remote wired LAN segment and can associate with root bridges and other non-root bridges that accept client associations. It also can accept associations from other non-root bridges, repeater access points, and client devices. Primary LAN In an AP, if the destinations of inbound unicast frames are unknown, the frames are sent toward the primary LAN defined on the device. Repeater Device that connects multiple segments, listening to each and regenerating the signal on one to every other connected one; so that the signal can travel further. Repeater or Non-root Access Point The repeater access point is not connected to the wired LAN. The Repeater is a wireless LAN transceiver that transfers data between a client and another access point, another repeater, or between two bridges. The repeater is placed within radio range of an access point connected to the wired LAN, another repeater, or an non-root bridge to extend the range of the infrastructure. Radio Frequency Radio wave and modulation process or operation. Root Access Point This access point connects clients to the main wired LAN. Root (Wireless) Bridge This wireless bridge connects to the main wired LAN. It can communicate with non-root wireless bridges, repeater access points, and client devices but not with another wireless root bridge. Only one wireless bridge in a wireless LAN can be set as the wireless root bridge. Service Set ID SSID is a unique identifier that APs and clients use to identify with each other. SSID is a simple means of access control and is not for security. The SSID can be any alphanumeric entry up to 32 characters. Virtual LAN VLAN defined in the IEEE 802.1Q VLAN standard supports logically segmenting of LAN infrastructure into different subnets or workgroups so that packets are switched only between ports within the same VLAN. VLAN ID Each VLAN is identified by a 12-bit 'VLAN ID'. A VLAN ID of '0' is used to indicate 'no VLAN ID'. Valid VLAN IDs range from '1' to '4095'. VLAN of ID '4095' is the default VLAN for Cisco VoIP Phones. Wired Equivalent Privacy WEP is generally used to refer to 802.11 encryption.
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.413IdentityciscoDot11SsidSecMIBThis MIB module provides network management support for Cisco IEEE 802.11 Wireless LAN devices association and authentication. ACRONYMS AES Advanced Encryption…
1.3.6.1.4.1.9.9.413.1NodeciscoDot11SsidSecMIBObjects
1.3.6.1.4.1.9.9.413.1.1Nodecdot11SecSsidManagement
1.3.6.1.4.1.9.9.413.1.1.1Tablecdot11SecAuxSsidTablenot-accessiblecurrentThis table contains the list of SSIDs that all radio interfaces of this device should install and use for client associations.
1.3.6.1.4.1.9.9.413.1.1.1.1Rowcdot11SecAuxSsidEntrynot-accessiblecurrentA collection of attributes defining an auxiliary service set ID which client stations can use for association for the device. Entries can be installed on multi…
1.3.6.1.4.1.9.9.413.1.1.1.1.1Columncdot11SecAuxSsidnot-accessiblecurrentThis object specifies a SSID defined on this IEEE 802.11 wireless LAN device. The SSID will be installed on the radio interfaces for client associations. The r…
1.3.6.1.4.1.9.9.413.1.1.1.1.2Columncdot11SecAuxSsidBroadcastread-createcurrentThis object indicates if an auxiliary SSID is a Broadcast SSID. There should only be one Broadcast SSID installed on any IEEE 802.11 radio interface if Multipl…
1.3.6.1.4.1.9.9.413.1.1.1.1.3Columncdot11SecAuxSsidInfraStructread-createcurrentThis object indicates if an auxiliary SSID is an infra-structure SSID. There should only be one infra-structure SSID installed on any IEEE 802.11 radio interfa…
1.3.6.1.4.1.9.9.413.1.1.1.1.4Columncdot11SecAuxSsidProxyMobileIpread-createcurrentThis object indicates if an auxiliary SSID is enabled for Proxy Mobile-IP support. If Proxy Mobile-IP is not supported in VLAN network environment, cdot11SecAu…
1.3.6.1.4.1.9.9.413.1.1.1.1.5Columncdot11SecAuxSsidMaxStationsread-createcurrentThis object defines the maximum number of IEEE 802.11 stations which may associate to a radio interface through this SSID. If the value is '0', the maximum num…
1.3.6.1.4.1.9.9.413.1.1.1.1.6Columncdot11SecAuxSsidVlanread-createcurrentThis object defines the VLAN trunk at which the traffic will be used when a client is associating with this SSID. The default value is '0', no VLAN is configur…
1.3.6.1.4.1.9.9.413.1.1.1.1.7Columncdot11SecAuxSsidWpaPskread-createcurrentThis object configures Wi-Fi Protected Access Pre-shared Key for this SSID. This key is used for association authentication and dynamic encryption key generati…
1.3.6.1.4.1.9.9.413.1.1.1.1.8Columncdot11SecAuxRadiusAccountingread-createcurrentThis object defines the name of the AAA accounting list to be used for association accounting. The default value is an empty string if AAA accounting is not en…
1.3.6.1.4.1.9.9.413.1.1.1.1.9Columncdot11SecAuxSsidLoginUsernameread-createcurrentThis object specifies the username used for LEAP authentication and association to an uplink AP while this SSID is in infra-structure mode, i.e. cdot11SecAuxSs…
1.3.6.1.4.1.9.9.413.1.1.1.1.10Columncdot11SecAuxSsidLoginPasswordread-createcurrentThis object specifies the password used for LEAP authentication association to an uplink AP while this SSID is in infra-structure mode, i.e. cdot11SecAuxSsidIn…
1.3.6.1.4.1.9.9.413.1.1.1.1.11Columncdot11SecAuxSsidAuthKeyMgmtread-createcurrentThis object specifies the type of key management employed for encryption keys defined for the VLAN in cdot11SecAuxSsidVlan. WPA key management('wpa') should on…
1.3.6.1.4.1.9.9.413.1.1.1.1.12Columncdot11SecAuxSsidAuthKeyMgmtOptread-createcurrentThis object specifies if the type of key management, cdot11SecAuxSsidAuthKeyMgmt, selected is optional. If it is 'true' and cdot11SecAuxSsidAuthKeyMgmt is not …
1.3.6.1.4.1.9.9.413.1.1.1.1.13Columncdot11SecAuxSsidRowStatusread-createcurrentThis is used to create a new SSID entry on this device, and modify or delete an existing SSID entry. Creation of rows must be done via 'createAndGo' with or wi…
1.3.6.1.4.1.9.9.413.1.1.1.1.14Columncdot11SecAuxSsidWirelessNetIdread-createcurrentThis object sets the Wireless Network ID of this SSID. This ID is used for Cisco GRE tunneling in layer 3 switching. The valid range for the ID is '1' to '4096…
1.3.6.1.4.1.9.9.413.1.1.1.1.15Columncdot11SecSsidRedirectAddrTyperead-createcurrentThis is the address type of for the cdot11SecSsidRedirectDestAddr.
1.3.6.1.4.1.9.9.413.1.1.1.1.16Columncdot11SecSsidRedirectDestAddrread-createcurrentThis is the destination address set to all packets received from wireless clients associated to this wireless station using the cdot11SecAuxSsid. The cdot11Sec…
1.3.6.1.4.1.9.9.413.1.1.1.1.17Columncdot11SecSsidRedirectFilterread-createcurrentWhen the packet redirection feature is enable (i.e., cdot11SecSsidRedirectAddrType is 'ipv4' and cdot11SecSsidRedirectDestAddr value is not '00000000'H), this …
1.3.6.1.4.1.9.9.413.1.1.1.1.18Columncdot11SecSsidInformationElementread-createcurrentThis is the set of Information Elements and extended capabilities embedded in the SSID broadcasted in beacons and probe responses. The extended capabilities 'a…
1.3.6.1.4.1.9.9.413.1.1.1.1.19Columncdot11SecAuxSsidVlanNameread-createcurrentThis is the name of the cdot11SecAuxSsidVlan. Either cdot11SecAuxSsidVlan or cdot11SecAuxSsidVlanName can be used to set the VLAN trunk for client traffic of t…
1.3.6.1.4.1.9.9.413.1.1.1.1.20Columncdot11SecAuxSsidMbssidBroadcastread-createcurrentThis object controls if this SSID shall be broadcasted if MBSSID is enabled at the interface which this SSID is attached, i.e. if both cd11IfMultipleBssidEnabl…
1.3.6.1.4.1.9.9.413.1.1.1.1.21Columncdot11SecAuxSsidMbssidDtimPeriodread-createcurrentThis is the DTIM period for this MBSSID enabled SSID. It is the number of beacon intervals that shall elapse between transmission of Beacons frames containing …
1.3.6.1.4.1.9.9.413.1.1.2Tablecdot11SecAuxSsidAuthTablenot-accessiblecurrentThis table contains attributes to configure authentication parameters for SSIDs listed in the cdot11SecAuxSsidTable. This table extends the IEEE802dot11-MIB do…
1.3.6.1.4.1.9.9.413.1.1.2.1Rowcdot11SecAuxSsidAuthEntrynot-accessiblecurrentEach entry specifies a pre-defined authentication algorithms and additional authentication procedures for clients of an auxiliary SSID. The three pre-defined a…
1.3.6.1.4.1.9.9.413.1.1.2.1.1Columncdot11SecAuxSsidAuthEnabledread-writecurrentIf the value is 'true', this device may authenticate an association using SSID (specified by cdot11SecAuxSsid) with the corresponding pre-defined algorithm (id…
1.3.6.1.4.1.9.9.413.1.1.2.1.2Columncdot11SecAuxSsidAuthPlusEapread-writecurrentIf both the values of this object and cdot11SecAuxSsidAuthEnabled are 'true', the association authentication must complete additional network-level EAP authent…
1.3.6.1.4.1.9.9.413.1.1.2.1.3Columncdot11SecAuxSsidAuthPlusMacread-writecurrentIf both the values of this object and cdot11SecAuxSsidAuthEnabled are 'true', the association authentication must complete additional MAC address authenticatio…
1.3.6.1.4.1.9.9.413.1.1.2.1.4Columncdot11SecAuxSsidAuthEapMethodread-writecurrentIf the value of cdot11SecAuxSsidAuthPlusEap is 'true' or dot11AuthenticationAlgorithm is Network-EAP, this is the EAP method list to use for the EAP authentica…
1.3.6.1.4.1.9.9.413.1.1.2.1.5Columncdot11SecAuxSsidAuthMacMethodread-writecurrentIf the value of cdot11SecAuxSsidAuthPlusMac is 'true', this is the MAC address method list to use for the MAC authentication. The default is an empty string if…
1.3.6.1.4.1.9.9.413.1.1.2.1.6Columncdot11SecAuxSsidAuthMacAlternateread-writecurrentIf the values of this object, cdot11SecAuxSsidAuthEnabled, cdot11SecAuxSsidAuthPlusMac, and cdot11SecAuxSsidAuthPlusEap are all 'true' and the dot11Authenticat…
1.3.6.1.4.1.9.9.413.1.1.3Tablecdot11SecInterfSsidTablenot-accessiblecurrentThis table contains the list of SSIDs installed on radio interfaces of this device and are used for client association. This table has an expansion dependent r…
1.3.6.1.4.1.9.9.413.1.1.3.1Rowcdot11SecInterfSsidEntrynot-accessiblecurrentA collection of attributes for an auxiliary service set ID installed on a IEEE 802.11 radio interface. An interface can have multiple auxiliary service set ID …
1.3.6.1.4.1.9.9.413.1.1.3.1.1Columncdot11SecInterfSsidRowStatusread-createcurrentThis is used to install a new SSID configuration, and modify or delete an existing SSID configuration on a radio interface. Creation of rows must be done via '…
1.3.6.1.4.1.9.9.413.1.1.4Tablecdot11MbssidMacAddrSupportTablenot-accessiblecurrentThis table contains the list of available radio MAC addresses for supporting MBSSID on the IEEE 802.11 radio. This table has an expansion dependent relationshi…
1.3.6.1.4.1.9.9.413.1.1.4.1Rowcdot11MbssidMacAddrSupportEntrynot-accessiblecurrentEach entry is a MAC address assigned to the IEEE 802.11 radio available to be used as a BSSID and broadcasted in the radio beacon when MBSSID feature is enable…
1.3.6.1.4.1.9.9.413.1.1.4.1.1Columncdot11MbssidMacAddrIndexread-onlycurrentThis is an unique index identifying the MAC address assigned on the radio. If MBSSID is not supported on this device, the only available index number is 1. Cur…
1.3.6.1.4.1.9.9.413.1.1.4.1.2Columncdot11MbssidMacAddrSupportedread-onlycurrentThis MAC address can be used as BSSID and broadcasted in the beacon with a SSID when cd11IfMultipleBssidEnable is 'true'.
1.3.6.1.4.1.9.9.413.1.1.5Tablecdot11MbssidInterfaceTablenot-accessiblecurrentThis table displays the list of SSIDs and their corresponding BSSIDs configured on the IEEE 802.11 radios. This table has an expansion dependent relationship o…
1.3.6.1.4.1.9.9.413.1.1.5.1Rowcdot11MbssidInterfaceEntrynot-accessiblecurrentEach entry defines an SSID being configured on the radio and the corresponding BSSID.
1.3.6.1.4.1.9.9.413.1.1.5.1.1Columncdot11MbssidIfMacAddressread-onlycurrentThis is the BSSID to be sent with the radio SSID. If MBSSID feature is not enabled (i.e. cd11IfMultipleBssidEnable is 'false'), all SSIDs will be sent by the r…
1.3.6.1.4.1.9.9.413.1.1.5.1.2Columncdot11MbssidIfBroadcastread-onlycurrentIf d11IfMultipleBssidEnable is 'true', MBSSID is enabled for the radio and this SSID is a broadcast SSID as follows 'true' - This SSID is a broadcast SSID and …
1.3.6.1.4.1.9.9.413.1.1.6Scalarcdot11SecSsidMaxBackupVlansread-writecurrentMaximum number of backup VLANs that can be configured on a SSID.
1.3.6.1.4.1.9.9.413.1.1.7Tablecdot11SecSsidBackupVlanTablenot-accessiblecurrentThis table lists the backup VLANs configured on a SSID. The number of backup VLANs that can be configured for each SSID identified by cdot11SecAuxSsid is limit…
1.3.6.1.4.1.9.9.413.1.1.7.1Rowcdot11SecSsidBackupVlanEntrynot-accessiblecurrentEach entry defines a backup VLAN configured on an SSID.
1.3.6.1.4.1.9.9.413.1.1.7.1.1Columncdot11SecSsidBackupVlannot-accessiblecurrentThe backup VLAN configured on a SSID identified by the instance identifier value of cdot11SecAuxSsid.
1.3.6.1.4.1.9.9.413.1.1.7.1.2Columncdot11SecSsidBackupVlanRowStatusread-createcurrentThe status of this conceptual row.
1.3.6.1.4.1.9.9.413.1.2Nodecdot11SecAuthManagement
1.3.6.1.4.1.9.9.413.1.2.1Scalarcdot11SecLocalAuthServerEnabledread-writecurrentThis object configures the use of local authentication server. If it is 'true', local authentication server is enabled. If it is 'false', the local authenticat…
1.3.6.1.4.1.9.9.413.1.3Nodecdot11SecStatistics
1.3.6.1.4.1.9.9.413.1.4Nodecdot11SecVlanManagement
1.3.6.1.4.1.9.9.413.1.4.1Tablecdot11SecVlanNameTablenot-accessiblecurrentThis table contains the mapping of VLAN names to IDs. A RADIUS server servering this wireless station can assign wireless clients associating to this station t…
1.3.6.1.4.1.9.9.413.1.4.1.1Rowcdot11SecVlanNameEntrynot-accessiblecurrentA collection of attributes defining the properties of a VLAN name and the corresponding VLAN ID.
1.3.6.1.4.1.9.9.413.1.4.1.1.1Columncdot11SecVlanNamenot-accessiblecurrentThis object defines the VLAN name assigned to wireless clients by the RADIUS server serving this wireless station.
1.3.6.1.4.1.9.9.413.1.4.1.1.2Columncdot11SecVlanNameIdread-createcurrentThis object defines the VLAN trunk to which a client associating to this wireless station will be on. The value is '0' is not valid.
1.3.6.1.4.1.9.9.413.1.4.1.1.3Columncdot11SecVlanNameRowStatusread-createcurrentThis is used to create a new VLAN name to ID mapping entry on this device, and modify or delete an existing mapping entry. Creation of rows must be done via 'c…
1.3.6.1.4.1.9.9.413.2NodeciscoDot11SsidSecMIBConformance
1.3.6.1.4.1.9.9.413.2.1NodeciscoDot11SsidSecMIBCompliances
1.3.6.1.4.1.9.9.413.2.1.1ComplianceciscoDot11SsidSecCompliancedeprecatedThis is the compliance statement for the ciscoDot11SsidSecMIB module.
1.3.6.1.4.1.9.9.413.2.1.2ComplianceciscoDot11SsidSecComplianceRev1currentThis is the compliance statement for the ciscoDot11SsidSecMIB module.
1.3.6.1.4.1.9.9.413.2.2NodeciscoDot11SsidSecMIBGroups
1.3.6.1.4.1.9.9.413.2.2.1Groupcdot11SecSsidManagementGroupcurrentThis group includes objects to manage SSID on IEEE 802.11 devices and interfaces.
1.3.6.1.4.1.9.9.413.2.2.2Groupcdot11SsidAuthenticationGroupcurrentThis group includes objects to manage the association and authentication algorithms for SSIDs.
1.3.6.1.4.1.9.9.413.2.2.3Groupcdot11ModuleAuthenticationGroupcurrentThis group includes objects to manage the association and authentication of this wireless station module.
1.3.6.1.4.1.9.9.413.2.2.4Groupcdot11SecVlanManagementGroupcurrentThis group includes objects to manage the VLAN name and ID mapping table.
1.3.6.1.4.1.9.9.413.2.2.5Groupcdot11MbssidSupportGroupcurrentThis group includes objects providing MBSSID configuration information.
1.3.6.1.4.1.9.9.413.2.2.6Groupcdot11SecSsidBackupVlanManagementGroupcurrentThis group of objects are to manage the backup VLAN configuration on a SSID.
Type Definitions
NameSyntaxStatusDescription
CDot11InformationElementTypeBITS { ssidl(0), advertisement(1), wps(2) }currentThis is the set of Information Elements embedded in the wireless device beacons and probe response and the extended capabilities configurable on the IEs: ssidl - send SSIDL IE and may advertise extended capabilities, i.…
CDot11SecAuthKeyMgmtTypeBITS { cckm(0), wpa(1), wpa1(2), wpa2(3) }currentThis is the encryption key management type applied to different encryption key algorithms, like TKIP, WEP, and CKIP. cckm - Cisco Central Key Management wpa - Key management WPA version 1 for TKIP Cipher and Key managem…
CDot11SsidStringOCTET STRING (SIZE(1..32))currentThis is the SSID string defined for IEEE 802.11 wireless LAN devices.
CDot11VlanNameOCTET STRING (SIZE(1..32))currentThis is a VLAN name string configured on RADIUS servers. This should be an alpha-numeric string with at least one alpha.
CDot11WiFiPaPreSharedKeyOCTET STRING (SIZE (0..128))currentThis is a 64-hexadecimal digit Wi-Fi Protected Access Pre-shared Key. This key is used for association authentication and dynamic encryption key generation. The key can also be in the form of a character string.