MIB Viewer

CISCO-LWAPP-MFP-MIB

57 objects
This MIB is intended to be implemented on all those devices operating as Central Controllers (CC) that terminate the Light Weight Access Point Protocol tunnel from Light-weight LWAPP Access Points. This MIB instrumentation provides the parameters used by the controller to control and monitor the behavior of the associated Access Points when following the newly defined Management Frame Protocol. The controller would pass the MFP settings configured by the user through this MIB to the APs through LWAPP messages. The APs then begin to validate and verify the integrity of 802.11 Management frames and report the anomalies found, if any, to the controller. The relationship between CC and the LWAPP APs can be depicted as follows. +......+ +......+ +......+ +......+ + + + + + + + + + CC + + CC + + CC + + CC + + + + + + + + + +......+ +......+ +......+ +......+ .. . . . .. . . . . . . . . . . . . . . . . . . . . . . . +......+ +......+ +......+ +......+ +......+ + + + + + + + + + + + AP + + AP + + AP + + AP + + AP + + + + + + + + + + + +......+ +......+ +......+ +......+ +......+ . . . . . . . . . . . . . . . . . . . . . . . . +......+ +......+ +......+ +......+ +......+ + + + + + + + + + + + MN + + MN + + MN + + MN + + MN + + + + + + + + + + + +......+ +......+ +......+ +......+ +......+ The LWAPP tunnel exists between the controller and the APs. The MNs communicate with the APs through the protocol defined by the 802.11 standard. LWAPP APs, upon bootup, discover and join one of the controllers and the controller pushes the configuration, which includes the WLAN parameters, to the LWAPP APs. The APs then encapsulate all the 802.11 frames from wireless clients inside LWAPP frames and forward the LWAPP frames to the controller. Reference [2] explains in detail about the communication between the controller and APs, while Reference [1] explains the AP-MN communication. To secure the 802.11 management traffic, the controller and the APs perform specific roles. The controller acts as the central entity to generate and distribute signature keys using which the APs generate integrity check values, also known as signatures, for individual management frames. The APs append this signature in the form of an Information Element to the respective management frame to be transmitted. This is needed to isolate those potential rogue APs whose frames may not carry the frame signature. The APs use the signature keys, generated and pushed to them by the controller for each BSSID reported as heard by the APs, to validate the integrity of the the management traffic originating from various 802.11 sources. Any anomalies observed by the APs are reported to the controller. The controller makes the information about such events available for a network management Station in the form of notifications. GLOSSARY Access Point ( AP ) An entity that contains an 802.11 media access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients. LWAPP APs encapsulate all the 802.11 frames in LWAPP frames and sends them to the controller to which it is logically connected. AP-Authentication With this feature enabled, the Access Points sending radio resource management neighbor packets with different RF network names will be reported as rogues. Basic Service Set Identifier ( BSSID ) The identifier of the Basic Service Set controlled by a single coordination function. The identifier is usually the MAC address of the radio interface that hosts the BSS. Central Controller ( CC ) The central entity that terminates the LWAPP protocol tunnel from the LWAPP APs. Throughout this MIB, this entity is also referred to as 'controller'. Light Weight Access Point Protocol ( LWAPP ) This is a generic protocol that defines the communication between the Access Points and the Central Controller. Management Frame Protection ( MFP ) A proprietary mechanism devised to integrity protect the otherwise unprotected management frames of the 802.11 protocol specification. Message Integrity Check ( MIC ) A checksum computed on a sequence of bytes and made known to the receiving party in a data communication, to let the receiving party make sure the bytes received were not compromised enroute. Mobile Node ( MN ) A roaming 802.11 wireless device in a wireless network associated with an access point. Network Management Station ( NMS ) The system through which the network administrator manages the controller and the APs associated to it. REFERENCE [1] Wireless LAN Medium Access Control ( MAC ) and Physical Layer ( PHY ) Specifications, ANSI/IEEE Std 802.11, 1999 Edition. [2] Draft-obara-Capwap-lwapp-00.txt, IETF Light Weight Access Point Protocol
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.518IdentityciscoLwappMfpMIBThis MIB is intended to be implemented on all those devices operating as Central Controllers (CC) that terminate the Light Weight Access Point Protocol tunnel …
1.3.6.1.4.1.9.9.518.0NodeciscoLwappMfpMIBNotifs
1.3.6.1.4.1.9.9.518.0.1NotificationciscoLwappMfpProtectConfigMismatchcurrentThis notification is sent by the agent when the controller detects that the AP couldn't apply the protection configuration to the specific radio interface for …
1.3.6.1.4.1.9.9.518.0.2NotificationciscoLwappMfpValidationConfigMismatchcurrentThis notification is sent by the agent when the controller detects that the AP couldn't configure itself with the MFP signature validation configuration. The c…
1.3.6.1.4.1.9.9.518.0.3NotificationciscoLwappMfpTimebaseStatuscurrentThis notification is sent by the agent to indicate the controller's status of synchronization of its timebase with that of a central timebase. The notification…
1.3.6.1.4.1.9.9.518.0.4NotificationciscoLwappMfpAnomalyDetecteddeprecatedThis notification is sent by the agent when the MFP configuration of the WLAN was violated by the radio interface cLApIfSmtDot11Bssid and detected by the radio…
1.3.6.1.4.1.9.9.518.0.5NotificationciscoLwappMfpAnomalyDetected1currentThis notification is sent by the agent when the MFP configuration of the WLAN was violated by the radio interface cLApIfSmtDot11Bssid and detected by the radio…
1.3.6.1.4.1.9.9.518.1NodeciscoLwappMfpMIBNotifObjects
1.3.6.1.4.1.9.9.518.1.1ScalarcLApMacAddressaccessible-for-notifycurrentThis object represents the radio MAC address of a LWAPP AP.
1.3.6.1.4.1.9.9.518.1.2ScalarcLApDot11IfSlotIdxaccessible-for-notifycurrentThis object represents the slotId of the dot11 interface.
1.3.6.1.4.1.9.9.518.1.3ScalarcLWlanIdxaccessible-for-notifycurrentThis object represents the identifier for a WLAN.
1.3.6.1.4.1.9.9.518.1.4ScalarcLMfpApIfMfpProtectionActualaccessible-for-notifycurrentThis object represents the actual protection configuration for a specific WLAN as applicable to a dot11 interface of a specific AP.
1.3.6.1.4.1.9.9.518.1.5ScalarcLMfpEventTypeaccessible-for-notifycurrentThis object represents the type of the MFP anomaly event.
1.3.6.1.4.1.9.9.518.1.6ScalarcLMfpEventTotalaccessible-for-notifycurrentThis object represents the number of MFP anomaly events detected in the prior period indicated by cLMfpEventPeriod. cLMfpEventType indicates the type of the an…
1.3.6.1.4.1.9.9.518.1.7ScalarcLMfpEventPeriodaccessible-for-notifycurrentThis object represents the time period, in hundredths of a second, in which the reported number of events are detected. This is the time interval at which the …
1.3.6.1.4.1.9.9.518.1.8ScalarcLMfpEventFramesaccessible-for-notifycurrentThis object indicates which type of 802.11 management frames contain anomalies of type cLMfpEventType. When the controller detects anomalies using the MFP vali…
1.3.6.1.4.1.9.9.518.1.10ScalarcLClientLastSourceMacAddressaccessible-for-notifycurrentThis object represents the MAC address of the client that is responsible for the most recent event related to a wireless client. This information is useful to …
1.3.6.1.4.1.9.9.518.2NodeciscoLwappMfpMIBObjects
1.3.6.1.4.1.9.9.518.2.1NodeciscoLwappMfpConfig
1.3.6.1.4.1.9.9.518.2.1.1ScalarcLMfpProtectTyperead-writecurrentThis object specifies the authentication mechanism to be used to secure the WLANs managed through this controller. A value of 'cLMfpProtectNone' specifies no a…
1.3.6.1.4.1.9.9.518.2.1.2TablecLMfpWlanConfigTablenot-accessiblecurrentThis table represents the configuration needed by the controller to enable management frame protection on a particular WLAN. A controller, when configured, ena…
1.3.6.1.4.1.9.9.518.2.1.2.1RowcLMfpWlanConfigEntrynot-accessiblecurrentA conceptual row in cLMfpWlanConfigTable and represents the MFP configuration on a particular WLAN.
1.3.6.1.4.1.9.9.518.2.1.2.1.2ColumncLMfpVersionRequiredread-writecurrentThis object specifies the version of the management frame protection protocol required for the MFP framework when the MFP protection is enabled through the cLM…
1.3.6.1.4.1.9.9.518.2.1.2.1.3ColumncLMfpProtectionEnableread-writedeprecatedThis object specifies whether the MFP protection on this WLAN be enabled or not. A value of 'true' enables management frame protection on the WLAN and 'false' …
1.3.6.1.4.1.9.9.518.2.1.2.1.4ColumncLMfpClientProtectionread-writecurrentThis object specifies the level of client MFP protection for this WLAN. A value of 'disabled' specifies client protection is disabled. A value of 'enabled' spe…
1.3.6.1.4.1.9.9.518.2.1.3ScalarcLMfpApImpersonationread-writecurrentThe authentication mechanism to be used to secure the WLANs managed through this controller. The ap imporesonation allows AP to detect attacks which takes in f…
1.3.6.1.4.1.9.9.518.2.1.4ScalarcLMfpKeyRefreshIntervalread-writecurrentThe authentication mechanism to be used to secure the WLANs managed through this controller. It defines the time interval in which keys of MFP are to be refres…
1.3.6.1.4.1.9.9.518.2.2NodeciscoLwappMfpStatus
1.3.6.1.4.1.9.9.518.2.2.1ScalarcLMfpCtrlTimeBaseStatusread-onlycurrentThis object indicates the status of synchronization of the MFP-aware LWAPP controller's timebase with that of a central time server.
1.3.6.1.4.1.9.9.518.2.2.2TablecLMfpApParamTablenot-accessiblecurrentThis table represents the configuration of MFP related parameters corresponding to a particular AP. A row is added to the table by the agent when a a row is ad…
1.3.6.1.4.1.9.9.518.2.2.2.1RowcLMfpApParamEntrynot-accessiblecurrentThis object represents a conceptual row in this table and represents the MFP parameters of a particular AP.
1.3.6.1.4.1.9.9.518.2.2.2.1.1ColumncLMfpApMfpValidationEnableread-writecurrentThis object specifies whether the AP should validate the management frames received by it in accordance with the MFP version or not. A value of 'true' indicate…
1.3.6.1.4.1.9.9.518.2.2.2.1.2ColumncLMfpApMfpValidationActualread-onlycurrentThis object indicates the status of MFP validation being done as reported by the AP in response to the controller's request to perform MFP validation. A value …
1.3.6.1.4.1.9.9.518.2.2.3TablecLMfpApIfSmtCapTablenot-accessibledeprecatedThis table represents the MFP capabilities on a dot11 radio interface of an AP that has joined this controller. An AP performs the role of protecting and valid…
1.3.6.1.4.1.9.9.518.2.2.3.1RowcLMfpApIfSmtCapEntrynot-accessibledeprecatedThis object represents a conceptual row in this table and represents the MFP capabilities on the dot11 interface of a particular LWAPP AP.
1.3.6.1.4.1.9.9.518.2.2.3.1.1ColumncLMfpApIfMfpVersionSupportedread-onlydeprecatedThis object represents the version of the MFP protocol currently supported by this radio interface.
1.3.6.1.4.1.9.9.518.2.2.3.1.2ColumncLMfpApIfMfpProtectionCapabilityread-onlydeprecatedThis object represents the management frame protection capability urrently exhibited by the dot11 interface. A value of 'protectCapNone' represents protection …
1.3.6.1.4.1.9.9.518.2.2.3.1.3ColumncLMfpApIfMfpValidationCapabilityread-onlydeprecatedThis object represents the management frame validation capability currently exhibited by this dot11 interface. A value of 'validateCapNone' represents the MFP …
1.3.6.1.4.1.9.9.518.2.2.4ScalarcLMfpCtrlNotifEnableread-writecurrentThe object specifies to control the generation of notifications defined in this MIB. A value of 'true' specifies that the agent generates the notifications def…
1.3.6.1.4.1.9.9.518.2.2.5TablecLMfpClientTablenot-accessiblecurrentThis table represents the MFP information for 802.11 wireless clients that are associated with the APs that have joined this controller.
1.3.6.1.4.1.9.9.518.2.2.5.1RowcLMfpClientEntrynot-accessiblecurrentEach entry represents a conceptual row in this table and provides MFP information about the clients associated to the APs that have joined the controller.
1.3.6.1.4.1.9.9.518.2.2.5.1.1ColumncLMfpClientMfpEnabledread-onlycurrentThis object indicates whether MFP protection is enabled for a particular client. A value of 'true' indicates that MFP protection is enabled. A value of 'false'…
1.3.6.1.4.1.9.9.518.3NodeciscoLwappMfpMIBConform
1.3.6.1.4.1.9.9.518.3.1NodeciscoLwappMfpMIBCompliances
1.3.6.1.4.1.9.9.518.3.1.1ComplianceciscoLwappMfpMIBCompliancedeprecatedThe compliance statement for the SNMP entities that implement the ciscoLwappMfpMIB module.
1.3.6.1.4.1.9.9.518.3.1.2ComplianceciscoLwappMfpMIBComplianceRev1deprecatedThe compliance statement for the SNMP entities that implement the ciscoLwappMfpMIB module.
1.3.6.1.4.1.9.9.518.3.1.3ComplianceciscoLwappMfpMIBComplianceRev2currentThe compliance statement for the SNMP entities that implement the ciscoLwappMfpMIB module.
1.3.6.1.4.1.9.9.518.3.2NodeciscoLwappMfpMIBGroups
1.3.6.1.4.1.9.9.518.3.2.1GroupciscoLwappMfpConfigGroupdeprecatedThis collection of objects represent the global and WLAN-specific protection capabilities on the controller.
1.3.6.1.4.1.9.9.518.3.2.2GroupciscoLwappMfpStatusGroupcurrentThis collection of objects provides the information about the MFP signature protection capabilities as observed on the dot11 interfaces of the LWAPP APs.
1.3.6.1.4.1.9.9.518.3.2.3GroupciscoLwappMfpNotifObjsGroupcurrentThis collection of objects represent the information carried by the MFP related notifications sent by the agent to a network management station.
1.3.6.1.4.1.9.9.518.3.2.4GroupciscoLwappMfpNotifsGroupdeprecatedThis collection of objects represent the MFP related notifications sent by the agent to a network management station.
1.3.6.1.4.1.9.9.518.3.2.5GroupciscoLwappMfpConfigSup1GroupcurrentThis collection of objects represent the configuration for client protection on the controller.
1.3.6.1.4.1.9.9.518.3.2.6GroupciscoLwappMfpStatusSup1GroupcurrentThis collection of objects represent the status of client protection on the controller.
1.3.6.1.4.1.9.9.518.3.2.7GroupciscoLwappMfpNotifObjsSup1GroupcurrentThis collection of objects represent the client related information in the MFP notifications generated by the controller.
1.3.6.1.4.1.9.9.518.3.2.8GroupciscoLwappMfpNotifsNewGroupcurrentThis collection of objects represent the MFP related notifications sent by the agent to a network management station.
1.3.6.1.4.1.9.9.518.3.2.9GroupciscoLwappMfpConfigGroupVer1currentThis collection of objects represent the global and WLAN-specific protection capabilities on the controller.