MIB Viewer

CISCO-TRUSTSEC-MIB

103 objects
This MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis. Glossary : TrustSec - Cisco Trusted Security EAP-FAST - Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (RFC 4851) PAC - Protected Access Credential A credential dynamically downloaded from the Access Control Server. ACS - Access Control Server SGT - Security Group Tag A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud.
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.730IdentityciscoTrustSecMIBThis MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticati…
1.3.6.1.4.1.9.9.730.0NodeciscoTrustSecMIBNotifs
1.3.6.1.4.1.9.9.730.0.1NotificationctsSwKeystoreFileErrNotifcurrentA ctsSwKeystoreFileErrNotif is generated when system encounters an error while performing operation on the software keystore file.
1.3.6.1.4.1.9.9.730.0.2NotificationctsSwKeystoreSyncFailNotifcurrentA ctsSwKeystoreSyncFailNotifReason is generated when system fails to sync software keystore information from the active supervisor to the standby supervisor.
1.3.6.1.4.1.9.9.730.0.3NotificationctsAuthzCacheFileErrNotifcurrentA ctsAuthzCacheFileErrNotif is generated when the system encounters error downloading TrustSec authorization related environment data to a cache file.
1.3.6.1.4.1.9.9.730.0.4NotificationctsCacheFileAccessErrNotifcurrentA ctsCacheFileAccessErrNotif is generated when the system fails to perform open/read/write operation for a TrustSec cache file.
1.3.6.1.4.1.9.9.730.0.5NotificationctsSrcEntropyFailNotifcurrentA ctsSrcEntropyFailNotif is generated when the periodic health tests for the CTR-DRBG (Counter- Deterministic Random Bit Generator) implementation fails due to…
1.3.6.1.4.1.9.9.730.0.6NotificationctsSapRandomNumberFailNotifcurrentA ctsSapRandomNumberFailNotif is generated when the the system fails to obtain a random number from CTR-DRBG block for SAP (Security Association Protocol) key-…
1.3.6.1.4.1.9.9.730.1NodeciscoTrustSecMIBObjects
1.3.6.1.4.1.9.9.730.1.1NodectsCacheObjects
1.3.6.1.4.1.9.9.730.1.1.1ScalarctsCacheEnabledread-writecurrentThis object specifies if the TrustSec cache is enabled in the system.
1.3.6.1.4.1.9.9.730.1.1.2ScalarctsCacheNvStorageread-writecurrentThe object specifies the location on the device where TrustSec cache files will be created. The location may be specified in <device>:[directory] format, where…
1.3.6.1.4.1.9.9.730.1.1.3ScalarctsCacheClearread-writecurrentThis object allows user to clear the cache files for Cisco Trusted Security feature on this device. When read, this object always returns the value 'none'. 'no…
1.3.6.1.4.1.9.9.730.1.2NodectsSgtObjects
1.3.6.1.4.1.9.9.730.1.2.1ScalarctsSecurityGroupTagIdread-writecurrentThis object allows user to specify the SGT for the packets originating from this device. A value of zero for this object indicates that no SGT has been configu…
1.3.6.1.4.1.9.9.730.1.2.2ScalarctsSgtAssignmentMethodread-writecurrentThis object specifies the method used for assignment of TrustSec SGT for the line cards without TrustSec tagging capability. 'none' - assignment of TrustSec SG…
1.3.6.1.4.1.9.9.730.1.3NodectsCredentialObjects
1.3.6.1.4.1.9.9.730.1.3.1ScalarctsDeviceIdread-writecurrentThis object allows user to specify the identifier for the device. This identifier and the device password (specified by ctsDevicePassword) are used together by…
1.3.6.1.4.1.9.9.730.1.3.2ScalarctsDevicePasswordTyperead-writecurrentThis object specifies the type of encryption employed to encrypt password in ctsDevicePassword object. Value for this object must be specified as 'clearText', …
1.3.6.1.4.1.9.9.730.1.3.3ScalarctsDevicePasswordread-writecurrentThis object allows user to specify the password for the device. This password and the device identifier (specified by ctsDeviceId) are used together by the Cis…
1.3.6.1.4.1.9.9.730.1.3.4ScalarctsKeystoreTyperead-onlycurrentThis object indicates the type of keystore employed by the device. 'hardwareKeystore' - Keystore functionality is implemented in hardware. 'softwareEmulation' …
1.3.6.1.4.1.9.9.730.1.3.5ScalarctsKeystoreFwVersionread-onlycurrentThis object indicates the firmware version of the hardware keystore. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeystore'.
1.3.6.1.4.1.9.9.730.1.3.6ScalarctsKeystoreFwAlertsread-onlycurrentThis object indicates the number of hardware keystore alerts that occurred. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeys…
1.3.6.1.4.1.9.9.730.1.3.7ScalarctsKeystoreFwResetsread-onlycurrentThis object indicates the number of times the keystore firmware was reset. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeyst…
1.3.6.1.4.1.9.9.730.1.3.8ScalarctsKeystoreRxTimeoutsread-onlycurrentThis object indicates the number of times the system timed out awaiting response from keystore firmware. This object is only instantiated when the value of cts…
1.3.6.1.4.1.9.9.730.1.3.9ScalarctsKeystoreRxBadChecksumsread-onlycurrentThis object indicates the number of message fragments the system received from keystore firmware that had bad checksum value. This object is only instantiated …
1.3.6.1.4.1.9.9.730.1.3.10ScalarctsKeystoreRxBadFragmentLengthsread-onlycurrentThis object indicates the number of message fragments the system received from keystore firmware that had illegal lengths. This object is only instantiated whe…
1.3.6.1.4.1.9.9.730.1.3.11ScalarctsKeystoreCorruptionsread-onlycurrentThis object indicates the number of times keystore firmware reported detection of one or more corrupted records in the hardware keystore. This object is only i…
1.3.6.1.4.1.9.9.730.1.3.13TablectsKeystorePasswordRecordTablenot-accessiblecurrentA list of Cisco Trusted Security password records stored in the hardware or software keystore of this device.
1.3.6.1.4.1.9.9.730.1.3.13.1RowctsKeystorePasswordRecordEntrynot-accessiblecurrentAn entry describing individual password record in the keystore of this device. An entry will be created or deleted from this table when a password record is ad…
1.3.6.1.4.1.9.9.730.1.3.13.1.1ColumnctsKeystorePasswordRecordNamenot-accessiblecurrentThis object identifies a password record.
1.3.6.1.4.1.9.9.730.1.3.13.1.2ColumnctsKeystorePasswordRecordTyperead-onlycurrentThis object indicates the type of credential in this record.
1.3.6.1.4.1.9.9.730.1.3.14TablectsKeystorePacRecordTablenot-accessiblecurrentA list of Cisco Trusted Security PAC records stored in the hardware or software keystore of this device.
1.3.6.1.4.1.9.9.730.1.3.14.1RowctsKeystorePacRecordEntrynot-accessiblecurrentAn entry describing individual PAC record in the keystore of this device. An entry will be created or deleted by the system when a PAC record is added or remov…
1.3.6.1.4.1.9.9.730.1.3.14.1.1ColumnctsKeystorePacRecordNamenot-accessiblecurrentThe name of this PAC record.
1.3.6.1.4.1.9.9.730.1.3.14.1.2ColumnctsKeystorePacRecordTyperead-onlycurrentThis object indicates the type of credential in this record.
1.3.6.1.4.1.9.9.730.1.3.15TablectsPacInfoTablenot-accessiblecurrentA list of PACs on this device.
1.3.6.1.4.1.9.9.730.1.3.15.1RowctsPacInfoEntrynot-accessiblecurrentAn entry providing management information of a particular PAC record. An entry can only be created dynamically by the system when a new PAC is installed in the…
1.3.6.1.4.1.9.9.730.1.3.15.1.1ColumnctsPacAcsAuthIdnot-accessiblecurrentThis object indicates the unique authority identity of the ACS server from where the PAC was downloaded.
1.3.6.1.4.1.9.9.730.1.3.15.1.2ColumnctsPacAcsDescriptionread-onlycurrentThis object indicates the description of the ACS server from where the PAC was downloaded.
1.3.6.1.4.1.9.9.730.1.3.15.1.3ColumnctsPacTyperead-onlycurrentThis object indicates the type of PAC this entry represents. 'unknown' - Any other type of PAC that is not covered below 'tunnel' - Distributed shared secret b…
1.3.6.1.4.1.9.9.730.1.3.15.1.4ColumnctsPacExpirationTimeread-onlycurrentThis object indicates the time when this PAC will be expired.
1.3.6.1.4.1.9.9.730.1.3.15.1.5ColumnctsPacTimeToRefreshread-onlycurrentThis object indicates the time left for this PAC to be refreshed from the ACS.
1.3.6.1.4.1.9.9.730.1.3.15.1.6ColumnctsPacStatusread-createcurrentThis object is used to manage the deletion of rows in this table. This object only supports the values 'active' and 'destroy'. Setting this object to 'destroy'…
1.3.6.1.4.1.9.9.730.1.3.16ScalarctsCredentialsClearAllread-writecurrentThis object allows user to clear all the PACs and Cisco Trusted Security credentials on the device. Setting the object to 'true' will clear all the PACs and cr…
1.3.6.1.4.1.9.9.730.1.4NodectsEnvironmentDataObjects
1.3.6.1.4.1.9.9.730.1.4.1ScalarctsEnvDataLastDownloadStatusread-onlycurrentThis object indicates the status of the last attempt to download the Environment Data. 'other' - Any other state not covered by below enumerations. 'succeeded'…
1.3.6.1.4.1.9.9.730.1.4.2ScalarctsEnvSecurityGroupTagIdread-onlycurrentThis object indicates the SGT for packets originating on this device downloaded from the ACS. A value of zero for this object indicates that no SGT has been do…
1.3.6.1.4.1.9.9.730.1.4.3ScalarctsEnvSecurityGroupTagGenIdread-onlycurrentThis object indicates the generation identifier associated with the downloaded SGT on this device.
1.3.6.1.4.1.9.9.730.1.4.4ScalarctsEnvDataLastUpdateread-onlycurrentThis object indicates the last time Cisco Trusted Security Environment Data was successfully updated from ACS. This object will contain 0-1-1,00:00:00:0 if Env…
1.3.6.1.4.1.9.9.730.1.4.5ScalarctsEnvDataRefreshIntervalread-onlycurrentThis object indicates the time interval for which Trusted Security Environment Data is valid. The Trusted Security Environment Data will be refreshed i.e. down…
1.3.6.1.4.1.9.9.730.1.4.6ScalarctsEnvDataTimeLeftread-onlycurrentThis object indicates the time left for the currently installed Trusted Security Environment Data to expire.
1.3.6.1.4.1.9.9.730.1.4.7ScalarctsEnvDataTimeToRefreshread-onlycurrentThis object indicates the time interval after which Trusted Security Environment Data will be refreshed i.e. downloaded from the ACS due to Environment Data ex…
1.3.6.1.4.1.9.9.730.1.4.8ScalarctsEnvDataSourceread-onlycurrentThis object indicates the source of current Environment Data installed on the system. 'none' - No Environment Data is currently installed. 'cached' - Environme…
1.3.6.1.4.1.9.9.730.1.4.9ScalarctsEnvDataActionread-writecurrentThis object allows user to specify the action to be taken for all the Cisco Trusted Security Environment Data on this device. When read, this object always ret…
1.3.6.1.4.1.9.9.730.1.4.16TablectsEnvSecurityGroupNameTablenot-accessiblecurrentA list of Security Group Names in Cisco Trusted Security environment.
1.3.6.1.4.1.9.9.730.1.4.16.1RowctsEnvSecurityGroupNameEntrynot-accessiblecurrentAn entry listing the name assigned to each SGT in Cisco Trusted Security environment. Entries will be populated in this table when system downloads Security Gr…
1.3.6.1.4.1.9.9.730.1.4.16.1.1ColumnctsEnvSecurityGroupNameSgtnot-accessiblecurrentThis object identifies a SGT in Trusted Security environment.
1.3.6.1.4.1.9.9.730.1.4.16.1.2ColumnctsEnvSecurityGroupNameSgtGenIdread-onlycurrentThis object indicates the Generation Identifier associated with this SGT.
1.3.6.1.4.1.9.9.730.1.4.16.1.3ColumnctsEnvSecurityGroupNameSgtFlagread-onlycurrentThis object indicates the flag associated with this SGT. 'recognizedSgt' - indicates a recognized SGT when set to 1, else indicates a reserved SGT. 'unicastSgt…
1.3.6.1.4.1.9.9.730.1.4.16.1.4ColumnctsEnvSecurityGroupNameread-onlycurrentThis object indicates the Security Group Name assigned to this SGT.
1.3.6.1.4.1.9.9.730.1.5NodectsNotifsControlObjects
1.3.6.1.4.1.9.9.730.1.5.1ScalarctsSwKeystoreFileErrNotifEnableread-writecurrentThis object specifies if the system generates ctsSwKeystoreFileErrNotif. A value of 'false' will prevent ctsSwKeystoreFileErrNotif notifications from being gen…
1.3.6.1.4.1.9.9.730.1.5.2ScalarctsSwKeystoreSyncFailNotifEnableread-writecurrentThis object specifies if the system generates ctsSwKeystoreSyncFailNotif. A value of 'false' will prevent ctsSwKeystoreSyncFailNotif notifications from being g…
1.3.6.1.4.1.9.9.730.1.5.3ScalarctsAuthzCacheFileErrNotifEnableread-writecurrentThis object specifies if the system generates ctsAuthzCacheFileErrNotif. A value of 'false' will prevent ctsAuthzCacheFileErrNotif notifications from being gen…
1.3.6.1.4.1.9.9.730.1.5.4ScalarctsCacheFileAccessErrNotifEnableread-writecurrentThis object specifies if the system generates ctsCacheFileAccessErrNotif. A value of 'false' will prevent ctsCacheFileAccessErrNotif notifications from being g…
1.3.6.1.4.1.9.9.730.1.5.5ScalarctsSrcEntropyFailNotifEnableread-writecurrentThis object specifies if the system generates ctsSrcEntropyFailNotif. A value of 'false' will prevent ctsSrcEntropyFailNotif notifications from being generated…
1.3.6.1.4.1.9.9.730.1.5.6ScalarctsSapRandomNumberFailNotifEnableread-writecurrentThis object specifies if the system generates ctsSapRandomNumberFailNotif. A value of 'false' will prevent ctsSapRandomNumberFailNotif notifications from being…
1.3.6.1.4.1.9.9.730.1.6NodectsNotifsInfoObjects
1.3.6.1.4.1.9.9.730.1.6.1ScalarctsFileErrNotifReasonaccessible-for-notifycurrentThis object indicates the reason file error related notification was generated. 'openFailedForWrite' - System failed to open a file to write TrustSec informati…
1.3.6.1.4.1.9.9.730.1.6.2ScalarctsSwKeystoreSyncFailNotifReasonaccessible-for-notifycurrentThis object indicates the reason ctsSwKeystoreSyncFailNotif notification was generated. 'ipcPortCreationFailed' - Keystore information could not be synced beca…
1.3.6.1.4.1.9.9.730.1.6.3ScalarctsNotifMessageStringaccessible-for-notifycurrentThe object indicates additional information for a TrustSec notification.
1.3.6.1.4.1.9.9.730.1.7NodectsCriticalAuthObjects
1.3.6.1.4.1.9.9.730.1.7.1ScalarctsCriticalAuthEnabledread-writecurrentThis object specifies if the Critical-Auth functionality is enabled in the system. Setting the object to 'true' will enable Critical-Auth functionality in the …
1.3.6.1.4.1.9.9.730.1.7.2ScalarctsCriticalAuthFallbackread-writecurrentThis object specifies the CTS Critical-Auth fallback policy. default - Critical-Auth fallback policy is default. cache - Critical-Auth fallback policy is cache.
1.3.6.1.4.1.9.9.730.1.7.3ScalarctsCriticalAuthPeerSgtread-writecurrentThis object specifies the CTS Critical-Auth SGT tag of the remote peer. ctsCriticalAuthPeerSgt cannot be set to zero when ctsCriticalAuthEnable is enable. ctsC…
1.3.6.1.4.1.9.9.730.1.7.4ScalarctsCriticalAuthPeerSgtTrustread-writecurrentThis object specifies the CTS Critical-Auth peer's sgt trust state. This object can only be set when ctsCriticalAuthPeerSgt is non-zero.
1.3.6.1.4.1.9.9.730.1.7.5ScalarctsCriticalAuthDefaultPmkread-writecurrentThis object specifies the CTS Critical-Auth default PMK used by SAP. The purpose of this object is to only allow configuration of Critical-Auth PMK. The ctsCri…
1.3.6.1.4.1.9.9.730.1.7.6ScalarctsCriticalAuthViewDefaultPmkread-onlycurrentThis object indicates the CTS Critical-Auth default PMK. The purpose of this object is to only display the configured Critical-Auth PMK. A zero length string f…
1.3.6.1.4.1.9.9.730.2NodeciscoTrustSecMIBConform
1.3.6.1.4.1.9.9.730.2.1NodeciscoTrustSecMIBCompliances
1.3.6.1.4.1.9.9.730.2.1.1ComplianceciscoTrustSecMIBComplianceread-onlydeprecatedThe compliance statement for the CISCO-TRUSTSEC-MIB.
1.3.6.1.4.1.9.9.730.2.1.2ComplianceciscoTrustSecMIBCompliance2read-onlydeprecatedThe compliance statement for the CISCO-TRUSTSEC-MIB.
1.3.6.1.4.1.9.9.730.2.1.3ComplianceciscoTrustSecMIBCompliance3read-onlydeprecatedThe compliance statement for the CISCO-TRUSTSEC-MIB.
1.3.6.1.4.1.9.9.730.2.1.4ComplianceciscoTrustSecMIBCompliance4read-onlycurrentThe compliance statement for the CISCO-TRUSTSEC-MIB.
1.3.6.1.4.1.9.9.730.2.2NodeciscoTrustSecMIBGroups
1.3.6.1.4.1.9.9.730.2.2.1GroupciscoTrustSecCacheGroupcurrentA collection of objects that provides the cache configuration for TrustSec in the system.
1.3.6.1.4.1.9.9.730.2.2.2GroupciscoTrustSecSgtGroupcurrentA collection of objects to manage SGT for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.3GroupciscoTrustSecCredentialsGroupcurrentA collection of objects to manage credentials parameters for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.4GroupciscoTrustSecHwKeystoreInfoGroupcurrentA collection of objects to manage hardware keystore for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.5GroupciscoTrustSecEnvDataGroupcurrentA collection of objects to manage Environment Data for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.6GroupciscoTrustSecSgtAssignmentGroupcurrentA collection of objects to manage assignment of TrustSec SGT.
1.3.6.1.4.1.9.9.730.2.2.7GroupciscoTrustSecEnvSecGroupNameGroupcurrentA collection of object(s) to manage Security Group Name information for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.8GroupciscoTrustSecSwKeystoreNotifsInfoGroupcurrentA collection of object(s) to provide information regarding software keystore notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.9GroupciscoTrustSecSwKeystoreNotifsControlGroupcurrentA collection of object(s) to control software keystore notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.10GroupciscoTrustSecSwKeystoreNotifsGroupcurrentA collection of software keystore related notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.11GroupciscoTrustSecFileErrNotifsInfoGroupcurrentA collection of object(s) to provide information regarding file error related notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.12GroupciscoTrustSecNotifsMessageStringInfoGroupcurrentA collection of object(s) to provide information regarding TrustSec notification.
1.3.6.1.4.1.9.9.730.2.2.13GroupciscoTrustSecCacheFileNotifsControlGroupcurrentA collection of object(s) to control cache file related notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.14GroupciscoTrustSecCacheFileNotifsGroupcurrentA collection of TrustSec cache file related notifications.
1.3.6.1.4.1.9.9.730.2.2.15GroupciscoTrustSecCtrDrbgNotifsControlGroupcurrentA collection of object(s) to control CTR-DRBG related notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.16GroupciscoTrustSecCtrDrbgNotifsGroupcurrentA collection of CTR-DRBG related notifications for TrustSec.
1.3.6.1.4.1.9.9.730.2.2.17GroupciscoTrustSecCrtclAuthGroupcurrentA collection of CTS Critical Auth Config objects