CISCO-TRUSTSEC-MIB
103 objects
This MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis. Glossary : TrustSec - Cisco Trusted Security EAP-FAST - Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (RFC 4851) PAC - Protected Access Credential A credential dynamically downloaded from the Access Control Server. ACS - Access Control Server SGT - Security Group Tag A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud.
Imported Objects
| CISCO-SMI | ciscoMgmt |
| CISCO-TRUSTSEC-TC-MIB | CtsAcsAuthorityIdentity CtsCredentialRecordType CtsGenerationId CtsPasswordEncryptionType CtsSecurityGroupTag |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP |
| SNMPv2-SMI | Counter32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | DateAndTime RowStatus TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.9.9.730 | IdentityciscoTrustSecMIB | This MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticati… | ||
| 1.3.6.1.4.1.9.9.730.0 | NodeciscoTrustSecMIBNotifs | |||
| 1.3.6.1.4.1.9.9.730.0.1 | NotificationctsSwKeystoreFileErrNotif | current | A ctsSwKeystoreFileErrNotif is generated when system encounters an error while performing operation on the software keystore file. | |
| 1.3.6.1.4.1.9.9.730.0.2 | NotificationctsSwKeystoreSyncFailNotif | current | A ctsSwKeystoreSyncFailNotifReason is generated when system fails to sync software keystore information from the active supervisor to the standby supervisor. | |
| 1.3.6.1.4.1.9.9.730.0.3 | NotificationctsAuthzCacheFileErrNotif | current | A ctsAuthzCacheFileErrNotif is generated when the system encounters error downloading TrustSec authorization related environment data to a cache file. | |
| 1.3.6.1.4.1.9.9.730.0.4 | NotificationctsCacheFileAccessErrNotif | current | A ctsCacheFileAccessErrNotif is generated when the system fails to perform open/read/write operation for a TrustSec cache file. | |
| 1.3.6.1.4.1.9.9.730.0.5 | NotificationctsSrcEntropyFailNotif | current | A ctsSrcEntropyFailNotif is generated when the periodic health tests for the CTR-DRBG (Counter- Deterministic Random Bit Generator) implementation fails due to… | |
| 1.3.6.1.4.1.9.9.730.0.6 | NotificationctsSapRandomNumberFailNotif | current | A ctsSapRandomNumberFailNotif is generated when the the system fails to obtain a random number from CTR-DRBG block for SAP (Security Association Protocol) key-… | |
| 1.3.6.1.4.1.9.9.730.1 | NodeciscoTrustSecMIBObjects | |||
| 1.3.6.1.4.1.9.9.730.1.1 | NodectsCacheObjects | |||
| 1.3.6.1.4.1.9.9.730.1.1.1 | ScalarctsCacheEnabled | read-write | current | This object specifies if the TrustSec cache is enabled in the system. |
| 1.3.6.1.4.1.9.9.730.1.1.2 | ScalarctsCacheNvStorage | read-write | current | The object specifies the location on the device where TrustSec cache files will be created. The location may be specified in <device>:[directory] format, where… |
| 1.3.6.1.4.1.9.9.730.1.1.3 | ScalarctsCacheClear | read-write | current | This object allows user to clear the cache files for Cisco Trusted Security feature on this device. When read, this object always returns the value 'none'. 'no… |
| 1.3.6.1.4.1.9.9.730.1.2 | NodectsSgtObjects | |||
| 1.3.6.1.4.1.9.9.730.1.2.1 | ScalarctsSecurityGroupTagId | read-write | current | This object allows user to specify the SGT for the packets originating from this device. A value of zero for this object indicates that no SGT has been configu… |
| 1.3.6.1.4.1.9.9.730.1.2.2 | ScalarctsSgtAssignmentMethod | read-write | current | This object specifies the method used for assignment of TrustSec SGT for the line cards without TrustSec tagging capability. 'none' - assignment of TrustSec SG… |
| 1.3.6.1.4.1.9.9.730.1.3 | NodectsCredentialObjects | |||
| 1.3.6.1.4.1.9.9.730.1.3.1 | ScalarctsDeviceId | read-write | current | This object allows user to specify the identifier for the device. This identifier and the device password (specified by ctsDevicePassword) are used together by… |
| 1.3.6.1.4.1.9.9.730.1.3.2 | ScalarctsDevicePasswordType | read-write | current | This object specifies the type of encryption employed to encrypt password in ctsDevicePassword object. Value for this object must be specified as 'clearText', … |
| 1.3.6.1.4.1.9.9.730.1.3.3 | ScalarctsDevicePassword | read-write | current | This object allows user to specify the password for the device. This password and the device identifier (specified by ctsDeviceId) are used together by the Cis… |
| 1.3.6.1.4.1.9.9.730.1.3.4 | ScalarctsKeystoreType | read-only | current | This object indicates the type of keystore employed by the device. 'hardwareKeystore' - Keystore functionality is implemented in hardware. 'softwareEmulation' … |
| 1.3.6.1.4.1.9.9.730.1.3.5 | ScalarctsKeystoreFwVersion | read-only | current | This object indicates the firmware version of the hardware keystore. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeystore'. |
| 1.3.6.1.4.1.9.9.730.1.3.6 | ScalarctsKeystoreFwAlerts | read-only | current | This object indicates the number of hardware keystore alerts that occurred. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeys… |
| 1.3.6.1.4.1.9.9.730.1.3.7 | ScalarctsKeystoreFwResets | read-only | current | This object indicates the number of times the keystore firmware was reset. This object is only instantiated when the value of ctsKeystoreType is 'hardwareKeyst… |
| 1.3.6.1.4.1.9.9.730.1.3.8 | ScalarctsKeystoreRxTimeouts | read-only | current | This object indicates the number of times the system timed out awaiting response from keystore firmware. This object is only instantiated when the value of cts… |
| 1.3.6.1.4.1.9.9.730.1.3.9 | ScalarctsKeystoreRxBadChecksums | read-only | current | This object indicates the number of message fragments the system received from keystore firmware that had bad checksum value. This object is only instantiated … |
| 1.3.6.1.4.1.9.9.730.1.3.10 | ScalarctsKeystoreRxBadFragmentLengths | read-only | current | This object indicates the number of message fragments the system received from keystore firmware that had illegal lengths. This object is only instantiated whe… |
| 1.3.6.1.4.1.9.9.730.1.3.11 | ScalarctsKeystoreCorruptions | read-only | current | This object indicates the number of times keystore firmware reported detection of one or more corrupted records in the hardware keystore. This object is only i… |
| 1.3.6.1.4.1.9.9.730.1.3.13 | TablectsKeystorePasswordRecordTable | not-accessible | current | A list of Cisco Trusted Security password records stored in the hardware or software keystore of this device. |
| 1.3.6.1.4.1.9.9.730.1.3.13.1 | RowctsKeystorePasswordRecordEntry | not-accessible | current | An entry describing individual password record in the keystore of this device. An entry will be created or deleted from this table when a password record is ad… |
| 1.3.6.1.4.1.9.9.730.1.3.13.1.1 | ColumnctsKeystorePasswordRecordName | not-accessible | current | This object identifies a password record. |
| 1.3.6.1.4.1.9.9.730.1.3.13.1.2 | ColumnctsKeystorePasswordRecordType | read-only | current | This object indicates the type of credential in this record. |
| 1.3.6.1.4.1.9.9.730.1.3.14 | TablectsKeystorePacRecordTable | not-accessible | current | A list of Cisco Trusted Security PAC records stored in the hardware or software keystore of this device. |
| 1.3.6.1.4.1.9.9.730.1.3.14.1 | RowctsKeystorePacRecordEntry | not-accessible | current | An entry describing individual PAC record in the keystore of this device. An entry will be created or deleted by the system when a PAC record is added or remov… |
| 1.3.6.1.4.1.9.9.730.1.3.14.1.1 | ColumnctsKeystorePacRecordName | not-accessible | current | The name of this PAC record. |
| 1.3.6.1.4.1.9.9.730.1.3.14.1.2 | ColumnctsKeystorePacRecordType | read-only | current | This object indicates the type of credential in this record. |
| 1.3.6.1.4.1.9.9.730.1.3.15 | TablectsPacInfoTable | not-accessible | current | A list of PACs on this device. |
| 1.3.6.1.4.1.9.9.730.1.3.15.1 | RowctsPacInfoEntry | not-accessible | current | An entry providing management information of a particular PAC record. An entry can only be created dynamically by the system when a new PAC is installed in the… |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.1 | ColumnctsPacAcsAuthId | not-accessible | current | This object indicates the unique authority identity of the ACS server from where the PAC was downloaded. |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.2 | ColumnctsPacAcsDescription | read-only | current | This object indicates the description of the ACS server from where the PAC was downloaded. |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.3 | ColumnctsPacType | read-only | current | This object indicates the type of PAC this entry represents. 'unknown' - Any other type of PAC that is not covered below 'tunnel' - Distributed shared secret b… |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.4 | ColumnctsPacExpirationTime | read-only | current | This object indicates the time when this PAC will be expired. |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.5 | ColumnctsPacTimeToRefresh | read-only | current | This object indicates the time left for this PAC to be refreshed from the ACS. |
| 1.3.6.1.4.1.9.9.730.1.3.15.1.6 | ColumnctsPacStatus | read-create | current | This object is used to manage the deletion of rows in this table. This object only supports the values 'active' and 'destroy'. Setting this object to 'destroy'… |
| 1.3.6.1.4.1.9.9.730.1.3.16 | ScalarctsCredentialsClearAll | read-write | current | This object allows user to clear all the PACs and Cisco Trusted Security credentials on the device. Setting the object to 'true' will clear all the PACs and cr… |
| 1.3.6.1.4.1.9.9.730.1.4 | NodectsEnvironmentDataObjects | |||
| 1.3.6.1.4.1.9.9.730.1.4.1 | ScalarctsEnvDataLastDownloadStatus | read-only | current | This object indicates the status of the last attempt to download the Environment Data. 'other' - Any other state not covered by below enumerations. 'succeeded'… |
| 1.3.6.1.4.1.9.9.730.1.4.2 | ScalarctsEnvSecurityGroupTagId | read-only | current | This object indicates the SGT for packets originating on this device downloaded from the ACS. A value of zero for this object indicates that no SGT has been do… |
| 1.3.6.1.4.1.9.9.730.1.4.3 | ScalarctsEnvSecurityGroupTagGenId | read-only | current | This object indicates the generation identifier associated with the downloaded SGT on this device. |
| 1.3.6.1.4.1.9.9.730.1.4.4 | ScalarctsEnvDataLastUpdate | read-only | current | This object indicates the last time Cisco Trusted Security Environment Data was successfully updated from ACS. This object will contain 0-1-1,00:00:00:0 if Env… |
| 1.3.6.1.4.1.9.9.730.1.4.5 | ScalarctsEnvDataRefreshInterval | read-only | current | This object indicates the time interval for which Trusted Security Environment Data is valid. The Trusted Security Environment Data will be refreshed i.e. down… |
| 1.3.6.1.4.1.9.9.730.1.4.6 | ScalarctsEnvDataTimeLeft | read-only | current | This object indicates the time left for the currently installed Trusted Security Environment Data to expire. |
| 1.3.6.1.4.1.9.9.730.1.4.7 | ScalarctsEnvDataTimeToRefresh | read-only | current | This object indicates the time interval after which Trusted Security Environment Data will be refreshed i.e. downloaded from the ACS due to Environment Data ex… |
| 1.3.6.1.4.1.9.9.730.1.4.8 | ScalarctsEnvDataSource | read-only | current | This object indicates the source of current Environment Data installed on the system. 'none' - No Environment Data is currently installed. 'cached' - Environme… |
| 1.3.6.1.4.1.9.9.730.1.4.9 | ScalarctsEnvDataAction | read-write | current | This object allows user to specify the action to be taken for all the Cisco Trusted Security Environment Data on this device. When read, this object always ret… |
| 1.3.6.1.4.1.9.9.730.1.4.16 | TablectsEnvSecurityGroupNameTable | not-accessible | current | A list of Security Group Names in Cisco Trusted Security environment. |
| 1.3.6.1.4.1.9.9.730.1.4.16.1 | RowctsEnvSecurityGroupNameEntry | not-accessible | current | An entry listing the name assigned to each SGT in Cisco Trusted Security environment. Entries will be populated in this table when system downloads Security Gr… |
| 1.3.6.1.4.1.9.9.730.1.4.16.1.1 | ColumnctsEnvSecurityGroupNameSgt | not-accessible | current | This object identifies a SGT in Trusted Security environment. |
| 1.3.6.1.4.1.9.9.730.1.4.16.1.2 | ColumnctsEnvSecurityGroupNameSgtGenId | read-only | current | This object indicates the Generation Identifier associated with this SGT. |
| 1.3.6.1.4.1.9.9.730.1.4.16.1.3 | ColumnctsEnvSecurityGroupNameSgtFlag | read-only | current | This object indicates the flag associated with this SGT. 'recognizedSgt' - indicates a recognized SGT when set to 1, else indicates a reserved SGT. 'unicastSgt… |
| 1.3.6.1.4.1.9.9.730.1.4.16.1.4 | ColumnctsEnvSecurityGroupName | read-only | current | This object indicates the Security Group Name assigned to this SGT. |
| 1.3.6.1.4.1.9.9.730.1.5 | NodectsNotifsControlObjects | |||
| 1.3.6.1.4.1.9.9.730.1.5.1 | ScalarctsSwKeystoreFileErrNotifEnable | read-write | current | This object specifies if the system generates ctsSwKeystoreFileErrNotif. A value of 'false' will prevent ctsSwKeystoreFileErrNotif notifications from being gen… |
| 1.3.6.1.4.1.9.9.730.1.5.2 | ScalarctsSwKeystoreSyncFailNotifEnable | read-write | current | This object specifies if the system generates ctsSwKeystoreSyncFailNotif. A value of 'false' will prevent ctsSwKeystoreSyncFailNotif notifications from being g… |
| 1.3.6.1.4.1.9.9.730.1.5.3 | ScalarctsAuthzCacheFileErrNotifEnable | read-write | current | This object specifies if the system generates ctsAuthzCacheFileErrNotif. A value of 'false' will prevent ctsAuthzCacheFileErrNotif notifications from being gen… |
| 1.3.6.1.4.1.9.9.730.1.5.4 | ScalarctsCacheFileAccessErrNotifEnable | read-write | current | This object specifies if the system generates ctsCacheFileAccessErrNotif. A value of 'false' will prevent ctsCacheFileAccessErrNotif notifications from being g… |
| 1.3.6.1.4.1.9.9.730.1.5.5 | ScalarctsSrcEntropyFailNotifEnable | read-write | current | This object specifies if the system generates ctsSrcEntropyFailNotif. A value of 'false' will prevent ctsSrcEntropyFailNotif notifications from being generated… |
| 1.3.6.1.4.1.9.9.730.1.5.6 | ScalarctsSapRandomNumberFailNotifEnable | read-write | current | This object specifies if the system generates ctsSapRandomNumberFailNotif. A value of 'false' will prevent ctsSapRandomNumberFailNotif notifications from being… |
| 1.3.6.1.4.1.9.9.730.1.6 | NodectsNotifsInfoObjects | |||
| 1.3.6.1.4.1.9.9.730.1.6.1 | ScalarctsFileErrNotifReason | accessible-for-notify | current | This object indicates the reason file error related notification was generated. 'openFailedForWrite' - System failed to open a file to write TrustSec informati… |
| 1.3.6.1.4.1.9.9.730.1.6.2 | ScalarctsSwKeystoreSyncFailNotifReason | accessible-for-notify | current | This object indicates the reason ctsSwKeystoreSyncFailNotif notification was generated. 'ipcPortCreationFailed' - Keystore information could not be synced beca… |
| 1.3.6.1.4.1.9.9.730.1.6.3 | ScalarctsNotifMessageString | accessible-for-notify | current | The object indicates additional information for a TrustSec notification. |
| 1.3.6.1.4.1.9.9.730.1.7 | NodectsCriticalAuthObjects | |||
| 1.3.6.1.4.1.9.9.730.1.7.1 | ScalarctsCriticalAuthEnabled | read-write | current | This object specifies if the Critical-Auth functionality is enabled in the system. Setting the object to 'true' will enable Critical-Auth functionality in the … |
| 1.3.6.1.4.1.9.9.730.1.7.2 | ScalarctsCriticalAuthFallback | read-write | current | This object specifies the CTS Critical-Auth fallback policy. default - Critical-Auth fallback policy is default. cache - Critical-Auth fallback policy is cache. |
| 1.3.6.1.4.1.9.9.730.1.7.3 | ScalarctsCriticalAuthPeerSgt | read-write | current | This object specifies the CTS Critical-Auth SGT tag of the remote peer. ctsCriticalAuthPeerSgt cannot be set to zero when ctsCriticalAuthEnable is enable. ctsC… |
| 1.3.6.1.4.1.9.9.730.1.7.4 | ScalarctsCriticalAuthPeerSgtTrust | read-write | current | This object specifies the CTS Critical-Auth peer's sgt trust state. This object can only be set when ctsCriticalAuthPeerSgt is non-zero. |
| 1.3.6.1.4.1.9.9.730.1.7.5 | ScalarctsCriticalAuthDefaultPmk | read-write | current | This object specifies the CTS Critical-Auth default PMK used by SAP. The purpose of this object is to only allow configuration of Critical-Auth PMK. The ctsCri… |
| 1.3.6.1.4.1.9.9.730.1.7.6 | ScalarctsCriticalAuthViewDefaultPmk | read-only | current | This object indicates the CTS Critical-Auth default PMK. The purpose of this object is to only display the configured Critical-Auth PMK. A zero length string f… |
| 1.3.6.1.4.1.9.9.730.2 | NodeciscoTrustSecMIBConform | |||
| 1.3.6.1.4.1.9.9.730.2.1 | NodeciscoTrustSecMIBCompliances | |||
| 1.3.6.1.4.1.9.9.730.2.1.1 | ComplianceciscoTrustSecMIBCompliance | read-only | deprecated | The compliance statement for the CISCO-TRUSTSEC-MIB. |
| 1.3.6.1.4.1.9.9.730.2.1.2 | ComplianceciscoTrustSecMIBCompliance2 | read-only | deprecated | The compliance statement for the CISCO-TRUSTSEC-MIB. |
| 1.3.6.1.4.1.9.9.730.2.1.3 | ComplianceciscoTrustSecMIBCompliance3 | read-only | deprecated | The compliance statement for the CISCO-TRUSTSEC-MIB. |
| 1.3.6.1.4.1.9.9.730.2.1.4 | ComplianceciscoTrustSecMIBCompliance4 | read-only | current | The compliance statement for the CISCO-TRUSTSEC-MIB. |
| 1.3.6.1.4.1.9.9.730.2.2 | NodeciscoTrustSecMIBGroups | |||
| 1.3.6.1.4.1.9.9.730.2.2.1 | GroupciscoTrustSecCacheGroup | current | A collection of objects that provides the cache configuration for TrustSec in the system. | |
| 1.3.6.1.4.1.9.9.730.2.2.2 | GroupciscoTrustSecSgtGroup | current | A collection of objects to manage SGT for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.3 | GroupciscoTrustSecCredentialsGroup | current | A collection of objects to manage credentials parameters for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.4 | GroupciscoTrustSecHwKeystoreInfoGroup | current | A collection of objects to manage hardware keystore for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.5 | GroupciscoTrustSecEnvDataGroup | current | A collection of objects to manage Environment Data for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.6 | GroupciscoTrustSecSgtAssignmentGroup | current | A collection of objects to manage assignment of TrustSec SGT. | |
| 1.3.6.1.4.1.9.9.730.2.2.7 | GroupciscoTrustSecEnvSecGroupNameGroup | current | A collection of object(s) to manage Security Group Name information for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.8 | GroupciscoTrustSecSwKeystoreNotifsInfoGroup | current | A collection of object(s) to provide information regarding software keystore notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.9 | GroupciscoTrustSecSwKeystoreNotifsControlGroup | current | A collection of object(s) to control software keystore notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.10 | GroupciscoTrustSecSwKeystoreNotifsGroup | current | A collection of software keystore related notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.11 | GroupciscoTrustSecFileErrNotifsInfoGroup | current | A collection of object(s) to provide information regarding file error related notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.12 | GroupciscoTrustSecNotifsMessageStringInfoGroup | current | A collection of object(s) to provide information regarding TrustSec notification. | |
| 1.3.6.1.4.1.9.9.730.2.2.13 | GroupciscoTrustSecCacheFileNotifsControlGroup | current | A collection of object(s) to control cache file related notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.14 | GroupciscoTrustSecCacheFileNotifsGroup | current | A collection of TrustSec cache file related notifications. | |
| 1.3.6.1.4.1.9.9.730.2.2.15 | GroupciscoTrustSecCtrDrbgNotifsControlGroup | current | A collection of object(s) to control CTR-DRBG related notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.16 | GroupciscoTrustSecCtrDrbgNotifsGroup | current | A collection of CTR-DRBG related notifications for TrustSec. | |
| 1.3.6.1.4.1.9.9.730.2.2.17 | GroupciscoTrustSecCrtclAuthGroup | current | A collection of CTS Critical Auth Config objects |