MIB Viewer

CISCO-TRUSTSEC-POLICY-MIB

198 objects
This MIB module defines managed objects that facilitate the management of various policies within the Cisco Trusted Security (TrustSec) infrastructure. The information available through this MIB includes: o Device and interface level configuration for enabling SGACL (Security Group Access Control List) enforcement on Layer2/3 traffic. o Administrative and operational SGACL mapping to Security Group Tag (SGT). o Various statistics counters for traffic subject to SGACL enforcement. o TrustSec policies with respect to peer device. o Interface level configuration for enabling the propagation of SGT along with the Layer 3 traffic in portions of network which does not have the capability to support TrustSec feature. o TrustSec policies with respect to SGT propagation with Layer 3 traffic. The following terms are used throughout this MIB: VRF: Virtual Routing and Forwarding. SGACL: Security Group Access Control List. ACE: Access Control Entries. SXP: SGT Propagation Protocol. SVI: Switch Virtual Interface. IPM: Identity Port Mapping. SGT (Security Group Tag) is a unique 16 bits value assigned to every security group and used by network devices to enforce SGACL. Peer is another device connected to the local device on the other side of a TrustSec link. Default Policy: Policy applied to traffic when there is no explicit policy between the SGT associated with the originator of the traffic and the SGT associated with the destination of the traffic.
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.713IdentityciscoTrustSecPolicyMIBThis MIB module defines managed objects that facilitate the management of various policies within the Cisco Trusted Security (TrustSec) infrastructure. The inf…
1.3.6.1.4.1.9.9.713.0NodeciscoTrustSecPolicyMIBNotifs
1.3.6.1.4.1.9.9.713.0.1NotificationctspPeerPolicyUpdatedNotifcurrentA ctspPeerPolicyUpdatedNotif is generated when the SGT value of a peer device has been updated.
1.3.6.1.4.1.9.9.713.0.2NotificationctspAuthorizationSgaclFailNotifcurrentA ctspAuthorizationSgaclFailNotif is generated when the authorization of SGACL fails.
1.3.6.1.4.1.9.9.713.1NodeciscoTrustSecPolicyMIBObjects
1.3.6.1.4.1.9.9.713.1.1NodectspSgacl
1.3.6.1.4.1.9.9.713.1.1.1NodectspSgaclGlobals
1.3.6.1.4.1.9.9.713.1.1.1.1ScalarctspSgaclEnforcementEnableread-writecurrentThis object specifies whether SGACL enforcement for all Layer 3 interfaces (excluding SVIs) is enabled at the managed system. 'none' indicates that SGACL enfor…
1.3.6.1.4.1.9.9.713.1.1.1.2ScalarctspSgaclIpv4DropNetflowMonitorread-writecurrentThis object specifies an existing flexible netflow monitor name used to collect and export the IPv4 traffic dropped packets statistics due to SGACL enforcement…
1.3.6.1.4.1.9.9.713.1.1.1.3ScalarctspSgaclIpv6DropNetflowMonitorread-writecurrentThis object specifies an existing flexible netflow monitor name used to collect and export the IPv6 traffic dropped packets statistics due to SGACL enforcement…
1.3.6.1.4.1.9.9.713.1.1.1.4TablectspVlanConfigTablenot-accessiblecurrentThis table lists the SGACL enforcement for Layer 2 and Layer 3 switched packet in a VLAN as well as VRF information for VLANs in the device.
1.3.6.1.4.1.9.9.713.1.1.1.4.1RowctspVlanConfigEntrynot-accessiblecurrentEach row contains the SGACL enforcement information for Layer 2 and Layer 3 switched packets in a VLAN identified by its VlanIndex value. Entry in this table i…
1.3.6.1.4.1.9.9.713.1.1.1.4.1.1ColumnctspVlanConfigIndexnot-accessiblecurrentThis object indicates the VLAN-ID of this VLAN.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.2ColumnctspVlanConfigSgaclEnforcementread-createcurrentThis object specifies the configured SGACL enforcement status for this VLAN i.e., 'true' = enabled and 'false' = disabled.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.3ColumnctspVlanSviActiveread-onlycurrentThis object indicates if there is an active SVI associated with this VLAN. 'true' indicates that there is an active SVI associated with this VLAN. and SGACL is…
1.3.6.1.4.1.9.9.713.1.1.1.4.1.4ColumnctspVlanConfigVrfNameread-createcurrentThis object specifies an existing VRF where this VLAN belongs to. The zero length value indicates this VLAN belongs to the default VRF.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.5ColumnctspVlanConfigStorageTyperead-createcurrentThe objects specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.6ColumnctspVlanConfigRowStatusread-createcurrentThe status of this conceptual row entry. This object is used to manage creation and deletion of rows in this table. When this object value is 'active', other w…
1.3.6.1.4.1.9.9.713.1.1.2NodectspSgaclMappings
1.3.6.1.4.1.9.9.713.1.1.2.1TablectspConfigSgaclMappingTablenot-accessiblecurrentThis table contains the SGACLs information which is applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.1.1RowctspConfigSgaclMappingEntrynot-accessiblecurrentEach row contains the SGACL mapping to source and destination SGT for a certain traffic type as well as status of this instance. A row instance can be created …
1.3.6.1.4.1.9.9.713.1.1.2.1.1.1ColumnctspConfigSgaclMappingIpTrafficTypenot-accessiblecurrentThis object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.2ColumnctspConfigSgaclMappingDestSgtnot-accessiblecurrentThis object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.3ColumnctspConfigSgaclMappingSourceSgtnot-accessiblecurrentThis object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.4ColumnctspConfigSgaclMappingSgaclNameread-createcurrentThis object specifies the list of existing SGACLs which is administratively configured to apply to unicast IP traffic carrying the source SGT to the destinatio…
1.3.6.1.4.1.9.9.713.1.1.2.1.1.5ColumnctspConfigSgaclMappingStorageTyperead-createcurrentThe storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.6ColumnctspConfigSgaclMappingRowStatusread-createcurrentThis object is used to manage the creation and deletion of rows in this table. ctspConfigSgaclName may be modified at any time.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.7ColumnctspConfigSgaclMonitorread-createcurrentThis object specifies whether SGACL monitor mode is turned on for the configured SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.2ScalarctspDefConfigIpv4Sgaclsread-writecurrentThis object specifies the SGACLs of the unicast default policy for IPv4 traffic. If there is no SGACL configured for unicast default policy for IPv4 traffic, t…
1.3.6.1.4.1.9.9.713.1.1.2.3ScalarctspDefConfigIpv6Sgaclsread-writecurrentThis object specifies the SGACLs of the unicast default policy for IPv6 traffic. If there is no SGACL configured for unicast default policy for IPv6 traffic, t…
1.3.6.1.4.1.9.9.713.1.1.2.4TablectspDownloadedSgaclMappingTablenot-accessiblecurrentThis table contains the downloaded SGACLs information applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1RowctspDownloadedSgaclMappingEntrynot-accessiblecurrentEach row contains the downloaded SGACLs mapping. A row instance is added for each pair of <source SGT, destination SGT> which contains SGACL that is dynamicall…
1.3.6.1.4.1.9.9.713.1.1.2.4.1.1ColumnctspDownloadedSgaclDestSgtnot-accessiblecurrentThis object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.2ColumnctspDownloadedSgaclSourceSgtnot-accessiblecurrentThis object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.3ColumnctspDownloadedSgaclIndexnot-accessiblecurrentThis object identifies the downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.4ColumnctspDownloadedSgaclNameread-onlycurrentThis object indicates the name of downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.5ColumnctspDownloadedSgaclGenIdread-onlycurrentThis object indicates the generation identification of downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.6ColumnctspDownloadedIpTrafficTyperead-onlycurrentThis object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement by this d…
1.3.6.1.4.1.9.9.713.1.1.2.4.1.7ColumnctspDownloadedSgaclMonitorread-onlycurrentThis object indicates whether SGACL monitor mode is turned on for the downloaded SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5TablectspDefDownloadedSgaclMappingTablenot-accessiblecurrentThis table contains the downloaded SGACLs information of the default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1RowctspDefDownloadedSgaclMappingEntrynot-accessiblecurrentEach row contains the downloaded SGACLs mapping. A row instance contains the SGACL information of the default policy dynamically downloaded from ACS server for…
1.3.6.1.4.1.9.9.713.1.1.2.5.1.1ColumnctspDefDownloadedSgaclIndexnot-accessiblecurrentThis object identifies the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.2ColumnctspDefDownloadedSgaclNameread-onlycurrentThis object indicates the name of the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.3ColumnctspDefDownloadedSgaclGenIdread-onlycurrentThis object indicates the generation identification of the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.4ColumnctspDefDownloadedIpTrafficTyperead-onlycurrentThis object indicates the type of the IP traffic subjected to SGACL enforcement by this downloaded default policy.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.5ColumnctspDefDownloadedSgaclMonitorread-onlycurrentThis object indicates whether SGACL monitor mode is turned on for the default downloaded SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.6TablectspOperSgaclMappingTablenot-accessiblecurrentThis table contains the operational SGACLs information applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1RowctspOperSgaclMappingEntrynot-accessiblecurrentEach row contains the operational SGACLs mapping. A row instance is added for each pair of <source SGT, destination SGT> which contains the SGACL that either s…
1.3.6.1.4.1.9.9.713.1.1.2.6.1.1ColumnctspOperIpTrafficTypenot-accessiblecurrentThis object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.2ColumnctspOperSgaclDestSgtnot-accessiblecurrentThis object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.3ColumnctspOperSgaclSourceSgtnot-accessiblecurrentThis object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.4ColumnctspOperSgaclIndexnot-accessiblecurrentThis object identifies the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.5ColumnctspOperationalSgaclNameread-onlycurrentThis object indicates the name of the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.6ColumnctspOperationalSgaclGenIdread-onlycurrentThis object indicates the generation identification of the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.7ColumnctspOperSgaclMappingSourceread-onlycurrentThis object indicates the source of SGACL mapping for the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT. 'do…
1.3.6.1.4.1.9.9.713.1.1.2.6.1.8ColumnctspOperSgaclConfigSourceread-onlycurrentThis object indicates the source of SGACL creation for this SGACL. 'configured' indicates that the SGACL is locally configured in the local device. 'downloaded…
1.3.6.1.4.1.9.9.713.1.1.2.6.1.9ColumnctspOperSgaclMonitorread-onlycurrentThis object indicates whether SGACL monitor mode is turned on for the SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7TablectspDefOperSgaclMappingTablenot-accessiblecurrentThis table contains the operational SGACLs information of the default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1RowctspDefOperSgaclMappingEntrynot-accessiblecurrentA row instance contains the SGACL information of the default policy which is either statically configured at the device or dynamically downloaded from ACS serv…
1.3.6.1.4.1.9.9.713.1.1.2.7.1.1ColumnctspDefOperIpTrafficTypenot-accessiblecurrentThis object indicates the type of the unicast IP traffic subjected to default policy enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.2ColumnctspDefOperSgaclIndexnot-accessiblecurrentThis object identifies the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.3ColumnctspDefOperationalSgaclNameread-onlycurrentThis object indicates the name of the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.4ColumnctspDefOperationalSgaclGenIdread-onlycurrentThis object indicates the generation identification of the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.5ColumnctspDefOperSgaclMappingSourceread-onlycurrentThis object indicates the source of SGACL mapping for the SGACL of default policy operationally applied to unicast IP traffic. 'downloaded' indicates that the …
1.3.6.1.4.1.9.9.713.1.1.2.7.1.6ColumnctspDefOperSgaclConfigSourceread-onlycurrentThis object indicates the source of SGACL creation for the SGACL of default policy operationally applied to unicast IP traffic. 'downloaded' indicates that the…
1.3.6.1.4.1.9.9.713.1.1.2.7.1.7ColumnctspDefOperSgaclMonitorread-onlycurrentThis object indicates whether SGACL monitor mode is turned on for the SGACL of default policy enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.8ScalarctspDefConfigIpv4SgaclsMonitorread-writecurrentThis object specifies whether SGACL monitor mode is turned on for the default configured SGACL enforced Ipv4 traffic.
1.3.6.1.4.1.9.9.713.1.1.2.9ScalarctspDefConfigIpv6SgaclsMonitorread-writecurrentThis object specifies whether SGACL monitor mode is turned on for the default configured SGACL enforced Ipv6 traffic.
1.3.6.1.4.1.9.9.713.1.1.2.10ScalarctspSgaclMonitorEnableread-writecurrentThis object specifies whether SGACL monitor mode is turned on for the entire system. It has precedence than the per SGACL ctspConfigSgaclMonitor control. It co…
1.3.6.1.4.1.9.9.713.1.1.3NodectspSgaclStatistics
1.3.6.1.4.1.9.9.713.1.1.3.1TablectspSgtStatsTablenot-accessiblecurrentThis table describes SGACL statistics counters per a pair of <source SGT, destination SGT> that is capable of providing this information.
1.3.6.1.4.1.9.9.713.1.1.3.1.1RowctspSgtStatsEntrynot-accessiblecurrentEach row contains the SGACL statistics related to IPv4 or IPv6 packets carrying the source SGT travelling to the destination SGT and subjected to SGACL enforce…
1.3.6.1.4.1.9.9.713.1.1.3.1.1.1ColumnctspStatsIpTrafficTypenot-accessiblecurrentThis object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.2ColumnctspStatsDestSgtnot-accessiblecurrentThis object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.3ColumnctspStatsSourceSgtnot-accessiblecurrentThis object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.4ColumnctspStatsIpSwDropPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are dropped by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.5ColumnctspStatsIpHwDropPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are dropped by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.6ColumnctspStatsIpSwPermitPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are permitted by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.7ColumnctspStatsIpHwPermitPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are permitted by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.8ColumnctspStatsIpSwMonitorPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are SGACL enforced & monitored.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.9ColumnctspStatsIpHwMonitorPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are SGACL enforced & monitored.
1.3.6.1.4.1.9.9.713.1.1.3.2TablectspDefStatsTablenot-accessiblecurrentThis table describes statistics counters for unicast IP traffic subjected to default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1RowctspDefStatsEntrynot-accessiblecurrentEach row contains the statistics counter for each IP traffic type.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.1ColumnctspDefIpTrafficTypenot-accessiblecurrentThis object indicates the type of the IP traffic subjected to default unicast policy enforcement.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.2ColumnctspDefIpSwDropPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are dropped by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.3ColumnctspDefIpHwDropPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are dropped by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.4ColumnctspDefIpSwPermitPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are permitted by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.5ColumnctspDefIpHwPermitPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are permitted by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.6ColumnctspDefIpSwMonitorPktsread-onlycurrentThis object indicates the number of software-forwarded IP packets which are monitored by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.7ColumnctspDefIpHwMonitorPktsread-onlycurrentThis object indicates the number of hardware-forwarded IP packets which are monitored by default unicast policy.
1.3.6.1.4.1.9.9.713.1.2NodectspPeerPolicy
1.3.6.1.4.1.9.9.713.1.2.1ScalarctspAllPeerPolicyActionread-writecurrentThis object allows user to specify the action to be taken with respect to all peer policies in the device. When read, this object always returns the value 'non…
1.3.6.1.4.1.9.9.713.1.2.2TablectspPeerPolicyTablenot-accessiblecurrentThis table lists the peer policy information for each peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1RowctspPeerPolicyEntrynot-accessiblecurrentEach row contains the managed objects for peer policies for each peer device based on its name.
1.3.6.1.4.1.9.9.713.1.2.2.1.1ColumnctspPeerNamenot-accessiblecurrentThis object uniquely identifies a peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.2ColumnctspPeerSgtread-onlycurrentThis object indicates the SGT value of this peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.3ColumnctspPeerSgtGenIdread-onlycurrentThis object indicates the generation identification of the SGT value assigned to this peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.4ColumnctspPeerTrustStateread-onlycurrentThis object indicates the TrustSec trust state of this peer device. 'trusted' indicates that this is a trusted peer device. 'noTrust' indicates that this peer …
1.3.6.1.4.1.9.9.713.1.2.2.1.5ColumnctspPeerPolicyLifeTimeread-onlycurrentThis object indicates the policy life time which provides the time interval during which the peer policy is valid.
1.3.6.1.4.1.9.9.713.1.2.2.1.6ColumnctspPeerPolicyLastUpdateread-onlycurrentThis object indicates the time when this peer policy is last updated.
1.3.6.1.4.1.9.9.713.1.2.2.1.7ColumnctspPeerPolicyActionread-writecurrentThis object allows user to specify the action to be taken with this peer policy. When read, this object always returns the value 'none'. 'none' - No operation.…
1.3.6.1.4.1.9.9.713.1.3NodectspLayer3Transport
1.3.6.1.4.1.9.9.713.1.3.1TablectspLayer3PolicyTablenot-accessiblecurrentThis table describes Layer 3 transport policy for IP traffic regarding SGT propagation.
1.3.6.1.4.1.9.9.713.1.3.1.1RowctspLayer3PolicyEntrynot-accessiblecurrentEach row contains the Layer 3 transport policies per IP traffic type per policy type.
1.3.6.1.4.1.9.9.713.1.3.1.1.1ColumnctspLayer3PolicyIpTrafficTypenot-accessiblecurrentThis object indicates the type of the IP traffic affected by Layer-3 transport policy. 'ipv4' indicates that the affected traffic is IPv4 traffic. 'ipv6' indic…
1.3.6.1.4.1.9.9.713.1.3.1.1.2ColumnctspLayer3PolicyTypenot-accessiblecurrentThis object indicates the type of the Layer-3 transport policy affecting IP traffic regarding SGT propagation. 'permit' indicates that the transport policy is …
1.3.6.1.4.1.9.9.713.1.3.1.1.3ColumnctspLayer3PolicyLocalConfigread-writecurrentThis object specifies the name of an ACL that is administratively configured to classify Layer3 traffic. Zero-length string indicates there is no such configur…
1.3.6.1.4.1.9.9.713.1.3.1.1.4ColumnctspLayer3PolicyDownloadedread-onlycurrentThis object specifies the name of an ACL that is downloaded from policy server to classify Layer3 traffic. Zero-length string indicates there is no such downlo…
1.3.6.1.4.1.9.9.713.1.3.1.1.5ColumnctspLayer3PolicyOperationalread-onlycurrentThis object specifies the name of an operational ACL currently used to classify Layer3 traffic. Zero-length string indicates there is no such policy in effect.
1.3.6.1.4.1.9.9.713.1.3.2TablectspIfL3PolicyConfigTablenot-accessiblecurrentThis table lists the interfaces which support Layer3 Transport policy.
1.3.6.1.4.1.9.9.713.1.3.2.1RowctspIfL3PolicyConfigEntrynot-accessiblecurrentEach row contains managed objects for Layer3 Transport on interface capable of providing this information.
1.3.6.1.4.1.9.9.713.1.3.2.1.1ColumnctspIfL3Ipv4PolicyEnabledread-writecurrentThis object specifies whether the Layer3 Transport policies will be applied on this interface for egress IPv4 traffic. 'true' indicates that Layer3 permit and …
1.3.6.1.4.1.9.9.713.1.3.2.1.2ColumnctspIfL3Ipv6PolicyEnabledread-writecurrentThis object specifies whether the Layer3 Transport policies will be applied on this interface for egress IPv6 traffic. 'true' indicates that Layer3 permit and …
1.3.6.1.4.1.9.9.713.1.4NodectspIpSgtMappings
1.3.6.1.4.1.9.9.713.1.4.1TablectspIpSgtMappingTablenot-accessiblecurrentThis table contains the IP-to-SGT mapping information in the device.
1.3.6.1.4.1.9.9.713.1.4.1.1RowctspIpSgtMappingEntrynot-accessiblecurrentEach row contains the IP-to-SGT mapping and status of this instance. Entry in this table is either populated automatically by the device or manually configured…
1.3.6.1.4.1.9.9.713.1.4.1.1.1ColumnctspIpSgtVrfNamenot-accessiblecurrentThis object indicates the VRF where IP-SGT mapping belongs to. The zero length value indicates the default VRF.
1.3.6.1.4.1.9.9.713.1.4.1.1.2ColumnctspIpSgtAddressTypenot-accessiblecurrentThis object indicates the type of Internet address.
1.3.6.1.4.1.9.9.713.1.4.1.1.3ColumnctspIpSgtIpAddressnot-accessiblecurrentThis object indicates an Internet address. The type of this address is determined by the value of ctspIpSgtAddressType object.
1.3.6.1.4.1.9.9.713.1.4.1.1.4ColumnctspIpSgtAddressLengthnot-accessiblecurrentThis object indicates the length of an Internet address prefix.
1.3.6.1.4.1.9.9.713.1.4.1.1.5ColumnctspIpSgtValueread-createcurrentThis object specifies the SGT value assigned to an Internet address.
1.3.6.1.4.1.9.9.713.1.4.1.1.6ColumnctspIpSgtSourceread-createcurrentThis object indicates the source of the mapping. 'configured' indicates that the mapping is manually configured by user. 'arp' indicates that the mapping is dy…
1.3.6.1.4.1.9.9.713.1.4.1.1.7ColumnctspIpSgtStorageTyperead-createcurrentThe storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.4.1.1.8ColumnctspIpSgtRowStatusread-createcurrentThis object is used to manage the creation and deletion of rows in this table. If this object value is 'active', user cannot modify any writable object in this…
1.3.6.1.4.1.9.9.713.1.5NodectspSgtPolicy
1.3.6.1.4.1.9.9.713.1.5.1ScalarctspAllSgtPolicyActionread-writecurrentThis object allows user to specify the action to be taken with respect to all SGT policies in the device. When read, this object always returns the value 'none…
1.3.6.1.4.1.9.9.713.1.5.2TablectspDownloadedSgtPolicyTablenot-accessiblecurrentThis table lists the SGT policy information downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.2.1RowctspDownloadedSgtPolicyEntrynot-accessiblecurrentEach row contains the managed objects for SGT policies downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.2.1.1ColumnctspDownloadedSgtPolicySgtnot-accessiblecurrentThis object indicates the SGT value for which the downloaded policy is applied to. Value of zero indicates that the SGT is unknown.
1.3.6.1.4.1.9.9.713.1.5.2.1.2ColumnctspDownloadedSgtPolicySgtGenIdread-onlycurrentThis object indicates the generation identification of the SGT value denoted by ctspDownloadedSgtPolicySgt object.
1.3.6.1.4.1.9.9.713.1.5.2.1.3ColumnctspDownloadedSgtPolicyLifeTimeread-onlycurrentThis object indicates the policy life time which provides the time interval during which this downloaded policy is valid.
1.3.6.1.4.1.9.9.713.1.5.2.1.4ColumnctspDownloadedSgtPolicyLastUpdateread-onlycurrentThis object indicates the time when this downloaded SGT policy is last updated.
1.3.6.1.4.1.9.9.713.1.5.2.1.5ColumnctspDownloadedSgtPolicyActionread-writecurrentThis object allows user to specify the action to be taken with this downloaded SGT policy. When read, this object always returns the value 'none'. 'none' - No …
1.3.6.1.4.1.9.9.713.1.5.3TablectspDownloadedDefSgtPolicyTablenot-accessiblecurrentThis table lists the default SGT policy information downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.3.1RowctspDownloadedDefSgtPolicyEntrynot-accessiblecurrentEach row contains the managed objects for default SGT policies downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.3.1.1ColumnctspDownloadedDefSgtPolicyTypenot-accessiblecurrentThis object indicates the downloaded default SGT policy type. 'unicastDefault' indicates the SGT policy applied to traffic which carries the default unicast SG…
1.3.6.1.4.1.9.9.713.1.5.3.1.2ColumnctspDownloadedDefSgtPolicySgtGenIdread-onlycurrentThis object indicates the generation identification of the downloaded default SGT policy.
1.3.6.1.4.1.9.9.713.1.5.3.1.3ColumnctspDownloadedDefSgtPolicyLifeTimeread-onlycurrentThis object indicates the policy life time which provides the time interval during which this download default policy is valid.
1.3.6.1.4.1.9.9.713.1.5.3.1.4ColumnctspDownloadedDefSgtPolicyLastUpdateread-onlycurrentThis object indicates the time when this downloaded SGT policy is last updated.
1.3.6.1.4.1.9.9.713.1.5.3.1.5ColumnctspDownloadedDefSgtPolicyActionread-writecurrentThis object allows user to specify the action to be taken with this default downloaded SGT policy. When read, this object always returns the value 'none'. 'non…
1.3.6.1.4.1.9.9.713.1.6NodectspIfSgtMappings
1.3.6.1.4.1.9.9.713.1.6.1TablectspIfSgtMappingTablenot-accessiblecurrentThis table contains the Interface-to-SGT mapping configuration information in the device.
1.3.6.1.4.1.9.9.713.1.6.1.1RowctspIfSgtMappingEntrynot-accessiblecurrentEach row contains the SGT mapping configuration of a particular interface. A row instance can be created or removed by setting ctspIfSgtRowStatus.
1.3.6.1.4.1.9.9.713.1.6.1.1.1ColumnctspIfSgtValueread-createcurrentThis object specifies the SGT value assigned to the interface.
1.3.6.1.4.1.9.9.713.1.6.1.1.2ColumnctspIfSgNameread-createcurrentThis object specifies the Security Group Name assigned to the interface.
1.3.6.1.4.1.9.9.713.1.6.1.1.3ColumnctspIfSgtStorageTyperead-createcurrentThe storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.6.1.1.4ColumnctspIfSgtRowStatusread-createcurrentThis object is used to manage the creation and deletion of rows in this table.
1.3.6.1.4.1.9.9.713.1.6.2TablectspIfSgtMappingInfoTablenot-accessiblecurrentThis table contains the Interface-to-SGT mapping status information in the device.
1.3.6.1.4.1.9.9.713.1.6.2.1RowctspIfSgtMappingInfoEntrynot-accessiblecurrentContaining the Interface-to-SGT mapping status of the specified interface.
1.3.6.1.4.1.9.9.713.1.6.2.1.1ColumnctspL3IPMStatusread-onlycurrentThis object indicates the Layer 3 Identity Port Mapping(IPM) operational mode. disabled - The L3 IPM is not configured. active - The L3 IPM is configured for t…
1.3.6.1.4.1.9.9.713.1.7NodectspVlanSgtMappings
1.3.6.1.4.1.9.9.713.1.7.1TablectspVlanSgtMappingTablenot-accessiblecurrentThis table contains the Vlan-SGT mapping information in the device.
1.3.6.1.4.1.9.9.713.1.7.1.1RowctspVlanSgtMappingEntrynot-accessiblecurrentEach row contains the SGT mapping configuration of a particular VLAN. A row instance can be created or removed by setting ctspVlanSgtRowStatus.
1.3.6.1.4.1.9.9.713.1.7.1.1.1ColumnctspVlanSgtMappingIndexnot-accessiblecurrentThis object specifies the VLAN-ID which is used as index.
1.3.6.1.4.1.9.9.713.1.7.1.1.2ColumnctspVlanSgtMapValueread-createcurrentThis object specifies the SGT value assigned to the vlan.
1.3.6.1.4.1.9.9.713.1.7.1.1.3ColumnctspVlanSgtStorageTyperead-createcurrentThe storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.7.1.1.4ColumnctspVlanSgtRowStatusread-createcurrentThis object is used to manage the creation and deletion of rows in this table.
1.3.6.1.4.1.9.9.713.1.8NodectspSgtCaching
1.3.6.1.4.1.9.9.713.1.8.1ScalarctspSgtCachingModeread-writecurrentThis object specifies which SGT-caching mode is configured for SGT caching capable interfaces at the managed system. 'none' indicates that sgt-caching for all …
1.3.6.1.4.1.9.9.713.1.8.2ScalarctspSgtCachingVlansFirst2Kread-writecurrentA string of octets containing one bit per VLAN for VLANs 0 to 2047. If the bit corresponding to a VLAN is set to 1, it indicates SGT-caching is enabled on the …
1.3.6.1.4.1.9.9.713.1.8.3ScalarctspSgtCachingVlansSecond2Kread-writecurrentA string of octets containing one bit per VLAN for VLANs 2048 to 4095. If the bit corresponding to a VLAN is set to 1, it indicates SGT-caching is enabled on t…
1.3.6.1.4.1.9.9.713.1.9NodectspNotifsControl
1.3.6.1.4.1.9.9.713.1.9.1ScalarctspPeerPolicyUpdatedNotifEnableread-writecurrentThis object specifies whether the system generates ctspPeerPolicyUpdatedNotif. A value of 'false' will prevent ctspPeerPolicyUpdatedNotif notifications from be…
1.3.6.1.4.1.9.9.713.1.9.2ScalarctspAuthorizationSgaclFailNotifEnableread-writecurrentThis object specifies whether this system generates the ctspAuthorizationSgaclFailNotif. A value of 'false' will prevent ctspAuthorizationSgaclFailNotif notifi…
1.3.6.1.4.1.9.9.713.1.10NodectspNotifsOnlyInfo
1.3.6.1.4.1.9.9.713.1.10.1ScalarctspOldPeerSgtaccessible-for-notifycurrentThis object provides the old sgt value for ctspPeerPolicyUpdatedNotif, i.e., the sgt value before the policy is updated.
1.3.6.1.4.1.9.9.713.1.10.2ScalarctspAuthorizationSgaclFailReasonaccessible-for-notifycurrentThis object indicates the reason of failure during SGACL acquisitions, installations and uninstallations, which is associated with ctspAuthorizationSgaclFailNo…
1.3.6.1.4.1.9.9.713.1.10.3ScalarctspAuthorizationSgaclFailInfoaccessible-for-notifycurrentThis object provides additional information about authorization SGACL failure, which is associated with ctspAuthorizationSgaclFailNotif.
1.3.6.1.4.1.9.9.713.2NodeciscoTrustSecPolicyMIBConformance
1.3.6.1.4.1.9.9.713.2.1NodeciscoTrustSecPolicyMIBCompliances
1.3.6.1.4.1.9.9.713.2.1.1ComplianceciscoTrustSecPolicyMIBComplianceread-onlydeprecatedThe compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
1.3.6.1.4.1.9.9.713.2.1.2ComplianceciscoTrustSecPolicyMIBComplianceRev2read-onlycurrentThe compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
1.3.6.1.4.1.9.9.713.2.2NodeciscoTrustSecPolicyMIBGroups
1.3.6.1.4.1.9.9.713.2.2.1GroupctspGlobalSgaclEnforcementGroupcurrentA collection of object which provides the SGACL enforcement information for all TrustSec capable Layer 3 interfaces (excluding SVIs) at the device level.
1.3.6.1.4.1.9.9.713.2.2.2GroupctspSgaclIpv4DropNetflowMonitorGroupcurrentA collection of object which provides netflow monitor information for IPv4 traffic drop packet due to SGACL enforcement in the device.
1.3.6.1.4.1.9.9.713.2.2.3GroupctspSgaclIpv6DropNetflowMonitorGroupcurrentA collection of object which provides netflow monitor information for IPv6 traffic drop packet due to SGACL enforcement in the device.
1.3.6.1.4.1.9.9.713.2.2.4GroupctspVlanConfigGroupcurrentA collection of object which provides the SGACL enforcement and VRF information for each VLAN.
1.3.6.1.4.1.9.9.713.2.2.5GroupctspConfigSgaclMappingGroupcurrentA collection of objects which provides the administratively configured SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.6GroupctspDownloadedSgaclMappingGroupcurrentA collection of objects which provides the downloaded SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.7GroupctspOperSgaclMappingGroupcurrentA collection of objects which provides the operational SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.8GroupctspIpSwStatisticsGroupcurrentA collection of objects which provides software statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.9GroupctspIpHwStatisticsGroupcurrentA collection of objects which provides hardware statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.10GroupctspDefSwStatisticsGroupcurrentA collection of objects which provides software statistics counters for unicast IP traffic subjected to unicast default policy enforcement.
1.3.6.1.4.1.9.9.713.2.2.11GroupctspDefHwStatisticsGroupcurrentA collection of objects which provides hardware statistics counters for unicast IP traffic subjected to unicast default policy enforcement.
1.3.6.1.4.1.9.9.713.2.2.12GroupctspPeerPolicyActionGroupcurrentA collection of object which provides refreshing of all peer policies in the device.
1.3.6.1.4.1.9.9.713.2.2.13GroupctspPeerPolicyGroupcurrentA collection of object which provides peer policy information in the device.
1.3.6.1.4.1.9.9.713.2.2.14GroupctspLayer3TransportGroupcurrentA collection of objects which provides managed information regarding the SGT propagation along with Layer 3 traffic in the device.
1.3.6.1.4.1.9.9.713.2.2.15GroupctspIfL3PolicyConfigGroupcurrentA collection of objects which provides managed information for Layer3 Tranport policy enforcement on capable interface in the device.
1.3.6.1.4.1.9.9.713.2.2.16GroupctspIpSgtMappingGroupcurrentA collection of objects which provides managed information regarding IP-to-Sgt mapping in the device.
1.3.6.1.4.1.9.9.713.2.2.17GroupctspSgtPolicyGroupcurrentA collection of object which provides SGT policy information in the device.
1.3.6.1.4.1.9.9.713.2.2.18GroupctspIfSgtMappingGroupcurrentA collection of objects which provides managed information regarding Interface-to-Sgt mapping in the device.
1.3.6.1.4.1.9.9.713.2.2.19GroupctspVlanSgtMappingGroupcurrentA collection of objects which provides sgt mapping information for the IP traffic in the specified Vlan.
1.3.6.1.4.1.9.9.713.2.2.20GroupctspSgtCachingGroupcurrentA collection of objects which provides sgt Caching information.
1.3.6.1.4.1.9.9.713.2.2.21GroupctspSgaclMonitorGroupcurrentA collection of objects which provides SGACL monitor information.
1.3.6.1.4.1.9.9.713.2.2.22GroupctspSgaclMonitorStatisticGroupcurrentA collection of objects which provides monitor statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.23GroupctspNotifCtrlGroupcurrentA collection of objects providing notification control for TrustSec policy notifications.
1.3.6.1.4.1.9.9.713.2.2.24GroupctspNotifGroupcurrentA collection of notifications for TrustSec policy.
1.3.6.1.4.1.9.9.713.2.2.25GroupctspNotifInfoGroupcurrentA collection of objects providing the variable binding for TrustSec policy notifications.