CISCO-WDS-IDS-MIB
17 objects
This MIB is intended to be implemented on all IOS based network entities that provide Wireless Domain Services, for the purpose of providing network management stations information about the various attempts to compromise the security in the 802.11-based wireless networks. Entities that can be configured to provide Wireless Domain Services could be an 802.11 Access Point, a Switch or any other IOS network device, that allows the WDS configuration. The MIB reports the information about the MAC spoofing attempts made by wireless clients to compromise the security of the network. MAC Spoofing is detected by the WDS when clients attempt to authenticate with the WDS using the MAC address of another client while roaming from one AP to another. Upon detecting this, the WDS provides the information about the client and the username to the NMS as MIB objects. The hierarchy of the WDS, AP and MNs is as follows. +=====+ +=====+ +=====+ | | | | | | | WDS | | WDS | | WDS | | | | | | | +=====+ +=====+ +=====+ / \ \ \ / \ \ \ / \ \ \ / \ \ \ / \ \ \ \/ \/ \/ \/ +~-~-~+ +~-~-~+ +~-~-~+ +~-~-~+ + + + + + + + + + AP + + AP + + AP + + AP + + + + + + + + + +~-~-~+ +~-~-~+ +~-~-~+ +~-~-~+ .. . . . .. . . . . . . . . . . . . . . . . . . . . . . . \/ \/ \/ \/ \/ +.....+ +.....+ +-.-.-.+ +~-~-~+ +......+ + + + + + + + + + + + MN + + MN + + MN + + MN + + MN + + + + + + + + + + + +.....+ +.....+ +-.-.-.+ +~-~-~+ +......+ The WDS include authentication and registration services for the APs. An AP provides Proxy Authentication and registration services for the MNs. The wireless connections are represented as dotted lines in the above diagram. GLOSSARY Access Point ( AP ) An entity that contains an 802.11 medium access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients. Mobile Node ( MN ) A roaming 802.11 wireless device in a wireless network associated with an access point. Wireless Domain Services (WDS) The set of services being offered at a particular broadcast domain that may be an IP subnet or a particular VLAN, or across the L3 cloud. The services include the following. 1. MN security credential caching to provide seamless, secure intra-subnet roaming. 2. Authenticated context transfer for roaming client within the subnet. Context The mobility context for an MN includes its current mobility bindings with the APs, IP/802 address bindings, cached configuration parameters, QoS state, IP group membership, authentication state, accounting statistics, and other dynamically derived protocol state information.
Imported Objects
| CISCO-SMI | ciscoMgmt |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE OBJECT-GROUP |
| SNMPv2-SMI | Integer32 MODULE-IDENTITY OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | MacAddress TimeStamp |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.9.9.457 | IdentityciscoWdsIdsMIB | This MIB is intended to be implemented on all IOS based network entities that provide Wireless Domain Services, for the purpose of providing network management… | ||
| 1.3.6.1.4.1.9.9.457.1 | NodeciscoWdsIdsMIBObjects | |||
| 1.3.6.1.4.1.9.9.457.1.1 | NodeciscoWdsIdsMacSpoofing | |||
| 1.3.6.1.4.1.9.9.457.1.1.1 | ScalarciscoWdsIdsMaxMacAddresses | read-write | current | This object indicates the maximum number of different MAC addresses for which spoofing events are held in this table. |
| 1.3.6.1.4.1.9.9.457.1.1.2 | ScalarciscoWdsIdsMaxEntriesPerMac | read-write | current | This object indicates the maximum number of entries that can be held for a particular MAC address indicated by the object ciscoWdsIdsMacSpoofStaMacAddress. |
| 1.3.6.1.4.1.9.9.457.1.1.3 | TableciscoWdsIdsMacSpoofTable | not-accessible | current | This table gives the information about the MAC spoofing attacks detected by the network entity offering WDS. An entry in this table is created by the agent whe… |
| 1.3.6.1.4.1.9.9.457.1.1.3.1 | RowciscoWdsIdsMacSpoofEntry | not-accessible | current | An entry holds the information about one instance of MAC spoofing attack detected on the radio interface of the AP identified by ciscoWdsIdsMacSpoofStaMacAddre… |
| 1.3.6.1.4.1.9.9.457.1.1.3.1.1 | ColumnciscoWdsIdsMacSpoofStaMacAddress | not-accessible | current | This object identifies the radio interface of the 802.11 station, that has forwarded the authentication request of the client with the spoofed MAC address indi… |
| 1.3.6.1.4.1.9.9.457.1.1.3.1.2 | ColumnciscoWdsIdsMacSpoofIndex | not-accessible | current | This object identifies the set of information about one instance of a MAC spoofing attack detected by the WDS. The radio interface of the 802.11 station that h… |
| 1.3.6.1.4.1.9.9.457.1.1.3.1.3 | ColumnciscoWdsIdsMacSpoofClient | read-only | current | This object indicates the MAC address that has been spoofed. |
| 1.3.6.1.4.1.9.9.457.1.1.3.1.4 | ColumnciscoWdsIdsMacSpoofUserId | read-only | current | This object indicates the userId used by the wireless client when attempting the MAC spoofing attack. |
| 1.3.6.1.4.1.9.9.457.1.1.3.1.5 | ColumnciscoWdsIdsMacSpoofDetectTime | read-only | current | This object indicates the time at which this MAC spoofing attempt is detected by the WDS. |
| 1.3.6.1.4.1.9.9.457.2 | NodeciscoWdsIdsMIBConform | |||
| 1.3.6.1.4.1.9.9.457.2.1 | NodeciscoWdsIdsMIBCompliances | |||
| 1.3.6.1.4.1.9.9.457.2.1.1 | ComplianceciscoWdsIdsMIBCompliance | current | The compliance statement for the SNMP entities that implement the ciscoWdsIdsMIB module. | |
| 1.3.6.1.4.1.9.9.457.2.2 | NodeciscoWdsIdsMIBGroups | |||
| 1.3.6.1.4.1.9.9.457.2.2.1 | GroupciscoWdsIdsMacSpoofingGroup | current | This collection of objects provide the information about the various attempts to spoof the MAC addresses of valid wireless clients in the network. |