CM-SECURITY-MIB
85 objects
This module defines the Security MIB definitions used by the F3 (FSP150CM/CC) product lines. These are used to manage the user/authentication for CLI/GUI sessions. Copyright (C) ADVA Optical Networking.
Imported Objects
| ADVA-MIB | fsp150cm |
| CM-COMMON-MIB | IpVersion UserInterfaceType |
| IPV6-TC | Ipv6Address |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMP-USER-BASED-SM-MIB | usmUserEntry |
| SNMPv2-CONF | MODULE-COMPLIANCE OBJECT-GROUP |
| SNMPv2-SMI | Integer32 IpAddress MODULE-IDENTITY OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | DateAndTime DisplayString RowStatus StorageType TEXTUAL-CONVENTION TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.2544.1.12.10 | IdentitycmSecurityMIB | This module defines the Security MIB definitions used by the F3 (FSP150CM/CC) product lines. These are used to manage the user/authentication for CLI/GUI sessi… | ||
| 1.3.6.1.4.1.2544.1.12.10.1 | NodecmSecurityObjects | |||
| 1.3.6.1.4.1.2544.1.12.10.1.1 | ScalarcmAuthProtocol | read-write | current | Remote user authentication protocol. |
| 1.3.6.1.4.1.2544.1.12.10.1.2 | ScalarcmAccessOrder | read-write | current | Order of access for security, i.e. try 'local' first or 'remote' first. |
| 1.3.6.1.4.1.2544.1.12.10.1.3 | ScalarcmAuthType | read-write | current | In case of remote authentication, the chosen protocol. |
| 1.3.6.1.4.1.2544.1.12.10.1.4 | ScalarcmNASIpAddress | read-write | current | In case of remote authentication RADIUS, the Network Access Server's IP Address. |
| 1.3.6.1.4.1.2544.1.12.10.1.5 | TablecmSecurityUserTable | not-accessible | current | A list of entries corresponding to the security users. Entries cannot be created in this table by management application action. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1 | RowcmSecurityUserEntry | not-accessible | current | An entry containing information applicable to a particular security user. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.1 | ColumncmSecurityUserName | read-create | current | Security User Name. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.2 | ColumncmSecurityUserComment | read-create | current | Notes on Security User. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.3 | ColumncmSecurityUserPrivLevel | read-create | current | Security User Privilege Level. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.4 | ColumncmSecurityUserLoginTimeout | read-create | current | Security User Login Timeout. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.5 | ColumncmSecurityUserNumFailedLoginAttempts | read-only | current | Security User Number of Failed Login Attempts. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.6 | ColumncmSecurityUserLastLoginTime | read-only | current | Security User Last Login Time. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.7 | ColumncmSecurityUserLockedout | read-only | current | Whether the security user has been locked out. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.8 | ColumncmSecurityUserLastLockedoutTime | read-only | current | Security User Last Locked out Time. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.9 | ColumncmSecurityUserCliPagingEnable | read-create | current | Whether the security user has CLI paging enabled. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.10 | ColumncmSecurityUserRemoteUser | read-only | current | Whether the security user is a remote user. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.11 | ColumncmSecurityUserPassword | read-create | current | Password of the security user. Note that this attribute is a SET only attribute. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.12 | ColumncmSecurityUserStorageType | read-create | current | The type of storage configured for this entry. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.13 | ColumncmSecurityUserRowStatus | read-create | current | The status of this row. An entry MUST NOT exist in the active state unless all objects in the entry have an appropriate value, as described in the description … |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.14 | ColumncmSecurityUserAction | read-write | current | This object provides ability to perform specific actions on security user. remove-lockout - this removes the locked out condition on the security user . |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.15 | ColumncmSecurityCryptoPassword | read-create | current | Second level password used in connectguard configurations. This applies only to crypto users. Note that this attribute is a SET only attribute. |
| 1.3.6.1.4.1.2544.1.12.10.1.5.1.16 | ColumncmSecurityUserRemoteCryptoUser | read-create | current | Indicates if a security user is a remote crypto user. |
| 1.3.6.1.4.1.2544.1.12.10.1.6 | TablecmRemoteAuthServerTable | not-accessible | current | A list of entries corresponding to the remote authentication servers. Entries cannot be created in this table by management application action. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1 | RowcmRemoteAuthServerEntry | not-accessible | current | An entry containing information applicable to a particular remote authentication server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.1 | ColumncmRemoteAuthServerIndex | read-only | current | Unique index to address/configure a specific Remote Authentication Server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.2 | ColumncmRemoteAuthServerEnabled | read-write | current | This object allows enabling/disabling a Remote Authentication Server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.3 | ColumncmRemoteAuthServerOrder | read-write | current | This object determines the order in which the Remote Authentication Servers are accessed for security information. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.4 | ColumncmRemoteAuthServerIpAddress | read-write | current | This object allows to specify an IP Address for the Remote Authentication Server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.5 | ColumncmRemoteAuthServerPort | read-write | current | This object allows to specify a Port for Remote Authentication Server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.6 | ColumncmRemoteAuthServerNumRetries | read-write | current | This object allows to specify the number of retries the Remote Authentication Server must be tried for security access before giving up. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.7 | ColumncmRemoteAuthServerTimeout | read-write | current | This object allows to specify the timeout period for timing out a security access request to the Remote Authentication Server. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.8 | ColumncmRemoteAuthServerSecret | read-write | current | This allows configuration of secret password for Remote Authentication Server request. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.9 | ColumncmRemoteAuthServerAccountingPort | read-write | current | This object allows to specify a Port for RADIUS Accounting. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.10 | ColumncmRemoteAuthServerIpVersion | read-write | current | This object describe the Ip Version. |
| 1.3.6.1.4.1.2544.1.12.10.1.6.1.11 | ColumncmRemoteAuthServerIpv6Addr | read-write | current | This object describe the Ipv6 Address. |
| 1.3.6.1.4.1.2544.1.12.10.1.7 | ScalarcmSecurityPolicyStrength | read-write | current | This object represents the security policy strength of the system. Based on this value, the system puts additional restrictions on the user id and password rul… |
| 1.3.6.1.4.1.2544.1.12.10.1.8 | ScalarcmRemoteAuthServerAccountingEnabled | read-write | current | This object allows to enable/disable RADIUS Accounting on all authentication servers. |
| 1.3.6.1.4.1.2544.1.12.10.1.9 | Tablef3UsmUserTable | not-accessible | current | This table is the extension of the F3 USM User Table. |
| 1.3.6.1.4.1.2544.1.12.10.1.9.1 | Rowf3UsmUserEntry | not-accessible | current | An entry in the F3 USM User Table. |
| 1.3.6.1.4.1.2544.1.12.10.1.9.1.1 | Columnf3UsmUserAccessType | read-only | current | This indicates the type of USM User, read-only, read-write, trap-only. |
| 1.3.6.1.4.1.2544.1.12.10.1.10 | Scalarf3TacacsPrivLevelControlEnabled | read-write | current | This object allows to enable/disable the use of ENABLE authorization control to determine the Privilege Level configured by the remote authentication server. T… |
| 1.3.6.1.4.1.2544.1.12.10.1.11 | Scalarf3TacacsDefaultPrivLevel | read-write | current | This object allows specification of the default privilege level of the TACACS+ user, when the use of ENABLE authorization control is DISABLED, i.e. f3TacacsPri… |
| 1.3.6.1.4.1.2544.1.12.10.1.12 | Scalarf3NasIpv6Addr | read-write | current | This object describe the ipv6 address. |
| 1.3.6.1.4.1.2544.1.12.10.1.13 | Scalarf3SecurityTrapType | read-write | current | This object provides ability to manage whether report security trap. |
| 1.3.6.1.4.1.2544.1.12.10.1.14 | Scalarf3SecurityTrapInfo | read-only | current | This object is used to describe the security trap info. This object is used only in trap and GET operation on this object will return empty string. |
| 1.3.6.1.4.1.2544.1.12.10.1.15 | Tablef3PrivilegeChangeTable | not-accessible | current | This table is used for Restricted User Login via NMS. This is for users with lower privileges to elevate them to higher ones for limited amount of time. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1 | Rowf3PrivilegeChangeEntry | not-accessible | current | Column for privilegeChangeTable. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.1 | Columnf3PrivilegeChangeId | not-accessible | current | Unique index identifying a request. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.2 | Columnf3PrivilegeChangeUserName | read-only | current | The name string for user authentication purposes |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.3 | Columnf3PrivilegeChangeIpv4Address | read-only | current | IPv4 address of interface to which user's terminal is connected. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.4 | Columnf3PrivilegeChangeIpv6Address | read-only | current | IPv6 address of interface to which user's terminal is connected. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.5 | Columnf3PrivilegeChangeTerminalIpv4Address | read-only | current | Source IPv4 address of connected terminal. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.6 | Columnf3PrivilegeChangeTerminalIpv6Address | read-only | current | Source IPv6 address of connected terminal. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.7 | Columnf3PrivilegeChangeInterface | read-only | current | Interface used by the user |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.8 | Columnf3PrivilegeChangeCurrentPrivilege | read-only | current | Current privilege level of the user, who is requesting role upgrade. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.9 | Columnf3PrivilegeChangeRequestedPrivilege | read-only | current | Privilege requested by user for session. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.10 | Columnf3PrivilegeChangeDuration | read-only | current | Requested time period by user (in minutes). |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.11 | Columnf3PrivilegeChangeAction | read-write | current | Privilege request action. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.12 | Columnf3PrivilegeChangeState | read-only | current | Privilege request state. |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.13 | Columnf3PrivilegeChangeRemainingTime | read-only | current | Time remaining in session with upgrade user privilege (in seconds). |
| 1.3.6.1.4.1.2544.1.12.10.1.15.1.14 | Columnf3PrivilegeChangeRemoteName | read-only | current | The name string for Radius/Tacacs authentication purposes. |
| 1.3.6.1.4.1.2544.1.12.10.1.16 | Scalarf3UserPrivMgmtControl | read-write | current | This object is used to enable/disable User Privilege Management. |
| 1.3.6.1.4.1.2544.1.12.10.1.17 | Scalarf3UserPrivRspTimeout | read-write | current | This object is used to set response timeout for user privilege upgrade request in minutes. |
| 1.3.6.1.4.1.2544.1.12.10.2 | NodecmSecurityConformance | |||
| 1.3.6.1.4.1.2544.1.12.10.2.1 | NodecmSecurityCompliances | |||
| 1.3.6.1.4.1.2544.1.12.10.2.1.1 | CompliancecmSecurityCompliance | current | Describes the requirements for conformance to the CM Security group. | |
| 1.3.6.1.4.1.2544.1.12.10.2.2 | NodecmSecurityGroups | |||
| 1.3.6.1.4.1.2544.1.12.10.2.2.1 | GroupcmSecurityObjectGroup | current | A collection of objects used to manage the CM Security group. | |
| 1.3.6.1.4.1.2544.1.12.10.2.2.2 | GroupcmSecurityNotifGroup | current | A collection of notifications used in the CM Security group. | |
| 1.3.6.1.4.1.2544.1.12.10.3 | NodecmSecurityNotifications | |||
| 1.3.6.1.4.1.2544.1.12.10.3.1 | Notificationf3SecurityTrap | current | This is security trap. Security traps are reported according to value of f3SecurityTrapType object. | |
| 1.3.6.1.4.1.2544.1.12.10.3.2 | Notificationf3PrivilegeChangeTrap | current | This trap is sent every time a privilege change request is changed (added, modified, removed). |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| CmRemoteAuthOrder | INTEGER { first (1), second (2), third (3) } | current | Enumerations for order for remote authentication access. first - first to access the remote authentication, second - second to access the remote authentication, third - third to access the remote authentication. |
| CmRemoteAuthProtocol | INTEGER { none (1), radius (2), tacacs (3) } | current | Enumerations for remote authentication protocol. none - No remote authentication protocol, radius - RADIUS (Remote Authentication Dial-In User Service), tacacs - TACACS+(Terminal Access Controller Access Control System). |
| CmSecurityAccessOrder | INTEGER { local (1), remote (2) } | current | Enumerations for order for security access. local - Local database for user/security validation, remote - Remote protocol for user/security validation. |
| CmSecurityAuthType | INTEGER { pap (1), chap (2) } | current | Enumerations for remote authentication protocol types. pap - Password Authentication Protocol, chap - Challenge-Handshake Authentication Protocol. |
| CmSecurityPolicyStrength | INTEGER { low (1), medium (2), high (3) } | current | Enumerations for security policy strength low - Low Security Policy, medium - Medium Security Policy, high - High Security Policy. |
| CmSecurityPrivLevel | INTEGER { not-applicable(0), retrieve (1), maintenance (2), provisioning (3), superuser (4), testuser (5), cryptouser (6), netconf (7) } | current | Enumerations for Security Privilege Level. retrieve - Retrieve Privilege Level (can only VIEW management information), maintenance - Maintenance Privilege Level (can VIEW management, as well as perform maintenance opera… |
| PrivilegeRequestAction | INTEGER { undefined(0), none(1), approve(2), deny(3), cancel(4) } | current | Privilege request action. |
| PrivilegeRequestState | INTEGER { none(1), requestSent(2), requestCanceled(3), requestApproved(4), requestDenied(5), requestTimeout(6), accessExpired(7), accessCanceled(8) } | current | Privilege request state. |
| SecurityUserAction | INTEGER { not-applicable(0), remove-lockout(1) } | current | Provides ability to manage security users. |
| SnmpSecurityTrapType | INTEGER { all(1), loginFailed(2), disabled(3) } | current | Provides ability to manage security traps. all - trap is reported when user logs in, logs out or is locked out loginFailed - trap is reported only when user failed to log in disabled - security traps are disabled. |
| UsmUserAccessType | INTEGER { read-only (1), read-write (2), trap-only (3) } | current | Enumerations for type of USM User read-only - Read only, read-write - Read write , trap-only - Trap Only. |