MIB Viewer

FOUNDRY-SN-IP-ACL-MIB

123 objects
Copyright 1996-2010 Brocade Communications Systems, Inc. All rights reserved. This Brocade Communications Systems SNMP Management Information Base Specification embodies Brocade Communications Systems' confidential and proprietary intellectual property. Brocade Communications Systems retains all title and ownership in the Specification, including any revisions. This Specification is supplied AS IS, and Brocade Communications Systems makes no warranty, either express or implied, as to the use, operation, condition, or performance of the specification, and any unintended consequence it may on the user environment.
OIDNameAccessStatusDescription
1.3.6.1.4.1.1991.1.2.2.15IdentitysnAgAclCopyright 1996-2010 Brocade Communications Systems, Inc. All rights reserved. This Brocade Communications Systems SNMP Management Information Base Specificatio…
1.3.6.1.4.1.1991.1.2.2.15.1NodesnAgAclGlobal
1.3.6.1.4.1.1991.1.2.2.15.1.1ScalarsnAgAclGblCurRowIndexread-onlycurrentThe current row index of the ACL table entry.
1.3.6.1.4.1.1991.1.2.2.15.1.2ScalarsnAgAclGblAcctEnableread-writecurrentSpecifies the administration status of the ACL accounting. This object is not supported in CES/CER platforms.
1.3.6.1.4.1.1991.1.2.2.15.1.3ScalarsnAgAclGblIfIPv4AcctClearread-writecurrentClears the IPv4 ACL accounting information for the given interface. If the value is 0 then it clears IPv4 ACL accounting information for all the interfaces.
1.3.6.1.4.1.1991.1.2.2.15.1.4ScalarsnAgAclGblIfIPv6AcctClearread-writecurrentClears the IPv6 ACL accounting information for the given interface. If the value is 0 then it clears IPv6 accounting information for all the interfaces.
1.3.6.1.4.1.1991.1.2.2.15.1.5ScalarsnAgAclGblRebindAclNumberread-writecurrentThe access-list number for rebind
1.3.6.1.4.1.1991.1.2.2.15.1.6ScalarsnAgAclGblRebindAclNameread-writecurrentThe access-list name for rebind.
1.3.6.1.4.1.1991.1.2.2.15.1.7ScalarbrcdPbrAclAccntFilterAclNameread-writecurrentThis object can be used to control the content of brcdPbrAclAccntTable. Any ACL filter that has a full or partial match with ACL name will not be returned in t…
1.3.6.1.4.1.1991.1.2.2.15.1.8ScalarbrcdPbrAclAccntCounterTyperead-writecurrentThis contains ACL Number, ACL Name, ACL Filter Id, last five minutes and cumulative accounting data since the ACL was installed. Each field is separated by a p…
1.3.6.1.4.1.1991.1.2.2.15.2TablesnAgAclTablenot-accessiblecurrentTable of Access Control List
1.3.6.1.4.1.1991.1.2.2.15.2.1RowsnAgAclEntrynot-accessiblecurrentAn entry in the IP access control list table.
1.3.6.1.4.1.1991.1.2.2.15.2.1.1ColumnsnAgAclIndexread-onlycurrentThe Access control list item number for an entry. This is a unique number that identifies different Access list entries combined with the Access list name and …
1.3.6.1.4.1.1991.1.2.2.15.2.1.2ColumnsnAgAclNumberread-writecurrentThe access-list number for this entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.3ColumnsnAgAclNameread-writecurrentACL name for an entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.4ColumnsnAgAclActionread-writecurrentAction to take if the ip packet matches with this access control list.
1.3.6.1.4.1.1991.1.2.2.15.2.1.5ColumnsnAgAclProtocolread-writecurrentTransport protocol. Valid values for the IP protocol are: 0 = any IP protocol 1 = ICMP 2 = IGMP 3 = ggp 4 = ipencap 5 = st2 6 = TCP 7 = cbt 8 = egp 9 = igp 10 …
1.3.6.1.4.1.1991.1.2.2.15.2.1.6ColumnsnAgAclSourceIpread-writecurrentSource IP address.
1.3.6.1.4.1.1991.1.2.2.15.2.1.7ColumnsnAgAclSourceMaskread-writecurrentSource IP subnet mask.
1.3.6.1.4.1.1991.1.2.2.15.2.1.8ColumnsnAgAclSourceOperatorread-writecurrentType of comparison to perform. For now, this only applys to tcp or udp to compare the port number
1.3.6.1.4.1.1991.1.2.2.15.2.1.9ColumnsnAgAclSourceOperand1read-writecurrentFor now this only refers to transport protocol port number. 0 means NA
1.3.6.1.4.1.1991.1.2.2.15.2.1.10ColumnsnAgAclSourceOperand2read-writecurrentFor now this only refers to transport protocol port number. Used in ICMP Protocol to convey the ICMP Type value. 0 means NA. Valid values for ICMP Type: 1 = Ec…
1.3.6.1.4.1.1991.1.2.2.15.2.1.11ColumnsnAgAclDestinationIpread-writecurrentDestination IP address.
1.3.6.1.4.1.1991.1.2.2.15.2.1.12ColumnsnAgAclDestinationMaskread-writecurrentDestination IP subnet mask.
1.3.6.1.4.1.1991.1.2.2.15.2.1.13ColumnsnAgAclDestinationOperatorread-writecurrentType of comparison to perform. For now, this only applys to tcp or udp to compare the port number
1.3.6.1.4.1.1991.1.2.2.15.2.1.14ColumnsnAgAclDestinationOperand1read-writecurrentFor now this only refers to transport protocol port number. 0 means NA
1.3.6.1.4.1.1991.1.2.2.15.2.1.15ColumnsnAgAclDestinationOperand2read-writecurrentFor now this only refers to transport protocol port number. 0 means NA
1.3.6.1.4.1.1991.1.2.2.15.2.1.16ColumnsnAgAclPrecedenceread-writecurrentThis refers to IP precedence value in the range <0-7> critical(5), flash(3), flash-override(4), immediate(2), internet(6), network(7), priority(1), routine(0)
1.3.6.1.4.1.1991.1.2.2.15.2.1.17ColumnsnAgAclTosread-writecurrentThis refers to the IP type of service value in range <0-15>, which is the sum of numeric vlaues of the following options - match packets with maximum reliabili…
1.3.6.1.4.1.1991.1.2.2.15.2.1.18ColumnsnAgAclEstablishedread-writecurrentEnable/Disable the filtering of established TCP packets of which the ACK or RESET flag is on. This additional filter only applies to TCP transport protocol.
1.3.6.1.4.1.1991.1.2.2.15.2.1.19ColumnsnAgAclLogOptionread-writecurrentLog flag
1.3.6.1.4.1.1991.1.2.2.15.2.1.20ColumnsnAgAclStandardFlagread-writecurrentReturn whether the ACL is standard or extended, 1 for standard ACL
1.3.6.1.4.1.1991.1.2.2.15.2.1.21ColumnsnAgAclRowStatusread-writecurrentTo create or delete a access list entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.22ColumnsnAgAclFlowCounterread-onlycurrentApproximate count of flows matching individual ACL entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.23ColumnsnAgAclPacketCounterread-onlycurrentAccurate count of packets matching individual ACL entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.24ColumnsnAgAclCommentsread-writecurrentRemark description of individual ACL entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.25ColumnsnAgAclIpPriorityread-writecurrentQoS priority option for IP ACL entry.
1.3.6.1.4.1.1991.1.2.2.15.2.1.26ColumnsnAgAclPriorityForceread-writecurrentForce packet outgoing priority. Not defined(4)
1.3.6.1.4.1.1991.1.2.2.15.2.1.27ColumnsnAgAclPriorityMappingread-writecurrentMap incoming packet priority. Not defined(8)
1.3.6.1.4.1.1991.1.2.2.15.2.1.28ColumnsnAgAclDscpMarkingread-writecurrentMark packets with given DSCP value. Not defined(64)
1.3.6.1.4.1.1991.1.2.2.15.2.1.29ColumnsnAgAclDscpMappingread-writecurrentMap incoming DSCP value. Not defined(64)
1.3.6.1.4.1.1991.1.2.2.15.2.1.30ColumnsnAgAclIcmpCoderead-writecurrentICMP Message Code value. Used in combination with ICMP Message Type (use snAgAclSourceOperand2) to setup an ICMP filter. This object is not used with any other…
1.3.6.1.4.1.1991.1.2.2.15.2.1.31ColumnsnAgAclParametersread-writecurrentThis mask represents multiple parameters configured for this ACL. Bit 0 specified in the BITS construct is the MS bit of the first octet. Bit 0: Match fragment…
1.3.6.1.4.1.1991.1.2.2.15.2.1.32ColumnsnAgAclVlanIdread-createcurrentOptional VLAN ID to match against that of the incoming packet. By default, the VLAN ID field is ignored during the match. In this case, value 0 is returned.
1.3.6.1.4.1.1991.1.2.2.15.2.1.33ColumnsnAgAclClauseStringread-onlycurrentReturns the equivalent filter clause string.
1.3.6.1.4.1.1991.1.2.2.15.3TablesnAgAclBindToPortTablenot-accessiblecurrentTable of ACL binding to port for router
1.3.6.1.4.1.1991.1.2.2.15.3.1RowsnAgAclBindToPortEntrynot-accessiblecurrentAn entry in the ACL-binding-to-port table.
1.3.6.1.4.1.1991.1.2.2.15.3.1.1ColumnsnAgAclPortNumread-onlycurrentBinding-to port num, either physical port or virtual interface.
1.3.6.1.4.1.1991.1.2.2.15.3.1.2ColumnsnAgAclPortBindDirectionread-onlycurrentACL port direction, inbound or outbound
1.3.6.1.4.1.1991.1.2.2.15.3.1.3ColumnsnAgAclNumread-writecurrentDefined ACL number
1.3.6.1.4.1.1991.1.2.2.15.3.1.4ColumnsnAgAclNameStringread-writecurrentDefined ACL name
1.3.6.1.4.1.1991.1.2.2.15.3.1.5ColumnsnAgBindPortListInVirtualInterfaceread-writecurrentPort list for binding virtual interface
1.3.6.1.4.1.1991.1.2.2.15.3.1.6ColumnsnAgAclPortRowStatusread-writecurrentTo create or delete a ACL port entry.
1.3.6.1.4.1.1991.1.2.2.15.4TablesnAgAclIfBindTablenot-accessiblecurrentTable of ACL binding to port for router
1.3.6.1.4.1.1991.1.2.2.15.4.1RowsnAgAclIfBindEntrynot-accessiblecurrentAn entry in the ACL-binding-to-port table.
1.3.6.1.4.1.1991.1.2.2.15.4.1.1ColumnsnAgAclIfBindIndexread-onlycurrentBinding-to port num, either physical port or virtual interface.
1.3.6.1.4.1.1991.1.2.2.15.4.1.2ColumnsnAgAclIfBindDirectionread-onlycurrentACL port direction, inbound or outbound
1.3.6.1.4.1.1991.1.2.2.15.4.1.3ColumnsnAgAclIfBindNumread-createcurrentThe id of the IPv4 ACL bound to this Interface (0 represents named ACL)
1.3.6.1.4.1.1991.1.2.2.15.4.1.4ColumnsnAgAclIfBindNameread-createcurrentThe name of the IPv4 ACL name bound to this Interface
1.3.6.1.4.1.1991.1.2.2.15.4.1.5ColumnsnAgAclIfBindVifPortListread-createcurrentThis object specifies the port list for binding virtual interface. Each port index is an ifIndex, if there are consecutive 4 or more ifIndex then, they will be…
1.3.6.1.4.1.1991.1.2.2.15.4.1.6ColumnsnAgAclIfBindRowStatusread-createcurrentTo create or delete a ACL port entry.
1.3.6.1.4.1.1991.1.2.2.15.4.1.7ColumnsnAgAclIfBindDenyLoggingread-createcurrentEnable or disable deny logging.
1.3.6.1.4.1.1991.1.2.2.15.4.1.8ColumnsnAgAclIfIpv6BindNameread-createcurrentThe name of the IPv6 ACL name bound to this Interface
1.3.6.1.4.1.1991.1.2.2.15.5TableagAclAccntTablenot-accessiblecurrentTable of ACL Accounting Statistics for router
1.3.6.1.4.1.1991.1.2.2.15.5.1RowagAclAccntEntrynot-accessiblecurrentAn entry in the ACL-binding-to-port table.
1.3.6.1.4.1.1991.1.2.2.15.5.1.1ColumnagAclAccntKindnot-accessiblecurrentKind of ACL Accounting statistics needed. ipv4PolicyBasedRouting(2) and ipv6PolicyBasedRouting(6) are implemented in brcdPbrAclAccntTable. Agent will fail for …
1.3.6.1.4.1.1991.1.2.2.15.5.1.2ColumnagAclAccntIfIndexnot-accessiblecurrentPhysical or virtual interface on which ACL accounting is desired. For Receive ACL, we use the lowest port of the management module as value for this object.
1.3.6.1.4.1.1991.1.2.2.15.5.1.3ColumnagAclAccntDirectionnot-accessiblecurrentACL port direction, inbound or outbound. For receive-acl kind, direction cannot be outbound.
1.3.6.1.4.1.1991.1.2.2.15.5.1.4ColumnagAclAccntAclNumbernot-accessiblecurrentThe access-list number for this entry.
1.3.6.1.4.1.1991.1.2.2.15.5.1.5ColumnagAclAccntFilterIdnot-accessiblecurrentFilterId within a given ACL. This is a zero based value.
1.3.6.1.4.1.1991.1.2.2.15.5.1.6ColumnagAclAccntAclNameread-onlycurrentACL name for an entry, if applicable. Otherwise, null string is returned.
1.3.6.1.4.1.1991.1.2.2.15.5.1.7ColumnagAclAccntOneSecondread-onlycurrentLast one second accounting data.
1.3.6.1.4.1.1991.1.2.2.15.5.1.8ColumnagAclAccntOneMinuteread-onlycurrentLast one minute accounting data.
1.3.6.1.4.1.1991.1.2.2.15.5.1.9ColumnagAclAccntFiveMinuteread-onlycurrentLast five minute accounting data.
1.3.6.1.4.1.1991.1.2.2.15.5.1.10ColumnagAclAccntCumulativeread-onlycurrentCummulative accounting data since the ACL was installed.
1.3.6.1.4.1.1991.1.2.2.15.5.1.11ColumnagAclAccntRaclDropCntread-onlycurrentReceive-ACL drop counter used for rate limiting. Not used for other ACL kind. The value returned is per ACL, instead of per filter within the ACL.
1.3.6.1.4.1.1991.1.2.2.15.5.1.12ColumnagAclAccntRaclFwdCntread-onlycurrentReceive-ACL forward counter used for rate limiting. Not used for other ACL kind. The value returned is per ACL, instead of per filter within the ACL.
1.3.6.1.4.1.1991.1.2.2.15.5.1.13ColumnagAclAccntRaclRemarkCntread-onlycurrentReceive-ACL remark counter used for rate limiting. Not used for other ACL kind. The value returned is per ACL, instead of per filter within the ACL.
1.3.6.1.4.1.1991.1.2.2.15.5.1.14ColumnagAclAccntRaclTotalCntread-onlycurrentReceive-ACL total counter used for rate limiting. Not used for other ACL kind. The value returned is per ACL, instead of per filter within the ACL.
1.3.6.1.4.1.1991.1.2.2.15.5.1.15ColumnagAclAccntRaclTotalSWHitCountCntread-onlycurrentReceive-ACL cumulative software hit counter. Not used for other ACL kind. The value returned is per ACL, instead of per filter within the ACL.
1.3.6.1.4.1.1991.1.2.2.15.6TablefdryL2AclNextClauseTablenot-accessiblecurrentThis read-only table contains the list of next lowest available clause index that can be used for creating a new instance in the fdryL2AclTable. The clause ind…
1.3.6.1.4.1.1991.1.2.2.15.6.1RowfdryL2AclNextClauseEntrynot-accessiblecurrentAn entry specifying the next lowest available clause index for this ACL number.
1.3.6.1.4.1.1991.1.2.2.15.6.1.1ColumnfdryL2AclNextClauseIndexread-onlycurrentThe next lowest available clause index for a given ACL number. The maximum value of this object is the configured maximum number of clauses for a L2 ACL.
1.3.6.1.4.1.1991.1.2.2.15.7TablefdryL2AclTablenot-accessiblecurrentTable of Layer 2 Access Control Lists. Layer 2 ACLs filter traffic based on any of the following fields: - Source MAC address and source MAC mask - Destination…
1.3.6.1.4.1.1991.1.2.2.15.7.1RowfdryL2AclEntrynot-accessiblecurrentAn entry in the L2 Access Control List table.
1.3.6.1.4.1.1991.1.2.2.15.7.1.1ColumnfdryL2AclNumbernot-accessiblecurrentThe access-list number for this entry. For L2ACL, the valid values are between 400 and 599.
1.3.6.1.4.1.1991.1.2.2.15.7.1.2ColumnfdryL2AclClauseIndexnot-accessiblecurrentThe index of the clause within a given ACL number. During row creation, the clause index value should match with the next available clause index for a given AC…
1.3.6.1.4.1.1991.1.2.2.15.7.1.3ColumnfdryL2AclActionread-createcurrentAction to take if the ingress L2 packet matches this ACL.
1.3.6.1.4.1.1991.1.2.2.15.7.1.4ColumnfdryL2AclSourceMacread-createcurrentOptional Source MAC address. By default, it matches with any source MAC within a packet.
1.3.6.1.4.1.1991.1.2.2.15.7.1.5ColumnfdryL2AclSourceMacMaskread-createcurrentOptional Source MAC address mask. For Set operation, this object can only be used in conjunction with fdryL2AclSourceMac. By default, it matches with any sourc…
1.3.6.1.4.1.1991.1.2.2.15.7.1.6ColumnfdryL2AclDestinationMacread-createcurrentOptional destination MAC address. By default, it matches with any destination MAC within a packet.
1.3.6.1.4.1.1991.1.2.2.15.7.1.7ColumnfdryL2AclDestinationMacMaskread-createcurrentOptional destination MAC address mask. For Set operation, this object can only be used in conjunction with fdryL2AclDestinationMac. By default, it matches with…
1.3.6.1.4.1.1991.1.2.2.15.7.1.8ColumnfdryL2AclVlanIdread-createcurrentOptional VLAN ID to match against that of the incoming packet. By default, the VLAN ID field is ignored during the match. In this case, value 0 is returned.
1.3.6.1.4.1.1991.1.2.2.15.7.1.9ColumnfdryL2AclEthernetTyperead-createcurrentOptional Ethernet Type to match against the etype field of the incoming packet. By default, etype field is ignored during the match.
1.3.6.1.4.1.1991.1.2.2.15.7.1.10ColumnfdryL2AclDot1pPriorityread-createcurrentThe priority option assigns traffic that matches the ACL to a hardware forwarding queue. In addition to changing the internal forwarding priority, if the outgo…
1.3.6.1.4.1.1991.1.2.2.15.7.1.11ColumnfdryL2AclDot1pPriorityForceread-createcurrentThe priority-force option assigns packets of outgoing traffic that match the ACL to a specific hardware forwarding queue, even though the incoming packet may b…
1.3.6.1.4.1.1991.1.2.2.15.7.1.12ColumnfdryL2AclDot1pPriorityMappingread-createcurrentThe priority-mapping option matches on the packets 802.1p value. This option does not change the packets forwarding priority through the device or mark the pac…
1.3.6.1.4.1.1991.1.2.2.15.7.1.13ColumnfdryL2AclMirrorPacketsread-createcurrentMirror packets matching ACL permit clause.
1.3.6.1.4.1.1991.1.2.2.15.7.1.14ColumnfdryL2AclLogEnableread-createcurrentOptional parameter to enable logging only when deny clause is specified. Note that traffic denied by implicit deny mechanism is not subject to logging. The imp…
1.3.6.1.4.1.1991.1.2.2.15.7.1.15ColumnfdryL2AclRowStatusread-createcurrentThe row status variable, used according to installation and removal conventions for conceptual rows. Setting this object to active(1) or createAndGo(4) results…
1.3.6.1.4.1.1991.1.2.2.15.8TablefdryL2AclIfBindTablenot-accessiblecurrentTable of L2 ACL binding to port. - One cannot bind Layer 2 ACLs and Layer 3 ACLs to the same port. However, one can configure a port to use Layer 2 ACLs, and a…
1.3.6.1.4.1.1991.1.2.2.15.8.1RowfdryL2AclIfBindEntrynot-accessiblecurrentAn entry in the L2ACL binding table which lists the ACL bindings to a port.
1.3.6.1.4.1.1991.1.2.2.15.8.1.1ColumnfdryL2AclIfBindDirectionnot-accessiblecurrentDirection in which this ACL should be applied on this port.
1.3.6.1.4.1.1991.1.2.2.15.8.1.2ColumnfdryL2AclIfBindAclNumberread-createcurrentThe ACL number that is to be bound to given physical interface. The valid values for L2 numbered ACLs are between 400 and 599.
1.3.6.1.4.1.1991.1.2.2.15.8.1.3ColumnfdryL2AclIfBindRowStatusread-createcurrentThe row status variable, used according to installation and removal conventions for conceptual rows. Setting this object to active(1) or createAndGo(4) results…
1.3.6.1.4.1.1991.1.2.2.15.9TablebrcdPbrAclAccntTablenot-accessiblecurrentTable of PBR ACL Accounting Statistics for router.
1.3.6.1.4.1.1991.1.2.2.15.9.1RowbrcdPbrAclAccntEntrynot-accessiblecurrentAn entry in the PBR ACL-binding-to-port table.
1.3.6.1.4.1.1991.1.2.2.15.9.1.1ColumnbrcdPbrAclAccntKindnot-accessiblecurrentKind of PBR ACL Accounting statistics needed.
1.3.6.1.4.1.1991.1.2.2.15.9.1.2ColumnbrcdPbrAclAccntIfIndexnot-accessiblecurrentPhysical or virtual interface on which ACL accounting is desired
1.3.6.1.4.1.1991.1.2.2.15.9.1.3ColumnbrcdPbrSerialNumbernot-accessiblecurrentThis is a running number and may change if an acl or routemap is modified
1.3.6.1.4.1.1991.1.2.2.15.9.1.4ColumnbrcdPbrAclAccntAclInforead-onlycurrentThis contains ACL Number, ACL Name, ACL Filter Id, last five minutes and cumulative accounting data since the ACL was installed. Each field is separated by a p…
Type Definitions
NameSyntaxStatusDescription
AclNameStringOCTET STRING (SIZE (0..255))currentThe optional name for a given access-list. In general, the ACL number for a named ACL is in the range of 200 and 399.
AclNumberINTEGER (1..5100)currentThe Access control list number for an entry. The standard Access list is in the range <1-99>. The extended Access list is in the range <100-199>. The named standard Access list is in the range <200-299>. The named exten…
ActionINTEGER { deny(0), permit(1) }currentThe action to be taken on the packet after filtering is done.
DirectionINTEGER { inbound(0), outbound(1) }currentThe packet flow direction within an interface for which ACL needs to be applied.
FdryClauseIndexTCUnsigned32currentOne-based clause index value within a given ACL number.
FdryEnetTypeOrZeroTCINTEGER { invalid(0), ipv4(1), arp(2), ipv6(3) }currentEthernet Type field within the Ethernet-II frame
IpProtocolInteger32 (0..255)currentThe IP protocol number on which ACL can be applied.
OperatorINTEGER { eq(0), neq(1), lt(2), gt(3), range(4), undefined(7) }currentThe operation used within a given ACL filter to determine permit or deny.
PrecedenceValueINTEGER { routine(0), priority(1), immediate(2), flash(3), flashoverride(4), critical(5), internet(6), network(7), undefined(8) }currentThe IP precedence value on which ACL can be applied.
SnRowStatusINTEGER {other(1), valid(2), delete(3), create(4)}currentThe status of a given row in the table.
TosValueINTEGER { normal(0), minMonetaryCost(1), maxReliability(2), tosValue3(3), maxThroughput(4), tosValue5(5), tosValue6(6), tosValue7(7), minDelay(8), tosValue9(9), tosValue10(10), tosValue11(11), tosValue12(12), tosValue13(13), tosValue14(14), tosValue15(15), undefined(16) }currentThe IP TOS value on which ACL can be applied.
TruthValINTEGER { false (0), true (1) }currentBoolean value.