NETGEAR-RADLAN-SECURITY-SUITE
52 objects
The private MIB module definition for blocking attacks such as DoS(=Denial Of Service), SYN and well known viruses Attacks in Radlan devices.
Imported Objects
| IF-MIB | ifIndex InterfaceIndex InterfaceIndexOrZero |
| NETGEAR-RADLAN-MIB | Percents rnd |
| Q-BRIDGE-MIB | PortList |
| SNMPv2-SMI | Counter32 Gauge32 IpAddress MODULE-IDENTITY OBJECT-TYPE TimeTicks Unsigned32 |
| SNMPv2-TC | DisplayString RowPointer RowStatus TEXTUAL-CONVENTION TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.4526.17.120 | IdentityrlSecuritySuiteMib | The private MIB module definition for blocking attacks such as DoS(=Denial Of Service), SYN and well known viruses Attacks in Radlan devices. | ||
| 1.3.6.1.4.1.4526.17.120.1 | ScalarrlSecuritySuiteGlobalEnable | read-write | current | This scalar globally enables/disables the DoS attack Suite. |
| 1.3.6.1.4.1.4526.17.120.2 | TablerlSecuritySuiteKnownDoSAttacksTable | not-accessible | current | This table enables/disable well-know DoS attacks, applied globally to all ifIndexes. |
| 1.3.6.1.4.1.4526.17.120.2.1 | RowrlSecuritySuiteKnownDoSAttacksEntry | not-accessible | current | Each entry in this table describes one well known DoS attack address |
| 1.3.6.1.4.1.4526.17.120.2.1.1 | ColumnrlSecuritySuiteKnownDoSAttack | not-accessible | current | A well-known DoS attack to enable |
| 1.3.6.1.4.1.4526.17.120.2.1.2 | ColumnrlSecuritySuiteKnownDoSAttackEnable | read-write | current | Enable/Disable a well-known DoS attack |
| 1.3.6.1.4.1.4526.17.120.3 | TablerlSecuritySuiteKnownDoSAttacksDetailsTable | not-accessible | current | This read-only table used to present the detailed attributes of each well-known DoS attack. Used for presentation propose only. |
| 1.3.6.1.4.1.4526.17.120.3.1 | RowrlSecuritySuiteKnownDoSAttacksDetailsEntry | not-accessible | current | Each entry in this table describes one well known DoS attack address , |
| 1.3.6.1.4.1.4526.17.120.3.1.1 | ColumnrlSecuritySuiteKnownDoSAttackProtocl | read-only | current | Specifies the protocol type of the relevant well-known attack |
| 1.3.6.1.4.1.4526.17.120.3.1.2 | ColumnrlSecuritySuiteKnownDoSAttackSrcTcpUdpPort | read-only | current | Specifies the source tcp/udp port of the relevant well-known attack |
| 1.3.6.1.4.1.4526.17.120.3.1.3 | ColumnrlSecuritySuiteKnownDoSAttackDestTcpUdpPort | read-only | current | Specifies the destination tcp/udp port of the relevant well-known attack |
| 1.3.6.1.4.1.4526.17.120.4 | ScalarrlSecuritySuiteReservedMartianAddresses | read-write | current | This scalar globally enables/disables discarding of the IP well-known addresses described below: | Address block | Present use | |0.0.0.0/8 | Addresses in this… |
| 1.3.6.1.4.1.4526.17.120.5 | TablerlSecuritySuiteMartianAddrAllTable | not-accessible | current | This read-only table specifies all current configured Martian addresses - both pre-defined (=reserved) and used-configured (=static) addresses |
| 1.3.6.1.4.1.4526.17.120.5.1 | RowrlSecuritySuiteMartianAddrAllEntry | not-accessible | current | Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded. |
| 1.3.6.1.4.1.4526.17.120.5.1.1 | ColumnrlSecuritySuiteMartianAddr | not-accessible | current | An IP address to discard all packets with that address as source or destination |
| 1.3.6.1.4.1.4526.17.120.5.1.2 | ColumnrlSecuritySuiteMartianAddrNetMask | not-accessible | current | Specify the net mask that comprise the destination IP address prefix. |
| 1.3.6.1.4.1.4526.17.120.5.1.3 | ColumnrlSecuritySuiteAllMartianEntryType | read-only | current | Specific the entry origin: pre-defined (reserved) of statically configured. |
| 1.3.6.1.4.1.4526.17.120.6 | TablerlSecuritySuiteMartianAddrTable | not-accessible | current | This table specifies the Martian addresses - the addresses that packets with these IP addressed as source or destination are discarded. |
| 1.3.6.1.4.1.4526.17.120.6.1 | RowrlSecuritySuiteMartianAddrEntry | not-accessible | current | Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded. |
| 1.3.6.1.4.1.4526.17.120.6.1.1 | ColumnrlSecuritySuiteMartianAddrStatus | read-create | current | The status of a table entry. It is used to delete/Add an entry from this table. |
| 1.3.6.1.4.1.4526.17.120.7 | TablerlSecuritySuiteDoSSynAttackTable | not-accessible | current | This table contains IP address and rate, to limit DoS SYN attacks from a specific IP address and interface(s) |
| 1.3.6.1.4.1.4526.17.120.7.1 | RowrlSecuritySuiteDoSSynAttackEntry | not-accessible | current | Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded. |
| 1.3.6.1.4.1.4526.17.120.7.1.1 | ColumnrlSecuritySuiteDoSSynAttackIfIndex | not-accessible | current | Interface which the attack is applied on |
| 1.3.6.1.4.1.4526.17.120.7.1.2 | ColumnrlSecuritySuiteDoSSynAttackAddr | not-accessible | current | An IP address to discard all packets with that address as destination |
| 1.3.6.1.4.1.4526.17.120.7.1.3 | ColumnrlSecuritySuiteDoSSynAttackNetMask | not-accessible | current | Relevant when rlSecuritySuiteSynAttackRangeType equals prefix(2). Specify the number of bits that comprise the destination IP address prefix. |
| 1.3.6.1.4.1.4526.17.120.7.1.4 | ColumnrlSecuritySuiteDoSSynAttackSynRate | read-create | current | Specify the maximum connections per second allowed from this IP address and rlSecuritySuiteSynAttackPortList |
| 1.3.6.1.4.1.4526.17.120.7.1.6 | ColumnrlSecuritySuiteDoSSynAttackStatus | read-create | current | The status of a table entry. It is used to delete/Add an entry from this table. |
| 1.3.6.1.4.1.4526.17.120.8 | TablerlSecuritySuiteDenyTypesTable | not-accessible | current | This table specifies the ip address and TCP ports that TCP SYN packets from them on a specific interfaces are dropped. |
| 1.3.6.1.4.1.4526.17.120.8.1 | RowrlSecuritySuiteDenyTypesEntry | not-accessible | current | Each entry in this table describes one ip address, TCP port and list of ifIndexes, that packets with these attributes are discarded. |
| 1.3.6.1.4.1.4526.17.120.8.1.1 | ColumnrlSecuritySuiteDenyIfIndex | not-accessible | current | Interface which the attack is applied on |
| 1.3.6.1.4.1.4526.17.120.8.1.2 | ColumnrlSecuritySuiteDenyAttackType | not-accessible | current | The specific deny attack type |
| 1.3.6.1.4.1.4526.17.120.8.1.3 | ColumnrlSecuritySuiteDenyDestAddr | not-accessible | current | An IP address to discard all packets with that address as destination |
| 1.3.6.1.4.1.4526.17.120.8.1.4 | ColumnrlSecuritySuiteDenyNetMask | not-accessible | current | Relevant when rlSecuritySuiteDenyTCPRangeType equals mask(1). Specify the number of bits that comprise the destination IP address prefix. |
| 1.3.6.1.4.1.4526.17.120.8.1.5 | ColumnrlSecuritySuiteDenyDestPort | not-accessible | current | Destination TCP port. Use 65553 to specify all ports. This key-field is relevant in specific attack types (not all) Use 0 when not relevant. |
| 1.3.6.1.4.1.4526.17.120.8.1.6 | ColumnrlSecuritySuiteDenyStatus | read-create | current | The status of a table entry. It is used to delete/Add an entry from this table. |
| 1.3.6.1.4.1.4526.17.120.9 | ScalarrlSecuritySuiteDenySynFinTcp | read-write | current | This scalar globally enable or disable dropping of tcp packets with both SYN and FIN flags enabled. |
| 1.3.6.1.4.1.4526.17.120.10 | ScalarrlSecuritySuiteSynProtectionMode | read-write | current | This scalar globally set protection mode on TCP SYN traffic. Disabled - the system doesn't support protection against TCP SYN attack. Report - the system doesn… |
| 1.3.6.1.4.1.4526.17.120.11 | ScalarrlSecuritySuiteSynProtectionTreshold | read-write | current | This scalar globally set protection mode treshold value in packet per second on TCP SYN traffic. |
| 1.3.6.1.4.1.4526.17.120.12 | ScalarrlSecuritySuiteSynProtectionRecoveryTimeout | read-write | current | This scalar globally set protection reovery time out in secounds. |
| 1.3.6.1.4.1.4526.17.120.13 | TablerlSecuritySuiteSynProtectionPortTable | not-accessible | current | This table keeps SYN protection status per port. |
| 1.3.6.1.4.1.4526.17.120.13.1 | RowrlSecuritySuiteSynProtectionPortEntry | not-accessible | current | Each entry in this table describes TCP SYN protection status for one port. |
| 1.3.6.1.4.1.4526.17.120.13.1.1 | ColumnrlSecuritySuiteSynProtectionPortMode | read-only | current | The port's TCP SYN protection mode. |
| 1.3.6.1.4.1.4526.17.120.13.1.2 | ColumnrlSecuritySuiteSynProtectionPortModeLastTimeAttack | read-only | current | The port's TCP SYN protection last attack time mode. |
| 1.3.6.1.4.1.4526.17.120.13.1.3 | ColumnrlSecuritySuiteSynProtectionPortLastTimeAttack | read-only | current | The port's TCP SYN protection last attack time. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| RlSecuritySuiteAllMartianEntryType | INTEGER { reserved(1), static(2) } | current | Specifies Martian-address origin: pre-defined (reserved) or statically configured |
| RlSecuritySuiteDenyAttackType | INTEGER { syn(1), icmp-echo-request(2), fragmented(3) } | current | Specifies the deny attack types |
| RlSecuritySuiteDenySynFinTcp | INTEGER { deny(1), permit(2) } | current | Specifies the dropping SYN, FIN flags enabled TCP packets status |
| RlsecuritySuiteGlobalEnableType | INTEGER { enable-global-rules-only(1), enable-all-rules-types(2), disable(3) } | current | Specifies the operating modes of the security-suite |
| RlSecuritySuiteKnownDosAttackProtocolType | INTEGER { tcp(1), upd(2) } | current | Specifies protocol type of the well-known DoS attack |
| RlSecuritySuiteKnownDosAttackType | INTEGER { stacheldraht(1), invasor-Trojan(2), back-orifice-Trojan(3) } | current | Specifies well-known DoS attack |
| RlSecuritySuiteSynProtectionMode | INTEGER { disabled(1), report(2), block(3) } | current | Specifies the TCP SYN attack protection mode . |
| RlSecuritySuiteSynProtectionPortMode | INTEGER { normal(1), attacked(2), blocked(3) } | current | Specifies the TCP SYN attack protection mode . |