MIBs Depot

CISCO-LWAPP-ROGUE-MIB

Registered at
1.3.6.1.4.1.9.9.610
Last updated
2017-03-21 00:00
Organization
Cisco Systems Inc.
Revisions
2020-12-02 00:00, 2017-03-21 00:00, 2011-09-07 00:00, 2011-03-11 00:00, 2010-07-17 00:00, 2007-02-06 00:00
Namespace
cisco
Source file
CISCO-LWAPP-ROGUE-MIB
Digest
sha256:8907fe7aea921be6fe28a55fdf13b46c4ae2d36efe5493dd4793874132b76896

Description

This MIB is intended to be implemented on all those devices operating as Central Controllers, that terminate the Light Weight Access Point Protocol tunnel from Cisco Light-weight LWAPP Access Points. This MIB provides information about the Rogue APs and Clients that are detected by the controller. The relationship between CC and the LWAPP APs can be depicted as follows: +......+ +......+ +......+ + + + + + + + CC + + CC + + CC + + + + + + + +......+ +......+ +......+ .. . . .. . . . . . . . . . . . . . . . . . . +......+ +......+ +......+ +......+ + + + + + + + + + AP + + AP + + AP + + AP + + + + + + + + + +......+ +......+ +......+ +......+ . . . . . . . . . . . . . . . . . . . +......+ +......+ +......+ +......+ + + + + + + + + + MN + + MN + + MN + + MN + + + + + + + + + +......+ +......+ +......+ +......+ The LWAPP tunnel exists between the controller and the APs. The MNs communicate with the APs through the protocol defined by the 802.11 standard. LWAPP APs, upon bootup, discover and join one of the controllers and the controller pushes the configuration, that includes the WLAN parameters, to the LWAPP APs. The APs then encapsulate all the 802.11 frames from wireless clients inside LWAPP frames and forward the LWAPP frames to the controller. GLOSSARY Access Point ( AP ) An entity that contains an 802.11 medium access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients. LWAPP APs encapsulate all the 802.11 frames in LWAPP frames and sends them to the controller to which it is logically connected. Light Weight Access Point Protocol ( LWAPP ) This is a generic protocol that defines the communication between the Access Points and the Central Controller. Mobile Node ( MN ) A roaming 802.11 wireless device in a wireless network associated with an access point. Mobile Node and client are used interchangeably. Rogue Any 802.11 device which is not part of the RF network is a Rogue device. Ad-hoc Network A set of mobile devices within direct communication range establishing a network among themselves for transmitting data, without the use of a Access point is called a ad-hoc network. Rogue Ad-hoc Client Any 802.11 client which is part of that ad-hoc network, but not in the trusted list. Service Set Identifier ( SSID ) SSID is a unique identifier that APs and clients use to identify with each other. SSID is a simple means of access control and is not for security. The SSID can be any alphanumeric entry up to 32 characters. RSSI Received Signal Strength Indication (RSSI), the IEEE 802.11 standard defines a mechanism by which RF energy is to be measured by the circuitry on a wireless NIC. Its value is measured in dBm and ranges from -128 to 0. Rogue Location Detection Protocol (RLDP) RLDP is a protocol to detect and automatically contain rogue devices. When the controller discovers a rogue access point, it uses the Rogue Location Discovery Protocol (RLDP) to determine if the rogue is attached to your network. RLDP can be enabled/disabled per controller level. LRAD (LWAPP RADIO) Light Weight Access Point Protocol Radio basically ones own AP. REFERENCE [1] Wireless LAN Medium Access Control ( MAC ) and Physical Layer ( PHY ) Specifications. [2] Draft-obara-capwap-lwapp-00.txt, IETF Light Weight Access Point Protocol.

Contact

Cisco Systems, Customer Service Postal: 170 West Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS Email: cs-wnbu-snmp@cisco.com

Imports

FromSymbols
CISCO-LWAPP-AP-MIBcLApDot11IfType, cLApDot11RadioChannelNumber, cLApDot11RadioMACAddress, cLApIfSmtDot11Bssid, cLApName, cLApRogueApMacAddress, cLApRogueDetectedChannel, cLApRogueDot11RadioBand, cLApRogueMode
CISCO-LWAPP-DOT11-CLIENT-MIBcldcClientMacAddress
CISCO-SMIciscoMgmt
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP
SNMPv2-SMIInteger32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDisplayString, MacAddress, RowStatus, StorageType, TEXTUAL-CONVENTION, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

BRIDGE-MIB
CISCO-LWAPP-AP-MIB
CISCO-LWAPP-DOT11-CLIENT-MIB
CISCO-LWAPP-DOT11-MIB
CISCO-LWAPP-MOBILITY-EXT-MIB
CISCO-LWAPP-RF-MIB
CISCO-LWAPP-ROGUE-MIB
CISCO-LWAPP-TC-MIB
CISCO-LWAPP-WLAN-MIB
CISCO-LWAPP-WLAN-POLICY-MIB
CISCO-QOS-PIB-MIB
CISCO-SMI
CISCO-TC
ENTITY-MIB
IANA-ENTITY-MIB
IANAifType-MIB
IF-MIB
INET-ADDRESS-MIB
P-BRIDGE-MIB
Q-BRIDGE-MIB
RFC1158-MIB
RFC1271-MIB
RMON-MIB
RMON2-MIB
SNMP-FRAMEWORK-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC
TOKEN-RING-RMON-MIB
UUID-TC-MIB

Textual conventions

NameOIDSyntaxAccessStatus
CLAutoContainActions
TEXTUAL-CONVENTION
This textual convention represents the action that should be taken with respect to auto containment feature when any of the following are detected by the switch: rogue adhoc network rogues APs that are advertising our SSID trusted clients that are associated to rogue APs alarmOnly(1) - only an alarm will be generated contain(2) - contain automatically
current

Objects

NameOIDSyntaxAccessStatus
ciscoLwappRogueMIBNotifs
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.0
ciscoLwappRogueMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1
cLRogueConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1
cLRoguePolicyConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.1
cLRogueAdhocRogueReportEnable
OBJECT-TYPE
This object is used to turn on and off ad-hoc rogue reporting. A value of 'true' indicates that adhoc rogue reporting is enabled. A value of 'false' indicates that adhoc rogue reporting is disabled.
1.3.6.1.4.1.9.9.610.1.1.1.1TruthValueread-writecurrent
cLRogueReportInterval
OBJECT-TYPE
This object specifies the rogue report interval, which is the interval that monitor mode APs send rogue detection details to the controller.
1.3.6.1.4.1.9.9.610.1.1.1.2Unsigned32 (10..300)read-writecurrent
cLRogueMinimumRssi
OBJECT-TYPE
This object specifies the minimum value of RSSI considered for detection of rogues.
1.3.6.1.4.1.9.9.610.1.1.1.3Integer32 (-128..-70)read-writecurrent
cLRogueTransientInterval
OBJECT-TYPE
This object specifies the rogue transient interval. A value of '0' specifies that an AP sends rogue detection details to the controller as soon as it detects a rogue. A non-zero value specifies that an AP sends rogue detection details to the controller if it hears the rogue more than once in the specified interval.
1.3.6.1.4.1.9.9.610.1.1.1.4Unsigned32 (0 | 120..1800)read-writecurrent
cLRogueClientNumThreshold
OBJECT-TYPE
This object specifies the number of clients the Rogue AP can have. A value of zero indicates no limitation on the number of clients the Rogue AP can have.
1.3.6.1.4.1.9.9.610.1.1.1.5Unsigned32read-writecurrent
cLRogueDetectionSecurityLevel
OBJECT-TYPE
This object specifies the rogue detection security level. When the object has value of 'low', 'high' or 'critical', controller uses pre-defined rogue detection parameters for the specified security level. When the object has value of 'custom', controller uses the user configured rogue detection parameters. low - security level is low high - security level is high critical - security level is critical custom - customized security level
1.3.6.1.4.1.9.9.610.1.1.1.6INTEGER {low(1), high(2), critical(3), custom(4)}read-writecurrent
cLRogueValidateRogueClientsAgainstMse
OBJECT-TYPE
The object specifies whether the controller validates 'valid' clients which are associating with rogue AP, against Mse. A value of 'enable' indicates that the controller does validates 'valid'clients which are associating with rogue AP, against Mse. A value of 'disable' indicates that the controller does not validates 'valid' clients which are associating with rogue AP, against Mse.
1.3.6.1.4.1.9.9.610.1.1.1.7INTEGER {disable(1), enable(2)}read-writecurrent
cLRogueValidateRogueApsAgainstAAA
OBJECT-TYPE
This flag should be turned on to allow the controller to validate 'valid' Aps against radius server.
1.3.6.1.4.1.9.9.610.1.1.1.8INTEGER {disable(1), enable(2)}read-writecurrent
cLRogueApPollingInterval
OBJECT-TYPE
This object represents the polling interval of rogue Ap in seconds.
1.3.6.1.4.1.9.9.610.1.1.1.9Unsigned32read-writecurrent
cLRogueContainAutoRateEnable
OBJECT-TYPE
This object is used to turn on and off rogue containment automatic rate selection. A value of 'true' indicates that automatic rate selection will be enabled. A value of 'false' indicates that automatic rate selection will be disabled.
1.3.6.1.4.1.9.9.610.1.1.1.10TruthValueread-writecurrent
cLRogueAdhocRogueNotifEnabled
OBJECT-TYPE
The object to control the generation of cLRogueAdhocDetected notification. A value of 'true' indicates that the agent generates cLRogueAdhocDetected notification. A value of 'false' indicates that the agent doesn't generate cLRogueAdhocDetected notification.
1.3.6.1.4.1.9.9.610.1.1.2TruthValueread-writecurrent
cLRogueRuleConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.3
cLRuleConfigTable
OBJECT-TYPE
This table provides the configuration needed by the controller for classifying rogue APs. The user defines the custom rules which are used to classify the APs under different classification types. When a new rule is created priority will be assigned automatically by controller, highest priority given to rule which are created first. Also if user is changing the priority of a rule manually, the new priority should not be used by any other existing rule.
1.3.6.1.4.1.9.9.610.1.1.3.1not-accessiblecurrent
cLRuleConfigEntry
OBJECT-TYPE
Each entry represents a conceptual row (as identified by a rule name)in cLRuleConfigTable.
1.3.6.1.4.1.9.9.610.1.1.3.1.1not-accessiblecurrent
cLRuleName
OBJECT-TYPE
This object represents the rule name to identify this entry.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.1SnmpAdminString (SIZE(1..32))not-accessiblecurrent
cLRuleRogueType
OBJECT-TYPE
This object specifies the classification applied to the rogue AP that matches this rule. friendly - known and acknowledged rogue AP malicious - unknown AP that matches user defined malicious rules unclassified - an unknown AP that did not match malicious or friendly rules. custom - user can configure rogue detection parameters.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.2INTEGER {friendly(1), malicious(2), unclassified(3), custom(4)}read-createcurrent
cLRuleConditionsMatch
OBJECT-TYPE
This object specifies how the conditions defined by corresponding instances of cLConditionType, are matched under each rule. all - all the conditions defined per rule should be matched any - any conditions defined per rule can be matched.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.3INTEGER {all(1), any(2)}read-createcurrent
cLRulePriority
OBJECT-TYPE
This object specifies the order in which the rules will be applied. The rules will be applied from lowest to highest and gaps are allowed. Each rule must have and unique value for this object.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.4Unsigned32read-createcurrent
cLRuleEnable
OBJECT-TYPE
This object specifies whether this rule is enabled or not. A value of 'true' specifies this rule is enabled. A value of 'false' specifies this rule is disabled.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.5TruthValueread-createcurrent
cLRuleStorageType
OBJECT-TYPE
This object specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.6StorageTyperead-createcurrent
cLRuleRowStatus
OBJECT-TYPE
This object specifies the status column for a conceptual row in this table. All writable objects in this row may be modified when the row is active.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.7RowStatusread-createcurrent
cLRuleSeverityScore
OBJECT-TYPE
This object specifies the custom classification severity score of the rules. This object is applicable when cLRuleRogueType is configured as 'custom'.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.8Unsigned32read-createcurrent
cLRuleClassificationName
OBJECT-TYPE
This object represents the rule classification name. This object is applicable when cLRuleRogueType is configured as 'custom'.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.9SnmpAdminStringread-writecurrent
cLRuleNotifyType
OBJECT-TYPE
This object specifies how the notification is defined for the rogue rule. global - Configure notification to trap receiver only. local - Configure notification to monitor page(local) only. none - Configure no notification to monitor page and trap receiver. all - Configure notify to both monitor page and trap receiver.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.10INTEGER {global(1), local(2), none(3), all(4)}read-createcurrent
cLRuleStateType
OBJECT-TYPE
This object specifies the rule to configure state of the rogue. alert - Configure alert state on rogue ap. contain - Configure contain state on rogue ap. internal - Configure internal state on rogue ap. external - Configure external state on rogue ap. external - Configure deletion state on rogue ap.
1.3.6.1.4.1.9.9.610.1.1.3.1.1.11INTEGER {alert(1), contain(2), internal(3), external(4), delete(5)}read-createcurrent
cLConditionConfigTable
OBJECT-TYPE
This table represents the configuration of conditions that can be applied to a rule.
1.3.6.1.4.1.9.9.610.1.1.3.2not-accessiblecurrent
cLConditionConfigEntry
OBJECT-TYPE
Each entry represents a conceptual row in cLConditionConfigTable, as identified by a specific condition name to be applied on a specific rule name.
1.3.6.1.4.1.9.9.610.1.1.3.2.1not-accessiblecurrent
cLConditionName
OBJECT-TYPE
This object represents the condition name.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.1SnmpAdminString (SIZE(1..64))not-accessiblecurrent
cLConditionType
OBJECT-TYPE
This object specifies the condition type for this condition associated with a rule. managedSsid - matches managed SSID rssi - required minimum RSSI duration - limited to this time duration clientCount - number of associated clients noEncryption - no encryption rule userConfigSsid - matches user configured SSID
1.3.6.1.4.1.9.9.610.1.1.3.2.1.2INTEGER {managedSsid(1), rssi(2), duration(3), clientCount(4), noEncryption(5), userConfigSsid(6), wildCardSsid(7)}read-createcurrent
cLConditionValue
OBJECT-TYPE
This object specifies the value associated with the condition type as specified by the corresponding cLConditionType instance. If cLConditionType is 'userConfigSsid', then corresponding 'cLConditionValue' can only take on the value of zero.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.3Integer32read-createcurrent
cLConditionEnable
OBJECT-TYPE
This object specifies whether matching against this condition is enabled or not. A value of 'true' indicates matching against this condition is enabled. A value of 'false' indicates matching against this condition is disabled.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.4TruthValueread-createcurrent
cLConditionStorageType
OBJECT-TYPE
This object specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.5StorageTyperead-createcurrent
cLConditionRowStatus
OBJECT-TYPE
This object specifies the status column for a conceptual row in this table. All writable objects except cLConditionType in this row may be modified when the row is active.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.6RowStatusread-createcurrent
cLConditionRssi
OBJECT-TYPE
This object specifies the minimum value of RSSI that a rogue AP must have in order to match cLConditionType of 'rssi'.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.7Integer32read-createcurrent
cLConditionClientCount
OBJECT-TYPE
This object specifies the minimum value of client count that a rogue AP must have in order to match cLConditionType of 'clientCount'.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.8Unsigned32read-createcurrent
cLConditionNoEncryptionEnabled
OBJECT-TYPE
This object specifies whether or not encryption is enabled. A value of 'true' indicates that encryption is not enabled. A value of 'false' indicates that encryption is enabled for this condition.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.9TruthValueread-createcurrent
cLConditionManagedSsidEnabled
OBJECT-TYPE
This object specifies whether or not managed SSID is enabled. A value of 'true' indicates managed SSID is enabled. A value of 'false' indicates managed SSID is not enabled for this condition.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.10TruthValueread-createcurrent
cLConditionDuration
OBJECT-TYPE
This object specifies the minimum value of duration, in seconds, a rogue AP must be present in order to match cLConditionType of 'duration'.
1.3.6.1.4.1.9.9.610.1.1.3.2.1.11Unsigned32read-createcurrent
cLConditionSsidConfigTable
OBJECT-TYPE
This table represents the configuration of SSID for a rule. This is applicable to conditions within a rule which has the corresponding cLConditionType taking on the value of 'userConfigSsid'.
1.3.6.1.4.1.9.9.610.1.1.3.3not-accessiblecurrent
cLConditionSsidConfigEntry
OBJECT-TYPE
Each entry represents a conceptual row in cLConditionSsidConfigTable.
1.3.6.1.4.1.9.9.610.1.1.3.3.1not-accessiblecurrent
cLConditionSsidValue
OBJECT-TYPE
This object represents the SSID value for this condition associated with a rule.
1.3.6.1.4.1.9.9.610.1.1.3.3.1.1SnmpAdminString (SIZE(1..32))not-accessiblecurrent
cLConditionSsidStorageType
OBJECT-TYPE
This object specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.610.1.1.3.3.1.2StorageTyperead-createcurrent
cLConditionSsidRowStatus
OBJECT-TYPE
This object specifies the status column for a conceptual row in this table. All writable objects in this row may not be modified when the row is active.
1.3.6.1.4.1.9.9.610.1.1.3.3.1.3RowStatusread-createcurrent
cLConditionSsidType
OBJECT-TYPE
This object specifies the ssid type that is present in the rule condition.
1.3.6.1.4.1.9.9.610.1.1.3.3.1.4INTEGER {normal(1), wildCard(2)}read-createcurrent
cLRogueIgnoreListConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.4
cLRogueIgnoreListTable
OBJECT-TYPE
The table lists the APs, as identified by the AP's mac address, which should not be treated as rogue by the controller. These APs are the autonomous access points that have been manually added to WCS.
1.3.6.1.4.1.9.9.610.1.1.4.1not-accessiblecurrent
cLRogueIgnoreListEntry
OBJECT-TYPE
Each entry represents a conceptual row in this table. There will be a row for each entry of the autonomous APs which are manually added to WCS. When the autonomous AP is no longer managed by WCS, the corresponding row entry will be removed.
1.3.6.1.4.1.9.9.610.1.1.4.1.1not-accessiblecurrent
cLRogueIgnoreListMACAddress
OBJECT-TYPE
This is the MAC Address of the AP to be put in the rogue ignore list.
1.3.6.1.4.1.9.9.610.1.1.4.1.1.1MacAddressnot-accessiblecurrent
cLRogueIgnoreListStorageType
OBJECT-TYPE
This object specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.610.1.1.4.1.1.2StorageTyperead-createcurrent
cLRogueIgnoreListRowStatus
OBJECT-TYPE
This object specifies the status of the conceptual row. All writable objects in this row may not be modified when the row is active.
1.3.6.1.4.1.9.9.610.1.1.4.1.1.3RowStatusread-createcurrent
cLRldpAutoContainConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.5
cLRldpAutoContainFeatureOnWiredNetwork
OBJECT-TYPE
This object represents the RLDP Auto contain feature status. disable - automatic containment of rogues on wired network is disabled enable - automatic containment of rogues on wired network is enabled NOTE: Using this feature may have legal consequences!!!
1.3.6.1.4.1.9.9.610.1.1.5.1INTEGER {disable(1), enable(2)}read-writecurrent
cLRldpAutoContainRoguesAdvertisingSsid
OBJECT-TYPE
This is the action with respect to auto containment feature, that should be taken when switch detects rogues that are advertising our SSID. NOTE: Using this feature may have legal consequences!!!
1.3.6.1.4.1.9.9.610.1.1.5.2CLAutoContainActionsread-writecurrent
cLRldpAutoContainAdhocNetworks
OBJECT-TYPE
This is the action with respect to auto containment feature, that should be taken when adhoc networks are detected by the switch. NOTE: Using this feature may have legal consequences!!!
1.3.6.1.4.1.9.9.610.1.1.5.3CLAutoContainActionsread-writecurrent
cLRldpAutoContainTrustedClientsOnRogueAps
OBJECT-TYPE
This is the action with respect to auto containment feature, that should be taken when trusted clients that are associated to rogue APs are detected by the switch. NOTE: Using this feature may have legal consequences!!!
1.3.6.1.4.1.9.9.610.1.1.5.4CLAutoContainActionsread-writecurrent
cLRldpAutoContainLevel
OBJECT-TYPE
This object is used to specify the level of auto containment. The level actually denotes the number of APs that should be used by the controller for auto containment. A value of '0' means level of auto containment is selected automatically.
1.3.6.1.4.1.9.9.610.1.1.5.5Integer32 (0..4)read-writecurrent
cLRldpAutoContainOnlyforMonitorModeAps
OBJECT-TYPE
This object is used to specify if auto containment should be done only using monitor mode APs or not. disable - auto containment will be done using all APs irrespective of the mode enable - auto containment will be done only using monitor mode APs.
1.3.6.1.4.1.9.9.610.1.1.5.6INTEGER {disable(1), enable(2)}read-writecurrent
cLRldpAutoContainFlexStandaloneAp
OBJECT-TYPE
This object is used to specify if auto containment should be done on FlexConnect standalone APs. disable - auto containment will not be done on FlexConnect standalone APs enable - auto containment will be done on FlexConnect standalone APs.
1.3.6.1.4.1.9.9.610.1.1.5.7INTEGER {disable(1), enable(2)}read-writecurrent
cLRogueApConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.6
cLRogueApTable
OBJECT-TYPE
The table lists the configured rogue APs in the system.
1.3.6.1.4.1.9.9.610.1.1.6.1not-accessibledeprecated
cLRogueApEntry
OBJECT-TYPE
An entry containing contains management information of a particular rogue AP. An entry can be created, or deleted by using cLRogueApRowStatus.
1.3.6.1.4.1.9.9.610.1.1.6.1.1not-accessibledeprecated
cLRogueApMACAddress
OBJECT-TYPE
MAC Address of a rogue AP.
1.3.6.1.4.1.9.9.610.1.1.6.1.1.1MacAddressnot-accessibledeprecated
cLRogueApClassType
OBJECT-TYPE
This object specifies the type of a rogue AP. friendly - existing known, Acknowledge, and Trust missing rogue states are classified as Friendly. malicious - unknown AP that could be a threat. unclassified - an unknown AP or rogue AP is identified but it does not belong to Friendly or Malicious rogue types. custom - AP that matches user defined custom rules.
1.3.6.1.4.1.9.9.610.1.1.6.1.1.2INTEGER {friendly(1), malicious(2), unclassified(3), custom(4)}read-createdeprecated
cLRogueApState
OBJECT-TYPE
This objects specifies the state in which the rogue AP is. pending - a read-only value indicates that rogue AP can not be state to any of the following type. alert - rogue AP can be a potential threat. Trap will be sent out to trap recipients. detectedLrad - a read-only value indicates that a LRAD that got detected as rogue. known - a read-only value indicates that an internal AP which is not on the same switch. acknowledge - a read-only value indicates that an external AP whose existence is acceptable and not a threat(probably from vendor other than cisco). contained - containment is initiated and ongoing. threat - rogue AP is found on wired network. containedPending - a read-only value indicates that no AP resources available for containment. knownContained - a read-only value indicates that no longer used. trustedMissing - rogue AP is friendly but there is no slot for friendly AP. initializing - a read-only value indicates that rogue AP is being initialized. For a friendly rogue AP, only two states are valid: 'known' and 'acknowledge'. 'known', 'knownContained' and 'trustedMissing' can appear in known rogue list. Known rogues can be pre-provisioned and known rogues state can be changed to 'alert'.
1.3.6.1.4.1.9.9.610.1.1.6.1.1.3INTEGER {pending(1), alert(2), detectedLrad(3), known(4), acknowledge(5), contained(6), threat(7), containedPending(8), knownContained(9), trustedMissing(10), initializing(11)}read-createdeprecated
cLRogueApStorageType
OBJECT-TYPE
This object specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.610.1.1.6.1.1.4StorageTyperead-createdeprecated
cLRogueApRowStatus
OBJECT-TYPE
The status of the conceptual row. All writable objects in this row may be modified when the row is active.
1.3.6.1.4.1.9.9.610.1.1.6.1.1.5RowStatusread-createdeprecated
cLRogueApListTable
OBJECT-TYPE
Rogue Table. This table lists all the Rogue APs detected by Detecting APs.
1.3.6.1.4.1.9.9.610.1.1.6.2not-accessiblecurrent
cLRogueApListEntry
OBJECT-TYPE
An entry containing contains management information of a particular rogue AP.
1.3.6.1.4.1.9.9.610.1.1.6.2.1not-accessiblecurrent
cLRogueApMacAddr
OBJECT-TYPE
MAC Address of the rogue AP Interface.
1.3.6.1.4.1.9.9.610.1.1.6.2.1.1MacAddressnot-accessiblecurrent
cLRogueApSeverityScore
OBJECT-TYPE
This object represents the severity score of the AP Interface.
1.3.6.1.4.1.9.9.610.1.1.6.2.1.2Unsigned32read-onlycurrent
cLRogueApRuleName
OBJECT-TYPE
This object represents the rule name that is applied.
1.3.6.1.4.1.9.9.610.1.1.6.2.1.3SnmpAdminStringread-onlycurrent
cLRogueApClassName
OBJECT-TYPE
This object represents the class name that is applied.
1.3.6.1.4.1.9.9.610.1.1.6.2.1.4SnmpAdminStringread-onlycurrent
cLRogueClientConfig
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.7
cLRogueClientTable
OBJECT-TYPE
Rogue Table. This table lists all the Rogue Clients detected by APs.
1.3.6.1.4.1.9.9.610.1.1.7.1not-accessiblecurrent
cLRogueClientEntry
OBJECT-TYPE
An Entry in cLRogueClientTable.
1.3.6.1.4.1.9.9.610.1.1.7.1.1not-accessiblecurrent
cLRogueClientMacAddress
OBJECT-TYPE
MAC Address of the rogue AP Client Interface.
1.3.6.1.4.1.9.9.610.1.1.7.1.1.1MacAddressnot-accessiblecurrent
cLRogueClientGatewayMacAddress
OBJECT-TYPE
This object represents the MAC Address of the rogue AP Client gateway.
1.3.6.1.4.1.9.9.610.1.1.7.1.1.2MacAddressread-onlycurrent
cLRogueApDetectingApDetails
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.1.1.8
cLRogueAPDetectingAPTable
OBJECT-TYPE
Rogue Station Table. This table lists all the Detecting AP Interfaces that detected a particular Rogue.
1.3.6.1.4.1.9.9.610.1.1.8.1not-accessiblecurrent
cLRogueAPDetectingAPEntry
OBJECT-TYPE
An entry in cLRogueAPDetectingAPEntry.
1.3.6.1.4.1.9.9.610.1.1.8.1.1not-accessiblecurrent
cLRogueAPDetectingAPMacAddress
OBJECT-TYPE
This object represents the MAC Address of Detecting AP Interface that Detected the Rogue.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.1MacAddressread-onlycurrent
cLRogueAPDetectingAPSlotId
OBJECT-TYPE
This object represent the slot and band index of the Detecting AP Interface that detected the Rogue. Use cLRogueAPPhysicalAPSlot for Slot ID of the Detecting AP Interface.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.2Unsigned32 (0..2)read-onlycurrent
cLRogueAPRadioType
OBJECT-TYPE
This object represents the Detecting AP Interface type that detected the Rogue.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.3INTEGER {dot11b(1), dot11a(2), dot11abgn(3), uwb(4), dot11g(5), dot11n24(6), dot11n5(7), unknown(8), dot11ac(9), dot11ax24(10), dot11ax5(11), dot11ax6(12)}read-onlycurrent
cLRogueAPDetectingAPName
OBJECT-TYPE
This object represents the name of Detecting AP Interface that detected the Rogue.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.4SnmpAdminStringread-onlycurrent
cLRogueAPChannelNumber
OBJECT-TYPE
This object represents the advertised Channel Number of the Detecting AP Interface picked up from the Rogue. Use in conjuction with cLRogueAPRadioType to resolve ambiguity between channels numbers of 2.4GHz and 5GHz bands versus 6GHz band.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.5Integer32read-onlycurrent
cLRogueAPSsid
OBJECT-TYPE
This object represents the SSID Advertised by Rogue Station.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.6SnmpAdminStringread-onlycurrent
cLRogueAPHiddenSsid
OBJECT-TYPE
This object represents the hidden ssid indication on this detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.7INTEGER {disabled(0), enabled(1)}read-onlycurrent
cLRogueAPDetectingAPRSSI
OBJECT-TYPE
This object represents the Rogue RSSI as seen by Detecting AP Interface.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.8Integer32read-onlycurrent
cLRogueAPContainmentMode
OBJECT-TYPE
This object represents the containment mode used by the AP if the rogue is in 'contained' state. A value of '0' indicates invalid containment mode. A value of '1' indicates deauth broadcast used for contianment. A value of '2' indicates CFP containment. A value of '3' indicates cleint contianment. A value of '4' indicates adhoc containment. A value of '5' indicates max value i.e invalid. A value of '99' indicates unknown contianment type.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.9INTEGER {invalid(0), deauthBroadcast(1), cfp(2), clientContianment(3), adhocContainment(4), max(5), unknown(99)}read-onlycurrent
cLRogueAPContainmentChannelCount
OBJECT-TYPE
This object represents the number of channels used for rogue containment.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.10Unsigned32read-onlycurrent
cLRogueAPContainmentChannels
OBJECT-TYPE
This object represents the comma separated string of channels used for rogue containment.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.11SnmpAdminStringread-onlycurrent
cLRogueAPDetectingAPLastHeard
OBJECT-TYPE
This object represents the no. of seconds ago when this Rogue was last heard by this AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.12Counter32read-onlycurrent
cLRogueAPDetectingAPWepMode
OBJECT-TYPE
This object represents the WEP mode on this detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.13INTEGER {disabled(0), enabled(1)}read-onlycurrent
cLRogueAPDetectingAPPreamble
OBJECT-TYPE
This object represents the Preamble on this detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.14INTEGER {long(0), short(1), notSupported(2)}read-onlycurrent
cLRogueAPDetectingAPWpaMode
OBJECT-TYPE
This object represents the WPA mode on this detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.15INTEGER {disabled(0), enabled(1)}read-onlycurrent
cLRogueAPDetectingAPWpa2Mode
OBJECT-TYPE
This object represents the WPA2 mode on this detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.16INTEGER {disabled(0), enabled(1)}read-onlycurrent
cLRogueAPDetectingAPFTMode
OBJECT-TYPE
This object represents the Fast transition mode on this detecting AP. A value of 'disabled' indicates FT is disabled on the detecting AP. A value of 'enabled' indicates FT is enabled on the detecting AP.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.17INTEGER {disabled(0), enabled(1)}read-onlycurrent
cLRogueAPDetectingAPSNR
OBJECT-TYPE
This object represents the SNR seen by Detecting AP Interface from Rogue
1.3.6.1.4.1.9.9.610.1.1.8.1.1.18Integer32read-onlycurrent
cLRogueAPChannelWidth
OBJECT-TYPE
This object represents the represents the channel width of the detecting AP. Each enumeration represents which part of the band the detecting AP is configured.
1.3.6.1.4.1.9.9.610.1.1.8.1.1.19INTEGER {five(1), ten(2), twenty(3), aboveforty(4), belowforty(5), abovefortyAndEighty(6), abovefortyBelowEighty(7), aboveEightyBelowforty(8), belowfortyBelowEighty(9), aboveOnesixtyAboveFortyAboveEighty(10), belowOnesixtyAboveFortyAboveEighty(11), aboveOnesixtyBelowFortyAboveEighty(12), belowOnesixtyBelowFortyAboveEighty(13), aboveOnesixtyAboveFortyBelowEighty(14), belowOnesixtyAboveFortyBelowEighty(15), aboveOnesixtyBelowFortyBelowEighty(16), belowOnesixtyBelowFortyBelowEighty(17)}read-onlycurrent
cLRogueAPPhysicalAPSlot
OBJECT-TYPE
Reporting AP Physical Slot ID
1.3.6.1.4.1.9.9.610.1.1.8.1.1.20Integer32read-onlycurrent
ciscoLwappRogueMIBConform
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.2
ciscoLwappRogueMIBCompliances
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.2.1
ciscoLwappRogueMIBGroups
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.2.2
ciscoLwappRogueMIBNotifObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.610.3
cLRogueApContainmentLevel
OBJECT-TYPE
This object specifies the state of the rogue contained, Higher the level of containment, more the number of detecting APs that are used to contain it. Value between 1 to 4 is for 'contained' state. Value of 0 means 'contained' state is stopped.
1.3.6.1.4.1.9.9.610.3.1INTEGER {unassigned(0), level1(1), level2(2), level3(3), level4(4)}accessible-for-notifycurrent
cLRogueClientTotalDetectingAPs
OBJECT-TYPE
This object represents the total number of detecting APs that detected this rogue.
1.3.6.1.4.1.9.9.610.3.2Integer32read-onlycurrent
cLRogueClientFirstReported
OBJECT-TYPE
This object represents the time Stamp when this Rogue client was First Detected.
1.3.6.1.4.1.9.9.610.3.3SnmpAdminStringread-onlycurrent
cLRogueClientLastReported
OBJECT-TYPE
This object represents the time Stamp `when this Rogue client was Last Detected.
1.3.6.1.4.1.9.9.610.3.4SnmpAdminStringread-onlycurrent
cLRogueClientGatewayMac
OBJECT-TYPE
Gateway Mac Address of Rogue Station.
1.3.6.1.4.1.9.9.610.3.5MacAddressnot-accessiblecurrent
cLLastDetectingRadioMACAddress
OBJECT-TYPE
Last detecting AP of the rogue client.
1.3.6.1.4.1.9.9.610.3.6MacAddressnot-accessiblecurrent

Notifications

NameOIDStatus
cLRogueAdhocRogueDetected
NOTIFICATION-TYPE
This notification is generated by the controller when a a rogue is detected. The name of the AP that detected this rogue is sent in the notification.
1.3.6.1.4.1.9.9.610.0.1current
cLRogueClientExceededThreshold
NOTIFICATION-TYPE
This notification is generated by the controller when a rogue client exceeds its maximum threshold configured. The details of Rogue AP and Rogue Clients is sent in the notification.
1.3.6.1.4.1.9.9.610.0.2current
cLRogueExceededClientRemovedThreshold
NOTIFICATION-TYPE
This notification is generated by the controller when a rogue client is removed from the rogue AP and still the client count of the rogue AP is greater than the maximum threshold configured. The details of Rogue AP and Rogue Clients is sent in the notification.
1.3.6.1.4.1.9.9.610.0.3current
cLRogueApRuleContained
NOTIFICATION-TYPE
This notification is generated by the controller when a rogue AP is contained due to Rogue Rule.
1.3.6.1.4.1.9.9.610.0.4current
cLRogueClientDetected
NOTIFICATION-TYPE
This notification is generated by the controller when a rogue client is detected.
1.3.6.1.4.1.9.9.610.0.5current

Conformance

NameOIDStatus
ciscoLwappRogueMIBCompliance
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.1deprecated
ciscoLwappRogueMIBComplianceRev1
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.2deprecated
ciscoLwappRogueMIBComplianceRev2
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.3deprecated
ciscoLwappRogueMIBComplianceRev3
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.4deprecated
ciscoLwappRogueMIBComplianceRev4
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.5deprecated
ciscoLwappRogueMIBComplianceRev5
MODULE-COMPLIANCE
The compliance statement for the SNMP entities that implement the ciscoLwappRogueMIB module.
1.3.6.1.4.1.9.9.610.2.1.6current
ciscoLwappRogueConfigGroup
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller.
1.3.6.1.4.1.9.9.610.2.2.1current
ciscoLwappRogueNotifsGroup
NOTIFICATION-GROUP
This collection of objects specifies the notifications for rogue detection.
1.3.6.1.4.1.9.9.610.2.2.2current
ciscoLwappRogueConfigSup1Group
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller. ciscoLwappRogueConfigSup1Group object is superseded by ciscoLwappRogueConfigSup2Group.
1.3.6.1.4.1.9.9.610.2.2.3deprecated
ciscoLwappRogueConfigSup2Group
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller. ciscoLwappRogueConfigSup2Group object is superseded by ciscoLwappRogueConfigSup3Group.
1.3.6.1.4.1.9.9.610.2.2.4deprecated
ciscoLwappRogueConfigSup3Group
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller.
1.3.6.1.4.1.9.9.610.2.2.5current
ciscoLwappRogueConfigSup4Group
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller.
1.3.6.1.4.1.9.9.610.2.2.6current
ciscoLwappRogueConfigSup5Group
OBJECT-GROUP
This collection of objects represent the rogue configuration on the controller.
1.3.6.1.4.1.9.9.610.2.2.7current