MIBs Depot

CISCO-TRUSTSEC-POLICY-MIB

Registered at
1.3.6.1.4.1.9.9.713
Last updated
2012-12-19 00:00
Organization
Cisco Systems, Inc.
Revisions
2012-12-19 00:00, 2009-11-06 00:00
Namespace
cisco
Source file
CISCO-TRUSTSEC-POLICY-MIB
Digest
sha256:0f2176af61a7a78d02d2d5f9940755de3267f6a7f8b73f98a327d340646532aa

Description

This MIB module defines managed objects that facilitate the management of various policies within the Cisco Trusted Security (TrustSec) infrastructure. The information available through this MIB includes: o Device and interface level configuration for enabling SGACL (Security Group Access Control List) enforcement on Layer2/3 traffic. o Administrative and operational SGACL mapping to Security Group Tag (SGT). o Various statistics counters for traffic subject to SGACL enforcement. o TrustSec policies with respect to peer device. o Interface level configuration for enabling the propagation of SGT along with the Layer 3 traffic in portions of network which does not have the capability to support TrustSec feature. o TrustSec policies with respect to SGT propagation with Layer 3 traffic. The following terms are used throughout this MIB: VRF: Virtual Routing and Forwarding. SGACL: Security Group Access Control List. ACE: Access Control Entries. SXP: SGT Propagation Protocol. SVI: Switch Virtual Interface. IPM: Identity Port Mapping. SGT (Security Group Tag) is a unique 16 bits value assigned to every security group and used by network devices to enforce SGACL. Peer is another device connected to the local device on the other side of a TrustSec link. Default Policy: Policy applied to traffic when there is no explicit policy between the SGT associated with the originator of the traffic and the SGT associated with the destination of the traffic.

Contact

Cisco Systems Customer Service Postal: 170 W Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS E-mail: cs-lan-switch-snmp@cisco.com

Imports

FromSymbols
CISCO-SMIciscoMgmt
CISCO-TCCisco2KVlanList, CiscoVrfName
CISCO-TRUSTSEC-TC-MIBCtsAclList, CtsAclListOrEmpty, CtsAclName, CtsAclNameOrEmpty, CtsGenerationId, CtsSecurityGroupTag, CtsSgaclMonitorMode
IF-MIBifIndex
INET-ADDRESS-MIBInetAddress, InetAddressPrefixLength, InetAddressType
Q-BRIDGE-MIBVlanIndex
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP
SNMPv2-SMICounter64, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDateAndTime, DisplayString, RowStatus, StorageType, TEXTUAL-CONVENTION, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

BRIDGE-MIB
CISCO-SMI
CISCO-TC
CISCO-TRUSTSEC-POLICY-MIB
CISCO-TRUSTSEC-TC-MIB
IANAifType-MIB
IF-MIB
INET-ADDRESS-MIB
P-BRIDGE-MIB
Q-BRIDGE-MIB
RFC1158-MIB
RFC1271-MIB
RMON-MIB
RMON2-MIB
SNMP-FRAMEWORK-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC
TOKEN-RING-RMON-MIB

Objects

NameOIDSyntaxAccessStatus
ciscoTrustSecPolicyMIBNotifs
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.0
ciscoTrustSecPolicyMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1
ctspSgacl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.1
ctspSgaclGlobals
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.1.1
ctspSgaclEnforcementEnable
OBJECT-TYPE
This object specifies whether SGACL enforcement for all Layer 3 interfaces (excluding SVIs) is enabled at the managed system. 'none' indicates that SGACL enforcement for all Layer 3 interfaces (excluding SVIs) is disabled. 'l3Only' indicates that SGACL enforcement is enabled on every TrustSec capable Layer3 interface (excluding SVIs) in the device.
1.3.6.1.4.1.9.9.713.1.1.1.1INTEGER {none(1), l3Only(2)}read-writecurrent
ctspSgaclIpv4DropNetflowMonitor
OBJECT-TYPE
This object specifies an existing flexible netflow monitor name used to collect and export the IPv4 traffic dropped packets statistics due to SGACL enforcement. The zero-length string indicates that no such netflow monitor is configured in the device.
1.3.6.1.4.1.9.9.713.1.1.1.2SnmpAdminStringread-writecurrent
ctspSgaclIpv6DropNetflowMonitor
OBJECT-TYPE
This object specifies an existing flexible netflow monitor name used to collect and export the IPv6 traffic dropped packets statistics due to SGACL enforcement. The zero-length string indicates that no such netflow monitor is configured in the device.
1.3.6.1.4.1.9.9.713.1.1.1.3SnmpAdminStringread-writecurrent
ctspVlanConfigTable
OBJECT-TYPE
This table lists the SGACL enforcement for Layer 2 and Layer 3 switched packet in a VLAN as well as VRF information for VLANs in the device.
1.3.6.1.4.1.9.9.713.1.1.1.4not-accessiblecurrent
ctspVlanConfigEntry
OBJECT-TYPE
Each row contains the SGACL enforcement information for Layer 2 and Layer 3 switched packets in a VLAN identified by its VlanIndex value. Entry in this table is populated for VLANs which contains SGACL enforcement or VRF configuration.
1.3.6.1.4.1.9.9.713.1.1.1.4.1not-accessiblecurrent
ctspVlanConfigIndex
OBJECT-TYPE
This object indicates the VLAN-ID of this VLAN.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.1VlanIndexnot-accessiblecurrent
ctspVlanConfigSgaclEnforcement
OBJECT-TYPE
This object specifies the configured SGACL enforcement status for this VLAN i.e., 'true' = enabled and 'false' = disabled.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.2TruthValueread-createcurrent
ctspVlanSviActive
OBJECT-TYPE
This object indicates if there is an active SVI associated with this VLAN. 'true' indicates that there is an active SVI associated with this VLAN. and SGACL is enforced for both Layer 2 and Layer 3 switched packets within that VLAN. 'false' indicates that there is no active SVI associated with this VLAN, and SGACL is only enforced for Layer 2 switched packets within that VLAN.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.3TruthValueread-onlycurrent
ctspVlanConfigVrfName
OBJECT-TYPE
This object specifies an existing VRF where this VLAN belongs to. The zero length value indicates this VLAN belongs to the default VRF.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.4CiscoVrfNameread-createcurrent
ctspVlanConfigStorageType
OBJECT-TYPE
The objects specifies the storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.5StorageTyperead-createcurrent
ctspVlanConfigRowStatus
OBJECT-TYPE
The status of this conceptual row entry. This object is used to manage creation and deletion of rows in this table. When this object value is 'active', other writable objects in the same row cannot be modified.
1.3.6.1.4.1.9.9.713.1.1.1.4.1.6RowStatusread-createcurrent
ctspSgaclMappings
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.1.2
ctspConfigSgaclMappingTable
OBJECT-TYPE
This table contains the SGACLs information which is applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.1not-accessiblecurrent
ctspConfigSgaclMappingEntry
OBJECT-TYPE
Each row contains the SGACL mapping to source and destination SGT for a certain traffic type as well as status of this instance. A row instance can be created or removed by setting the appropriate value of its RowStatus object.
1.3.6.1.4.1.9.9.713.1.1.2.1.1not-accessiblecurrent
ctspConfigSgaclMappingIpTrafficType
OBJECT-TYPE
This object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspConfigSgaclMappingDestSgt
OBJECT-TYPE
This object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.2CtsSecurityGroupTagnot-accessiblecurrent
ctspConfigSgaclMappingSourceSgt
OBJECT-TYPE
This object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.3CtsSecurityGroupTagnot-accessiblecurrent
ctspConfigSgaclMappingSgaclName
OBJECT-TYPE
This object specifies the list of existing SGACLs which is administratively configured to apply to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.4CtsAclListread-createcurrent
ctspConfigSgaclMappingStorageType
OBJECT-TYPE
The storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.5StorageTyperead-createcurrent
ctspConfigSgaclMappingRowStatus
OBJECT-TYPE
This object is used to manage the creation and deletion of rows in this table. ctspConfigSgaclName may be modified at any time.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.6RowStatusread-createcurrent
ctspConfigSgaclMonitor
OBJECT-TYPE
This object specifies whether SGACL monitor mode is turned on for the configured SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.1.1.7CtsSgaclMonitorModeread-createcurrent
ctspDefConfigIpv4Sgacls
OBJECT-TYPE
This object specifies the SGACLs of the unicast default policy for IPv4 traffic. If there is no SGACL configured for unicast default policy for IPv4 traffic, the value of this object is the zero-length string.
1.3.6.1.4.1.9.9.713.1.1.2.2CtsAclListOrEmptyread-writecurrent
ctspDefConfigIpv6Sgacls
OBJECT-TYPE
This object specifies the SGACLs of the unicast default policy for IPv6 traffic. If there is no SGACL configured for unicast default policy for IPv6 traffic, the value of this object is the zero-length string.
1.3.6.1.4.1.9.9.713.1.1.2.3CtsAclListOrEmptyread-writecurrent
ctspDownloadedSgaclMappingTable
OBJECT-TYPE
This table contains the downloaded SGACLs information applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4not-accessiblecurrent
ctspDownloadedSgaclMappingEntry
OBJECT-TYPE
Each row contains the downloaded SGACLs mapping. A row instance is added for each pair of <source SGT, destination SGT> which contains SGACL that is dynamically downloaded from ACS server.
1.3.6.1.4.1.9.9.713.1.1.2.4.1not-accessiblecurrent
ctspDownloadedSgaclDestSgt
OBJECT-TYPE
This object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.1CtsSecurityGroupTagnot-accessiblecurrent
ctspDownloadedSgaclSourceSgt
OBJECT-TYPE
This object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.2CtsSecurityGroupTagnot-accessiblecurrent
ctspDownloadedSgaclIndex
OBJECT-TYPE
This object identifies the downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.3Unsigned32 (1..65535)not-accessiblecurrent
ctspDownloadedSgaclName
OBJECT-TYPE
This object indicates the name of downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.4CtsAclNameread-onlycurrent
ctspDownloadedSgaclGenId
OBJECT-TYPE
This object indicates the generation identification of downloaded SGACL which is applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.5CtsGenerationIdread-onlycurrent
ctspDownloadedIpTrafficType
OBJECT-TYPE
This object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement by this downloaded default policy.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.6Bits {ipv4(0), ipv6(1)}read-onlycurrent
ctspDownloadedSgaclMonitor
OBJECT-TYPE
This object indicates whether SGACL monitor mode is turned on for the downloaded SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.4.1.7CtsSgaclMonitorModeread-onlycurrent
ctspDefDownloadedSgaclMappingTable
OBJECT-TYPE
This table contains the downloaded SGACLs information of the default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5not-accessiblecurrent
ctspDefDownloadedSgaclMappingEntry
OBJECT-TYPE
Each row contains the downloaded SGACLs mapping. A row instance contains the SGACL information of the default policy dynamically downloaded from ACS server for unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1not-accessiblecurrent
ctspDefDownloadedSgaclIndex
OBJECT-TYPE
This object identifies the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.1Unsigned32 (1..65535)not-accessiblecurrent
ctspDefDownloadedSgaclName
OBJECT-TYPE
This object indicates the name of the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.2CtsAclNameread-onlycurrent
ctspDefDownloadedSgaclGenId
OBJECT-TYPE
This object indicates the generation identification of the SGACL of downloaded default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.3CtsGenerationIdread-onlycurrent
ctspDefDownloadedIpTrafficType
OBJECT-TYPE
This object indicates the type of the IP traffic subjected to SGACL enforcement by this downloaded default policy.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.4Bits {ipv4(0), ipv6(1)}read-onlycurrent
ctspDefDownloadedSgaclMonitor
OBJECT-TYPE
This object indicates whether SGACL monitor mode is turned on for the default downloaded SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.5.1.5CtsSgaclMonitorModeread-onlycurrent
ctspOperSgaclMappingTable
OBJECT-TYPE
This table contains the operational SGACLs information applied to unicast IP traffic which carries a source SGT and travels to a destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6not-accessiblecurrent
ctspOperSgaclMappingEntry
OBJECT-TYPE
Each row contains the operational SGACLs mapping. A row instance is added for each pair of <source SGT, destination SGT> which contains the SGACL that either statically configured at the device or dynamically downloaded from ACS server.
1.3.6.1.4.1.9.9.713.1.1.2.6.1not-accessiblecurrent
ctspOperIpTrafficType
OBJECT-TYPE
This object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspOperSgaclDestSgt
OBJECT-TYPE
This object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.2CtsSecurityGroupTagnot-accessiblecurrent
ctspOperSgaclSourceSgt
OBJECT-TYPE
This object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.3CtsSecurityGroupTagnot-accessiblecurrent
ctspOperSgaclIndex
OBJECT-TYPE
This object identifies the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.4Unsigned32 (1..65535)not-accessiblecurrent
ctspOperationalSgaclName
OBJECT-TYPE
This object indicates the name of the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.5CtsAclNameread-onlycurrent
ctspOperationalSgaclGenId
OBJECT-TYPE
This object indicates the generation identification of the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.6CtsGenerationIdread-onlycurrent
ctspOperSgaclMappingSource
OBJECT-TYPE
This object indicates the source of SGACL mapping for the SGACL operationally applied to unicast IP traffic carrying the source SGT to the destination SGT. 'downloaded' indicates that the mapping is downloaded from ACS server. 'configured' indicates that the mapping is locally configured in the device.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.7INTEGER {configured(1), downloaded(2)}read-onlycurrent
ctspOperSgaclConfigSource
OBJECT-TYPE
This object indicates the source of SGACL creation for this SGACL. 'configured' indicates that the SGACL is locally configured in the local device. 'downloaded' indicates that the SGACL is created at ACS server and downloaded to the local device.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.8INTEGER {configured(1), downloaded(2)}read-onlycurrent
ctspOperSgaclMonitor
OBJECT-TYPE
This object indicates whether SGACL monitor mode is turned on for the SGACL enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.6.1.9CtsSgaclMonitorModeread-onlycurrent
ctspDefOperSgaclMappingTable
OBJECT-TYPE
This table contains the operational SGACLs information of the default policy applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7not-accessiblecurrent
ctspDefOperSgaclMappingEntry
OBJECT-TYPE
A row instance contains the SGACL information of the default policy which is either statically configured at the device or dynamically downloaded from ACS server for unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1not-accessiblecurrent
ctspDefOperIpTrafficType
OBJECT-TYPE
This object indicates the type of the unicast IP traffic subjected to default policy enforcement.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspDefOperSgaclIndex
OBJECT-TYPE
This object identifies the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.2Unsigned32 (1..65535)not-accessiblecurrent
ctspDefOperationalSgaclName
OBJECT-TYPE
This object indicates the name of the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.3CtsAclNameread-onlycurrent
ctspDefOperationalSgaclGenId
OBJECT-TYPE
This object indicates the generation identification of the SGACL of default policy operationally applied to unicast IP traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.4CtsGenerationIdread-onlycurrent
ctspDefOperSgaclMappingSource
OBJECT-TYPE
This object indicates the source of SGACL mapping for the SGACL of default policy operationally applied to unicast IP traffic. 'downloaded' indicates that the mapping is downloaded from ACS server. 'configured' indicates that the mapping is locally configured in the device.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.5INTEGER {configured(1), downloaded(2)}read-onlycurrent
ctspDefOperSgaclConfigSource
OBJECT-TYPE
This object indicates the source of SGACL creation for the SGACL of default policy operationally applied to unicast IP traffic. 'downloaded' indicates that the SGACL is created at ACS server and downloaded to the local device. 'configured' indicates that the SGACL is locally configured in the local device.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.6INTEGER {configured(1), downloaded(2)}read-onlycurrent
ctspDefOperSgaclMonitor
OBJECT-TYPE
This object indicates whether SGACL monitor mode is turned on for the SGACL of default policy enforced traffic.
1.3.6.1.4.1.9.9.713.1.1.2.7.1.7CtsSgaclMonitorModeread-onlycurrent
ctspDefConfigIpv4SgaclsMonitor
OBJECT-TYPE
This object specifies whether SGACL monitor mode is turned on for the default configured SGACL enforced Ipv4 traffic.
1.3.6.1.4.1.9.9.713.1.1.2.8CtsSgaclMonitorModeread-writecurrent
ctspDefConfigIpv6SgaclsMonitor
OBJECT-TYPE
This object specifies whether SGACL monitor mode is turned on for the default configured SGACL enforced Ipv6 traffic.
1.3.6.1.4.1.9.9.713.1.1.2.9CtsSgaclMonitorModeread-writecurrent
ctspSgaclMonitorEnable
OBJECT-TYPE
This object specifies whether SGACL monitor mode is turned on for the entire system. It has precedence than the per SGACL ctspConfigSgaclMonitor control. It could act as safety mechanism to turn off monitor in case the monitor feature impact system performance.
1.3.6.1.4.1.9.9.713.1.1.2.10CtsSgaclMonitorModeread-writecurrent
ctspSgaclStatistics
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.1.3
ctspSgtStatsTable
OBJECT-TYPE
This table describes SGACL statistics counters per a pair of <source SGT, destination SGT> that is capable of providing this information.
1.3.6.1.4.1.9.9.713.1.1.3.1not-accessiblecurrent
ctspSgtStatsEntry
OBJECT-TYPE
Each row contains the SGACL statistics related to IPv4 or IPv6 packets carrying the source SGT travelling to the destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.3.1.1not-accessiblecurrent
ctspStatsIpTrafficType
OBJECT-TYPE
This object indicates the type of the unicast IP traffic carrying the source SGT and travelling to destination SGT and subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspStatsDestSgt
OBJECT-TYPE
This object indicates the destination SGT value. Value of zero indicates that the destination SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.2CtsSecurityGroupTagnot-accessiblecurrent
ctspStatsSourceSgt
OBJECT-TYPE
This object indicates the source SGT value. Value of zero indicates that the source SGT is unknown.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.3CtsSecurityGroupTagnot-accessiblecurrent
ctspStatsIpSwDropPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are dropped by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.4Counter64read-onlycurrent
ctspStatsIpHwDropPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are dropped by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.5Counter64read-onlycurrent
ctspStatsIpSwPermitPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are permitted by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.6Counter64read-onlycurrent
ctspStatsIpHwPermitPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are permitted by SGACL.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.7Counter64read-onlycurrent
ctspStatsIpSwMonitorPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are SGACL enforced & monitored.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.8Counter64read-onlycurrent
ctspStatsIpHwMonitorPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are SGACL enforced & monitored.
1.3.6.1.4.1.9.9.713.1.1.3.1.1.9Counter64read-onlycurrent
ctspDefStatsTable
OBJECT-TYPE
This table describes statistics counters for unicast IP traffic subjected to default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2not-accessiblecurrent
ctspDefStatsEntry
OBJECT-TYPE
Each row contains the statistics counter for each IP traffic type.
1.3.6.1.4.1.9.9.713.1.1.3.2.1not-accessiblecurrent
ctspDefIpTrafficType
OBJECT-TYPE
This object indicates the type of the IP traffic subjected to default unicast policy enforcement.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspDefIpSwDropPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are dropped by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.2Counter64read-onlycurrent
ctspDefIpHwDropPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are dropped by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.3Counter64read-onlycurrent
ctspDefIpSwPermitPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are permitted by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.4Counter64read-onlycurrent
ctspDefIpHwPermitPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are permitted by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.5Counter64read-onlycurrent
ctspDefIpSwMonitorPkts
OBJECT-TYPE
This object indicates the number of software-forwarded IP packets which are monitored by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.6Counter64read-onlycurrent
ctspDefIpHwMonitorPkts
OBJECT-TYPE
This object indicates the number of hardware-forwarded IP packets which are monitored by default unicast policy.
1.3.6.1.4.1.9.9.713.1.1.3.2.1.7Counter64read-onlycurrent
ctspPeerPolicy
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.2
ctspAllPeerPolicyAction
OBJECT-TYPE
This object allows user to specify the action to be taken with respect to all peer policies in the device. When read, this object always returns the value 'none'. 'none' - No operation. 'refresh' - Refresh all peer policies in the device.
1.3.6.1.4.1.9.9.713.1.2.1INTEGER {none(1), refresh(2)}read-writecurrent
ctspPeerPolicyTable
OBJECT-TYPE
This table lists the peer policy information for each peer device.
1.3.6.1.4.1.9.9.713.1.2.2not-accessiblecurrent
ctspPeerPolicyEntry
OBJECT-TYPE
Each row contains the managed objects for peer policies for each peer device based on its name.
1.3.6.1.4.1.9.9.713.1.2.2.1not-accessiblecurrent
ctspPeerName
OBJECT-TYPE
This object uniquely identifies a peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.1SnmpAdminString (SIZE(1..128))not-accessiblecurrent
ctspPeerSgt
OBJECT-TYPE
This object indicates the SGT value of this peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.2CtsSecurityGroupTagread-onlycurrent
ctspPeerSgtGenId
OBJECT-TYPE
This object indicates the generation identification of the SGT value assigned to this peer device.
1.3.6.1.4.1.9.9.713.1.2.2.1.3CtsGenerationIdread-onlycurrent
ctspPeerTrustState
OBJECT-TYPE
This object indicates the TrustSec trust state of this peer device. 'trusted' indicates that this is a trusted peer device. 'noTrust' indicates that this peer device is not trusted.
1.3.6.1.4.1.9.9.713.1.2.2.1.4INTEGER {trusted(1), noTrust(2)}read-onlycurrent
ctspPeerPolicyLifeTime
OBJECT-TYPE
This object indicates the policy life time which provides the time interval during which the peer policy is valid.
1.3.6.1.4.1.9.9.713.1.2.2.1.5Unsigned32read-onlycurrent
ctspPeerPolicyLastUpdate
OBJECT-TYPE
This object indicates the time when this peer policy is last updated.
1.3.6.1.4.1.9.9.713.1.2.2.1.6DateAndTimeread-onlycurrent
ctspPeerPolicyAction
OBJECT-TYPE
This object allows user to specify the action to be taken with this peer policy. When read, this object always returns the value 'none'. 'none' - No operation. 'refresh' - Refresh this peer policy.
1.3.6.1.4.1.9.9.713.1.2.2.1.7INTEGER {none(1), refresh(2)}read-writecurrent
ctspLayer3Transport
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.3
ctspLayer3PolicyTable
OBJECT-TYPE
This table describes Layer 3 transport policy for IP traffic regarding SGT propagation.
1.3.6.1.4.1.9.9.713.1.3.1not-accessiblecurrent
ctspLayer3PolicyEntry
OBJECT-TYPE
Each row contains the Layer 3 transport policies per IP traffic type per policy type.
1.3.6.1.4.1.9.9.713.1.3.1.1not-accessiblecurrent
ctspLayer3PolicyIpTrafficType
OBJECT-TYPE
This object indicates the type of the IP traffic affected by Layer-3 transport policy. 'ipv4' indicates that the affected traffic is IPv4 traffic. 'ipv6' indicates that the affected traffic is IPv6 traffic.
1.3.6.1.4.1.9.9.713.1.3.1.1.1INTEGER {ipv4(1), ipv6(2)}not-accessiblecurrent
ctspLayer3PolicyType
OBJECT-TYPE
This object indicates the type of the Layer-3 transport policy affecting IP traffic regarding SGT propagation. 'permit' indicates that the transport policy is used to classify Layer-3 traffic which is subject to SGT propagation. 'exception' indicates that the transport policy is used to classify Layer-3 traffic which is NOT subject to SGT propagation.
1.3.6.1.4.1.9.9.713.1.3.1.1.2INTEGER {permit(1), exception(2)}not-accessiblecurrent
ctspLayer3PolicyLocalConfig
OBJECT-TYPE
This object specifies the name of an ACL that is administratively configured to classify Layer3 traffic. Zero-length string indicates there is no such configured policy.
1.3.6.1.4.1.9.9.713.1.3.1.1.3CtsAclNameOrEmptyread-writecurrent
ctspLayer3PolicyDownloaded
OBJECT-TYPE
This object specifies the name of an ACL that is downloaded from policy server to classify Layer3 traffic. Zero-length string indicates there is no such downloaded policy.
1.3.6.1.4.1.9.9.713.1.3.1.1.4CtsAclNameOrEmptyread-onlycurrent
ctspLayer3PolicyOperational
OBJECT-TYPE
This object specifies the name of an operational ACL currently used to classify Layer3 traffic. Zero-length string indicates there is no such policy in effect.
1.3.6.1.4.1.9.9.713.1.3.1.1.5CtsAclNameOrEmptyread-onlycurrent
ctspIfL3PolicyConfigTable
OBJECT-TYPE
This table lists the interfaces which support Layer3 Transport policy.
1.3.6.1.4.1.9.9.713.1.3.2not-accessiblecurrent
ctspIfL3PolicyConfigEntry
OBJECT-TYPE
Each row contains managed objects for Layer3 Transport on interface capable of providing this information.
1.3.6.1.4.1.9.9.713.1.3.2.1not-accessiblecurrent
ctspIfL3Ipv4PolicyEnabled
OBJECT-TYPE
This object specifies whether the Layer3 Transport policies will be applied on this interface for egress IPv4 traffic. 'true' indicates that Layer3 permit and exception policy will be applied at this interface for egress IPv4 traffic. 'false' indicates that Layer3 permit and exception policy will not be applied at this interface for egress IPv4 traffic.
1.3.6.1.4.1.9.9.713.1.3.2.1.1TruthValueread-writecurrent
ctspIfL3Ipv6PolicyEnabled
OBJECT-TYPE
This object specifies whether the Layer3 Transport policies will be applied on this interface for egress IPv6 traffic. 'true' indicates that Layer3 permit and exception policy will be applied at this interface for egress IPv6 traffic. 'false' indicates that Layer3 permit and exception policy will not be applied at this interface for egress IPv6 traffic.
1.3.6.1.4.1.9.9.713.1.3.2.1.2TruthValueread-writecurrent
ctspIpSgtMappings
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.4
ctspIpSgtMappingTable
OBJECT-TYPE
This table contains the IP-to-SGT mapping information in the device.
1.3.6.1.4.1.9.9.713.1.4.1not-accessiblecurrent
ctspIpSgtMappingEntry
OBJECT-TYPE
Each row contains the IP-to-SGT mapping and status of this instance. Entry in this table is either populated automatically by the device or manually configured by a user. A manually configured row instance can be created or removed by setting the appropriate value of its RowStatus object.
1.3.6.1.4.1.9.9.713.1.4.1.1not-accessiblecurrent
ctspIpSgtVrfName
OBJECT-TYPE
This object indicates the VRF where IP-SGT mapping belongs to. The zero length value indicates the default VRF.
1.3.6.1.4.1.9.9.713.1.4.1.1.1CiscoVrfNamenot-accessiblecurrent
ctspIpSgtAddressType
OBJECT-TYPE
This object indicates the type of Internet address.
1.3.6.1.4.1.9.9.713.1.4.1.1.2InetAddressTypenot-accessiblecurrent
ctspIpSgtIpAddress
OBJECT-TYPE
This object indicates an Internet address. The type of this address is determined by the value of ctspIpSgtAddressType object.
1.3.6.1.4.1.9.9.713.1.4.1.1.3InetAddressnot-accessiblecurrent
ctspIpSgtAddressLength
OBJECT-TYPE
This object indicates the length of an Internet address prefix.
1.3.6.1.4.1.9.9.713.1.4.1.1.4InetAddressPrefixLengthnot-accessiblecurrent
ctspIpSgtValue
OBJECT-TYPE
This object specifies the SGT value assigned to an Internet address.
1.3.6.1.4.1.9.9.713.1.4.1.1.5CtsSecurityGroupTagread-createcurrent
ctspIpSgtSource
OBJECT-TYPE
This object indicates the source of the mapping. 'configured' indicates that the mapping is manually configured by user. 'arp' indicates that the mapping is dynamically learnt from tagged ARP replies. 'localAuthenticated' indicates that the mapping is dynamically learnt from the device authentication of a host. 'sxp' indicates that the mapping is dynamically learnt from SXP (SGT Propagation Protocol). 'internal' indicates that the mapping is automatically created by the device between the device IP addresses and the device own SGT. 'l3if' indicates that Interface-SGT mapping is configured by user. 'vlan' indicates that Vlan-SGT mapping is configured by user. 'cached' indicates that sgt mapping is cached. Only 'configured' value is accepted when setting this object.
1.3.6.1.4.1.9.9.713.1.4.1.1.6INTEGER {configured(1), arp(2), localAuthenticated(3), sxp(4), internal(5), l3if(6), vlan(7), caching(8)}read-createcurrent
ctspIpSgtStorageType
OBJECT-TYPE
The storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.4.1.1.7StorageTyperead-createcurrent
ctspIpSgtRowStatus
OBJECT-TYPE
This object is used to manage the creation and deletion of rows in this table. If this object value is 'active', user cannot modify any writable object in this row. If value of ctspIpSgtSource object in an entry is not 'configured', user cannot change the value of this object.
1.3.6.1.4.1.9.9.713.1.4.1.1.8RowStatusread-createcurrent
ctspSgtPolicy
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.5
ctspAllSgtPolicyAction
OBJECT-TYPE
This object allows user to specify the action to be taken with respect to all SGT policies in the device. When read, this object always returns the value 'none'. 'none' - No operation. 'refresh' - Refresh all SGT policies in the device.
1.3.6.1.4.1.9.9.713.1.5.1INTEGER {none(1), refresh(2)}read-writecurrent
ctspDownloadedSgtPolicyTable
OBJECT-TYPE
This table lists the SGT policy information downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.2not-accessiblecurrent
ctspDownloadedSgtPolicyEntry
OBJECT-TYPE
Each row contains the managed objects for SGT policies downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.2.1not-accessiblecurrent
ctspDownloadedSgtPolicySgt
OBJECT-TYPE
This object indicates the SGT value for which the downloaded policy is applied to. Value of zero indicates that the SGT is unknown.
1.3.6.1.4.1.9.9.713.1.5.2.1.1CtsSecurityGroupTagnot-accessiblecurrent
ctspDownloadedSgtPolicySgtGenId
OBJECT-TYPE
This object indicates the generation identification of the SGT value denoted by ctspDownloadedSgtPolicySgt object.
1.3.6.1.4.1.9.9.713.1.5.2.1.2CtsGenerationIdread-onlycurrent
ctspDownloadedSgtPolicyLifeTime
OBJECT-TYPE
This object indicates the policy life time which provides the time interval during which this downloaded policy is valid.
1.3.6.1.4.1.9.9.713.1.5.2.1.3Unsigned32read-onlycurrent
ctspDownloadedSgtPolicyLastUpdate
OBJECT-TYPE
This object indicates the time when this downloaded SGT policy is last updated.
1.3.6.1.4.1.9.9.713.1.5.2.1.4DateAndTimeread-onlycurrent
ctspDownloadedSgtPolicyAction
OBJECT-TYPE
This object allows user to specify the action to be taken with this downloaded SGT policy. When read, this object always returns the value 'none'. 'none' - No operation. 'refresh' - Refresh this SGT policy.
1.3.6.1.4.1.9.9.713.1.5.2.1.5INTEGER {none(1), refresh(2)}read-writecurrent
ctspDownloadedDefSgtPolicyTable
OBJECT-TYPE
This table lists the default SGT policy information downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.3not-accessiblecurrent
ctspDownloadedDefSgtPolicyEntry
OBJECT-TYPE
Each row contains the managed objects for default SGT policies downloaded by the device.
1.3.6.1.4.1.9.9.713.1.5.3.1not-accessiblecurrent
ctspDownloadedDefSgtPolicyType
OBJECT-TYPE
This object indicates the downloaded default SGT policy type. 'unicastDefault' indicates the SGT policy applied to traffic which carries the default unicast SGT.
1.3.6.1.4.1.9.9.713.1.5.3.1.1INTEGER {unicastDefault(1)}not-accessiblecurrent
ctspDownloadedDefSgtPolicySgtGenId
OBJECT-TYPE
This object indicates the generation identification of the downloaded default SGT policy.
1.3.6.1.4.1.9.9.713.1.5.3.1.2CtsGenerationIdread-onlycurrent
ctspDownloadedDefSgtPolicyLifeTime
OBJECT-TYPE
This object indicates the policy life time which provides the time interval during which this download default policy is valid.
1.3.6.1.4.1.9.9.713.1.5.3.1.3Unsigned32read-onlycurrent
ctspDownloadedDefSgtPolicyLastUpdate
OBJECT-TYPE
This object indicates the time when this downloaded SGT policy is last updated.
1.3.6.1.4.1.9.9.713.1.5.3.1.4DateAndTimeread-onlycurrent
ctspDownloadedDefSgtPolicyAction
OBJECT-TYPE
This object allows user to specify the action to be taken with this default downloaded SGT policy. When read, this object always returns the value 'none'. 'none' - No operation. 'refresh' - Refresh this default SGT policy.
1.3.6.1.4.1.9.9.713.1.5.3.1.5INTEGER {none(1), refresh(2)}read-writecurrent
ctspIfSgtMappings
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.6
ctspIfSgtMappingTable
OBJECT-TYPE
This table contains the Interface-to-SGT mapping configuration information in the device.
1.3.6.1.4.1.9.9.713.1.6.1not-accessiblecurrent
ctspIfSgtMappingEntry
OBJECT-TYPE
Each row contains the SGT mapping configuration of a particular interface. A row instance can be created or removed by setting ctspIfSgtRowStatus.
1.3.6.1.4.1.9.9.713.1.6.1.1not-accessiblecurrent
ctspIfSgtValue
OBJECT-TYPE
This object specifies the SGT value assigned to the interface.
1.3.6.1.4.1.9.9.713.1.6.1.1.1CtsSecurityGroupTagread-createcurrent
ctspIfSgName
OBJECT-TYPE
This object specifies the Security Group Name assigned to the interface.
1.3.6.1.4.1.9.9.713.1.6.1.1.2SnmpAdminStringread-createcurrent
ctspIfSgtStorageType
OBJECT-TYPE
The storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.6.1.1.3StorageTyperead-createcurrent
ctspIfSgtRowStatus
OBJECT-TYPE
This object is used to manage the creation and deletion of rows in this table.
1.3.6.1.4.1.9.9.713.1.6.1.1.4RowStatusread-createcurrent
ctspIfSgtMappingInfoTable
OBJECT-TYPE
This table contains the Interface-to-SGT mapping status information in the device.
1.3.6.1.4.1.9.9.713.1.6.2not-accessiblecurrent
ctspIfSgtMappingInfoEntry
OBJECT-TYPE
Containing the Interface-to-SGT mapping status of the specified interface.
1.3.6.1.4.1.9.9.713.1.6.2.1not-accessiblecurrent
ctspL3IPMStatus
OBJECT-TYPE
This object indicates the Layer 3 Identity Port Mapping(IPM) operational mode. disabled - The L3 IPM is not configured. active - The L3 IPM is configured for this interface, and SGT is available. inactive - The L3 IPM is configured for this interface, and SGT is unavailable.
1.3.6.1.4.1.9.9.713.1.6.2.1.1INTEGER {disabled(1), active(2), inactive(3)}read-onlycurrent
ctspVlanSgtMappings
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.7
ctspVlanSgtMappingTable
OBJECT-TYPE
This table contains the Vlan-SGT mapping information in the device.
1.3.6.1.4.1.9.9.713.1.7.1not-accessiblecurrent
ctspVlanSgtMappingEntry
OBJECT-TYPE
Each row contains the SGT mapping configuration of a particular VLAN. A row instance can be created or removed by setting ctspVlanSgtRowStatus.
1.3.6.1.4.1.9.9.713.1.7.1.1not-accessiblecurrent
ctspVlanSgtMappingIndex
OBJECT-TYPE
This object specifies the VLAN-ID which is used as index.
1.3.6.1.4.1.9.9.713.1.7.1.1.1VlanIndexnot-accessiblecurrent
ctspVlanSgtMapValue
OBJECT-TYPE
This object specifies the SGT value assigned to the vlan.
1.3.6.1.4.1.9.9.713.1.7.1.1.2CtsSecurityGroupTagread-createcurrent
ctspVlanSgtStorageType
OBJECT-TYPE
The storage type for this conceptual row.
1.3.6.1.4.1.9.9.713.1.7.1.1.3StorageTyperead-createcurrent
ctspVlanSgtRowStatus
OBJECT-TYPE
This object is used to manage the creation and deletion of rows in this table.
1.3.6.1.4.1.9.9.713.1.7.1.1.4RowStatusread-createcurrent
ctspSgtCaching
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.8
ctspSgtCachingMode
OBJECT-TYPE
This object specifies which SGT-caching mode is configured for SGT caching capable interfaces at the managed system. 'none' indicates that sgt-caching for all Layer 3 interfaces (excluding SVIs) is disabled. 'standAlone' indicates that SGT-caching is enabled on every TrustSec capable Layer3 interface (excluding SVIs) in the device. 'withEnforcement' indicates that SGT-caching is enabled on interfaces that have RBAC enforcement enabled. 'vlan' indicates that SGT-caching is enabled on the VLANs specified by ctspSgtCachingVlansfFirst2K & ctspSgtCachingVlansSecond2K
1.3.6.1.4.1.9.9.713.1.8.1INTEGER {none(1), standAlone(2), withEnforcement(3), vlan(4)}read-writecurrent
ctspSgtCachingVlansFirst2K
OBJECT-TYPE
A string of octets containing one bit per VLAN for VLANs 0 to 2047. If the bit corresponding to a VLAN is set to 1, it indicates SGT-caching is enabled on the VLAN. If the bit corresponding to a VLAN is set to 0, it indicates SGT-caching is disabled on the VLAN.
1.3.6.1.4.1.9.9.713.1.8.2Cisco2KVlanListread-writecurrent
ctspSgtCachingVlansSecond2K
OBJECT-TYPE
A string of octets containing one bit per VLAN for VLANs 2048 to 4095. If the bit corresponding to a VLAN is set to 1, it indicates SGT-caching is enabled on the VLAN. If the bit corresponding to a VLAN is set to 0, it indicates SGT-caching is disabled on the VLAN.
1.3.6.1.4.1.9.9.713.1.8.3Cisco2KVlanListread-writecurrent
ctspNotifsControl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.9
ctspPeerPolicyUpdatedNotifEnable
OBJECT-TYPE
This object specifies whether the system generates ctspPeerPolicyUpdatedNotif. A value of 'false' will prevent ctspPeerPolicyUpdatedNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.713.1.9.1TruthValueread-writecurrent
ctspAuthorizationSgaclFailNotifEnable
OBJECT-TYPE
This object specifies whether this system generates the ctspAuthorizationSgaclFailNotif. A value of 'false' will prevent ctspAuthorizationSgaclFailNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.713.1.9.2TruthValueread-writecurrent
ctspNotifsOnlyInfo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.1.10
ctspOldPeerSgt
OBJECT-TYPE
This object provides the old sgt value for ctspPeerPolicyUpdatedNotif, i.e., the sgt value before the policy is updated.
1.3.6.1.4.1.9.9.713.1.10.1CtsSecurityGroupTagaccessible-for-notifycurrent
ctspAuthorizationSgaclFailReason
OBJECT-TYPE
This object indicates the reason of failure during SGACL acquisitions, installations and uninstallations, which is associated with ctspAuthorizationSgaclFailNotif; 'downloadACE' - Failure during downloading ACE in SGACL acquisition. 'downloadSrc' - Failure during downloading source list in SGACL acquisition. 'downloadDst' - Failure during downloading destination list in SGACL acquisition. 'installPolicy' - Failure during SGACL policy installation 'installPolicyStandby' - Failure during SGACL policy installation on standby 'installForIP' - Failure during SGACL installation for specific IP type. 'uninstall' - Failure during SGACL uninstallation.
1.3.6.1.4.1.9.9.713.1.10.2INTEGER {downloadACE(1), downloadSrc(2), downloadDst(3), installPolicy(4), installPolicyStandby(5), installForIP(6), uninstall(7)}accessible-for-notifycurrent
ctspAuthorizationSgaclFailInfo
OBJECT-TYPE
This object provides additional information about authorization SGACL failure, which is associated with ctspAuthorizationSgaclFailNotif.
1.3.6.1.4.1.9.9.713.1.10.3SnmpAdminStringaccessible-for-notifycurrent
ciscoTrustSecPolicyMIBConformance
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.2
ciscoTrustSecPolicyMIBCompliances
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.2.1
ciscoTrustSecPolicyMIBGroups
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.713.2.2

Notifications

NameOIDStatus
ctspPeerPolicyUpdatedNotif
NOTIFICATION-TYPE
A ctspPeerPolicyUpdatedNotif is generated when the SGT value of a peer device has been updated.
1.3.6.1.4.1.9.9.713.0.1current
ctspAuthorizationSgaclFailNotif
NOTIFICATION-TYPE
A ctspAuthorizationSgaclFailNotif is generated when the authorization of SGACL fails.
1.3.6.1.4.1.9.9.713.0.2current

Conformance

NameOIDStatus
ciscoTrustSecPolicyMIBCompliance
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
1.3.6.1.4.1.9.9.713.2.1.1deprecated
ciscoTrustSecPolicyMIBComplianceRev2
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-POLICY-MIB
1.3.6.1.4.1.9.9.713.2.1.2current
ctspGlobalSgaclEnforcementGroup
OBJECT-GROUP
A collection of object which provides the SGACL enforcement information for all TrustSec capable Layer 3 interfaces (excluding SVIs) at the device level.
1.3.6.1.4.1.9.9.713.2.2.1current
ctspSgaclIpv4DropNetflowMonitorGroup
OBJECT-GROUP
A collection of object which provides netflow monitor information for IPv4 traffic drop packet due to SGACL enforcement in the device.
1.3.6.1.4.1.9.9.713.2.2.2current
ctspSgaclIpv6DropNetflowMonitorGroup
OBJECT-GROUP
A collection of object which provides netflow monitor information for IPv6 traffic drop packet due to SGACL enforcement in the device.
1.3.6.1.4.1.9.9.713.2.2.3current
ctspVlanConfigGroup
OBJECT-GROUP
A collection of object which provides the SGACL enforcement and VRF information for each VLAN.
1.3.6.1.4.1.9.9.713.2.2.4current
ctspConfigSgaclMappingGroup
OBJECT-GROUP
A collection of objects which provides the administratively configured SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.5current
ctspDownloadedSgaclMappingGroup
OBJECT-GROUP
A collection of objects which provides the downloaded SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.6current
ctspOperSgaclMappingGroup
OBJECT-GROUP
A collection of objects which provides the operational SGACL mapping information in the device.
1.3.6.1.4.1.9.9.713.2.2.7current
ctspIpSwStatisticsGroup
OBJECT-GROUP
A collection of objects which provides software statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.8current
ctspIpHwStatisticsGroup
OBJECT-GROUP
A collection of objects which provides hardware statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.9current
ctspDefSwStatisticsGroup
OBJECT-GROUP
A collection of objects which provides software statistics counters for unicast IP traffic subjected to unicast default policy enforcement.
1.3.6.1.4.1.9.9.713.2.2.10current
ctspDefHwStatisticsGroup
OBJECT-GROUP
A collection of objects which provides hardware statistics counters for unicast IP traffic subjected to unicast default policy enforcement.
1.3.6.1.4.1.9.9.713.2.2.11current
ctspPeerPolicyActionGroup
OBJECT-GROUP
A collection of object which provides refreshing of all peer policies in the device.
1.3.6.1.4.1.9.9.713.2.2.12current
ctspPeerPolicyGroup
OBJECT-GROUP
A collection of object which provides peer policy information in the device.
1.3.6.1.4.1.9.9.713.2.2.13current
ctspLayer3TransportGroup
OBJECT-GROUP
A collection of objects which provides managed information regarding the SGT propagation along with Layer 3 traffic in the device.
1.3.6.1.4.1.9.9.713.2.2.14current
ctspIfL3PolicyConfigGroup
OBJECT-GROUP
A collection of objects which provides managed information for Layer3 Tranport policy enforcement on capable interface in the device.
1.3.6.1.4.1.9.9.713.2.2.15current
ctspIpSgtMappingGroup
OBJECT-GROUP
A collection of objects which provides managed information regarding IP-to-Sgt mapping in the device.
1.3.6.1.4.1.9.9.713.2.2.16current
ctspSgtPolicyGroup
OBJECT-GROUP
A collection of object which provides SGT policy information in the device.
1.3.6.1.4.1.9.9.713.2.2.17current
ctspIfSgtMappingGroup
OBJECT-GROUP
A collection of objects which provides managed information regarding Interface-to-Sgt mapping in the device.
1.3.6.1.4.1.9.9.713.2.2.18current
ctspVlanSgtMappingGroup
OBJECT-GROUP
A collection of objects which provides sgt mapping information for the IP traffic in the specified Vlan.
1.3.6.1.4.1.9.9.713.2.2.19current
ctspSgtCachingGroup
OBJECT-GROUP
A collection of objects which provides sgt Caching information.
1.3.6.1.4.1.9.9.713.2.2.20current
ctspSgaclMonitorGroup
OBJECT-GROUP
A collection of objects which provides SGACL monitor information.
1.3.6.1.4.1.9.9.713.2.2.21current
ctspSgaclMonitorStatisticGroup
OBJECT-GROUP
A collection of objects which provides monitor statistics counters for unicast IP traffic subjected to SGACL enforcement.
1.3.6.1.4.1.9.9.713.2.2.22current
ctspNotifCtrlGroup
OBJECT-GROUP
A collection of objects providing notification control for TrustSec policy notifications.
1.3.6.1.4.1.9.9.713.2.2.23current
ctspNotifGroup
NOTIFICATION-GROUP
A collection of notifications for TrustSec policy.
1.3.6.1.4.1.9.9.713.2.2.24current
ctspNotifInfoGroup
OBJECT-GROUP
A collection of objects providing the variable binding for TrustSec policy notifications.
1.3.6.1.4.1.9.9.713.2.2.25current