MIBs Depot

CISCO-TRUSTSEC-SXP-MIB

Registered at
1.3.6.1.4.1.9.9.720
Last updated
2013-07-29 00:00
Organization
Cisco Systems, Inc.
Revisions
2013-07-29 00:00, 2012-04-17 00:00, 2010-11-24 00:00, 2010-02-03 00:00
Namespace
cisco
Source file
CISCO-TRUSTSEC-SXP-MIB
Digest
sha256:d12b6e48d868d0993f934c9e59fde775d44fb4e9eb4406f803a2a52406470459

Description

This MIB module is for the configuration and status query of SGT Exchange Protocol over TCP (SXPoTCP) feature of the device on the Cisco's Trusted Security (TrustSec) system. Security Group Tag (SGT) identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud. SXPoTCP protocol extends the original SGT Exchange Protocol (SXP) protocol to enable a much wider array of deployment scenarios. This MIB uses the term SXP to refer to SXPoTCP. TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis. SXP allows the deployment of RBACL, a key component of the TrustSec architecture, in the absence of TrustSec capable hardware.

Contact

Cisco Systems Customer Service Postal: 170 W Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS E-mail: cs-lan-switch-snmp@cisco.com

Imports

FromSymbols
CISCO-SMIciscoMgmt
CISCO-TCCiscoVrfName
CISCO-TRUSTSEC-TC-MIBCtsPassword, CtsPasswordEncryptionType, CtsSecurityGroupTag, CtsSxpConnectionStatus
IF-MIBInterfaceIndexOrZero
INET-ADDRESS-MIBInetAddress, InetAddressPrefixLength, InetAddressType
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP
SNMPv2-SMIGauge32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDisplayString, RowStatus, StorageType, TEXTUAL-CONVENTION, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

CISCO-SMI
CISCO-TC
CISCO-TRUSTSEC-SXP-MIB
CISCO-TRUSTSEC-TC-MIB
IANAifType-MIB
IF-MIB
INET-ADDRESS-MIB
SNMP-FRAMEWORK-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC

Objects

NameOIDSyntaxAccessStatus
ciscoTrustSecSxpMIBNotifs
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.0
ciscoTrustSecSxpMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1
ctsxSxpGlobalObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1.1
ctsxSxpEnable
OBJECT-TYPE
This object specifies if the SXP (Security Group Tag Exchange Protocol) functionality is enabled on the device.
1.3.6.1.4.1.9.9.720.1.1.1TruthValueread-writecurrent
ctsxSxpConfigDefaultPasswordType
OBJECT-TYPE
This object specifies the type of encryption used to configure ctsxSxpConfigDefaultPassword string. When read, this object will always return 'other'. Value of this object must be set in the same PDU as ctsxSxpConfigDefaultPassword. Value of this object must be specified as 'clearText', 'typeSix' or 'typeSeven' to configure a non zero length password in ctsxSxpConfigDefaultPassword. Value for this object must be 'none' if ctsxSxpConfigDefaultPassword is a zero length string.
1.3.6.1.4.1.9.9.720.1.1.2CtsPasswordEncryptionTyperead-writecurrent
ctsxSxpConfigDefaultPassword
OBJECT-TYPE
This object specifies the default password for SXP connections. The type of encryption used to configure this password is determined by ctsxSxpConfigDefaultPasswordType. When read, this object will always return a zero length string. The value of this object must be set in the same PDU as ctsxSxpConfigDefaultPasswordType. A non zero length password must be specified for this object if the value of ctsxSxpConfigDefaultPasswordType is other than 'none' or 'other'. Value for this object must be a zero length string if the value of ctsxSxpConfigDefaultPasswordType is 'none'. The purpose of this object is to only allow configuration of the default password. The ctsxSxpViewDefaultPassword object is used to display the default password.
1.3.6.1.4.1.9.9.720.1.1.3CtsPasswordread-writecurrent
ctsxSxpViewDefaultPasswordType
OBJECT-TYPE
This object indicates the type of encryption in use for ctsxSxpViewDefaultPassword.
1.3.6.1.4.1.9.9.720.1.1.4CtsPasswordEncryptionTyperead-onlycurrent
ctsxSxpViewDefaultPassword
OBJECT-TYPE
This object indicates the default password for SXP connections. The type of encryption used to display this password is determined by the object ctsxSxpViewDefaultPasswordType. The purpose of this object is to only display the password. The ctsxSxpConfigDefaultPassword object is used to configure the password.
1.3.6.1.4.1.9.9.720.1.1.5CtsPasswordread-onlycurrent
ctsxSxpDefaultSourceAddrType
OBJECT-TYPE
The type of Internet address of the default source address for SXP connections.
1.3.6.1.4.1.9.9.720.1.1.6InetAddressTyperead-writecurrent
ctsxSxpDefaultSourceAddr
OBJECT-TYPE
The Internet address to be used as default source address for SXP connections. The type of this address is determined by the ctsxSxpDefaultSourceAddrType object. This address will be used as source address for SXP connections that do not have specific source-IP address configured via ctsxSxpConnSourceAddr object.
1.3.6.1.4.1.9.9.720.1.1.7InetAddressread-writecurrent
ctsxSxpRetryPeriod
OBJECT-TYPE
This object specifies the amount of time after which the device will make the retry attempt for the SXP connections that are not setup successfully. A value of zero for this object indicates that the device will never try to establish connections that were not setup successfully.
1.3.6.1.4.1.9.9.720.1.1.8Unsigned32read-writecurrent
ctsxSxpReconPeriod
OBJECT-TYPE
This object specifies the amount of time after which system will initiate removal of SGT mappings for a reconciled connection. A value of zero for this object indicates that SGT mappings for a reconciled connection will never be deleted.
1.3.6.1.4.1.9.9.720.1.1.9Unsigned32read-writecurrent
ctsxSxpBindingChangesLogEnable
OBJECT-TYPE
This object specifies if the system will generate system logging messages for SXP binding changes. A value of 'false' will prevent system from generating logging messages for SXP binding changes.
1.3.6.1.4.1.9.9.720.1.1.10TruthValueread-writecurrent
ctsxSgtMapExpansionLimit
OBJECT-TYPE
This object specifies the maximum number of SGT mapping entries that can be expanded on the system. Value of zero for this object indicates that SGT mapping expansion functionality is disabled.
1.3.6.1.4.1.9.9.720.1.1.11Gauge32read-writecurrent
ctsxSgtMapExpansionCount
OBJECT-TYPE
This object indicates the number of SGT mapping entries currently expanded on the system.
1.3.6.1.4.1.9.9.720.1.1.12Gauge32read-onlycurrent
ctsxSxpAdminNodeId
OBJECT-TYPE
This object specifies the administrative SXP node ID for this system. Setting this object to a non-zero value will clear the values in ctsxSxpNodeIdInterface and ctsxSxpNodeIdIpAddrType. This object can be set only if ctsxSxpEnable is 'false'.
1.3.6.1.4.1.9.9.720.1.1.13Unsigned32read-writecurrent
ctsxSxpNodeIdInterface
OBJECT-TYPE
This object specifies the interface to be used to select SXP node ID. Setting this object to a non-zero value will clear the values in ctsxSxpAdminNodeId and ctsxSxpNodeIdIpAddrType. This object can be set only if ctsxSxpEnable is 'false'.
1.3.6.1.4.1.9.9.720.1.1.14InterfaceIndexOrZeroread-writecurrent
ctsxSxpNodeIdIpAddrType
OBJECT-TYPE
This object specifies the type of Internet address to be used to select the SXP node ID.
1.3.6.1.4.1.9.9.720.1.1.15InetAddressTyperead-writecurrent
ctsxSxpNodeIdIpAddr
OBJECT-TYPE
This object specifies the Internet address to be used to select the SXP node ID. The type of this address is determined by ctsxSxpOperNodeIdIpAddrType object. Setting this object to a non-zero length value will clear the values in ctsxSxpAdminNodeId and ctsxSxpNodeIdInterface. This object can be set only if ctsxSxpEnable is 'false'.
1.3.6.1.4.1.9.9.720.1.1.16InetAddressread-writecurrent
ctsxSxpOperNodeId
OBJECT-TYPE
This object indicates the operational SXP node ID of the system.
1.3.6.1.4.1.9.9.720.1.1.17Unsigned32read-onlycurrent
ctsxSxpSpeakerMinHoldTime
OBJECT-TYPE
This object specifies the global minimum hold-time for SXP connections in 'speaker' mode.
1.3.6.1.4.1.9.9.720.1.1.18Unsigned32 (1..65534)read-writecurrent
ctsxSxpListenerMinHoldTime
OBJECT-TYPE
This object specifies the global minimum hold-time for SXP connections in 'listener' mode. Value of this object must be lesser than ctsxSxpListenerMaxHoldTime.
1.3.6.1.4.1.9.9.720.1.1.19Unsigned32 (1..65534)read-writecurrent
ctsxSxpListenerMaxHoldTime
OBJECT-TYPE
This object specifies the global maximum hold-time for SXP connections in 'listener' mode. Value of this object must be greater than ctsxSxpListenerMinHoldTime.
1.3.6.1.4.1.9.9.720.1.1.20Unsigned32 (1..65534)read-writecurrent
ctsxSxpVersionSupport
OBJECT-TYPE
The highest version of SXP protocol that this device supports. 'unknown' - The SXP protocol version capability for the device is unknown. 'one' - The device supports SXP protocol up to version 1. 'two' - The device supports SXP protocol up to version 2. 'three' - The device supports SXP protocol up to version 3. 'four' - The device supports SXP protocol up to version 4.
1.3.6.1.4.1.9.9.720.1.1.21INTEGER {unknown(1), one(2), two(3), three(4), four(5)}read-onlycurrent
ctsxSxpConnectionObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1.2
ctsxSxpConnectionTable
OBJECT-TYPE
A list of SXP peers configured on this device.
1.3.6.1.4.1.9.9.720.1.2.1not-accessiblecurrent
ctsxSxpConnectionEntry
OBJECT-TYPE
An entry containing management information of a particular SXP peers.
1.3.6.1.4.1.9.9.720.1.2.1.1not-accessiblecurrent
ctsxSxpConnVrfName
OBJECT-TYPE
The name of the Virtual Routing and Forwarding (VRF) table associated with this SXP connection. A zero length string implies that connection will be setup in the default virtual routing and forwarding domain.
1.3.6.1.4.1.9.9.720.1.2.1.1.1CiscoVrfNamenot-accessiblecurrent
ctsxSxpConnPeerAddrType
OBJECT-TYPE
The type of Internet address of the peer SXP device.
1.3.6.1.4.1.9.9.720.1.2.1.1.2InetAddressTypenot-accessiblecurrent
ctsxSxpConnPeerAddr
OBJECT-TYPE
The Internet address of the SXP peer device. The type of this address is determined by the value of ctsxSxpConnPeerAddrType object.
1.3.6.1.4.1.9.9.720.1.2.1.1.3InetAddress (SIZE(1..64))not-accessiblecurrent
ctsxSxpConnSourceAddrType
OBJECT-TYPE
The type of source Internet address that is configured for this SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.4InetAddressTyperead-createcurrent
ctsxSxpConnSourceAddr
OBJECT-TYPE
The source Internet address configured for this SXP connection. The type of this address is determined by the value of ctsxSxpConnSourceAddrType object. When specified, value of this object takes precedence over the ctsxSxpDefaultSourceAddr object.
1.3.6.1.4.1.9.9.720.1.2.1.1.5InetAddressread-createcurrent
ctsxSxpConnOperSourceAddrType
OBJECT-TYPE
The type of source Internet address that is in in use for this SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.6InetAddressTyperead-onlycurrent
ctsxSxpConnOperSourceAddr
OBJECT-TYPE
The source Internet address that is in use for this SXP connection. The type of this address is determined by the value of ctsxSxpConnSourceAddrType object.
1.3.6.1.4.1.9.9.720.1.2.1.1.7InetAddressread-onlycurrent
ctsxSxpConnPasswordUsed
OBJECT-TYPE
This object specifies the type of password to be used for this SXP connection. 'none' - No password required for the SXP connection. 'default' - The default password which is specified by the object ctsxSxpViewDefaultPassword, will be used for the SXP connection. 'connectionSpecific' - The password specified by the ctsxSxpConnViewPassword object will be used for the connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.8INTEGER {none(1), default(2), connectionSpecific(3)}read-createcurrent
ctsxSxpConnConfigPasswordType
OBJECT-TYPE
This object specifies the type of encryption used to configure ctsxSxpConnConfigPassword string. When read, this object will always return 'other'. Value for this object may be specified as 'clearText', 'typeSix' or 'typeSeven' if the value of the object ctsxSxpConnPasswordUsed is 'connectionSpecific'. Value for this object may not be specified if the value of ctsxSxpConnPasswordUsed is other than 'connectionSpecific'.
1.3.6.1.4.1.9.9.720.1.2.1.1.9CtsPasswordEncryptionTyperead-createcurrent
ctsxSxpConnConfigPassword
OBJECT-TYPE
This object is used to specify the password for this connection. The type of encryption used to configure this password is determined by ctsxSxpConnConfigPasswordType. When read, this object will always return a zero length string. A non zero length password must be specified for this object if the value of ctsxSxpConnConfigPasswordType is other than 'none' or 'other'. A value for this object may not be specified if the value of ctsxSxpConnPasswordUsed is other than 'connectionSpecific'. The purpose of this object is to only allow configuration of the password. The ctsxSxpConnViewPassword object is used to display the password.
1.3.6.1.4.1.9.9.720.1.2.1.1.10CtsPasswordread-createcurrent
ctsxSxpConnViewPasswordType
OBJECT-TYPE
This object indicates the type of encryption in use for ctsxSxpConnViewPassword.
1.3.6.1.4.1.9.9.720.1.2.1.1.11CtsPasswordEncryptionTyperead-onlycurrent
ctsxSxpConnViewPassword
OBJECT-TYPE
This object indicates the password associated with this connection. The type of encryption used to display this password is determined by the object ctsxSxpConnViewPasswordType. The purpose of this object is to only display the password. The ctsxSxpConnConfigPassword object is used to configure the password.
1.3.6.1.4.1.9.9.720.1.2.1.1.12CtsPasswordread-onlycurrent
ctsxSxpConnModeLocation
OBJECT-TYPE
This object specifies if ctsxSxpConnMode is applicable for local or the peer device. A value of 'local' indicates that ctsxSxpConnMode applies to the local device in this SXP connection. A value of 'peer' indicates that ctsxSxpConnMode applies to the peer device in this SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.13INTEGER {local(1), peer(2)}read-createcurrent
ctsxSxpConnMode
OBJECT-TYPE
This object specifies the device mode of this SXP connection. A value of 'speaker' indicates that device will acts as the speaker in this SXP connection. A value of 'listener' indicates that device will acts as the listener in this SXP connection. A value of 'both' indicates that device will acts as both speaker and listener making it a Bi-directional SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.14INTEGER {speaker(1), listener(2), both(3)}read-createcurrent
ctsxSxpConnInstance
OBJECT-TYPE
This object indicates the instance number associated with this SXP connection. The instance number is used to identify stale SGT mappings which need to be removed from the system.
1.3.6.1.4.1.9.9.720.1.2.1.1.15Unsigned32read-onlycurrent
ctsxSxpConnStatusLastChange
OBJECT-TYPE
The amount of time elapsed since change in status of this SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.16Unsigned32read-onlycurrent
ctsxSxpConnStatus
OBJECT-TYPE
This object indicates the status of this SXP connection. When the corresponding instance value of ctsxSxpConnMode is 'both', this object indicates the status of 'speaker' and ctsxSxpConnBiDirListenerStatus indicates the status of 'listener'.
1.3.6.1.4.1.9.9.720.1.2.1.1.17CtsSxpConnectionStatusread-onlycurrent
ctsxSxpVrfId
OBJECT-TYPE
The numerical identifier associated with ctsxSxpConnVrfName.
1.3.6.1.4.1.9.9.720.1.2.1.1.18Unsigned32read-onlycurrent
ctsxSxpConnStorageType
OBJECT-TYPE
The storage type of this conceptual row.
1.3.6.1.4.1.9.9.720.1.2.1.1.19StorageTyperead-createcurrent
ctsxSxpConnRowStatus
OBJECT-TYPE
The status of this conceptual row. Once a row becomes active, only the value in ctsxSxpConnModeLocation, ctsxSxpConnMode ctsxSxpConnSpeakerMinHoldTime, ctsxSxpConnListenerMinHoldTime, and ctsxSxpConnListenerMaxHoldTime within each a row can be modified.
1.3.6.1.4.1.9.9.720.1.2.1.1.20RowStatusread-createcurrent
ctsxSxpConnVersion
OBJECT-TYPE
The version of SXP protocol in use for this connection. 'unknown' - Version of SXP protocol for this connection is unknown. 'one' - Connection is using version 1 of the SXP protocol. 'two' - Connection is using version 2 of the SXP protocol. 'three' - Connection is using version 3 of the SXP protocol. 'four' - Connection is using version 4 of the SXP protocol.
1.3.6.1.4.1.9.9.720.1.2.1.1.21INTEGER {unknown(1), one(2), two(3), three(4), four(5)}read-onlycurrent
ctsxSxpConnSpeakerMinHoldTime
OBJECT-TYPE
This object specifies the minimum hold-time for this SXP connection when the device is acting as 'speaker'. Setting the object to zero indicates that the global value ctsxSxpSpeakerMinHoldTime will be used for the connection. Setting the object to 65535 indicates that the hold-time functionality has been disabled for the connection. Value of this object must be 65535 if the corresponding instance value of ctsxSxpConnListenerMinHoldTime is 65535. Value of this object should be ignored and can not be set if the corresponding instance values of ctsxSxpConnModeLocation is 'local' and ctsxSxpConnMode is 'listener' or ctsxSxpConnModeLocation is 'peer' and ctsxSxpConnMode is 'speaker'. Value of this object should be ignored and can not be set if the corresponding instance value of ctsxSxpConnMode is 'both'.
1.3.6.1.4.1.9.9.720.1.2.1.1.22Unsigned32 (0 | 1..65534 | 65535)read-createcurrent
ctsxSxpConnListenerMinHoldTime
OBJECT-TYPE
This object specifies the minimum hold-time for this SXP connection when the device is acting as 'listener'. Value of this object must be lesser than ctsxSxpConnListenerMaxHoldTime. Setting the object to zero indicates that the global value ctsxSxpListenerMinHoldTime will be used for the connection. Value of this object must be zero if the value of corresponding instance value of ctsxSxpConnListenerMaxHoldTime is zero. Setting the object to 65535 indicates that hold-time functionality has been disabled for the connection. Value of this object must be 65535 if the corresponding instance value of ctsxSxpConnListenerMaxHoldTime is 65535. Value of this object should be ignored and can not be set if the corresponding instance value of ctsxSxpConnModeLocation is 'local' and ctsxSxpConnMode is 'speaker' or ctsxSxpConnModeLocation is 'peer' and ctsxSxpConnMode is 'listener'. Value of this object should be ignored and can not be set if the value of ctsxSxpConnMode is 'both'.
1.3.6.1.4.1.9.9.720.1.2.1.1.23Unsigned32 (0 | 1..65534 | 65535)read-createcurrent
ctsxSxpConnListenerMaxHoldTime
OBJECT-TYPE
This object specifies the maximum hold-time for this SXP connection when the device is acting as 'listener'. Value of this object must be greater than ctsxSxpConnListenerMinHoldTime. Setting the object to zero indicates that the global value ctsxSxpListenerMaxHoldTime will be used for the connection. Value of this object must be zero if the corresponding instance value of ctsxSxpConnListenerMinHoldTime is zero. Setting the object to 65535 indicates that hold-time functionality has been disabled for the connection. Value of this object must be 65535 if the corresponding instance value ctsxSxpConnListenerMinHoldTime is 65535. Value of this object should be ignored and can not be set if the corresponding instance value of ctsxSxpConnModeLocation is 'local' and ctsxSxpConnMode is 'speaker' or ctsxSxpConnModeLocation is 'peer' and ctsxSxpConnMode is 'listener'. Value of this object should be ignored and can not be set if the value of ctsxSxpConnMode is 'both'.
1.3.6.1.4.1.9.9.720.1.2.1.1.24Unsigned32 (0 | 1..65534 | 65535)read-createcurrent
ctsxSxpConnHoldTime
OBJECT-TYPE
This object indicates the hold-time in use for this SXP connection. A value of 0 indicates that hold-time functionality has been disabled for this connection. When the corresponding instance value of ctsxSxpConnMode is 'both', this object indicates the hold-time in use by the 'speaker' and ctsxSxpConnBiDirListenerHoldTime indicates the hold-time in use by the 'listener'.
1.3.6.1.4.1.9.9.720.1.2.1.1.25Unsigned32read-onlycurrent
ctsxSxpConnCapability
OBJECT-TYPE
This object indicates the capability of SXP connection.
1.3.6.1.4.1.9.9.720.1.2.1.1.26Bits {ipv4(0), ipv6(1), subnet(2)}read-onlycurrent
ctsxSxpConnBiDirListenerStatus
OBJECT-TYPE
This object indicates the status of 'listener' for this Bi-directional SXP connection. Value of this object should be ignored if the corresponding instance value of ctsxSxpConnMode is not 'both'.
1.3.6.1.4.1.9.9.720.1.2.1.1.27CtsSxpConnectionStatusread-onlycurrent
ctsxSxpConnBiDirListenerHoldTime
OBJECT-TYPE
This object indicates the hold-time in use by the listener for this Bi-directional SXP connection. Value of this object should be ignored if the corresponding instance value of ctsxSxpConnMode is not 'both'.
1.3.6.1.4.1.9.9.720.1.2.1.1.28Unsigned32read-onlycurrent
ctsxSxpSgtObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1.3
ctsxIpSgtMappingTable
OBJECT-TYPE
A list of SGT mappings learnt by this device. If the value of ctsxSxpConnVersion is 'three' or above, this table populates entries for all mapping addresses without prefix. Addresses with prefix are not populated in this table. ctsxSxpSgtMapTable should be used in such case.
1.3.6.1.4.1.9.9.720.1.3.1not-accessiblecurrent
ctsxIpSgtMappingEntry
OBJECT-TYPE
An entry containing management information about SGT mapping learnt by this device. An entry will be created for each SGT mappings the device learns via SXP. An entry will be deleted if SXP connection from where the SGT mappings was learnt is disconnected.
1.3.6.1.4.1.9.9.720.1.3.1.1not-accessiblecurrent
ctsxIpSgtMappingVrfId
OBJECT-TYPE
The VRF number identifying the VRF where this SGT mapping was learnt.
1.3.6.1.4.1.9.9.720.1.3.1.1.1Unsigned32not-accessiblecurrent
ctsxIpSgtMappingAddrType
OBJECT-TYPE
The type of IP address in this SGT mapping.
1.3.6.1.4.1.9.9.720.1.3.1.1.2InetAddressTypenot-accessiblecurrent
ctsxIpSgtMappingAddr
OBJECT-TYPE
The IP address in this SGT mapping. The type of this address is determined by the value of ctsxIpSgtMappingAddrType object.
1.3.6.1.4.1.9.9.720.1.3.1.1.3InetAddress (SIZE(1..48))not-accessiblecurrent
ctsxIpSgtMappingPeerAddrType
OBJECT-TYPE
The type of IP address of the SXP peer device from where this SGT mapping was learnt.
1.3.6.1.4.1.9.9.720.1.3.1.1.4InetAddressTypenot-accessiblecurrent
ctsxIpSgtMappingPeerAddr
OBJECT-TYPE
The IP address of the peer SXP device from where this SGT mapping was learnt. The type of this address is determined by the value of ctsxIpSgtMappingPeerAddrType object.
1.3.6.1.4.1.9.9.720.1.3.1.1.5InetAddress (SIZE(1..48))not-accessiblecurrent
ctsxIpSgtMappingSgt
OBJECT-TYPE
The Security Group Tag (SGT) in this SGT mapping. ctsxIpSgtMappingAddr represents the IP address associated with this SGT.
1.3.6.1.4.1.9.9.720.1.3.1.1.6CtsSecurityGroupTagread-onlycurrent
ctsxIpSgtMappingInstance
OBJECT-TYPE
This object indicates the instance number of the SXP connection from where this SGT mapping was learnt. The instance number is used to determine if an SGT mapping entry is stale and needs to be removed from the system.
1.3.6.1.4.1.9.9.720.1.3.1.1.7Unsigned32read-onlycurrent
ctsxIpSgtMappingVrfName
OBJECT-TYPE
The name of the VRF identified by ctsxIpSgtMappingVrfId.
1.3.6.1.4.1.9.9.720.1.3.1.1.8CiscoVrfNameread-onlycurrent
ctsxIpSgtMappingStatus
OBJECT-TYPE
This object indicates the status of this SGT mapping. 'other' - Any other state no covered by below enumerations. 'active' - The SGT mapping is currently active.
1.3.6.1.4.1.9.9.720.1.3.1.1.9INTEGER {other(1), active(2)}read-onlycurrent
ctsxSxpSgtMapTable
OBJECT-TYPE
A list of SGT mappings learnt by this device.
1.3.6.1.4.1.9.9.720.1.3.2not-accessiblecurrent
ctsxSxpSgtMapEntry
OBJECT-TYPE
An entry containing management information about SGT mapping learnt by this device. An entry will be created for each of the SGT mappings the device learns via SXP. An entry will be deleted if SXP connection from where the SGT mappings was learnt is disconnected.
1.3.6.1.4.1.9.9.720.1.3.2.1not-accessiblecurrent
ctsxSxpSgtMapVrfId
OBJECT-TYPE
The VRF number identifying the VRF where this SGT mapping was learnt.
1.3.6.1.4.1.9.9.720.1.3.2.1.1Unsigned32not-accessiblecurrent
ctsxSxpSgtMapAddrType
OBJECT-TYPE
The type of address in this SGT mapping.
1.3.6.1.4.1.9.9.720.1.3.2.1.2InetAddressTypenot-accessiblecurrent
ctsxSxpSgtMapAddr
OBJECT-TYPE
The address in this SGT mapping. The type of this address is determined by the value of ctsxSxpSgtMapAddrType object.
1.3.6.1.4.1.9.9.720.1.3.2.1.3InetAddress (SIZE(1..48))not-accessiblecurrent
ctsxSxpSgtMapAddrPrefixLength
OBJECT-TYPE
This object indicates the length of the prefix associated with ctsxSxpSgtMapAddr. This object is always interpreted with the value of ctsxSxpSgtMapAddrType object.
1.3.6.1.4.1.9.9.720.1.3.2.1.4InetAddressPrefixLengthnot-accessiblecurrent
ctsxSxpSgtMapPeerAddrType
OBJECT-TYPE
The type of address of the SXP peer device from where this SGT mapping was learnt.
1.3.6.1.4.1.9.9.720.1.3.2.1.5InetAddressTypenot-accessiblecurrent
ctsxSxpSgtMapPeerAddr
OBJECT-TYPE
The address of the peer SXP device from where this SGT mapping was learnt. The type of this address is determined by the value of ctsxSxpSgtMapPeerAddrType object.
1.3.6.1.4.1.9.9.720.1.3.2.1.6InetAddress (SIZE(1..48))not-accessiblecurrent
ctsxSxpSgtMapSgt
OBJECT-TYPE
The Security Group Tag (SGT) in this SGT mapping. ctsxSxpSgtMapAddr represents the address associated with this SGT.
1.3.6.1.4.1.9.9.720.1.3.2.1.7CtsSecurityGroupTagread-onlycurrent
ctsxSxpSgtMapInstance
OBJECT-TYPE
This object indicates the instance number of the SXP connection from where this SGT binding was learnt. The instance number is used to determine if an SGT mapping entry is stale and needs to be removed from the system.
1.3.6.1.4.1.9.9.720.1.3.2.1.8Unsigned32read-onlycurrent
ctsxSxpSgtMapVrfName
OBJECT-TYPE
The name of the VRF identified by ctsxEnahncedSgtMapVrfId.
1.3.6.1.4.1.9.9.720.1.3.2.1.9CiscoVrfNameread-onlycurrent
ctsxSxpSgtMapPeerSeq
OBJECT-TYPE
The Peer Sequence associated with this SGT mapping entry. It is a sequence of node IDs though which SGT mapping has traversed. Each node ID is 4 octets long. The octets 1 to 4 represent the first node ID in the sequence, octets 5 to 8 represent the second node ID in the sequence and so on.
1.3.6.1.4.1.9.9.720.1.3.2.1.10OCTET STRINGread-onlycurrent
ctsxSxpSgtMapStatus
OBJECT-TYPE
This object indicates the status of this SGT mapping. 'other' - Any other state no covered by below enumerations. 'active' - The SGT mapping is currently active.
1.3.6.1.4.1.9.9.720.1.3.2.1.11INTEGER {other(1), active(2)}read-onlycurrent
ciscoTrustSecSxpMIBNotifsControl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1.4
ctsxSxpConnSourceAddrErrNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpConnSourceAddrErrNotif. A value of 'false' will prevent ctsxSxpConnSourceAddrErrNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.1TruthValueread-writecurrent
ctsxSxpMsgParseErrNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpMsgParseErrNotif. A value of 'false' will prevent ctsxSxpMsgParseErrNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.2TruthValueread-writecurrent
ctsxSxpConnConfigErrNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpConnConfigErrNotif. A value of 'false' will prevent ctsxSxpConnConfigErrNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.3TruthValueread-writecurrent
ctsxSxpBindingErrNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpBindingErrNotif. A value of 'false' will prevent ctsxSxpBindingErrNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.4TruthValueread-writecurrent
ctsxSxpConnUpNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpConnUpNotif. A value of 'false' will prevent ctsxSxpConnUpNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.5TruthValueread-writecurrent
ctsxSxpConnDownNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpConnDownNotif. A value of 'false' will prevent ctsxSxpConnDownNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.6TruthValueread-writecurrent
ctsxSxpExpansionFailNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpExpansionFailNotif. A value of 'false' will prevent ctsxSxpExpansionFailNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.7TruthValueread-writecurrent
ctsxSxpOperNodeIdChangeNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpOperNodeIdChangeNotif. A value of 'false' will prevent ctsxSxpOperNodeIdChangeNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.8TruthValueread-writecurrent
ctsxSxpBindingConflictNotifEnable
OBJECT-TYPE
This object specifies whether the system generates the ctsxSxpBindingConflictNotif. A value of 'false' will prevent ctsxSxpBindingConflictNotif notifications from being generated by this system.
1.3.6.1.4.1.9.9.720.1.4.9TruthValueread-writecurrent
ciscoTrustSecSxpMIBNotifsOnlyInfo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.1.5
ctsxSgtMapExpansionVrf
OBJECT-TYPE
This object indicates the VRF name for which host SGT bindings cannot be expanded.
1.3.6.1.4.1.9.9.720.1.5.1CiscoVrfNameaccessible-for-notifycurrent
ctsxSgtMapExpansionAddrType
OBJECT-TYPE
This object indicates the type of subnet address for which host SGT binding cannot be expanded.
1.3.6.1.4.1.9.9.720.1.5.2InetAddressTypeaccessible-for-notifycurrent
ctsxSgtMapExpansionAddr
OBJECT-TYPE
This object indicates the subnet address for which host SGT binding cannot be expanded. The type of this address is determined by the value of ctsxSgtMapExpansionAddrType object.
1.3.6.1.4.1.9.9.720.1.5.3InetAddressaccessible-for-notifycurrent
ctsxSgtMapExpansionAddrPrefixLength
OBJECT-TYPE
This object indicates the length of the prefix associated with ctsxSgtMapExpansionAddr. This object is always interpreted with the value of ctsxSgtMapExpansionAddrType object.
1.3.6.1.4.1.9.9.720.1.5.4InetAddressPrefixLengthaccessible-for-notifycurrent
ctsxSxpNotifErrMsg
OBJECT-TYPE
This object indicates error message associated with notifications.
1.3.6.1.4.1.9.9.720.1.5.5SnmpAdminStringaccessible-for-notifycurrent
ctsxSgtMapConflictingVrfName
OBJECT-TYPE
This object indicates the VRF name of the SXP connection on which conflicting SGT mapping was received.
1.3.6.1.4.1.9.9.720.1.5.6CiscoVrfNameaccessible-for-notifycurrent
ctsxSgtMapConflictingAddrType
OBJECT-TYPE
This object indicates the type of Internet address in the conflicting SGT mapping.
1.3.6.1.4.1.9.9.720.1.5.7InetAddressTypeaccessible-for-notifycurrent
ctsxSgtMapConflictingAddr
OBJECT-TYPE
This object indicates the Internet address in the conflicting SGT mapping. The type of this address is determined by the value of ctsxSgtMapConflictingAddrType object.
1.3.6.1.4.1.9.9.720.1.5.8InetAddressaccessible-for-notifycurrent
ctsxSgtMapConflictingOldSgt
OBJECT-TYPE
The existing value of Security Group Tag (SGT) in SGT mapping for which conflict has occurred.
1.3.6.1.4.1.9.9.720.1.5.9CtsSecurityGroupTagaccessible-for-notifycurrent
ctsxSgtMapConflictingNewSgt
OBJECT-TYPE
The new value of Security Group Tag (SGT) in SGT mapping that conflicts with the existing SGT.
1.3.6.1.4.1.9.9.720.1.5.10CtsSecurityGroupTagaccessible-for-notifycurrent
ctsxSxpOldOperNodeId
OBJECT-TYPE
The SXP node ID that was in use by this SXP node and now replaced by a new SXP node ID represented by ctsxSxpOperNodeId.
1.3.6.1.4.1.9.9.720.1.5.11Unsigned32accessible-for-notifycurrent
ciscoTrustSecSxpMIBConform
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.2
ciscoTrustSecSxpMIBCompliances
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.2.1
ciscoTrustSecSxpMIBGroups
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.720.2.2

Notifications

NameOIDStatus
ctsxSxpConnSourceAddrErrNotif
NOTIFICATION-TYPE
A ctsxSxpConnSourceAddrErrNotif is generated if the system is not able to establish SXP connection using ctsxSxpConnOperSourceAddr.
1.3.6.1.4.1.9.9.720.0.1current
ctsxSxpMsgParseErrNotif
NOTIFICATION-TYPE
A ctsxSxpMsgParseErrNotif is generated if the system is not able to parse a received SXP message.
1.3.6.1.4.1.9.9.720.0.2current
ctsxSxpConnConfigErrNotif
NOTIFICATION-TYPE
A ctsxSxpConnConfigErrNotif is generated if the system detects a configuration error for an SXP connection.
1.3.6.1.4.1.9.9.720.0.3current
ctsxSxpBindingErrNotif
NOTIFICATION-TYPE
A ctsxSxpBindingErrNotif is generated if the address in the SGT mapping is not found in routing and forwarding table of the system.
1.3.6.1.4.1.9.9.720.0.4current
ctsxSxpConnUpNotif
NOTIFICATION-TYPE
A ctsxSxpConnUpNotif is generated if the ctsxSxpConnStatus for an SXP connection transitioned into 'on' state.
1.3.6.1.4.1.9.9.720.0.5current
ctsxSxpConnDownNotif
NOTIFICATION-TYPE
A ctsxSxpConnDownNotif is generated if ctsxSxpConnStatus for an SXP connection left the 'on' state and transitioned into some other state.
1.3.6.1.4.1.9.9.720.0.6current
ctsxSxpExpansionFailNotif
NOTIFICATION-TYPE
A ctsxSxpExpansionFailNotif is generated if the number of expanded SGT maps reaches the configured limit and the received SGT mapping can not be expanded.
1.3.6.1.4.1.9.9.720.0.7current
ctsxSxpOperNodeIdChangeNotif
NOTIFICATION-TYPE
A ctsxSxpOperNodeIdChangeNotif is generated if the value of ctsxSxpOperNodeId changes.
1.3.6.1.4.1.9.9.720.0.8current
ctsxSxpBindingConflictNotif
NOTIFICATION-TYPE
A ctsxSxpBindingConflictNotif is generated if the device receives conflicting SGT mapping information.
1.3.6.1.4.1.9.9.720.0.9current

Conformance

NameOIDStatus
ciscoTrustSecSxpMIBCompliance
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
1.3.6.1.4.1.9.9.720.2.1.1deprecated
ciscoTrustSecSxpMIBCompliance2
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
1.3.6.1.4.1.9.9.720.2.1.2deprecated
ciscoTrustSecSxpMIBCompliance3
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
1.3.6.1.4.1.9.9.720.2.1.3deprecated
ciscoTrustSecSxpMIBCompliance4
MODULE-COMPLIANCE
The compliance statement for the CISCO-TRUSTSEC-SXP-MIB.
1.3.6.1.4.1.9.9.720.2.1.4current
ctsxSxpGlobalGroup
OBJECT-GROUP
A collection of objects providing management functionality of global SXP configuration.
1.3.6.1.4.1.9.9.720.2.2.1current
ctsxSxpConnectionGroup
OBJECT-GROUP
A collection of objects providing management functionality of SXP connections.
1.3.6.1.4.1.9.9.720.2.2.2current
ctsxIpSgtMappingGroup
OBJECT-GROUP
A collection of objects providing management functionality of SGT mapping for SXP.
1.3.6.1.4.1.9.9.720.2.2.3current
ctsxSxpVersionGroup
OBJECT-GROUP
A collection of object(s) providing version information for SXP.
1.3.6.1.4.1.9.9.720.2.2.4current
ctsxSxpBindingLogGroup
OBJECT-GROUP
A collection of object(s) providing logging control for SXP binding.
1.3.6.1.4.1.9.9.720.2.2.5current
ctsxSxpBindingNotifInfoGroup
OBJECT-GROUP
A collection of object(s) providing variable binding information for SXP notifications.
1.3.6.1.4.1.9.9.720.2.2.6current
ctsxSxpNotifErrMsgGroup
OBJECT-GROUP
A collection of object(s) providing detailed error messages for SXP notifications.
1.3.6.1.4.1.9.9.720.2.2.7current
ctsxSxpNodeIdInfoGroup
OBJECT-GROUP
A collection of object(s) providing SXP node ID information for the system.
1.3.6.1.4.1.9.9.720.2.2.8current
ctsxSxpSgtMapGroup
OBJECT-GROUP
A collection of objects providing management functionality of SGT mapping and expansion for SXP.
1.3.6.1.4.1.9.9.720.2.2.9current
ctsxNotifsControlGroup
OBJECT-GROUP
A collection of objects providing notification control for SXP.
1.3.6.1.4.1.9.9.720.2.2.10current
ctsxNotifsGroup
NOTIFICATION-GROUP
A collection of notifications for SXP.
1.3.6.1.4.1.9.9.720.2.2.11current
ctsxSxpGlobalHoldTimeGroup
OBJECT-GROUP
A collection of objects providing global hold-time information for SXP connections.
1.3.6.1.4.1.9.9.720.2.2.12current
ctsxSxpConnHoldTimeGroup
OBJECT-GROUP
A collection of objects providing hold-time information for each SXP connection.
1.3.6.1.4.1.9.9.720.2.2.13current
ctsxSxpConnCapbilityGroup
OBJECT-GROUP
A collection of object(s) providing capability information for each SXP connection.
1.3.6.1.4.1.9.9.720.2.2.14current
ctsxSxpVersionSupportGroup
OBJECT-GROUP
A collection of object(s) providing SXP version capability information.
1.3.6.1.4.1.9.9.720.2.2.15current
ctsxSgtMapPeerSeqGroup
OBJECT-GROUP
A collection of object(s) providing Peer Sequence information.
1.3.6.1.4.1.9.9.720.2.2.16current
ctsxBiDirectionalSxpGroup
OBJECT-GROUP
A collection of object(s) providing Bi-directional SXP information.
1.3.6.1.4.1.9.9.720.2.2.17current