MIBs Depot

CISCOSB-SECURITY-SUITE

Registered at
1.3.6.1.4.1.9.6.1.101.120
Last updated
2006-04-08 00:00
Organization
Cisco Systems, Inc.
Revisions
2006-01-09 00:00
Namespace
cisco
Source file
CISCOSB-SECURITY-SUITE
Digest
sha256:74254b5a892f4b258ad6dce6f5a3172ccf5c900ae81943252979050c41b9e13b

Description

The private MIB module definition for blocking attacks such as DoS(=Denial Of Service), SYN and well known viruses Attacks in CISCOSB devices.

Contact

Postal: 170 West Tasman Drive San Jose , CA 95134-1706 USA Website: Cisco Small Business Support Community <http://www.cisco.com/go/smallbizsupport>

Imports

FromSymbols
CISCOSB-MIBPercents, switch001
IF-MIBInterfaceIndex, InterfaceIndexOrZero, ifIndex
Q-BRIDGE-MIBPortList
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP
SNMPv2-SMICounter32, Gauge32, IpAddress, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, TimeTicks, Unsigned32, iso
SNMPv2-TCDisplayString, RowPointer, RowStatus, TEXTUAL-CONVENTION, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

BRIDGE-MIB
CISCOSB-MIB
CISCOSB-SECURITY-SUITE
IANAifType-MIB
IF-MIB
P-BRIDGE-MIB
Q-BRIDGE-MIB
RFC1158-MIB
RFC1271-MIB
RMON-MIB
RMON2-MIB
SNMP-FRAMEWORK-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC
TOKEN-RING-RMON-MIB

Textual conventions

NameOIDSyntaxAccessStatus
RlSecuritySuiteAllMartianEntryType
TEXTUAL-CONVENTION
Specifies Martian-address origin: pre-defined (reserved) or statically configured
current
RlSecuritySuiteDenyAttackType
TEXTUAL-CONVENTION
Specifies the deny attack types
current
RlSecuritySuiteDenySynFinTcp
TEXTUAL-CONVENTION
Specifies the dropping SYN, FIN flags enabled TCP packets status
current
RlSecuritySuiteKnownDosAttackProtocolType
TEXTUAL-CONVENTION
Specifies protocol type of the well-known DoS attack
current
RlSecuritySuiteKnownDosAttackType
TEXTUAL-CONVENTION
Specifies well-known DoS attack
current
RlSecuritySuiteSynProtectionMode
TEXTUAL-CONVENTION
Specifies the TCP SYN attack protection mode .
current
RlSecuritySuiteSynProtectionPortMode
TEXTUAL-CONVENTION
Specifies the TCP SYN attack protection mode .
current
RlsecuritySuiteGlobalEnableType
TEXTUAL-CONVENTION
Specifies the operating modes of the security-suite
current

Objects

NameOIDSyntaxAccessStatus
rlSecuritySuiteGlobalEnable
OBJECT-TYPE
This scalar globally enables/disables the DoS attack Suite.
1.3.6.1.4.1.9.6.1.101.120.1RlsecuritySuiteGlobalEnableTyperead-writecurrent
rlSecuritySuiteKnownDoSAttacksTable
OBJECT-TYPE
This table enables/disable well-know DoS attacks, applied globally to all ifIndexes.
1.3.6.1.4.1.9.6.1.101.120.2not-accessiblecurrent
rlSecuritySuiteKnownDoSAttacksEntry
OBJECT-TYPE
Each entry in this table describes one well known DoS attack address
1.3.6.1.4.1.9.6.1.101.120.2.1not-accessiblecurrent
rlSecuritySuiteKnownDoSAttack
OBJECT-TYPE
A well-known DoS attack to enable
1.3.6.1.4.1.9.6.1.101.120.2.1.1RlSecuritySuiteKnownDosAttackTypenot-accessiblecurrent
rlSecuritySuiteKnownDoSAttackEnable
OBJECT-TYPE
Enable/Disable a well-known DoS attack
1.3.6.1.4.1.9.6.1.101.120.2.1.2TruthValueread-writecurrent
rlSecuritySuiteKnownDoSAttacksDetailsTable
OBJECT-TYPE
This read-only table used to present the detailed attributes of each well-known DoS attack. Used for presentation propose only.
1.3.6.1.4.1.9.6.1.101.120.3not-accessiblecurrent
rlSecuritySuiteKnownDoSAttacksDetailsEntry
OBJECT-TYPE
Each entry in this table describes one well known DoS attack address ,
1.3.6.1.4.1.9.6.1.101.120.3.1not-accessiblecurrent
rlSecuritySuiteKnownDoSAttackProtocl
OBJECT-TYPE
Specifies the protocol type of the relevant well-known attack
1.3.6.1.4.1.9.6.1.101.120.3.1.1RlSecuritySuiteKnownDosAttackProtocolTyperead-onlycurrent
rlSecuritySuiteKnownDoSAttackSrcTcpUdpPort
OBJECT-TYPE
Specifies the source tcp/udp port of the relevant well-known attack
1.3.6.1.4.1.9.6.1.101.120.3.1.2INTEGERread-onlycurrent
rlSecuritySuiteKnownDoSAttackDestTcpUdpPort
OBJECT-TYPE
Specifies the destination tcp/udp port of the relevant well-known attack
1.3.6.1.4.1.9.6.1.101.120.3.1.3INTEGERread-onlycurrent
rlSecuritySuiteReservedMartianAddresses
OBJECT-TYPE
This scalar globally enables/disables discarding of the IP well-known addresses described below: ------------------------------------------------------------------------------- | Address block | Present use |------------------------------------------------------------------------------- |0.0.0.0/8 | Addresses in this block refer to source hosts |(except 0.0.0.0/32 | on 'this' network. | as source address) | |------------------------------------------------------------------------------ |127.0.0.0/8 | This block is assigned for use as the Internet host loop-back address. |----------------------------------------------------------------------------------------------------- |192.0.2.0/24 | This block is assigned as 'TEST-NET' | | for use in documentation and example code. |--------------------------------------------------------------------------- |224.0.0.0/4 as source. | This block, formerly known as the Class D address space, | | is allocated for use in IPv4 multicast address assignments. |------------------------------------------------------------------------------------------- |240.0.0.0/4 | |(except 255.255.255.255/32 | This block, formerly known as the Class E address space, is reserved. | as destination address) | |-------------------------------------------------------------------------------------------------------
1.3.6.1.4.1.9.6.1.101.120.4TruthValueread-writecurrent
rlSecuritySuiteMartianAddrAllTable
OBJECT-TYPE
This read-only table specifies all current configured Martian addresses - both pre-defined (=reserved) and used-configured (=static) addresses
1.3.6.1.4.1.9.6.1.101.120.5not-accessiblecurrent
rlSecuritySuiteMartianAddrAllEntry
OBJECT-TYPE
Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded.
1.3.6.1.4.1.9.6.1.101.120.5.1not-accessiblecurrent
rlSecuritySuiteMartianAddr
OBJECT-TYPE
An IP address to discard all packets with that address as source or destination
1.3.6.1.4.1.9.6.1.101.120.5.1.1IpAddressnot-accessiblecurrent
rlSecuritySuiteMartianAddrNetMask
OBJECT-TYPE
Specify the net mask that comprise the destination IP address prefix.
1.3.6.1.4.1.9.6.1.101.120.5.1.2IpAddressnot-accessiblecurrent
rlSecuritySuiteAllMartianEntryType
OBJECT-TYPE
Specific the entry origin: pre-defined (reserved) of statically configured.
1.3.6.1.4.1.9.6.1.101.120.5.1.3RlSecuritySuiteAllMartianEntryTyperead-onlycurrent
rlSecuritySuiteMartianAddrTable
OBJECT-TYPE
This table specifies the Martian addresses - the addresses that packets with these IP addressed as source or destination are discarded.
1.3.6.1.4.1.9.6.1.101.120.6not-accessiblecurrent
rlSecuritySuiteMartianAddrEntry
OBJECT-TYPE
Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded.
1.3.6.1.4.1.9.6.1.101.120.6.1not-accessiblecurrent
rlSecuritySuiteMartianAddrStatus
OBJECT-TYPE
The status of a table entry. It is used to delete/Add an entry from this table.
1.3.6.1.4.1.9.6.1.101.120.6.1.1RowStatusread-createcurrent
rlSecuritySuiteDoSSynAttackTable
OBJECT-TYPE
This table contains IP address and rate, to limit DoS SYN attacks from a specific IP address and interface(s)
1.3.6.1.4.1.9.6.1.101.120.7not-accessiblecurrent
rlSecuritySuiteDoSSynAttackEntry
OBJECT-TYPE
Each entry in this table describes one Martian address , packets with this address as IP source or IP destination, are discarded.
1.3.6.1.4.1.9.6.1.101.120.7.1not-accessiblecurrent
rlSecuritySuiteDoSSynAttackIfIndex
OBJECT-TYPE
Interface which the attack is applied on
1.3.6.1.4.1.9.6.1.101.120.7.1.1InterfaceIndexnot-accessiblecurrent
rlSecuritySuiteDoSSynAttackAddr
OBJECT-TYPE
An IP address to discard all packets with that address as destination
1.3.6.1.4.1.9.6.1.101.120.7.1.2IpAddressnot-accessiblecurrent
rlSecuritySuiteDoSSynAttackNetMask
OBJECT-TYPE
Relevant when rlSecuritySuiteSynAttackRangeType equals prefix(2). Specify the number of bits that comprise the destination IP address prefix.
1.3.6.1.4.1.9.6.1.101.120.7.1.3IpAddressnot-accessiblecurrent
rlSecuritySuiteDoSSynAttackSynRate
OBJECT-TYPE
Specify the maximum connections per second allowed from this IP address and rlSecuritySuiteSynAttackPortList
1.3.6.1.4.1.9.6.1.101.120.7.1.4INTEGERread-createcurrent
rlSecuritySuiteDoSSynAttackStatus
OBJECT-TYPE
The status of a table entry. It is used to delete/Add an entry from this table.
1.3.6.1.4.1.9.6.1.101.120.7.1.6RowStatusread-createcurrent
rlSecuritySuiteDenyTypesTable
OBJECT-TYPE
This table specifies the ip address and TCP ports that TCP SYN packets from them on a specific interfaces are dropped.
1.3.6.1.4.1.9.6.1.101.120.8not-accessiblecurrent
rlSecuritySuiteDenyTypesEntry
OBJECT-TYPE
Each entry in this table describes one ip address, TCP port and list of ifIndexes, that packets with these attributes are discarded.
1.3.6.1.4.1.9.6.1.101.120.8.1not-accessiblecurrent
rlSecuritySuiteDenyIfIndex
OBJECT-TYPE
Interface which the attack is applied on
1.3.6.1.4.1.9.6.1.101.120.8.1.1InterfaceIndexnot-accessiblecurrent
rlSecuritySuiteDenyAttackType
OBJECT-TYPE
The specific deny attack type
1.3.6.1.4.1.9.6.1.101.120.8.1.2RlSecuritySuiteDenyAttackTypenot-accessiblecurrent
rlSecuritySuiteDenyDestAddr
OBJECT-TYPE
An IP address to discard all packets with that address as destination
1.3.6.1.4.1.9.6.1.101.120.8.1.3IpAddressnot-accessiblecurrent
rlSecuritySuiteDenyNetMask
OBJECT-TYPE
Relevant when rlSecuritySuiteDenyTCPRangeType equals mask(1). Specify the number of bits that comprise the destination IP address prefix.
1.3.6.1.4.1.9.6.1.101.120.8.1.4IpAddressnot-accessiblecurrent
rlSecuritySuiteDenyDestPort
OBJECT-TYPE
Destination TCP port. Use 65553 to specify all ports. This key-field is relevant in specific attack types (not all) Use 0 when not relevant.
1.3.6.1.4.1.9.6.1.101.120.8.1.5INTEGERnot-accessiblecurrent
rlSecuritySuiteDenyStatus
OBJECT-TYPE
The status of a table entry. It is used to delete/Add an entry from this table.
1.3.6.1.4.1.9.6.1.101.120.8.1.6RowStatusread-createcurrent
rlSecuritySuiteDenySynFinTcp
OBJECT-TYPE
This scalar globally enable or disable dropping of tcp packets with both SYN and FIN flags enabled.
1.3.6.1.4.1.9.6.1.101.120.9RlSecuritySuiteDenySynFinTcpread-writecurrent
rlSecuritySuiteSynProtectionMode
OBJECT-TYPE
This scalar globally set protection mode on TCP SYN traffic. Disabled - the system doesn't support protection against TCP SYN attack. Report - the system doesn't support protection against TCP SYN attack,but reports about it. Block - the systems supports protection against TCP SYN attack by blocking this traffic on the port.
1.3.6.1.4.1.9.6.1.101.120.10RlSecuritySuiteSynProtectionModeread-writecurrent
rlSecuritySuiteSynProtectionTreshold
OBJECT-TYPE
This scalar globally set protection mode treshold value in packet per second on TCP SYN traffic.
1.3.6.1.4.1.9.6.1.101.120.11INTEGERread-writecurrent
rlSecuritySuiteSynProtectionRecoveryTimeout
OBJECT-TYPE
This scalar globally set protection reovery time out in secounds.
1.3.6.1.4.1.9.6.1.101.120.12INTEGERread-writecurrent
rlSecuritySuiteSynProtectionPortTable
OBJECT-TYPE
This table keeps SYN protection status per port.
1.3.6.1.4.1.9.6.1.101.120.13not-accessiblecurrent
rlSecuritySuiteSynProtectionPortEntry
OBJECT-TYPE
Each entry in this table describes TCP SYN protection status for one port.
1.3.6.1.4.1.9.6.1.101.120.13.1not-accessiblecurrent
rlSecuritySuiteSynProtectionPortMode
OBJECT-TYPE
The port's TCP SYN protection mode.
1.3.6.1.4.1.9.6.1.101.120.13.1.1RlSecuritySuiteSynProtectionPortModeread-onlycurrent
rlSecuritySuiteSynProtectionPortModeLastTimeAttack
OBJECT-TYPE
The port's TCP SYN protection last attack time mode.
1.3.6.1.4.1.9.6.1.101.120.13.1.2RlSecuritySuiteSynProtectionPortModeread-onlycurrent
rlSecuritySuiteSynProtectionPortLastTimeAttack
OBJECT-TYPE
The port's TCP SYN protection last attack time.
1.3.6.1.4.1.9.6.1.101.120.13.1.3DisplayStringread-onlycurrent