HP-ICF-ARP-PROTECT
- Registered at
- 1.3.6.1.4.1.11.2.14.11.5.1.37
- Last updated
- 2007-08-29 00:00
- Organization
- Hewlett-Packard Company ProCurve Networking Business
- Revisions
- 2007-08-29 00:00, 2006-05-03 00:27
- Namespace
- hp
- Source file
HP-ICF-ARP-PROTECT- Digest
sha256:8d5a8a3545db039ef9bf1b6674f550bbe9ae0a0a7f4a65a1ea35526260b8cd49
Description
This MIB module contains HP proprietary objects for managing Dynamic ARP Protection.
Contact
Hewlett-Packard Company 8000 Foothills Blvd. Roseville, CA 95747
Imports
| From | Symbols |
|---|---|
| HP-ICF-OID | hpSwitch |
| IF-MIB | ifIndex |
| INET-ADDRESS-MIB | InetAddress, InetAddressType |
| Q-BRIDGE-MIB | VlanIndex |
| SNMPv2-CONF | MODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP |
| SNMPv2-SMI | Counter32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, iso |
| SNMPv2-TC | DisplayString, MacAddress, TEXTUAL-CONVENTION, TruthValue |
Imported by
Nothing in this corpus imports this module.
Load order
Every file a consumer needs in order to load this module, dependencies first.
BRIDGE-MIB HP-ICF-ARP-PROTECT HP-ICF-OID IANAifType-MIB IF-MIB INET-ADDRESS-MIB P-BRIDGE-MIB Q-BRIDGE-MIB RFC1158-MIB RFC1271-MIB RMON-MIB RMON2-MIB SNMP-FRAMEWORK-MIB SNMPv2-CONF SNMPv2-MIB SNMPv2-SMI SNMPv2-TC TOKEN-RING-RMON-MIB
Objects
| Name | OID | Syntax | Access | Status |
|---|---|---|---|---|
| hpicfArpProtectNotifications OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.0 | |||
| hpicfArpProtectObjects OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.1 | |||
| hpicfArpProtectConfig OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1 | |||
| hpicfArpProtectGlobalCfg OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.1 | |||
| hpicfArpProtectEnable OBJECT-TYPE The administrative status of the ARP Protection feature. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.1.1 | TruthValue | read-write | current |
| hpicfArpProtectVlanEnable OBJECT-TYPE The administrative status for Dynamic ARP Protection on each VLAN. There will be one bit in this string for each possible VLAN ID. Each octet within this value specifies a set of eight VLANs, with the first octet specifying VLAN IDs 1 through 8, the second octet specifying VLAN IDs 9 through 16, etc. Within each octet, the most significant bit represents the lowest numbered VLAN ID, and the least significant bit represents the highest numbered VLAN ID. Thus, each possible VLAN ID of the bridge is represented by a single bit within the value of this object. If that bit has a value of '1', then Dynamic ARP Protection is enabled on that VLAN; Dynamic ARP Protection is not enabled on the VLAN its bit has a value of '0'. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.1.2 | OCTET STRING (SIZE(512)) | read-write | current |
| hpicfArpProtectValidation OBJECT-TYPE Additional validation checks to perform on ARP packets during Dynamic ARP Protection. srcMac - Drop any ARP request or response packet where the source MAC address in the Ethernet header does not match the sender MAC address in the body of the ARP packet. dstMac - Drop any unicast ARP response packet where the destination MAC address in the Ethernet header does not match the target MAC address in the body of the ARP packet. ip - Drop any ARP packet where the sender IP address is invalid. Drop any ARP response packet where the target IP address is invalid. Invalid addresses include 0.0.0.0, 255.255.255.255, all IP multicast addresses, and all class E IP addresses. These checks are only performed for ARP packets received on untrusted ports in VLANs that are enabled for Dynamic ARP Protection. ARP packets received on trusted ports, and ARP packets in VLANs for which Dynamic ARP Protection is disabled, are forwarded without validation. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.1.3 | Bits {srcMac(0), dstMac(1), ip(2)} | read-write | current |
| hpicfArpProtectErrantNotifyEnable OBJECT-TYPE Provides operational control of hpicfArpProtectErrantReply. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.1.4 | INTEGER {enabled(1), disabled(2)} | read-write | current |
| hpicfArpProtectPortTable OBJECT-TYPE Per-interface configuration for Dynamic ARP Protection. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.2 | not-accessible | current | |
| hpicfArpProtectPortEntry OBJECT-TYPE Dynamic ARP Protection configuration information for a single port. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.2.1 | not-accessible | current | |
| hpicfArpProtectPortTrust OBJECT-TYPE This object indicates whether this port is trusted for Dynamic ARP Protection. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.1.2.1.1 | TruthValue | read-write | current |
| hpicfArpProtectStatus OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2 | |||
| hpicfArpProtectVlanStatTable OBJECT-TYPE Per-VLAN statistics for Dynamic ARP Protection. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1 | not-accessible | current | |
| hpicfArpProtectVlanStatEntry OBJECT-TYPE Dynamic ARP Protection statistics for a single VLAN. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1 | not-accessible | current | |
| hpicfArpProtectVlanStatIndex OBJECT-TYPE This variable uniquely identifies the VLAN that the counters in this entry apply to. The VLAN identified by this object is the same VLAN as identified by the identical value in the dot1qVlanIndex object. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.1 | VlanIndex | not-accessible | current |
| hpicfArpProtectVlanStatForwards OBJECT-TYPE The number of ARP packets received on untrusted ports in this VLAN that were successfully validated and forwarded. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.2 | Counter32 | read-only | current |
| hpicfArpProtectVlanStatBadPkts OBJECT-TYPE The number of ARP packets received on untrusted ports that were dropped because they were malformed in some way. This may include an unrecognized opcode, an unrecognized protocol type, an unrecognized hardware type, an invalid protocol address length, or an invalid hardware address length. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.3 | Counter32 | read-only | current |
| hpicfArpProtectVlanStatBadBindings OBJECT-TYPE The number of ARP packets received on untrusted ports that were dropped because they advertized a source IP-to-MAC binding that did not match a known, valid binding. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.4 | Counter32 | read-only | current |
| hpicfArpProtectVlanStatBadSrcMacs OBJECT-TYPE The number of ARP packets received on untrusted ports that were dropped because the source MAC address in the Ethernet header did not match the sender MAC address in the body of the ARP packet. This count does not increment when source MAC validation is not enabled. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.5 | Counter32 | read-only | current |
| hpicfArpProtectVlanStatBadDstMacs OBJECT-TYPE The number of unicast ARP response packets received on untrusted ports that were dropped because the destination MAC address in the Ethernet header did not match the target MAC address in the body of the ARP packet. This count does not increment when destination address validation is not enabled. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.6 | Counter32 | read-only | current |
| hpicfArpProtectVlanStatBadIpAddrs OBJECT-TYPE The number of ARP packets received on untrusted ports that were dropped because they contained an invalid sender IP address, or they contained an invalid target IP address in an ARP response. This count does not increment when IP address validation is not enabled. This count does not increment for VLANs for which Dynamic ARP Protection is not enabled. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.2.1.1.7 | Counter32 | read-only | current |
| hpicfArpProtectErrantCnt OBJECT-TYPE A count of hpicfArpProtectErrantReply sent from the ARP Protection entity to the SNMP entity. This count may differ from the count of notifications transmitted due to rate limiting or configuration. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.3 | Counter32 | accessible-for-notify | current |
| hpicfArpProtectErrantSrcMac OBJECT-TYPE Errant source MAC address included in a hpicfArpProtectNotification. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.4 | MacAddress | accessible-for-notify | current |
| hpicfArpProtectErrantSrcIpType OBJECT-TYPE IP Address type reported in hpicfArpProtectErrantSrcIp. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.5 | InetAddressType | accessible-for-notify | current |
| hpicfArpProtectErrantSrcIp OBJECT-TYPE Errant source IP address included in a hpicfArpProtectNotification. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.6 | InetAddress | accessible-for-notify | current |
| hpicfArpProtectErrantDestMac OBJECT-TYPE Errant destination MAC address included in a hpicfArpProtectNotification. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.7 | MacAddress | accessible-for-notify | current |
| hpicfArpProtectErrantDestIpType OBJECT-TYPE IP Address type reported in hpicfArpProtectErrantDestIp. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.8 | InetAddressType | accessible-for-notify | current |
| hpicfArpProtectErrantDestIp OBJECT-TYPE Errant destination IP address included in a hpicfArpProtectNotification. | 1.3.6.1.4.1.11.2.14.11.5.1.37.1.9 | InetAddress | accessible-for-notify | current |
| hpicfArpProtectConformance OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.2 | |||
| hpicfArpProtectGroups OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.2.1 | |||
| hpicfArpProtectCompliances OBJECT-IDENTITY | 1.3.6.1.4.1.11.2.14.11.5.1.37.2.2 |
Notifications
| Name | OID | Status |
|---|---|---|
| hpicfArpProtectErrantReply NOTIFICATION-TYPE An hpicfArpProtectErrantReply notification signifies that the ARP protection entity is enabled and has detected an errant ARP reply packet. The source and destination addresses from the packet header are included in the notification. | 1.3.6.1.4.1.11.2.14.11.5.1.37.0.1 | current |
Conformance
| Name | OID | Status |
|---|---|---|
| hpicfArpProtectBaseGroup OBJECT-GROUP A collection of objects for configuring and monitoring the base Dynamic ARP Protection functionality. | 1.3.6.1.4.1.11.2.14.11.5.1.37.2.1.1 | current |
| hpicfArpProtectionNotifications NOTIFICATION-GROUP A group of Notifications whose implementation is mandatory when HP-ICF-ARP-PROTECTION is implemented. | 1.3.6.1.4.1.11.2.14.11.5.1.37.2.1.2 | current |
| hpicfArpProtectCompliance MODULE-COMPLIANCE The compliance statement for HP ProCurve switches that support Dynamic ARP Protection. | 1.3.6.1.4.1.11.2.14.11.5.1.37.2.2.1 | current |