EZ5 MIB Catalog

ARISTA-ACL-MIB

2014-08-15

The MIB module for managing Access Control Lists (ACLs) on Arista devices.

Download ARISTA-ACL-MIB.txt Open ARISTA-ACL-MIB.txt in a new tab

SCALARS (1) · TABLES (9)

Scalars (1)

NameOID
aristaAclDpSupportFlags1.3.6.1.4.1.30065.3.5.1.4

Tables (9)

NameOID
aristaIpAclTable1.3.6.1.4.1.30065.3.5.1.1.1
aristaIpAclRuleTable1.3.6.1.4.1.30065.3.5.1.1.2
aristaIpAclRuleStatsTable1.3.6.1.4.1.30065.3.5.1.1.3
aristaMacAclTable1.3.6.1.4.1.30065.3.5.1.2.1
aristaMacAclRuleTable1.3.6.1.4.1.30065.3.5.1.2.2
aristaMacAclRuleStatsTable1.3.6.1.4.1.30065.3.5.1.2.3
aristaIpv6AclTable1.3.6.1.4.1.30065.3.5.1.3.1
aristaIpv6AclRuleTable1.3.6.1.4.1.30065.3.5.1.3.2
aristaIpv6AclRuleStatsTable1.3.6.1.4.1.30065.3.5.1.3.3

END OF TOC

Scalar details

aristaAclDpSupportFlags

1.3.6.1.4.1.30065.3.5.1.4

BITS

This attribute describes the data-plane ACL support matrix. If data-plane ACLs are supported, the acl bit is 1; otherwise, other bits are 0. If data-plane ACLs are supported, the logging, counter and routerAcl bits indicate whether the data plane supports those features for ACLs.

Table details

aristaIpAclTable

1.3.6.1.4.1.30065.3.5.1.1.1

Index: aristaIpAclName

A table that contains IP ACLs that are configured on the switch.

aristaIpAclName

1.3.6.1.4.1.30065.3.5.1.1.1.1.1

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..100) · OCTET STRING · hint 255a

The name of the IP ACL.

aristaIpAclReadOnly

1.3.6.1.4.1.30065.3.5.1.1.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IP ACL is configured as read-only; otherwise, the value is 'false(2)'.

aristaIpAclStatsEnabled

1.3.6.1.4.1.30065.3.5.1.1.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IP ACL is configured to have per-rule statistics enabled; otherwise, the value is 'false(2)'.

aristaIpAclCountersIncomplete

1.3.6.1.4.1.30065.3.5.1.1.1.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IP ACL has incomplete counter; otherwise, the value is 'false(2)'.

aristaIpAclRuleTable

1.3.6.1.4.1.30065.3.5.1.1.2

Index: aristaIpAclName · aristaIpAclRuleSeqId

A table that contains IP ACL rules that are configured on the switch.

aristaIpAclRuleSeqId

1.3.6.1.4.1.30065.3.5.1.1.2.1.1

Unsigned32

This attribute is the sequence ID for this ACL rule.

aristaIpAclRuleProto

1.3.6.1.4.1.30065.3.5.1.1.2.1.2

Unsigned32 (0..255)

This attribute is the IP protocol to be matched by this ACL rule. The value 0 indicates the rule matches any IP protocol.

aristaIpAclRuleSrc

1.3.6.1.4.1.30065.3.5.1.1.2.1.3

IpAddress SIZE (4)

This attribute is the IP source address to be matched by this ACL rule, subject to the aristaIpAclRuleSrcMask value.

aristaIpAclRuleSrcMask

1.3.6.1.4.1.30065.3.5.1.1.2.1.4

IpAddress SIZE (4)

This attribute is the IP source-address mask in this ACL rule. For the source address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaIpAclRuleSrc.

aristaIpAclRuleDest

1.3.6.1.4.1.30065.3.5.1.1.2.1.5

IpAddress SIZE (4)

This attribute is the IP destination address to be matched by this ACL rule, subject to the aristaIpAclRuleDestMask value.

aristaIpAclRuleDestMask

1.3.6.1.4.1.30065.3.5.1.1.2.1.6

IpAddress SIZE (4)

This attribute is the IP destination-address mask in this ACL rule. For the destination address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaIpAclRuleDest.

aristaIpAclRuleL4PortSrcOper

1.3.6.1.4.1.30065.3.5.1.1.2.1.7

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute determines TCP/UDP source-port matching behavior in this ACL rule. If this attribute has value 'any(0)', then attribute aristaIpAclRuleL4PortsSrc is ignored.

aristaIpAclRuleL4PortsSrc

1.3.6.1.4.1.30065.3.5.1.1.2.1.8

OCTET STRING SIZE (0..60)

This attribute is a list of TCP/UDP source ports to be matched in this ACL rule. They are represented as decimal strings, separated by spaces. A maximum of 10 ports is allowed. Attribute aristaIpAclRuleL4PortSrcOper determines how the source ports are matched in this ACL rule.

aristaIpAclRuleL4PortDestOper

1.3.6.1.4.1.30065.3.5.1.1.2.1.9

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute determines TCP/UDP destination-port matching behavior in this ACL rule. If this attribute has value 'any(0)', then attribute aristaIpAclRuleL4PortsDest is ignored.

aristaIpAclRuleL4PortsDest

1.3.6.1.4.1.30065.3.5.1.1.2.1.10

OCTET STRING SIZE (0..60)

This attribute is a list of TCP/UDP destination ports to be matched in this ACL rule. They are represented as decimal strings, separated by spaces. A maximum of 10 ports is allowed. Attribute aristaIpAclRuleL4PortDestOper determines how the destination ports are matched in this ACL rule.

aristaIpAclRuleTtlOper

1.3.6.1.4.1.30065.3.5.1.1.2.1.11

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute is the IP TTL (Time To Live) operation code used in this ACL rule. Combined with attribute aristaIpAclRuleTtl, it specifies the IP TTL matching behavior in this ACL rule.

aristaIpAclRuleTtl

1.3.6.1.4.1.30065.3.5.1.1.2.1.12

Unsigned32 (0..255)

This attribute is the IP TTL value in this ACL rule. Attribute aristaIpAclRuleTtlOper determines how the TTL values is matched in this ACL rule.

aristaIpAclRuleTracked

1.3.6.1.4.1.30065.3.5.1.1.2.1.13

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has the value 'true(1)' if this ACL rule is tracked; otherwise, the value is 'false(2)'. A tracked rule matches packets in existing ICMP/UDP/TCP connections.

aristaIpAclRuleFragments

1.3.6.1.4.1.30065.3.5.1.1.2.1.14

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if this ACL rule is configured to match IP fragments; otherwise, the value is 'false(2)'.

aristaIpAclRuleTcpFlags

1.3.6.1.4.1.30065.3.5.1.1.2.1.15

BITS

This attribute describes TCP flags that are matched by this ACL rule.

aristaIpAclRuleEstablished

1.3.6.1.4.1.30065.3.5.1.1.2.1.16

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if this ACL rule matches existing TCP connections; otherwise, the value is 'false(2)'.

aristaIpAclRuleIcmpType

1.3.6.1.4.1.30065.3.5.1.1.2.1.17

Unsigned32 (0..65535)

This attribute is the ICMP type that is matched by this ACL rule. The attribute is ignored in the ACL rule if the value is 65535.

aristaIpAclRuleIcmpCode

1.3.6.1.4.1.30065.3.5.1.1.2.1.18

Unsigned32 (0..65535)

This attribute is the ICMP code that is matched by this ACL rule. The attribute is ignored in the ACL rule if the value is 65535.

aristaIpAclRuleAction

1.3.6.1.4.1.30065.3.5.1.1.2.1.19

AristaAclRuleAction0 = permit1 = deny2 = remarkAction associated with an ACL rule. If the action has value 'remark(2)', then only the remark field of the ACL rule is meaningful; all other fields are don't-cares. · Integer32

This attribute is the action applied to this ACL rule.

aristaIpAclRuleLog

1.3.6.1.4.1.30065.3.5.1.1.2.1.20

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if logging is required in this ACL rule; otherwise, the value is 'false(2)'.

aristaIpAclRuleRemark

1.3.6.1.4.1.30065.3.5.1.1.2.1.21

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..127) · OCTET STRING · hint 255a

This attribute is the remark string applied to this ACL rule.

aristaIpAclRuleStatsTable

1.3.6.1.4.1.30065.3.5.1.1.3

Index: aristaIpAclRuleTimeMark · aristaIpAclName · aristaIpAclRuleSeqId

A table that contains statistics for IP ACL rules.

aristaIpAclRuleTimeMark

1.3.6.1.4.1.30065.3.5.1.1.3.1.1

TimeFilterTo be used for the index to a table. Allows an application to download only those rows changed since a particular time. Note that this is not a history mechanism. Only current values of underlying objects are returned; saved instance values associated with particular values of sysUpTime are not. An entry is considered changed if the value of any object in the entry changes, if the row is created, or if any object in the entry is created or deleted. Note that deleted entries cannot be detected or downloaded. A time-filtered conceptual table is created by inserting a single object of SYNTAX TimeFilter as the first INDEX component in a copy of an existing basic conceptual table (i.e., any SEQUENCE without a TimeFilter INDEX component). Thus, for each conceptual entry 'I' in the basic table, there exists N conceptual entries in the time-filtered version, indexed N.I, where 'N' is equal to the value of sysUpTime. When an application retrieves conceptual instances from a time-filtered table, and an INDEX value is provided for the TimeFilter INDEX component 'N', the agent will only consider returning basic conceptual entries (e.g., 'fooColumn.N.I') if any column within the basic conceptual entry has changed since sysUpTime 'N'. If not, the basic conceptual entry will be ignored for the particular retrieval operation. When sysUpTime is equal to zero, this table shall be empty. One conceptual entry exists for each past value of sysUpTime, except that the whole table is purged should sysUpTime wrap. As an entry in a time-filtered table is updated (i.e., one of the columns in the basic conceptual table is changed), new conceptual entries are also created in the time-filtered version (which still shares the now updated object values with all other instances). The number of unique time-filtered instances that are created is determined by the value of sysUpTime at which the basic entry was last updated. One unique instance will exist for each value of sysUpTime at the last update time for the row. However, a new TimeFilter index instance is created for each new sysUpTime value. The TimeFilter index values not associated with entry updates are called duplicate time-filtered instances. After some deployment experience, it has been determined that a time-filtered table is more efficient if the agent stops a MIB walk operation by skipping over rows with a TimeFilter index value higher than the value in the received GetNext/GetBulk request. That is, instead of incrementing a TimeFilter index value, the agent will continue to the next object or table. As a consequence, GetNext or GetBulk operations will provide only one pass through a time-filtered table. It is suggested that an agent implement a time-filtered table in this manner to improve performance and avoid a MIB walk getting stuck in time-filtered tables. It is, however, still acceptable for an agent to implement a time-filtered table in the traditional manner (i.e., every conceptual time-filtered instance is returned in GetNext and GetBulk PDU responses), and management applications must be able to deal with such traditional implementations. See the appendix for further discussion of this textual convention. The following example is provided to demonstrate TimeFilter behavior: Consider the following basic conceptual table, basicFooTable. (Note that the basic version of a time-filtered table may not actually be defined.) basicFooTable: basicFooTable ... INDEX { fooIndex } BasicFooEntry { fooIndex Integer32, fooCounts Counter32 } For this example, the basicFooTable contains two static conceptual entries (fooIndex equals '1' and '2'), created at time zero. It also contains one dynamic conceptual entry (fooIndex equals '3'), which is created at time '3' and deleted at time '7'. The time-filtered version of the basicFooTable could be defined as follows: FooTable: fooTable ... INDEX { fooTimeMark, fooIndex } FooEntry { fooTimeMark TimeFilter, fooIndex Integer32, fooCounts Counter32 } Note that entries exist in the time-filtered conceptual table only if they actually exist in the underlying (basic) table. For this example, the fooTable will have three underlying basic entries (fooIndex == 1, 2, and 3), with the following activity (for sysUpTime equal 0 to 9): - fooEntry.N.1 is created at time '0' and most recently updated at time '6' to the value '5'. - fooEntry.N.2 is created at time '0' and most recently updated at time '8' to the value '9'. - fooEntry.N.3 is created at time '3', updated at time '5' to the value '17', and deleted at time '7'. The following tables show the values that would be returned for MIB walk operations with various TimeFilter values, done at different times. An application issues a retrieval request at time 'T', with a TimeFilter value, 'N' (typically set to a lower value, such as the value of sysUpTime at the last polling cycle). The following values would be returned in a MIB walk of fooCounts.N if T equals '0' and N equals '0': fooCounts.N.I Value ========================== fooCounts.0.1 0 fooCounts.0.2 0 Note that nothing is returned for fooCounts.0.3, since that entry does not exist at sysUpTime equals '0'. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '3' and N equals '0': fooCounts.N.I Value ======================= fooCounts.0.1 0 fooCounts.0.2 0 fooCounts.0.3 0 fooCounts.1.3 0 fooCounts.2.3 0 fooCounts.3.3 0 Note that there are no instances for T equals 1 or 2 for the first two values of N, as these entries did not change since they were created at time '0'. Note that the current value for 'fooCounts.N.3' is returned here, even for values of N less than '3' (when the entry was created). The agent only considers the current existence of an entry in the TimeFilter algorithm, not the time when the entry was created. Note that the instances 'fooCounts.0.3', 'fooCounts.1.3', and 'fooCounts.2.3' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '6' and N equals '3': fooCounts.N.I Value ======================= fooCounts.3.1 5 fooCounts.3.3 17 fooCounts.4.1 5 fooCounts.4.3 17 fooCounts.5.1 5 fooCounts.5.3 17 fooCounts.6.1 5 Note that no instances for entry 'fooCounts.N.2' are returned, since it has not changed since time '3'. Note that all instances except 'fooCounts.5.3' and 'fooCounts.6.1' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '9' and N equals '6': fooCounts.N.I Value ======================= fooCounts.6.1 5 fooCounts.6.2 9 fooCounts.7.2 9 fooCounts.8.2 9 Note that no instances for entry 'fooCounts.N.3' are returned, since it was deleted at time '7'. Note that instances 'fooCounts.6.2' and 'fooCounts.7.2' are duplicates and can be suppressed by the agent in a MIB walk. · TimeTicks

A TimeFilter for this entry. See the TimeFilter textual convention to see how this works.

aristaIpAclRuleStatsPktCount

1.3.6.1.4.1.30065.3.5.1.1.3.1.2

Counter64 (0..18446744073709551615)

This attribute is the number of packets that this ACL rule matched.

aristaIpAclRuleStatsLastUpdateTime

1.3.6.1.4.1.30065.3.5.1.1.3.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime at the time the aristaIpAclRuleStatsPktCount was last updated for this ACL rule.

aristaMacAclTable

1.3.6.1.4.1.30065.3.5.1.2.1

Index: aristaMacAclName

A table that contains MAC ACLs that are configured on the switch.

aristaMacAclName

1.3.6.1.4.1.30065.3.5.1.2.1.1.1

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..100) · OCTET STRING · hint 255a

The name of the MAC ACL.

aristaMacAclReadOnly

1.3.6.1.4.1.30065.3.5.1.2.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the MAC ACL is configured as read-only; otherwise, the value is 'false(2)'.

aristaMacAclStatsEnabled

1.3.6.1.4.1.30065.3.5.1.2.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the MAC ACL is configured to have per-entry statistics enabled; otherwise, the value is 'false(2)'.

aristaMacAclCountersIncomplete

1.3.6.1.4.1.30065.3.5.1.2.1.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the MAC ACL has incomplete counter statistics; otherwise, the value is 'false(2)'.

aristaMacAclRuleTable

1.3.6.1.4.1.30065.3.5.1.2.2

Index: aristaMacAclName · aristaMacAclRuleSeqId

A table that contains MAC ACL rules that are configured on the switch.

aristaMacAclRuleSeqId

1.3.6.1.4.1.30065.3.5.1.2.2.1.1

Unsigned32

This attribute is the sequence ID for this ACL rule.

aristaMacAclRuleSrc

1.3.6.1.4.1.30065.3.5.1.2.2.1.2

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

This attribute is the MAC source address to be matched by this ACL rule, subject to the aristaMacAclRuleSrcMask value.

aristaMacAclRuleSrcMask

1.3.6.1.4.1.30065.3.5.1.2.2.1.3

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

This attribute is the MAC source-address mask in this ACL rule. For the source address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaMacAclRuleSrc.

aristaMacAclRuleDest

1.3.6.1.4.1.30065.3.5.1.2.2.1.4

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

This attribute is the MAC destination address to be matched by this ACL rule, subject to the aristaMacAclRuleSrcMask value.

aristaMacAclRuleDestMask

1.3.6.1.4.1.30065.3.5.1.2.2.1.5

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

This attribute is the MAC destination-address mask in this ACL rule. For the destination address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaMacAclRuleDest.

aristaMacAclRuleProto

1.3.6.1.4.1.30065.3.5.1.2.2.1.6

Unsigned32

This attribute is the MAC protocol number to be matched by this ACL rule. The protocol value 4294967295 (0xFFFFFFFF) is a value that indicates the rule matches any protocol.

aristaMacAclRuleAction

1.3.6.1.4.1.30065.3.5.1.2.2.1.7

AristaAclRuleAction0 = permit1 = deny2 = remarkAction associated with an ACL rule. If the action has value 'remark(2)', then only the remark field of the ACL rule is meaningful; all other fields are don't-cares. · Integer32

This attribute is the action applied to this ACL rule.

aristaMacAclRuleLog

1.3.6.1.4.1.30065.3.5.1.2.2.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if logging is required in this ACL rule; otherwise, the value is 'false(2)'.

aristaMacAclRuleRemark

1.3.6.1.4.1.30065.3.5.1.2.2.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..127) · OCTET STRING · hint 255a

This attribute is the remark string applied to this ACL rule.

aristaMacAclRuleStatsTable

1.3.6.1.4.1.30065.3.5.1.2.3

Index: aristaMacAclRuleTimeMark · aristaMacAclName · aristaMacAclRuleSeqId

A table that contains statistics information for MAC ACL rules.

aristaMacAclRuleTimeMark

1.3.6.1.4.1.30065.3.5.1.2.3.1.1

TimeFilterTo be used for the index to a table. Allows an application to download only those rows changed since a particular time. Note that this is not a history mechanism. Only current values of underlying objects are returned; saved instance values associated with particular values of sysUpTime are not. An entry is considered changed if the value of any object in the entry changes, if the row is created, or if any object in the entry is created or deleted. Note that deleted entries cannot be detected or downloaded. A time-filtered conceptual table is created by inserting a single object of SYNTAX TimeFilter as the first INDEX component in a copy of an existing basic conceptual table (i.e., any SEQUENCE without a TimeFilter INDEX component). Thus, for each conceptual entry 'I' in the basic table, there exists N conceptual entries in the time-filtered version, indexed N.I, where 'N' is equal to the value of sysUpTime. When an application retrieves conceptual instances from a time-filtered table, and an INDEX value is provided for the TimeFilter INDEX component 'N', the agent will only consider returning basic conceptual entries (e.g., 'fooColumn.N.I') if any column within the basic conceptual entry has changed since sysUpTime 'N'. If not, the basic conceptual entry will be ignored for the particular retrieval operation. When sysUpTime is equal to zero, this table shall be empty. One conceptual entry exists for each past value of sysUpTime, except that the whole table is purged should sysUpTime wrap. As an entry in a time-filtered table is updated (i.e., one of the columns in the basic conceptual table is changed), new conceptual entries are also created in the time-filtered version (which still shares the now updated object values with all other instances). The number of unique time-filtered instances that are created is determined by the value of sysUpTime at which the basic entry was last updated. One unique instance will exist for each value of sysUpTime at the last update time for the row. However, a new TimeFilter index instance is created for each new sysUpTime value. The TimeFilter index values not associated with entry updates are called duplicate time-filtered instances. After some deployment experience, it has been determined that a time-filtered table is more efficient if the agent stops a MIB walk operation by skipping over rows with a TimeFilter index value higher than the value in the received GetNext/GetBulk request. That is, instead of incrementing a TimeFilter index value, the agent will continue to the next object or table. As a consequence, GetNext or GetBulk operations will provide only one pass through a time-filtered table. It is suggested that an agent implement a time-filtered table in this manner to improve performance and avoid a MIB walk getting stuck in time-filtered tables. It is, however, still acceptable for an agent to implement a time-filtered table in the traditional manner (i.e., every conceptual time-filtered instance is returned in GetNext and GetBulk PDU responses), and management applications must be able to deal with such traditional implementations. See the appendix for further discussion of this textual convention. The following example is provided to demonstrate TimeFilter behavior: Consider the following basic conceptual table, basicFooTable. (Note that the basic version of a time-filtered table may not actually be defined.) basicFooTable: basicFooTable ... INDEX { fooIndex } BasicFooEntry { fooIndex Integer32, fooCounts Counter32 } For this example, the basicFooTable contains two static conceptual entries (fooIndex equals '1' and '2'), created at time zero. It also contains one dynamic conceptual entry (fooIndex equals '3'), which is created at time '3' and deleted at time '7'. The time-filtered version of the basicFooTable could be defined as follows: FooTable: fooTable ... INDEX { fooTimeMark, fooIndex } FooEntry { fooTimeMark TimeFilter, fooIndex Integer32, fooCounts Counter32 } Note that entries exist in the time-filtered conceptual table only if they actually exist in the underlying (basic) table. For this example, the fooTable will have three underlying basic entries (fooIndex == 1, 2, and 3), with the following activity (for sysUpTime equal 0 to 9): - fooEntry.N.1 is created at time '0' and most recently updated at time '6' to the value '5'. - fooEntry.N.2 is created at time '0' and most recently updated at time '8' to the value '9'. - fooEntry.N.3 is created at time '3', updated at time '5' to the value '17', and deleted at time '7'. The following tables show the values that would be returned for MIB walk operations with various TimeFilter values, done at different times. An application issues a retrieval request at time 'T', with a TimeFilter value, 'N' (typically set to a lower value, such as the value of sysUpTime at the last polling cycle). The following values would be returned in a MIB walk of fooCounts.N if T equals '0' and N equals '0': fooCounts.N.I Value ========================== fooCounts.0.1 0 fooCounts.0.2 0 Note that nothing is returned for fooCounts.0.3, since that entry does not exist at sysUpTime equals '0'. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '3' and N equals '0': fooCounts.N.I Value ======================= fooCounts.0.1 0 fooCounts.0.2 0 fooCounts.0.3 0 fooCounts.1.3 0 fooCounts.2.3 0 fooCounts.3.3 0 Note that there are no instances for T equals 1 or 2 for the first two values of N, as these entries did not change since they were created at time '0'. Note that the current value for 'fooCounts.N.3' is returned here, even for values of N less than '3' (when the entry was created). The agent only considers the current existence of an entry in the TimeFilter algorithm, not the time when the entry was created. Note that the instances 'fooCounts.0.3', 'fooCounts.1.3', and 'fooCounts.2.3' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '6' and N equals '3': fooCounts.N.I Value ======================= fooCounts.3.1 5 fooCounts.3.3 17 fooCounts.4.1 5 fooCounts.4.3 17 fooCounts.5.1 5 fooCounts.5.3 17 fooCounts.6.1 5 Note that no instances for entry 'fooCounts.N.2' are returned, since it has not changed since time '3'. Note that all instances except 'fooCounts.5.3' and 'fooCounts.6.1' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '9' and N equals '6': fooCounts.N.I Value ======================= fooCounts.6.1 5 fooCounts.6.2 9 fooCounts.7.2 9 fooCounts.8.2 9 Note that no instances for entry 'fooCounts.N.3' are returned, since it was deleted at time '7'. Note that instances 'fooCounts.6.2' and 'fooCounts.7.2' are duplicates and can be suppressed by the agent in a MIB walk. · TimeTicks

A TimeFilter for this entry. See the TimeFilter textual convention to see how this works.

aristaMacAclRuleStatsPktCount

1.3.6.1.4.1.30065.3.5.1.2.3.1.2

Counter64 (0..18446744073709551615)

This attribute is the number of packets that this ACL rule matched.

aristaMacAclRuleStatsLastUpdateTime

1.3.6.1.4.1.30065.3.5.1.2.3.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime at the time the aristaMacAclRuleStatsPktCount was last updated for this ACL rule.

aristaIpv6AclTable

1.3.6.1.4.1.30065.3.5.1.3.1

Index: aristaIpv6AclName

A table that contains IPv6 ACLs that are configured on the switch.

aristaIpv6AclName

1.3.6.1.4.1.30065.3.5.1.3.1.1.1

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..100) · OCTET STRING · hint 255a

The name of the IPv6 ACL.

aristaIpv6AclReadOnly

1.3.6.1.4.1.30065.3.5.1.3.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IPv6 ACL is configured as read-only; otherwise, the value is 'false(2)'.

aristaIpv6AclStatsEnabled

1.3.6.1.4.1.30065.3.5.1.3.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IPv6 ACL is configured to have per-entry statistics enabled; otherwise, the value is 'false(2)'.

aristaIpv6AclCountersIncomplete

1.3.6.1.4.1.30065.3.5.1.3.1.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if the IPv6 ACL has incomplete counter statistics; otherwise, the value is 'false(2)'.

aristaIpv6AclRuleTable

1.3.6.1.4.1.30065.3.5.1.3.2

Index: aristaIpv6AclName · aristaIpv6AclRuleSeqId

A table that contains IPv6 ACL rules that are configured on the switch.

aristaIpv6AclRuleSeqId

1.3.6.1.4.1.30065.3.5.1.3.2.1.1

Unsigned32

This attribute is the sequence ID for this ACL rule.

aristaIpv6AclRuleProto

1.3.6.1.4.1.30065.3.5.1.3.2.1.2

Unsigned32 (0..255)

This attribute is the IPv6 upper layer protocol to be matched by this ACL rule. The value 0 indicates the rule matches any IPv6 protocol.

aristaIpv6AclRuleSrc

1.3.6.1.4.1.30065.3.5.1.3.2.1.3

InetAddressIPv6Represents an IPv6 network address: Octets Contents Encoding 1-16 IPv6 address network-byte order The corresponding InetAddressType value is ipv6(2). This textual convention SHOULD NOT be used directly in object definitions, as it restricts addresses to a specific format. However, if it is used, it MAY be used either on its own or in conjunction with InetAddressType, as a pair. SIZE (16) · OCTET STRING · hint 2x:2x:2x:2x:2x:2x:2x:2x

This attribute is the IPv6 source address to be matched by this ACL rule, subject to the aristaIpv6AclRuleSrcMask value.

aristaIpv6AclRuleSrcMask

1.3.6.1.4.1.30065.3.5.1.3.2.1.4

InetAddressIPv6Represents an IPv6 network address: Octets Contents Encoding 1-16 IPv6 address network-byte order The corresponding InetAddressType value is ipv6(2). This textual convention SHOULD NOT be used directly in object definitions, as it restricts addresses to a specific format. However, if it is used, it MAY be used either on its own or in conjunction with InetAddressType, as a pair. SIZE (16) · OCTET STRING · hint 2x:2x:2x:2x:2x:2x:2x:2x

This attribute is the IPv6 source-address mask in this ACL rule. For the source address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaIpv6AclRuleSrc.

aristaIpv6AclRuleDest

1.3.6.1.4.1.30065.3.5.1.3.2.1.5

InetAddressIPv6Represents an IPv6 network address: Octets Contents Encoding 1-16 IPv6 address network-byte order The corresponding InetAddressType value is ipv6(2). This textual convention SHOULD NOT be used directly in object definitions, as it restricts addresses to a specific format. However, if it is used, it MAY be used either on its own or in conjunction with InetAddressType, as a pair. SIZE (16) · OCTET STRING · hint 2x:2x:2x:2x:2x:2x:2x:2x

This attribute is the IPv6 destination address to be matched by this ACL rule, subject to the aristaIpv6AclRuleDestMask value.

aristaIpv6AclRuleDestMask

1.3.6.1.4.1.30065.3.5.1.3.2.1.6

InetAddressIPv6Represents an IPv6 network address: Octets Contents Encoding 1-16 IPv6 address network-byte order The corresponding InetAddressType value is ipv6(2). This textual convention SHOULD NOT be used directly in object definitions, as it restricts addresses to a specific format. However, if it is used, it MAY be used either on its own or in conjunction with InetAddressType, as a pair. SIZE (16) · OCTET STRING · hint 2x:2x:2x:2x:2x:2x:2x:2x

This attribute is the IPv6 destination-address mask in this ACL rule. For the destination address of the packet to match the rule, the bitwise logical-AND of the address and this mask must be equal to the value of aristaIpv6AclRuleDest.

aristaIpv6AclRuleL4PortSrcOper

1.3.6.1.4.1.30065.3.5.1.3.2.1.7

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute determines TCP/UDP source-port matching behavior in this ACL rule. If this attribute has value 'any(0)', then attribute aristaIpv6AclRuleL4PortsSrc is ignored.

aristaIpv6AclRuleL4PortsSrc

1.3.6.1.4.1.30065.3.5.1.3.2.1.8

OCTET STRING SIZE (0..60)

This attribute is a list of TCP/UDP source ports to be matched in this ACL rule. They are represented as decimal strings, separated by spaces. A maximum of 10 ports is allowed. Attribute aristaIpv6AclRuleL4PortSrcOper determines how the source ports are matched in this ACL rule.

aristaIpv6AclRuleL4PortDestOper

1.3.6.1.4.1.30065.3.5.1.3.2.1.9

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute determines TCP/UDP destination-port matching behavior in this ACL rule. If this attribute has value 'any(0)', then attribute aristaIpv6AclRuleL4PortsDest is ignored.

aristaIpv6AclRuleL4PortsDest

1.3.6.1.4.1.30065.3.5.1.3.2.1.10

OCTET STRING SIZE (0..60)

This attribute is a list of TCP/UDP destination ports to be matched in this ACL rule. They are represented as decimal strings, separated by spaces. A maximum of 10 ports is allowed. Attribute aristaIpv6AclRuleL4PortDestOper determines how the destination ports are matched in this ACL rule.

aristaIpv6AclRuleHopLimitOper

1.3.6.1.4.1.30065.3.5.1.3.2.1.11

AristaAclRangeOperator0 = any1 = eq2 = gt3 = lt4 = neq5 = rangeRange operator used by an ACL rule. · Integer32

This attribute is the IPv6 Hop Limit operation code used in this ACL rule. Combined with attribute aristaIpv6AclRuleHopLimit, it specifies the IPv6 Hop Limit matching behavior in this ACL rule.

aristaIpv6AclRuleHopLimit

1.3.6.1.4.1.30065.3.5.1.3.2.1.12

Unsigned32 (0..255)

This attribute is the IPv6 Hop Limit value in this ACL rule. Attribute aristaIpv6AclRuleHopLimitOper determines how the Hop Limit values is matched in this ACL rule.

aristaIpv6AclRuleTcpFlags

1.3.6.1.4.1.30065.3.5.1.3.2.1.13

BITS

This attribute describes TCP flags that are matched by this ACL rule.

aristaIpv6AclRuleEstablished

1.3.6.1.4.1.30065.3.5.1.3.2.1.14

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if this ACL rule matches existing TCP connections; otherwise, the value is 'false(2)'.

aristaIpv6AclRuleIcmpType

1.3.6.1.4.1.30065.3.5.1.3.2.1.15

Unsigned32 (0..65535)

This attribute is the ICMP type that is matched by this ACL rule. The attribute is ignored in the ACL rule if the value is 65535.

aristaIpv6AclRuleIcmpCode

1.3.6.1.4.1.30065.3.5.1.3.2.1.16

Unsigned32 (0..65535)

This attribute is the ICMP code that is matched by this ACL rule. The attribute is ignored in the ACL rule if the value is 65535.

aristaIpv6AclRuleAction

1.3.6.1.4.1.30065.3.5.1.3.2.1.17

AristaAclRuleAction0 = permit1 = deny2 = remarkAction associated with an ACL rule. If the action has value 'remark(2)', then only the remark field of the ACL rule is meaningful; all other fields are don't-cares. · Integer32

This attribute is the action applied to this ACL rule.

aristaIpv6AclRuleLog

1.3.6.1.4.1.30065.3.5.1.3.2.1.18

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This attribute has value 'true(1)' if logging is required in this ACL rule; otherwise, the value is 'false(2)'.

aristaIpv6AclRuleRemark

1.3.6.1.4.1.30065.3.5.1.3.2.1.19

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..127) · OCTET STRING · hint 255a

This attribute is the remark string applied to this ACL rule.

aristaIpv6AclRuleStatsTable

1.3.6.1.4.1.30065.3.5.1.3.3

Index: aristaIpv6AclRuleTimeMark · aristaIpv6AclName · aristaIpv6AclRuleSeqId

A table that contains statistics information for IPv6 ACL rules.

aristaIpv6AclRuleTimeMark

1.3.6.1.4.1.30065.3.5.1.3.3.1.1

TimeFilterTo be used for the index to a table. Allows an application to download only those rows changed since a particular time. Note that this is not a history mechanism. Only current values of underlying objects are returned; saved instance values associated with particular values of sysUpTime are not. An entry is considered changed if the value of any object in the entry changes, if the row is created, or if any object in the entry is created or deleted. Note that deleted entries cannot be detected or downloaded. A time-filtered conceptual table is created by inserting a single object of SYNTAX TimeFilter as the first INDEX component in a copy of an existing basic conceptual table (i.e., any SEQUENCE without a TimeFilter INDEX component). Thus, for each conceptual entry 'I' in the basic table, there exists N conceptual entries in the time-filtered version, indexed N.I, where 'N' is equal to the value of sysUpTime. When an application retrieves conceptual instances from a time-filtered table, and an INDEX value is provided for the TimeFilter INDEX component 'N', the agent will only consider returning basic conceptual entries (e.g., 'fooColumn.N.I') if any column within the basic conceptual entry has changed since sysUpTime 'N'. If not, the basic conceptual entry will be ignored for the particular retrieval operation. When sysUpTime is equal to zero, this table shall be empty. One conceptual entry exists for each past value of sysUpTime, except that the whole table is purged should sysUpTime wrap. As an entry in a time-filtered table is updated (i.e., one of the columns in the basic conceptual table is changed), new conceptual entries are also created in the time-filtered version (which still shares the now updated object values with all other instances). The number of unique time-filtered instances that are created is determined by the value of sysUpTime at which the basic entry was last updated. One unique instance will exist for each value of sysUpTime at the last update time for the row. However, a new TimeFilter index instance is created for each new sysUpTime value. The TimeFilter index values not associated with entry updates are called duplicate time-filtered instances. After some deployment experience, it has been determined that a time-filtered table is more efficient if the agent stops a MIB walk operation by skipping over rows with a TimeFilter index value higher than the value in the received GetNext/GetBulk request. That is, instead of incrementing a TimeFilter index value, the agent will continue to the next object or table. As a consequence, GetNext or GetBulk operations will provide only one pass through a time-filtered table. It is suggested that an agent implement a time-filtered table in this manner to improve performance and avoid a MIB walk getting stuck in time-filtered tables. It is, however, still acceptable for an agent to implement a time-filtered table in the traditional manner (i.e., every conceptual time-filtered instance is returned in GetNext and GetBulk PDU responses), and management applications must be able to deal with such traditional implementations. See the appendix for further discussion of this textual convention. The following example is provided to demonstrate TimeFilter behavior: Consider the following basic conceptual table, basicFooTable. (Note that the basic version of a time-filtered table may not actually be defined.) basicFooTable: basicFooTable ... INDEX { fooIndex } BasicFooEntry { fooIndex Integer32, fooCounts Counter32 } For this example, the basicFooTable contains two static conceptual entries (fooIndex equals '1' and '2'), created at time zero. It also contains one dynamic conceptual entry (fooIndex equals '3'), which is created at time '3' and deleted at time '7'. The time-filtered version of the basicFooTable could be defined as follows: FooTable: fooTable ... INDEX { fooTimeMark, fooIndex } FooEntry { fooTimeMark TimeFilter, fooIndex Integer32, fooCounts Counter32 } Note that entries exist in the time-filtered conceptual table only if they actually exist in the underlying (basic) table. For this example, the fooTable will have three underlying basic entries (fooIndex == 1, 2, and 3), with the following activity (for sysUpTime equal 0 to 9): - fooEntry.N.1 is created at time '0' and most recently updated at time '6' to the value '5'. - fooEntry.N.2 is created at time '0' and most recently updated at time '8' to the value '9'. - fooEntry.N.3 is created at time '3', updated at time '5' to the value '17', and deleted at time '7'. The following tables show the values that would be returned for MIB walk operations with various TimeFilter values, done at different times. An application issues a retrieval request at time 'T', with a TimeFilter value, 'N' (typically set to a lower value, such as the value of sysUpTime at the last polling cycle). The following values would be returned in a MIB walk of fooCounts.N if T equals '0' and N equals '0': fooCounts.N.I Value ========================== fooCounts.0.1 0 fooCounts.0.2 0 Note that nothing is returned for fooCounts.0.3, since that entry does not exist at sysUpTime equals '0'. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '3' and N equals '0': fooCounts.N.I Value ======================= fooCounts.0.1 0 fooCounts.0.2 0 fooCounts.0.3 0 fooCounts.1.3 0 fooCounts.2.3 0 fooCounts.3.3 0 Note that there are no instances for T equals 1 or 2 for the first two values of N, as these entries did not change since they were created at time '0'. Note that the current value for 'fooCounts.N.3' is returned here, even for values of N less than '3' (when the entry was created). The agent only considers the current existence of an entry in the TimeFilter algorithm, not the time when the entry was created. Note that the instances 'fooCounts.0.3', 'fooCounts.1.3', and 'fooCounts.2.3' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '6' and N equals '3': fooCounts.N.I Value ======================= fooCounts.3.1 5 fooCounts.3.3 17 fooCounts.4.1 5 fooCounts.4.3 17 fooCounts.5.1 5 fooCounts.5.3 17 fooCounts.6.1 5 Note that no instances for entry 'fooCounts.N.2' are returned, since it has not changed since time '3'. Note that all instances except 'fooCounts.5.3' and 'fooCounts.6.1' are duplicates and can be suppressed by the agent in a MIB walk. The following values would be returned in a full (traditional) MIB walk of fooCounts.N if T equals '9' and N equals '6': fooCounts.N.I Value ======================= fooCounts.6.1 5 fooCounts.6.2 9 fooCounts.7.2 9 fooCounts.8.2 9 Note that no instances for entry 'fooCounts.N.3' are returned, since it was deleted at time '7'. Note that instances 'fooCounts.6.2' and 'fooCounts.7.2' are duplicates and can be suppressed by the agent in a MIB walk. · TimeTicks

A TimeFilter for this entry. See the TimeFilter textual convention to see how this works.

aristaIpv6AclRuleStatsPktCount

1.3.6.1.4.1.30065.3.5.1.3.3.1.2

Counter64 (0..18446744073709551615)

This attribute is the number of packets that this ACL rule matched.

aristaIpv6AclRuleStatsLastUpdateTime

1.3.6.1.4.1.30065.3.5.1.3.3.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime at the time the aristaIpv6AclRuleStatsPktCount was last updated for this ACL rule.

↑ To TOC