MIB module for Authentication Framework in the system.
Authentication Framework provides generic configurations for authentication methods in the system and manage the failover sequence of these methods in a flexible manner.
Specifies the AAA recovery delay for authentication methods registered in Authentication Framework when AAA server becomes active again after being inactive. A value of zero indicates that AAA recovery delay is disabled in the system.
cafMacMoveMode
1.3.6.1.4.1.9.9.656.1.1.3
INTEGER1 = deny2 = permit · Integer32
This object specifies the MAC Move configuration for Authentication Framework.
deny : When a host is authenticated on one port, that address is not allowed on another authenticated manager-enabled port of the device.
permit: Authenticated hosts are allowed to move from one port to another on the same device. When a host moves to a new port, the authenticated session on the original port is deleted, and the host is reauthenticated on the new port.
cafCoABouncePortCommandIgnoreEnabled
1.3.6.1.4.1.9.9.656.1.1.4
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether the device ignores the bounce port command that sent from RADIUS via Change-of-Authorization (CoA) packets.
cafCoADisablePortCommandIgnoreEnabled
1.3.6.1.4.1.9.9.656.1.1.5
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether the device ingores the disable port command that sent from RADIUS via Change-of-Authorization (CoA) packets.
cafSecurityViolationNotifEnable
1.3.6.1.4.1.9.9.656.1.5.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This variable indicates whether the system produces the cafSecurityViolationNotif.
A 'false' value will prevent cafSecurityViolationNotif from being generated by this system.
cafAuthFailNotifEnable
1.3.6.1.4.1.9.9.656.1.5.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether the system produces the cafAuthFailNotif.
A 'true' value will cause cafAuthFailNotif to be generated by this system when an authentication failure happens.
A 'false' value will prevent cafAuthFailNotif from being generated by this system.
cafSecurityViolationClient
1.3.6.1.4.1.9.9.656.1.6.1
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
The MAC address included in the notification currently being sent, indicating the client who triggered the security violation notification.
cafAuthFailClient
1.3.6.1.4.1.9.9.656.1.6.2
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
The MAC address included in the cafAuthFailNotif being sent, indicating the client which failed to authenticate.
Table details
cafAuthMethodRegTable
1.3.6.1.4.1.9.9.656.1.1.2
Index: cafAuthMethod
A list of authentication methods which are currrently registered with Authentication Framework.
An entry is created by the agent when an authentication method has successfully registered with Authentication Framework.
An entry is deleted by the agent upon de-registration of the authentication method.
cafAuthMethod
1.3.6.1.4.1.9.9.656.1.1.2.1.1
CiscoAuthMethod1 = other2 = dot1x3 = macAuthBypass4 = webAuthThe authentication methods and protocols supported in Authentication Framework.
other : none of the below.
dot1x : 802.1x Protocol.
macAuthBypass: MAC Authentication Bypass.
webAuth : Web-Proxy Authentication.
'other' is a read only value which can not be used in set operation. · Integer32
The authentication method registered with Authentication Framework.
cafAuthMethodDefaultPriority
1.3.6.1.4.1.9.9.656.1.1.2.1.2
Unsigned32
A unique number which indicates the default priority of a authentication method.
The default priority is assigned by Authentication Framework during method registration. The method with smallest value has highest priority.
cafAuthMethodDefaultExecOrder
1.3.6.1.4.1.9.9.656.1.1.2.1.3
Unsigned32
A unique number which indicates the default execution order of a authentication method.
The default execution order is assigned by Authentication Framework during method registration. The method with smallest value will be execute first.
cafPortConfigTable
1.3.6.1.4.1.9.9.656.1.2.1
Index: ifIndex
A list of port entries. An entry will exist for each interface which support Authentication Framework feature.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafPortControlledDirection
1.3.6.1.4.1.9.9.656.1.2.1.1.1
CiscoAuthControlledDirections0 = both1 = inThe controlled direction values for capable ports in Authentication Framework.
both: control is required to be exerted over both incoming and outgoing traffic through the controlled port.
in : control is required to be exerted over the
incoming traffic through the controlled port. · Integer32
Specifies the controlled direction of this port.
cafPortFallBackProfile
1.3.6.1.4.1.9.9.656.1.2.1.1.2
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Specifies the name of the fallback profile to be used when failing over to Web Proxy Authentication. A zero length string indicates that fallback mechanism to Web Proxy Authentication is disabled in Authentication Framework.
cafPortAuthHostMode
1.3.6.1.4.1.9.9.656.1.2.1.1.3
CiscoAuthHostMode1 = singleHost2 = multiHost3 = multiAuth4 = multiDomainThe authentication mode of a controlled port.
singleHost: port allows one host to connect and authenticate in a single domain.
multiHost : port allows multiple hosts to connect. Once a host is authenticated, all remaining hosts are also authenticated in a single domain.
multiAuth : port allows multiple hosts to connect. Each host is authenticated separately in a single domain.
multiDomain: port allows multiple domains to be authenticated. · Integer32
Specifies the authentication host mode for this port.
cafPortPreAuthOpenAccess
1.3.6.1.4.1.9.9.656.1.2.1.1.4
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Specifies if the Pre-Authentication Open Access feature allows clients/devices to gain network access before authentication is performed.
A value of 'true' for this object indicates that client/device is able to gain network access before authentication is performed.
cafPortAuthorizeControl
1.3.6.1.4.1.9.9.656.1.2.1.1.5
CiscoAuthControlledPortControl1 = forceUnauthorized2 = auto3 = forceAuthorizedThe authorization control values of Authentication Framework on a controlled port.
forceUnauthorized: the controlled port is forced to be unauthorized unconditionally.
auto : authorization of the controlled
port will be determined by an authentication process.
forceAuthorized : The controlled port is forced to
be authorized unconditionally. · Integer32
Specifies the authorization control for this port.
cafPortReauthEnabled
1.3.6.1.4.1.9.9.656.1.2.1.1.6
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Specifies if reauthentication is enabled for this port.
cafPortReauthInterval
1.3.6.1.4.1.9.9.656.1.2.1.1.7
Unsigned32 · seconds
Specifies the reauthentication interval, after which the port will be reauthenticated if value of the corresponding instance of cafPortReauthEnabled is 'true'.
A value of zero indicates that the reauthentication interval is downloaded from AAA server when this port is authenticated.
cafPortRestartInterval
1.3.6.1.4.1.9.9.656.1.2.1.1.8
Unsigned32 · seconds
Specifies the interval after which a further authentication attempt should be made to this port if it is not authorized.
A value of zero indicates that no further authentication attempt will be made if this port is unauthorized.
cafPortInactivityTimeout
1.3.6.1.4.1.9.9.656.1.2.1.1.9
Integer32 (-1 | 0 | 1..65535) · seconds
Specifies the period of time that a client associating with this port is allowed to be inactive before being terminated.
A value of zero indicates that inactivity timeout is disabled on
this port.
A value of -1 indicates that inactivity timeout is downloaded from the AAA server when this port is authenticated.
Specifies the action to be taken due to a security violation occurs on this port.
restrict: This port will be moved to restricted state.
shutdown: This port will be shutdown from Authentication Framework perspective.
protect : This port will be moved to protected state.
replace : The current authentication session on this port will be terminated and replaced by a new authentication session, upon the detection of security violation on the current authentication session on the port.
cafPortMethodTable
1.3.6.1.4.1.9.9.656.1.2.2
Index: ifIndex
The table contains a list of port entries. An entry will exist for each port which supports Authentication Framework feature.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafPortMethodAdminExecOrder
1.3.6.1.4.1.9.9.656.1.2.2.1.1
CiscoAuthMethodListThe list of authentication methods provided within Authentication Framework.
Each octet represents an authentication method which is defined in CiscoAuthMethod.
The DESCRIPTION clause of CiscoAuthMethodList objects must fully describe the relationship between methods. · OCTET STRING
This object specifies the administrative execution order of authentication methods on the port. Methods are executed in the order as specified in the method list.
Method which is at the beginning of the method list will be executed first. Method which is at the end of method list will be executed last.
A zero length string of this object indicates that no per port execution order configuration has been specified on this port. The actual execution order is based on the value of cafAuthMethodDefaultExecOrder in cafAuthMethodRegTable.
cafPortMethodAdminPriority
1.3.6.1.4.1.9.9.656.1.2.2.1.2
CiscoAuthMethodListThe list of authentication methods provided within Authentication Framework.
Each octet represents an authentication method which is defined in CiscoAuthMethod.
The DESCRIPTION clause of CiscoAuthMethodList objects must fully describe the relationship between methods. · OCTET STRING
This object specifies the administrative priority of authentication methods on the port. The priority of each method is assigned based on the method list.
Method which is at the beginning of the method list has highest priority. Method which is at the end of method list has lowest priority.
A zero length string of this object indicates that no per port method priority configuration has been specified on this port. The actual execution order is based on the value of cafAuthMethodDefaultExecOrder in cafAuthMethodRegTable.
cafPortMethodAvailable
1.3.6.1.4.1.9.9.656.1.2.2.1.3
CiscoAuthMethodListThe list of authentication methods provided within Authentication Framework.
Each octet represents an authentication method which is defined in CiscoAuthMethod.
The DESCRIPTION clause of CiscoAuthMethodList objects must fully describe the relationship between methods. · OCTET STRING
This object indicates the authentication methods currently available on this port.
cafPortMethodOperExecOrder
1.3.6.1.4.1.9.9.656.1.2.2.1.4
CiscoAuthMethodListThe list of authentication methods provided within Authentication Framework.
Each octet represents an authentication method which is defined in CiscoAuthMethod.
The DESCRIPTION clause of CiscoAuthMethodList objects must fully describe the relationship between methods. · OCTET STRING
This object indicates the operational execution order of authentication methods on this port. Methods are executed in the order as specified in the method list.
Method which is at the beginning of the method list will be executed first. Method which is at the end of method list will be executed last.
cafPortMethodOperPriority
1.3.6.1.4.1.9.9.656.1.2.2.1.5
CiscoAuthMethodListThe list of authentication methods provided within Authentication Framework.
Each octet represents an authentication method which is defined in CiscoAuthMethod.
The DESCRIPTION clause of CiscoAuthMethodList objects must fully describe the relationship between methods. · OCTET STRING
This object indicates the operational priority of authentication methods on this port. Methods have the priority as specified in the method list.
Method which is at the beginning of the method list has highest priority. Method which is at the end of method list has lowest priority.
cafAuthFailedEventPortTable
1.3.6.1.4.1.9.9.656.1.3.1
Index: ifIndex
The table contains a list of port entries.
An entry will exist for each port which supports Authentication Fail event within the Authentication Framework.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafAuthFailedMaxRetry
1.3.6.1.4.1.9.9.656.1.3.1.1.1
Unsigned32
This object specifies the maximum number of retry should be performed before generating Authentication Fail event.
A value of zero indicates that Authentication Fail event will be generated upon authentication fail without any retry.
cafAuthFailedNoActionEnabled
1.3.6.1.4.1.9.9.656.1.3.1.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether no action will be performed when an Authentication Fail event occurs.
Setting 'true' on this object indicates that no action will be performed when Authentication Fail event occurs.
The read-only value 'false' indicates that an action will be performed when an Authentication Fail event occurs.
cafAuthFailedAuthorizedVlan
1.3.6.1.4.1.9.9.656.1.3.1.1.3
Integer32 (-1 | 0 | 1..2147483647)
This object specifies the Authentication Failed VLAN number.
The read-only value of -1 indicates that this object is not applicable on this port.
The read-only value of zero indicates that this port will not be authorized to any VLAN when Authentication Failed event occurs.
Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when Authentication Fail event occurs.
cafAuthFailedNextMethodEnabled
1.3.6.1.4.1.9.9.656.1.3.1.1.4
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether the next authentication method will be used if an Authentication Fail event is generated by the current authentication method.
Setting this object to 'true' indicates that the next available authentication method will be used when Authentication Fail event occurs.
The read-only value 'false' indicates that the next available authentication method will not be used when Authentication Fail event occurs.
cafClientNoRespEventPortTable
1.3.6.1.4.1.9.9.656.1.3.2
Index: ifIndex
The table contains a list of port entries.
An entry exists for each port which supports No Response event within the Authentication Framework.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafClientNoRespNoActionEnabled
1.3.6.1.4.1.9.9.656.1.3.2.1.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies whether an action is performed when No Response event occurs.
Setting 'true' on this object indicates that no action will be performed when No Response event occurs.
The read-only value 'false' of this object indicates that an action will be performed when No Response event occurs.
cafClientNoRespAuthorizedVlan
1.3.6.1.4.1.9.9.656.1.3.2.1.2
Integer32 (-1 | 0 | 1..2147483647)
This object specifies the No Response Authorized VLAN number.
The read-only value of -1 indicates that this object is not applicable on this port.
The read-only value of zero indicates that this port will not be authorized to any VLAN when No Response event occurs.
Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when No Response event occurs.
cafServerEventPortTable
1.3.6.1.4.1.9.9.656.1.3.3
Index: ifIndex
The table contains a list of port entries.
An entry exists for each port which supports AAA Server Reachability event within the Authentication Framework.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafServerDeadNoActionEnabled
1.3.6.1.4.1.9.9.656.1.3.3.1.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object indicates whether an action is performed if an AAA Server Reachability event occurs.
Setting 'true' on this object indicates that no action will be performed when AAA Server Reachability event occurs.
The read-only value 'false' indicates that an action will be performed when AAA Server Reachability event occurs.
cafServerDeadRemainAuthorized
1.3.6.1.4.1.9.9.656.1.3.3.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object specifies if current authorization will remain unchanged for the port when AAA Server Reachability event occurs.
Setting 'true' on this object indicates that current authorization will remain unchanged for the port when AAA Server Reachability event occurs.
The read-only value 'false' indicates that the current authorization will not be retained for the port when AAA Server Reachability event occurs.
cafServerDeadAuthorizedVlan
1.3.6.1.4.1.9.9.656.1.3.3.1.3
Integer32 (-1 | 0 | 1..2147483647)
This object specifies the AAA Server Reachability Authorized VLAN number.
The read-only value of -1 indicates that this object is not applicable on this port.
The read-only value of zero indicates that this port will not be authorized to any VLAN when AAA Server Reachability event occurs.
Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when AAA Server Reachability event occurs.
cafServerAliveAction
1.3.6.1.4.1.9.9.656.1.3.3.1.4
INTEGER1 = none2 = reinitialize · Integer32
This object specifies the action applied to the port upon AAA recovery.
none : no action will be applied.
reinitialize: the port will be reinitialized with the current authentication method.
cafSessionTable
1.3.6.1.4.1.9.9.656.1.4.1
Index: ifIndex · IMPLIED cafSessionId
The table contains a list of authentication session.
An entry is created when an authentication session has successfully created within Authentication Framework.
An entry is deleted when an authentication session has been removed.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafSessionId
1.3.6.1.4.1.9.9.656.1.4.1.1.1
OCTET STRING SIZE (1..64)
A unique identifier of the authentication session.
cafSessionClientMacAddress
1.3.6.1.4.1.9.9.656.1.4.1.1.2
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
Indicates the MAC address of the device associates with the authentication session.
cafSessionClientAddrType
1.3.6.1.4.1.9.9.656.1.4.1.1.3
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
Indicates the type of Internet address of the client associates with the authentication session.
cafSessionClientAddress
1.3.6.1.4.1.9.9.656.1.4.1.1.4
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
Indicates the Internet address of the client associates with the authentication session. The type of this address is determined by the value of cafSessionClientAddrType object.
Indicates the current status of the authentication session.
idle : the session has been initialized and no
method has run yet.
running : an authentication method is running for
this session.
noMethod : no authentication method has provided a
result for this session.
authenticationSuccess: an authentication method has resulted in authentication success for this session.
authenticationFailed: an authentication method has resulted in authentication failed for this session.
authorizationSuccess: authorization is successful for this session.
authorizationFailed : authorization is failed for this session.
cafSessionDomain
1.3.6.1.4.1.9.9.656.1.4.1.1.6
INTEGER1 = other2 = data3 = voice · Integer32
Indicates the type of domain that the authentication session belongs to.
other : none of the below.
data : indicates the data domain.
voice: indicates the voice domain.
cafSessionAuthHostMode
1.3.6.1.4.1.9.9.656.1.4.1.1.7
CiscoAuthHostMode1 = singleHost2 = multiHost3 = multiAuth4 = multiDomainThe authentication mode of a controlled port.
singleHost: port allows one host to connect and authenticate in a single domain.
multiHost : port allows multiple hosts to connect. Once a host is authenticated, all remaining hosts are also authenticated in a single domain.
multiAuth : port allows multiple hosts to connect. Each host is authenticated separately in a single domain.
multiDomain: port allows multiple domains to be authenticated. · Integer32
Indicates the authentication host mode of the port in the authentication session.
cafSessionControlledDirection
1.3.6.1.4.1.9.9.656.1.4.1.1.8
CiscoAuthControlledDirections0 = both1 = inThe controlled direction values for capable ports in Authentication Framework.
both: control is required to be exerted over both incoming and outgoing traffic through the controlled port.
in : control is required to be exerted over the
incoming traffic through the controlled port. · Integer32
Indicates the operational controlled directions parameter for this port in the authentication session.
cafSessionPostureToken
1.3.6.1.4.1.9.9.656.1.4.1.1.9
CnnEouPostureTokenStringPosture token which representing the endpoint device's relative compliance to the network compliance policy.
Valid characters are a-z, A-Z, 0-9, ,'#', '-', '_', and '.'. Posture token string is case sensitive and permits the value of empty string. SIZE (0..255) · OCTET STRING
Indicates the posture token associates with the authentication session.
cafSessionAuthUserName
1.3.6.1.4.1.9.9.656.1.4.1.1.10
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Indicates the name of the authenticated user for the authentication session.
cafSessionClientFramedIpPool
1.3.6.1.4.1.9.9.656.1.4.1.1.11
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Indicates the name of the address pool from which the session's client IP address is assigned.
cafSessionAuthorizedBy
1.3.6.1.4.1.9.9.656.1.4.1.1.12
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
Indicates the name of the feature which authorizes the authentication session.
cafSessionCriticalTimeLeft
1.3.6.1.4.1.9.9.656.1.4.1.1.13
Unsigned32 · seconds
Indicates the leftover time before the next authentication attempt for the authentication session after Server Reachability event occurred. Value zero indicates that this session is currently being authenticated or it is not applicable.
cafSessionAuthVlan
1.3.6.1.4.1.9.9.656.1.4.1.1.14
VlanIndexOrZeroThe VLAN ID or zero as defined for Private VLAN feature. If the value is between 1 and 4095 inclusive, it represents an IEEE 802.1Q VLAN-ID. If the value is zero, it is object-specific and must therefore be defined as part of the description of any object which uses this syntax. (0..4095) · Integer32
Indicates the authorized VLAN applied to the authentication session. Value zero indicates that no authorized VLAN has been applied, or it is not applicable.
cafSessionTimeout
1.3.6.1.4.1.9.9.656.1.4.1.1.15
Unsigned32 · seconds
Indicates the session timeout used by Authentication Framework in the authentication session.
cafSessionTimeLeft
1.3.6.1.4.1.9.9.656.1.4.1.1.16
Unsigned32 · seconds
Indicates the leftover time of the current authentication session.
Indicates the timeout action on the authentication session, when value of the corresponding instance of cafSessionTimeLeft reaches zero.
unknown : None of the below.
terminate : Session will be terminated.
reauthenticate: Session will be reauthenticated.
cafSessionInactivityTimeout
1.3.6.1.4.1.9.9.656.1.4.1.1.18
Unsigned32 · seconds
Indicates the inactivity timeout used by Authentication Framework in the authentication session.
cafSessionInactivityTimeLeft
1.3.6.1.4.1.9.9.656.1.4.1.1.19
Unsigned32 · seconds
Indicates the leftover time of the inactivity timer of the authentication session.
cafSessionReauth
1.3.6.1.4.1.9.9.656.1.4.1.1.20
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
The reauthentication control for the authentication session. Setting this object to 'true' cause the current authenticated session to reauthenticate the authenticated client. Setting this object to 'false' has no effect.
This object always returns 'false' when being read.
cafSessionTerminate
1.3.6.1.4.1.9.9.656.1.4.1.1.21
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
The termination request control for the authentication session. Setting this object to 'true' terminates the current session. Setting this object to 'false' has no effect.
This object always returns 'false' when being read.
cafSessionVlanGroupName
1.3.6.1.4.1.9.9.656.1.4.1.1.22
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The name of the VLAN group that has been used during VLAN assignment for this session.
A zero length string indicates that there is no VLAN group been used during VLAN assignment.
cafSessionMethodsInfoTable
1.3.6.1.4.1.9.9.656.1.4.2
Index: ifIndex · cafSessionId · cafSessionMethod
The table contains a list of authentication method for every authentication session.
An entry exists for each authentication method that can authenticate an authentication session within Authentication Framework.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cafSessionMethod
1.3.6.1.4.1.9.9.656.1.4.2.1.1
CiscoAuthMethod1 = other2 = dot1x3 = macAuthBypass4 = webAuthThe authentication methods and protocols supported in Authentication Framework.
other : none of the below.
dot1x : 802.1x Protocol.
macAuthBypass: MAC Authentication Bypass.
webAuth : Web-Proxy Authentication.
'other' is a read only value which can not be used in set operation. · Integer32
Indicates the state of this authentication method.
notRun : The method has not run for this session.
running : The method is running for this session.
failedOver : The method has failed and the next method is
expected to provide a result.
authcSuccess: The method has provided a successful authentication result for this session.
authcFailed : The method has provided a failed authentication result for this session.
Trap details
cafSecurityViolationNotif
1.3.6.1.4.1.9.9.656.0.1
A cafSecurityViolationNotif is sent if a security violation is detected on a port, and the instance value of cafSecurityViolationNotifEnable is 'true'.
ifIndex
1.3.6.1.2.1.2.2.1.1
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
ifName
1.3.6.1.2.1.31.1.1.1.1
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The textual name of the interface. The value of this object should be the name of the interface as assigned by the local device and should be suitable for use in commands entered at the device's `console'. This might be a text name, such as `le0' or a simple port number, such as `1', depending on the interface naming syntax of the device. If several entries in the ifTable together represent a single interface as named by the device, then each will have the same value of ifName. Note that for an agent which responds to SNMP queries concerning an interface on some other (proxied) device, then the value of ifName for such an interface is the proxied device's local name for it.
If there is no local name, or this object is otherwise not applicable, then this object contains a zero-length string.
cafSecurityViolationClient
1.3.6.1.4.1.9.9.656.1.6.1
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
The MAC address included in the notification currently being sent, indicating the client who triggered the security violation notification.
cafAuthFailNotif
1.3.6.1.4.1.9.9.656.0.2
A cafAuthFailNotif is sent if an authentication failure is detected on a port, and the instance value of cafAuthFailNotifEnable is 'true'.
ifName contains the name of the interface where the authentication failure happened.
cafAuthFailClient contains the mac address of the client which failed to authenticate.
ifName
1.3.6.1.2.1.31.1.1.1.1
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The textual name of the interface. The value of this object should be the name of the interface as assigned by the local device and should be suitable for use in commands entered at the device's `console'. This might be a text name, such as `le0' or a simple port number, such as `1', depending on the interface naming syntax of the device. If several entries in the ifTable together represent a single interface as named by the device, then each will have the same value of ifName. Note that for an agent which responds to SNMP queries concerning an interface on some other (proxied) device, then the value of ifName for such an interface is the proxied device's local name for it.
If there is no local name, or this object is otherwise not applicable, then this object contains a zero-length string.
cafAuthFailClient
1.3.6.1.4.1.9.9.656.1.6.2
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
The MAC address included in the cafAuthFailNotif being sent, indicating the client which failed to authenticate.