MIB module for monitoring and configuring MAC Authentication Bypass (MAB) feature in the system.
MAC Auth Bypass feature provides controlled access to devices based on their MAC addresses.
MAB allows non-dot1x compliant end devices controlled access to network and also provides a replacement technology for VLAN Management Policy Server (VMPS) environments.
MAB is also an intergal part of the Network Access Control (NAC) program which enables network access for the clients and subsequently carry out a posture assessment of these clients.
MAC Authentication Bypass feature provides a mechanism that uses the MAC address of the connecting device to grant or deny network access for it.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cmabIfAuthEnabled
1.3.6.1.4.1.9.9.654.1.1.1.1.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Specifies if MAC Authentication Bypass feature is enabled on the interface.
cmabIfAuthMethod
1.3.6.1.4.1.9.9.654.1.1.1.1.2
INTEGER1 = radius2 = eap · Integer32
Specifies the authentication method used by MAC Authentication Bypass.
radius(1) : communication with authentication server is performed via RADIUS messages.
eap(2) : communication with authentication server
is performed via EAP messages.
cmabClientInfoTable
1.3.6.1.4.1.9.9.654.1.2.1
Index: ifIndex · IMPLIED cmabClientSessionId
A list of active MAC Authentication Bypass clients in the system.
An entry exists for each MAC Authentication Bypass session in the system.
An entry is deleted if the MAC Authentication Bypass session is removed from the system.
InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d
A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.
cmabClientSessionId
1.3.6.1.4.1.9.9.654.1.2.1.1.1
OCTET STRING SIZE (1..64)
A unique identifier of the MAC Authentication Bypass session.
cmabClientMacAddress
1.3.6.1.4.1.9.9.654.1.2.1.1.2
MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:
Indicates the session state of the MAB state machine for the MAB client.
other : None of the below.
initialize : Initializing the authentication session.
acquiring : Acquiring client's MAC address for the
authentication process.
authorizing: Authorization is in progress.
terminate : Authorization is completed.
cmabClientAuthStatus
1.3.6.1.4.1.9.9.654.1.2.1.1.4
INTEGER1 = authorized2 = unauthorized · Integer32
This object indicates whether the MAB client is authorized.
authorized : the session is authorized.
unauthorized: the session is not authorized.