Acronyms and Definitions
The following acronyms and terms are used in this
document:
IPSec: Secure IP Protocol
VPN: Virtual Private Network
RAS: Remote Access Service
ISP: Internet Service Provider.
LAN: Local Area Network
Group: A collection of remote access users grouped and managed together as a single entity for administrative convenience.
Session: A Remote Access Session.
SVC: SSL VPN Client
Webvpn: VPN connection established using web browser.
Overview of the MIB
This is a MIB Module for monitoring the structures in Virtual
Private Networks based remote access networks. The MIB seeks
to create a common model of Remote Access across implementations
of the service on layer 2 (PPTP, L2TP, L2F), layer 3 (IPsec) and
layer 4 (SSL) virtual private networks. The MIB defines counters
and objects of interest to performance/fault monitoring in a
way which is independent of the technology of the remote access
implementation.
MIB contains eight major groups of objects which are used
to manage Remote Access connections:
a) Remote Access capacity group
This section defines metrics to gauge the limits of
resources on this device which are critical to RAS service.
b) Remote Access resource usage group
This section defines metrics to gauge the usage of
resources on this device which are critical to RAS service service.
c) Current activity and performance of RAS service
This section defines metrics to gauge the current
remote access activity.
d) Remote Access Service failures
This section defines metrics to monitor session
failures and failures of the service itself, measured
at aggregate level, session level and group level.
e) Security violations in the Remote Access service
This section defines metrics which reflect the state of remote access service of interest to Security Operations staff in an enterprise.
f) Threshold group (allows definition of high water marks)
This section allows the management entity to define
thresholds to set high water marks on critical metrics.
g) Notifications
This section defines notifications to signal
significant events pertaining to the Remote Access
Service.
The maximum number of remote access sessions
that may be supported on this device.
If the device imposes no arbitrary limit on the
maximum number of sessions, it should return a
value of 0.
crasMaxUsersSupportable
1.3.6.1.4.1.9.9.392.1.1.2
Integer32 (0..2147483647) · Users
The maximum number of remote access users
for whom Remote Access sessions may be supported on
this device.
If the device imposes no arbitrary limit on the
maximum number of users, it should return a
value of 0.
crasMaxGroupsSupportable
1.3.6.1.4.1.9.9.392.1.1.3
Integer32 (0..2147483647) · Groups
The maximum number of remote access groups
that may be defined on this device. 'Group'
refers to a collection of users grouped together
for administrative convenience.
If the device imposes no arbitrary limit on
the maximum number of groups, it should return a value of 0.
crasNumCryptoAccelerators
1.3.6.1.4.1.9.9.392.1.1.4
Integer32 (0..2147483647) · Users
The maximum number of hardware crypto accelerators
which can be installed on this device to support
remote access sessions. 'cryptoaccelerator' denotes
a hardware/software entity which the managed entity uses to offload some or all computations pertaining to cryptographic operations.
If the device imposes no arbitrary limit on the
number of crypto accelerators to support Remote Access
function, it should return a value of 0.
crasGlobalBwUsage
1.3.6.1.4.1.9.9.392.1.2.1
Gauge32 · MBytes/second
The average bandwidth used by all the active
remote access sessions.
crasNumSessions
1.3.6.1.4.1.9.9.392.1.3.1
Gauge32 · Sessions
The number of currently active sessions.
A session is a connection terminating on the managed
entity which has been established to provide remote
access connectivity to a user. A session is said to be
'active' if it is ready to carry application traffic
between the user and the managed entity. A session which
is not active is defined to be 'dormant'.
crasNumPrevSessions
1.3.6.1.4.1.9.9.392.1.3.2
Counter32 · Sessions
The number of remote access sessions which were
previously active but which where since terminated.
Measured since the last reboot of the device.
crasNumUsers
1.3.6.1.4.1.9.9.392.1.3.3
Gauge32 · Users
The number of users who have active sessions.
crasNumGroups
1.3.6.1.4.1.9.9.392.1.3.4
Gauge32 · Groups
The number of user groups whose members have
active sessions.
crasGlobalInPkts
1.3.6.1.4.1.9.9.392.1.3.5
Counter64 (0..18446744073709551615) · Packets
The total number of packets received by all
currently and previously active remote access
sessions.
crasGlobalOutPkts
1.3.6.1.4.1.9.9.392.1.3.6
Counter64 (0..18446744073709551615) · Packets
The total number of packets transmitted by all
currently and previously active remote access
sessions.
crasGlobalInOctets
1.3.6.1.4.1.9.9.392.1.3.7
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by all currently
and previously active remote access sessions.
This value is accumulated BEFORE determining whether
or not the packet should be decompressed.
crasGlobalInDecompOctets
1.3.6.1.4.1.9.9.392.1.3.8
Counter64 (0..18446744073709551615) · Octets
The total number of decompressed octets received
by all current and previous remote access sessions.
This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of crasGlobalInOctets.
crasGlobalOutOctets
1.3.6.1.4.1.9.9.392.1.3.9
Counter64 (0..18446744073709551615) · Octets
The total number of octets transmitted by all
currently and previously active remote access
sessions.
This value is accumulated AFTER determining
whether or not the packet should be compressed.
crasGlobalOutUncompOctets
1.3.6.1.4.1.9.9.392.1.3.10
Counter64 (0..18446744073709551615) · Octets
The total number of uncompressed octets sent
by all current and previous remote access sessions.
This value is accumulated BEFORE the packet is
compressed. If compression is not being used, this
value will match the value of crasGlobalOutOctets.
crasGlobalInDropPkts
1.3.6.1.4.1.9.9.392.1.3.11
Counter64 (0..18446744073709551615) · Packets
The total number of packets which were dropped
during receive processing by all currently and
previously active remote access sessions.
crasGlobalOutDropPkts
1.3.6.1.4.1.9.9.392.1.3.12
Counter64 (0..18446744073709551615) · Packets
The total number of packets which were
dropped during receive processing by all
currently and previously active remote access
sessions.
crasEmailNumSessions
1.3.6.1.4.1.9.9.392.1.3.23
Gauge32 · Sessions
The number of currently active Email proxy sessions.
crasEmailCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.24
Counter32 · Sessions
The number of cumulative Email proxy sessions since system up.
crasEmailPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.25
Unsigned32 · Sessions
The number of peak concurrent Email proxy sessions since system up.
crasIPSecNumSessions
1.3.6.1.4.1.9.9.392.1.3.26
Gauge32 · Sessions
The number of currently active IPSec sessions.
crasIPSecCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.27
Counter32 · Sessions
The number of cumulative IPSec sessions since system up.
crasIPSecPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.28
Unsigned32 · Sessions
The number of peak concurrent Email proxy sessions since system up.
crasL2LNumSessions
1.3.6.1.4.1.9.9.392.1.3.29
Gauge32 · Sessions
The number of currently active LAN to LAN sessions.
crasL2LCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.30
Counter32 · Sessions
The number of cumulative LAN to LAN sessions since system up.
crasL2LPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.31
Unsigned32 · Sessions
The number of peak concurrent LAN to LAN sessions since system up.
crasLBNumSessions
1.3.6.1.4.1.9.9.392.1.3.32
Gauge32 · Sessions
The number of currently active Load Balancing sessions.
crasLBCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.33
Counter32 · Sessions
The number of cumulative Load Balancing sessions since system up.
crasLBPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.34
Unsigned32 · Sessions
The number of peak concurrent Load Balancing sessions since system up.
crasSVCNumSessions
1.3.6.1.4.1.9.9.392.1.3.35
Gauge32 · Sessions
The number of currently active SVC sessions.
crasSVCCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.36
Counter32 · Sessions
The number of cumulative SVC sessions since system up.
crasSVCPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.37
Unsigned32 · Sessions
The number of peak concurrent SVC sessions since system up.
crasWebvpnNumSessions
1.3.6.1.4.1.9.9.392.1.3.38
Gauge32 · Sessions
The number of currently active Webvpn sessions.
crasWebvpnCumulateSessions
1.3.6.1.4.1.9.9.392.1.3.39
Counter32 · Sessions
The number of cumulative Webvpn sessions since system up.
crasWebvpnPeakConcurrentSessions
1.3.6.1.4.1.9.9.392.1.3.40
Unsigned32 · Sessions
The number of peak concurrent Webvpn sessions since system up.
crasNumPeakSessions
1.3.6.1.4.1.9.9.392.1.3.41
Unsigned32 · Sessions
The number of peak RA sessions since system up.
crasNumTotalFailures
1.3.6.1.4.1.9.9.392.1.4.1.1
Counter64 (0..18446744073709551615)
The number of attempts to establish sessions which
failed, since the last reboot of the managed device.
crasNumDeclinedSessions
1.3.6.1.4.1.9.9.392.1.4.1.2
Unsigned32 · Sessions
The number of session setup attempts, counted since
the last time the notification
'ciscoRasTooManyFailedAuths' was issued, which were
declined due to authentication or authorization
failure.
crasNumSetupFailInsufResources
1.3.6.1.4.1.9.9.392.1.4.1.3
Counter64 (0..18446744073709551615) · Sessions
The number of session setup attempts that failed
due to insufficient resources.
crasNumAbortedSessions
1.3.6.1.4.1.9.9.392.1.4.1.4
Counter64 (0..18446744073709551615) · Sessions
The number of sessions which were successfully
setup but were since terminated abnormally.
crasFailTableSize
1.3.6.1.4.1.9.9.392.1.4.2.1
Unsigned32
The window size of the Remote Access Failure tables.
The failure tables for session and group failures
maintain only the last crasFailTableSize number of
failure records. A value of 0 for this MIB variable
indicates that archiving of the failures is disabled.
An implementation may choose suitable minimum and
maximum values for this element based on the local
policy and available resources. If an SNMP SET request
specifies a value outside this window for this element,
a BAD VALUE may be returned.
crasFailLastFailIndex
1.3.6.1.4.1.9.9.392.1.4.3.2
FailureRecordIndexThe type used to index failure records in the
failure archive. (1..4294967295) · Unsigned32
The value of column 'crasSessFailIndex'
corresponding to the last row added to the
crasSessFailTable.
The value of this object is undefined and should
not be processed by the management entity if the
value of the object 'crasFailTableSize' is 0.
crasNumDisabledAccounts
1.3.6.1.4.1.9.9.392.1.5.1.1
Counter64 (0..18446744073709551615) · Users
The total number of user accounts which were
disabled due to repeated login failures.
crasThrMaxSessions
1.3.6.1.4.1.9.9.392.1.6.1
Integer32 (0..2147483647) · Sessions
The maximum number of sessions which are successfully
setup after which the managed entity should alert the
network management entity using the notification
'ciscoRasTooManySessions', if the notification has been enabled.
A value of 0 indicates that the threshold has not been
set.
crasThrMaxFailedAuths
1.3.6.1.4.1.9.9.392.1.6.2
Unsigned32
The value of object 'crasNumDeclinedSessions' at
which the managed entity should alert the network
management entity using the notification
'ciscoRasTooManyFailedAuths', if the notification
has been enabled.
A value of 0 indicates that the threshold has not been
set.
crasThrMaxThroughput
1.3.6.1.4.1.9.9.392.1.6.3
Integer32 (0..2147483647) · Octets Per Second
The highest throughput of the Remote Access Service at
which the managed entity should alert the network management
entity using the notification 'ciscoRasTooHighThroughput',
if the notification has been enabled.
The notification is disabled till the value of the
aggregate throughput of the managed entity drops below
the value of this object.
A value of 0 indicates that the threshold has not been set.
crasCntlTooManySessions
1.3.6.1.4.1.9.9.392.1.7.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of
sending the trap to signal the violation of the
Max session threshold.
crasCntlTooManyFailedAuths
1.3.6.1.4.1.9.9.392.1.7.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of
sending the trap to signal the violation of the
Max authentication failure count threshold.
crasCntlTooHighThroughput
1.3.6.1.4.1.9.9.392.1.7.3
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of
sending the trap to signal the violation of the
Max throughput threshold.
Table details
crasSessionTable
1.3.6.1.4.1.9.9.392.1.3.21
Index: crasUsername · crasSessionIndex
This table lists all the currently active sessions. For each session, it lists the attributes (user, group, protocol, security), statistics (packet and octets) and status.
crasUsername
1.3.6.1.4.1.9.9.392.1.3.21.1.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..128) · OCTET STRING · hint 255t
The name of the user associated with this remote access session.
crasGroup
1.3.6.1.4.1.9.9.392.1.3.21.1.2
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The name of the user group to which this remote
access session belongs.
crasSessionIndex
1.3.6.1.4.1.9.9.392.1.3.21.1.3
SessionIndexThe type used to index a remote access session. (1..2147483647) · Integer32
Unique index to distinguish between multiple
Remote Access Sessions associated with the same user.
The value of crasSessionIndex must increase monotonically
till it wraps. An implementation may choose to wrap this
index before the value of 2147483647.
crasAuthenMethod
1.3.6.1.4.1.9.9.392.1.3.21.1.4
UserAuthenMethod1 = none2 = other3 = radius4 = tacacsplus5 = kerberos6 = local7 = ldap8 = ntlm9 = sdiThe mechanism used to authenticate the user.
The value 'other' has been listed to allow for the
MIB to support proprietary authentication methods
not listed here. · Integer32
The method used to authenticate the user prior to establishing the session.
crasAuthorMethod
1.3.6.1.4.1.9.9.392.1.3.21.1.5
UserAuthorMethod1 = none2 = other3 = radius4 = tacacsplus5 = kerberos6 = local7 = ldapThe mechanism used to authorize the user.
The value 'other' has been listed to allow for the
MIB to support proprietary authorization mechanisms
not listed here. · Integer32
The method used to authorize the user prior to
establishing the session.
crasSessionDuration
1.3.6.1.4.1.9.9.392.1.3.21.1.6
Counter32
The number of seconds elapsed since this session
was established.
crasLocalAddressType
1.3.6.1.4.1.9.9.392.1.3.21.1.7
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasLocalAddress'.
crasLocalAddress
1.3.6.1.4.1.9.9.392.1.3.21.1.8
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address assigned to the client of this session
in the private network assigned by the managed entity.
crasISPAddressType
1.3.6.1.4.1.9.9.392.1.3.21.1.9
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasISPAddress'.
crasISPAddress
1.3.6.1.4.1.9.9.392.1.3.21.1.10
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the peer (client) assigned by the ISP.
This is the address of the client device in the public
network.
crasSessionProtocol
1.3.6.1.4.1.9.9.392.1.3.21.1.11
RasProtocol1 = other2 = ipsec3 = l2tp4 = l2tpoveripsec5 = pptp6 = l2f7 = sslThe protocol immediately underlying the remote
access session.
The value 'other' has been listed to allow for the
MIB to be supported on proprietary protocols not
listed here. · Integer32
The protocol underlying this remote access session.
crasProtocolElement
1.3.6.1.4.1.9.9.392.1.3.21.1.12
OBJECT IDENTIFIER
A reference to MIB definitions specific to the protocol
underlying corresponding to the session or tunnel
used to realized the remote access session corresponding
to this conceptual row.
For instance, if this remote access session is based on
IPsec, then this object must contain the complete
instance identifier of the IPsec tunnel corresponding
to this remote access session.
If no MIB definitions specific to the underlying
protocol are available, the value should be set to the
OBJECT IDENTIFIER { 0 0 }.
crasSessionEncryptionAlgo
1.3.6.1.4.1.9.9.392.1.3.21.1.13
SessionEncrAlgo1 = none2 = des3 = des34 = rc45 = rc56 = idea7 = cast8 = blowfish9 = aesThe encryption algorithm used to secure the remote
access session. · Integer32
The algorithm used by this remote access session to encrypt its payload.
crasSessionPktAuthenAlgo
1.3.6.1.4.1.9.9.392.1.3.21.1.14
SessionAuthAlgo1 = none2 = other3 = hmacMd54 = hmacShaThe authentication algorithm used by to perform
packet authentication in the remote access session.
The value 'other' has been listed to allow for the
MIB to support packet validation algorithms not
listed here. · Integer32
The algorithm used by this remote access session to to validate packets.
crasSessionCompressionAlgo
1.3.6.1.4.1.9.9.392.1.3.21.1.15
SessionCompressionAlgo1 = none2 = other3 = lzsThe compression algorithm used in the remote access
session.
The value 'other' has been listed to allow for the
MIB to support compression not listed here. · Integer32
The algorithm used by this remote access session to
compress packets.
crasHeartbeatInterval
1.3.6.1.4.1.9.9.392.1.3.21.1.16
Unsigned32 · Seconds
The interval in seconds between two successive heartbeats employed by this session. Value of 0 denotes that no heartbeat is used.
crasClientVendorString
1.3.6.1.4.1.9.9.392.1.3.21.1.17
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The string identifying the vendor of the client
application initiating this Remote Access session.
crasClientVersionString
1.3.6.1.4.1.9.9.392.1.3.21.1.18
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The string identifying the version of the of the client
application initiating the Remote Access session.
This can be used by the administrator to identify which users are running unsupported client versions.
crasClientOSVendorString
1.3.6.1.4.1.9.9.392.1.3.21.1.19
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The string identifying the vendor of the operating system
on which the client application initiating the Remote Access
Session is running.
crasClientOSVersionString
1.3.6.1.4.1.9.9.392.1.3.21.1.20
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The string identifying the version of the operating
system of the entity which initiated this Remote Access
session.
crasPrimWINSServerAddrType
1.3.6.1.4.1.9.9.392.1.3.21.1.21
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasPrimWINSServer'.
crasPrimWINSServer
1.3.6.1.4.1.9.9.392.1.3.21.1.22
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the primary WINS server assigned
managed entity to this client session.
crasSecWINSServerAddrType
1.3.6.1.4.1.9.9.392.1.3.21.1.23
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasSecWINSServer'.
crasSecWINSServer
1.3.6.1.4.1.9.9.392.1.3.21.1.24
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the secondary WINS server assigned
by the managed entity to this client session.
crasPrimDNSServerAddrType
1.3.6.1.4.1.9.9.392.1.3.21.1.25
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasPrimDNSServer'.
crasPrimDNSServer
1.3.6.1.4.1.9.9.392.1.3.21.1.26
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the primary DNS server assigned by
the managed entity to this client session.
crasSecDNSServerAddrType
1.3.6.1.4.1.9.9.392.1.3.21.1.27
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasSecDNSServer'.
crasSecDNSServer
1.3.6.1.4.1.9.9.392.1.3.21.1.28
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the secondary DNS server assigned
by the managed entity to this client session.
crasDHCPServerAddrType
1.3.6.1.4.1.9.9.392.1.3.21.1.29
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasDHCPServer'.
crasDHCPServer
1.3.6.1.4.1.9.9.392.1.3.21.1.30
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the DHCP server assigned by the
managed entity to this client session.
crasSessionInPkts
1.3.6.1.4.1.9.9.392.1.3.21.1.31
Counter64 (0..18446744073709551615) · Packets
The total number of packets received by this Remote
Access session.
crasSessionOutPkts
1.3.6.1.4.1.9.9.392.1.3.21.1.32
Counter64 (0..18446744073709551615) · Packets
The total number of packets transmitted by this
Remote Access Session.
crasSessionInDropPkts
1.3.6.1.4.1.9.9.392.1.3.21.1.33
Counter64 (0..18446744073709551615) · Packets
The total number of packets received for processing on this session which were dropped by the managed entity.
crasSessionOutDropPkts
1.3.6.1.4.1.9.9.392.1.3.21.1.34
Counter64 (0..18446744073709551615) · Packets
The total number of outgoing packets on this session which were dropped during transmit processing by the managed entity.
crasSessionInOctets
1.3.6.1.4.1.9.9.392.1.3.21.1.35
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by this Remote Access Session.
This value is accumulated BEFORE determining whether
or not the packet should be decompressed.
crasSessionOutOctets
1.3.6.1.4.1.9.9.392.1.3.21.1.36
Counter64 (0..18446744073709551615) · Octets
The total number of octets transmitted by this Remote Access Session.
This value is accumulated AFTER determining whether
or not the packet should be compressed.
crasSessionState
1.3.6.1.4.1.9.9.392.1.3.21.1.37
SessionStatus1 = initializing2 = established3 = terminatingThe status of a remote access session.
initializing: the session is in the process
of being established
established : the session is established and
is ready to carry application traffic. Sessions in this state may also be referred to as 'active' sessions.
terminating : the session is in the process
of termination.
Objects of this type may be used to terminate an
established session by setting value of the object
to terminating(3).
Management entity may not write values initializing(1)
or established(2) onto objects of this type. Doing so
would cause the managed entity to return an error
condition. · Integer32
The state of the remote access session corresponding to this conceptual row.
The management entity may use this object to terminate
an established session by setting value of the object
to 'terminating'.
crasActGroupTable
1.3.6.1.4.1.9.9.392.1.3.22
Index: crasActGrpName
This table lists all the currently active remote
access user groups. For each group, it lists the
attributes (group, aggregate activity, aggregate
traffic), and status.
crasActGrpName
1.3.6.1.4.1.9.9.392.1.3.22.1.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..64) · OCTET STRING · hint 255t
The name of the active user group corresponding to this entry.
crasActGrNumUsers
1.3.6.1.4.1.9.9.392.1.3.22.1.2
Integer32 (1..2147483647)
The number of users in this group currently connected
to the managed device.
crasActGrpInPkts
1.3.6.1.4.1.9.9.392.1.3.22.1.3
Counter64 (0..18446744073709551615) · Packets
The total number of packets received by this session.
crasActGrpOutPkts
1.3.6.1.4.1.9.9.392.1.3.22.1.4
Counter64 (0..18446744073709551615) · Packets
The total number of packets transmitted by this session.
crasActGrpInDropPkts
1.3.6.1.4.1.9.9.392.1.3.22.1.5
Counter64 (0..18446744073709551615) · Packets
The total number of packets dropped by this session
which were received for processing.
crasActGrpOutDropPkts
1.3.6.1.4.1.9.9.392.1.3.22.1.6
Counter64 (0..18446744073709551615) · Packets
The total number of outgoing packets which were
dropped during transmit processing by this session.
crasActGrpInOctets
1.3.6.1.4.1.9.9.392.1.3.22.1.7
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by this session.
crasActGrpOutOctets
1.3.6.1.4.1.9.9.392.1.3.22.1.8
Counter64 (0..18446744073709551615) · Octets
The total number of octets transmitted by this session.
crasSessFailTable
1.3.6.1.4.1.9.9.392.1.4.3.1
Index: crasSessFailIndex
This table records the last 'N' session failures,
where 'N' is the value of the MIB element
'crasFailTableSize' defined earlier.
A failure could be a failure to establish a session
('setup' failure) or a failure of a session after it
was established ('operational' failure).
crasSessFailIndex
1.3.6.1.4.1.9.9.392.1.4.3.1.1.1
FailureRecordIndexThe type used to index failure records in the
failure archive. (1..4294967295) · Unsigned32
The index of the session failure table. The value of the index is a number which
begins at one and is incremented with each
session failure. The value of this object will
wrap at 4,294,967,295.
crasSessFailUsername
1.3.6.1.4.1.9.9.392.1.4.3.1.1.2
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The name of the user associated with this failed
remote access session.
crasSessFailGroupname
1.3.6.1.4.1.9.9.392.1.4.3.1.1.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The name of the user group to which this failed
remote access session belongs.
The reason for the failure. Possible reasons
include: 1 = other (error which cannot be classified in
any of the types listed below).
2 = internal error occurred
3 = failed to authenticate the peer/user 4 = failed to authorize the peer/user
5 = system capacity exceeded (memory, cpu, max
users etc) 6 = peer requested to abort the session or the setup 7 = lost peer's heartbeat
8 = local management request.
crasSessFailTime
1.3.6.1.4.1.9.9.392.1.4.3.1.1.6
TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be
defined in the description of any object defined using this type.
If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks
The value of the MIB element 'sysUpTime'
at the time of the failure.
crasSessFailSessionIndex
1.3.6.1.4.1.9.9.392.1.4.3.1.1.7
SessionIndexThe type used to index a remote access session. (1..2147483647) · Integer32
The index of the session which failed (in case
this was an operational failure). In case of setup
failures (where the value of 'crasSessFailType' of
this conceptual row is 'operationalFailure'), the
value of this object is undefined and should not be
processed.
crasSessFailISPAddrType
1.3.6.1.4.1.9.9.392.1.4.3.1.1.8
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasSessFailISPAddr'.
crasSessFailISPAddr
1.3.6.1.4.1.9.9.392.1.4.3.1.1.9
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The public address of the peer.
crasSessFailLocalAddrType
1.3.6.1.4.1.9.9.392.1.4.3.1.1.10
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of the address returned in 'crasSessFailLocalAddr'.
crasSessFailLocalAddr
1.3.6.1.4.1.9.9.392.1.4.3.1.1.11
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The address assigned to the peer by the local address management mechanism. In case no address was assigned to the peer when the failure occurred, this MIB variable would contain the IPv4 address value 0.0.0.0
crasGrpFailTable
1.3.6.1.4.1.9.9.392.1.4.4.1
Index: crasGrpFailGroupname
This table records the last 'N' occurrences of
failures (setup or operational) per user group,
where 'N' is the value of the MIB element
'crasFailTableSize' defined earlier.
When 'N' entries have been created, the failure
information about a new user group must be created by
deleting the oldest entry in this table.
crasGrpFailGroupname
1.3.6.1.4.1.9.9.392.1.4.4.1.1.1
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..64) · OCTET STRING · hint 255t
The name of the user group to which this failure
record corresponds.
This is the index of the group failure table.
crasGrpFailNumFailAuths
1.3.6.1.4.1.9.9.392.1.4.4.1.1.2
Counter64 (0..18446744073709551615)
The number of sessions belonging to this group which
failed authentication; counted since last reboot.
crasGrpFailNumResourceFailures
1.3.6.1.4.1.9.9.392.1.4.4.1.1.3
Counter64 (0..18446744073709551615)
The number of session setup attempts which failed due to insufficient resources.
crasGrpFailNumDeclined
1.3.6.1.4.1.9.9.392.1.4.4.1.1.4
Counter64 (0..18446744073709551615)
The number of session setup attempts which were declined
by the managed entity due to local policy. These would
include sessions which were denied due to rate control
settings.
crasGrpFailNumTerminatedMgmt
1.3.6.1.4.1.9.9.392.1.4.4.1.1.5
Counter64 (0..18446744073709551615)
The number of established sessions which were terminated by explicit management action. The termination may have been triggered locally or based on a request from the peer.
crasGrpFailNumTerminatedOther
1.3.6.1.4.1.9.9.392.1.4.4.1.1.6
Counter64 (0..18446744073709551615)
The number of established sessions which were
terminated due to insufficient reasons, internal error
or other reasons not caused by management action.
Trap details
ciscoRasTooManySessions
1.3.6.1.4.1.9.9.392.0.1
This notification is generated when the managed entity detects that the number of sessions established exceeds the set threshold crasThrMaxSessions.
Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold.
crasNumSessions
1.3.6.1.4.1.9.9.392.1.3.1
Gauge32 · Sessions
The number of currently active sessions.
A session is a connection terminating on the managed
entity which has been established to provide remote
access connectivity to a user. A session is said to be
'active' if it is ready to carry application traffic
between the user and the managed entity. A session which
is not active is defined to be 'dormant'.
crasNumUsers
1.3.6.1.4.1.9.9.392.1.3.3
Gauge32 · Users
The number of users who have active sessions.
crasMaxSessionsSupportable
1.3.6.1.4.1.9.9.392.1.1.1
Integer32 (0..2147483647) · Sessions
The maximum number of remote access sessions
that may be supported on this device.
If the device imposes no arbitrary limit on the
maximum number of sessions, it should return a
value of 0.
crasMaxUsersSupportable
1.3.6.1.4.1.9.9.392.1.1.2
Integer32 (0..2147483647) · Users
The maximum number of remote access users
for whom Remote Access sessions may be supported on
this device.
If the device imposes no arbitrary limit on the
maximum number of users, it should return a
value of 0.
crasThrMaxSessions
1.3.6.1.4.1.9.9.392.1.6.1
Integer32 (0..2147483647) · Sessions
The maximum number of sessions which are successfully
setup after which the managed entity should alert the
network management entity using the notification
'ciscoRasTooManySessions', if the notification has been enabled.
A value of 0 indicates that the threshold has not been
set.
ciscoRasTooManyFailedAuths
1.3.6.1.4.1.9.9.392.0.2
This notification is generated when the managed entity detects that the number of login attempts (over all users) exceeds the set threshold for throughput (crasThrMaxFailedAuths).
Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold.
crasNumDeclinedSessions
1.3.6.1.4.1.9.9.392.1.4.1.2
Unsigned32 · Sessions
The number of session setup attempts, counted since
the last time the notification
'ciscoRasTooManyFailedAuths' was issued, which were
declined due to authentication or authorization
failure.
crasThrMaxFailedAuths
1.3.6.1.4.1.9.9.392.1.6.2
Unsigned32
The value of object 'crasNumDeclinedSessions' at
which the managed entity should alert the network
management entity using the notification
'ciscoRasTooManyFailedAuths', if the notification
has been enabled.
A value of 0 indicates that the threshold has not been
set.
ciscoRasTooHighThroughput
1.3.6.1.4.1.9.9.392.0.3
This notification is generated when the managed entity
detects that the current throughput of the device exceeds
the set threshold for throughput (crasThrMaxThroughput).
Once the notification has been issued, further
notiifcations are suppressed till the value returns below the specified threshold.
crasGlobalInOctets
1.3.6.1.4.1.9.9.392.1.3.7
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by all currently
and previously active remote access sessions.
This value is accumulated BEFORE determining whether
or not the packet should be decompressed.
crasGlobalOutOctets
1.3.6.1.4.1.9.9.392.1.3.9
Counter64 (0..18446744073709551615) · Octets
The total number of octets transmitted by all
currently and previously active remote access
sessions.
This value is accumulated AFTER determining
whether or not the packet should be compressed.
crasThrMaxThroughput
1.3.6.1.4.1.9.9.392.1.6.3
Integer32 (0..2147483647) · Octets Per Second
The highest throughput of the Remote Access Service at
which the managed entity should alert the network management
entity using the notification 'ciscoRasTooHighThroughput',
if the notification has been enabled.
The notification is disabled till the value of the
aggregate throughput of the managed entity drops below
the value of this object.
A value of 0 indicates that the threshold has not been set.