EZ5 MIB Catalog

ENTERASYS-8021X-EXTENSIONS-MIB

2003-11-21

This MIB module defines a portion of the SNMP enterprise MIBs under Enterasys Networks' enterprise OID pertaining to IEEE 802.1X authentication. This MIB is designed to supplement and be used in connection with the standard IEEE 802.1X-2001 MIB. It provides a convenient way to retrieve authentication status for station- based access control. (Here, a MAC address is a much more natural table index than a port or interface number.)

Download ENTERASYS-8021X-EXTENSIONS-MIB.txt Open ENTERASYS-8021X-EXTENSIONS-MIB.txt in a new tab

SCALARS (6) · TABLES (6)

Scalars (6)

NameOID
etsysDot1xAuthStatsSupported1.3.6.1.4.1.5624.1.2.18.1.2.1.6
etsysDot1xAuthDiagSupported1.3.6.1.4.1.5624.1.2.18.1.2.1.7
etsysDot1xAuthSessionSuppportedObjs1.3.6.1.4.1.5624.1.2.18.1.2.1.8
etsysDot1xMaxCapableAuthStations1.3.6.1.4.1.5624.1.2.18.1.2.1.9
etsysDot1xMaximumStationsStatsGathered1.3.6.1.4.1.5624.1.2.18.1.2.1.10
etsysDot1xCurrentStationsStatsGathered1.3.6.1.4.1.5624.1.2.18.1.2.1.11

Tables (6)

NameOID
etsysDot1xAuthStationTable1.3.6.1.4.1.5624.1.2.18.1.2.1.1
etsysDot1xAuthConfigTable1.3.6.1.4.1.5624.1.2.18.1.2.1.2
etsysDot1xAuthStatsTable1.3.6.1.4.1.5624.1.2.18.1.2.1.3
etsysDot1xAuthDiagTable1.3.6.1.4.1.5624.1.2.18.1.2.1.4
etsysDot1xAuthSessionStatsTable1.3.6.1.4.1.5624.1.2.18.1.2.1.5
etsysDot1xAuthStationWatchTable1.3.6.1.4.1.5624.1.2.18.1.2.1.12

END OF TOC

Scalar details

etsysDot1xAuthStatsSupported

1.3.6.1.4.1.5624.1.2.18.1.2.1.6

BITS

Defines the objects supported in the Authenticator Statistics Table.

etsysDot1xAuthDiagSupported

1.3.6.1.4.1.5624.1.2.18.1.2.1.7

BITS

Defines the objects supported in the Authenticator Diagnostics Table.

etsysDot1xAuthSessionSuppportedObjs

1.3.6.1.4.1.5624.1.2.18.1.2.1.8

BITS

Defines the objects supported in the Authenticator Session Statistics Table.

etsysDot1xMaxCapableAuthStations

1.3.6.1.4.1.5624.1.2.18.1.2.1.9

Unsigned32

The maximum number of stations this device can authenticate.

etsysDot1xMaximumStationsStatsGathered

1.3.6.1.4.1.5624.1.2.18.1.2.1.10

Unsigned32

The maximum number of stations that this device can gather statistics, diagnostics, and session statistics for.

etsysDot1xCurrentStationsStatsGathered

1.3.6.1.4.1.5624.1.2.18.1.2.1.11

Unsigned32

The number of stations that this device is currently gathering statistics, diagnostics, and session statistics for.

Table details

etsysDot1xAuthStationTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.1

Index: etsysDot1xAuthStationAddress

A table that contains basic status information for the Authenticator PAEs associated with station-based virtual ports.

etsysDot1xAuthStationAddress

1.3.6.1.4.1.5624.1.2.18.1.2.1.1.1.1

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

The 48-bit IEEE media access control address of the Supplicant associated with the logical station-based access control port.

etsysDot1xAuthStationPaePort

1.3.6.1.4.1.5624.1.2.18.1.2.1.1.1.2

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The dot1xPaePortNumber of the shared-media port that is associated with this Authenticator PAE.

etsysDot1xAuthStationPaeState

1.3.6.1.4.1.5624.1.2.18.1.2.1.1.1.3

INTEGER1 = initialize2 = disconnected3 = connecting4 = authenticating5 = authenticated6 = aborting7 = held8 = forceAuth9 = forceUnauth · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, Authenticator PAE state

The current value of the Authenticator PAE state machine.

etsysDot1xAuthStationBackendAuthState

1.3.6.1.4.1.5624.1.2.18.1.2.1.1.1.4

INTEGER1 = request2 = response3 = success4 = fail5 = timeout6 = idle7 = initialize · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, Backend Authentication state

The current state of the Backend Authentication state machine.

etsysDot1xAuthStationUserName

1.3.6.1.4.1.5624.1.2.18.1.2.1.1.1.5

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: IEEE 802.1X-2001 Section 9.4.4, Session User Name

The User-Name representing the identity of the Supplicant PAE.

etsysDot1xAuthConfigTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.2

Index: etsysDot1xAuthStationAddress

A table that contains configuration objects for the Authenticator PAE associated with each station-based virtual port. Station-based configuration management poses several rather major inconveniences, including a large number of rows, rows indexed by MAC address (rather than by user), and rows that come and go. Port-level and Authentication-Server-based management are quite a bit more convenient. Thus, most of the objects in this table are read-only; a way to see how other settings have interacted if you need this information for troubleshooting purposes.

etsysDot1xAuthInitialize

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Reference: IEEE 802.1X-2001 Section 9.6.1.2, Initialize Port

The initialization control for this Authenticator PAE. Setting this attribute to TRUE causes the PAE to be initialized. The attribute value reverts to FALSE once initialization has completed.

etsysDot1xAuthReauthenticate

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1.3 Reauthenticate

The reauthentication control for this Authenticator PAE. Setting this attribute to TRUE causes the Authenticator PAE state machine to reauthenticate the Supplicant. Setting this attribute FALSE has no effect. This attribute always returns FALSE when it is read.

etsysDot1xAuthAdminControlledDirections

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.3

PaeControlledDirections0 = both1 = inThe control mode values for the Authenticator PAE. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, Admin Control Mode

The current value of the administrative controlled directions parameter for the virtual port.

etsysDot1xAuthOperControlledDirections

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.4

PaeControlledDirections0 = both1 = inThe control mode values for the Authenticator PAE. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, Oper Control Mode

The current value of the operational controlled directions parameter for the virtual port.

etsysDot1xAuthAuthControlledPortStatus

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.5

PaeControlledPortStatus1 = authorized2 = unauthorizedThe status values of the Authenticator PAE controlled Port. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, AuthControlledPortStatus

The current value of the controlled Port status parameter for the virtual port.

etsysDot1xAuthAuthControlledPortControl

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.6

PaeControlledPortControl1 = forceUnauthorized2 = auto3 = forceAuthorizedThe control values of the Authenticator PAE controlled Port. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, AuthControlledPortControl

The current value of the controlled Port control parameter for the virtual port.

etsysDot1xAuthQuietPeriod

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.7

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, quietPeriod

The value, in seconds, of the quietPeriod constant currently in use by the Authenticator PAE state machine.

etsysDot1xAuthTxPeriod

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.8

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, txPeriod

The value, in seconds, of the txPeriod constant currently in use by the Authenticator PAE state machine.

etsysDot1xAuthSuppTimeout

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.9

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, suppTimeout

The value, in seconds, of the suppTimeout constant currently in use by the Backend Authentication state machine.

etsysDot1xAuthServerTimeout

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.10

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, serverTimeout

The value, in seconds, of the serverTimeout constant currently in use by the Backend Authentication state machine.

etsysDot1xAuthMaxReq

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.11

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, maxReq

The value of the maxReq constant currently in use by the Backend Authentication state machine.

etsysDot1xAuthReAuthPeriod

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.12

Unsigned32

Reference: IEEE 802.1X-2001 Section 9.4.1, reAuthPeriod

The value, in seconds, of the reAuthPeriod constant currently in use by the Reauthentication Timer state machine.

etsysDot1xAuthReAuthEnabled

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.13

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, reAuthEnabled

The enable/disable control used by the Reauthentication Timer state machine (IEEE 802.1X-2001 Section 8.5.5.1).

etsysDot1xAuthKeyTxEnabled

1.3.6.1.4.1.5624.1.2.18.1.2.1.2.1.14

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.1, keyTransmissionEnabled

The value of the keyTransmissionEnabled constant currently in use by the Authenticator PAE state machine.

etsysDot1xAuthStatsTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.3

Index: etsysDot1xAuthStationAddress

Reference: IEEE 802.1X-2001 Section 9.4.2 Authenticator Statistics

A table that contains the statistics objects for the Authenticator PAE associated with each supplicant/station.

etsysDot1xAuthEapolFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.1

Counter32

Reference: IEEE 802.1x Section 9.4.2, EAPOL frames received

The number of valid EAPOL frames of any type that have been received by this Authenticator.

etsysDot1xAuthEapolFramesTx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.2

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL frames transmitted

The number of EAPOL frames of any type that have been transmitted by this Authenticator.

etsysDot1xAuthEapolStartFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.3

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Start frames received

The number of EAPOL Start frames that have been received by this Authenticator.

etsysDot1xAuthEapolLogoffFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.4

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Logoff frames received

The number of EAPOL Logoff frames that have been received by this Authenticator.

etsysDot1xAuthEapolRespIdFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.5

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Resp/Id frames received

The number of EAP Resp/Id frames that have been received by this Authenticator.

etsysDot1xAuthEapolRespFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.6

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Response frames received

The number of valid EAP Response frames (other than Resp/Id frames) that have been received by this Authenticator.

etsysDot1xAuthEapolReqIdFramesTx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.7

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Req/Id frames transmitted

The number of EAP Req/Id frames that have been transmitted by this Authenticator.

etsysDot1xAuthEapolReqFramesTx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.8

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAPOL Request frames transmitted

The number of EAP Request frames (other than Rq/Id frames) that have been transmitted by this Authenticator.

etsysDot1xAuthInvalidEapolFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.9

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, Invalid EAPOL frames received

The number of EAPOL frames that have been received by this Authenticator in which the frame type is not recognized.

etsysDot1xAuthEapLengthErrorFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.10

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.2, EAP length error frames received

The number of EAPOL frames that have been received by this Authenticator in which the Packet Body Length field is invalid.

etsysDot1xAuthLastEapolFrameVersion

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.11

Unsigned32

Reference: IEEE 802.1x Section 9.4.2, Last EAPOL frame version

The protocol version number carried in the most recently received EAPOL frame.

etsysDot1xAuthLastEapolFrameSource

1.3.6.1.4.1.5624.1.2.18.1.2.1.3.1.12

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

Reference: IEEE 802.1x Section 9.4.2, Last EAPOL frame source

The source MAC address carried in the most recently received EAPOL frame.

etsysDot1xAuthDiagTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.4

Index: etsysDot1xAuthStationAddress

Reference: IEEE 802.1X-2001 Section 9.4.3 Authenticator Diagnostics

A table that contains the diagnostics objects for the Authenticator PAE associated with each Port. An entry appears in this table for each port that may authenticate access to itself.

etsysDot1xAuthEntersConnecting

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.1

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.1

Counts the number of times that the state machine transitions to the CONNECTING state from any other state.

etsysDot1xAuthEapLogoffsWhileConnecting

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.2

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.2

Counts the number of times that the state machine transitions from CONNECTING to DISCONNECTED as a result of receiving an EAPOL-Logoff message.

etsysDot1xAuthEntersAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.3

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.3

Counts the number of times that the state machine transitions from CONNECTING to AUTHENTICATING, as a result of an EAP-Response/Identity message being received from the Supplicant.

etsysDot1xAuthAuthSuccessWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.4

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.4

Counts the number of times that the state machine transitions from AUTHENTICATING to AUTHENTICATED, as a result of the Backend Authentication state machine indicating successful authentication of the Supplicant (authSuccess = TRUE).

etsysDot1xAuthAuthTimeoutsWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.5

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.5

Counts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of the Backend Authentication state machine indicating authentication timeout (authTimeout = TRUE).

etsysDot1xAuthAuthFailWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.6

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.6

Counts the number of times that the state machine transitions from AUTHENTICATING to HELD, as a result of the Backend Authentication state machine indicating authentication failure (authFail = TRUE).

etsysDot1xAuthAuthReauthsWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.7

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.7

Counts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of a reauthentication request (reAuthenticate = TRUE).

etsysDot1xAuthAuthEapStartsWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.8

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.8

Counts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of an EAPOL-Start message being received from the Supplicant.

etsysDot1xAuthAuthEapLogoffWhileAuthenticating

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.9

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.9

Counts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of an EAPOL-Logoff message being received from the Supplicant.

etsysDot1xAuthAuthReauthsWhileAuthenticated

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.10

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.10

Counts the number of times that the state machine transitions from AUTHENTICATED to CONNECTING, as a result of a reauthentication request (reAuthenticate = TRUE).

etsysDot1xAuthAuthEapStartsWhileAuthenticated

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.11

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.11

Counts the number of times that the state machine transitions from AUTHENTICATED to CONNECTING, as a result of an EAPOL-Start message being received from the Supplicant.

etsysDot1xAuthAuthEapLogoffWhileAuthenticated

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.12

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.4.2.12

Counts the number of times that the state machine transitions from AUTHENTICATED to DISCONNECTED, as a result of an EAPOL-Logoff message being received from the Supplicant.

etsysDot1xAuthBackendResponses

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.13

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.1

Counts the number of times that the state machine sends an initial Access-Request packet to the Authentication server (i.e., executes sendRespToServer on entry to the RESPONSE state). Indicates that the Authenticator attempted communication with the Authentication Server.

etsysDot1xAuthBackendAccessChallenges

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.14

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.2

Counts the number of times that the state machine receives an initial Access-Challenge packet from the Authentication server (i.e., aReq becomes TRUE, causing exit from the RESPONSE state). Indicates that the Authentication Server has communication with the Authenticator.

etsysDot1xAuthBackendOtherRequestsToSupplicant

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.15

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.3

Counts the number of times that the state machine sends an EAP-Request packet (other than an Identity, Notification, Failure or Success message) to the Supplicant (i.e., executes txReq on entry to the REQUEST state). Indicates that the Authenticator chose an EAP-method.

etsysDot1xAuthBackendNonNakResponsesFromSupplicant

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.16

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.4

Counts the number of times that the state machine receives a response from the Supplicant to an initial EAP-Request, and the response is something other than EAP-NAK (i.e., rxResp becomes TRUE, causing the state machine to transition from REQUEST to RESPONSE, and the response is not an EAP-NAK). Indicates that the Supplicant can respond to the Authenticator's chosen EAP-method.

etsysDot1xAuthBackendAuthSuccesses

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.17

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.5

Counts the number of times that the state machine receives an EAP-Success message from the Authentication Server (i.e., aSuccess becomes TRUE, causing a transition from RESPONSE to SUCCESS). Indicates that the Supplicant has successfully authenticated to the Authentication Server.

etsysDot1xAuthBackendAuthFails

1.3.6.1.4.1.5624.1.2.18.1.2.1.4.1.18

Counter32

Reference: IEEE 802.1X-2001 Sections 9.4.2, 8.5.6.2.6

Counts the number of times that the state machine receives an EAP-Failure message from the Authentication Server (i.e., aFail becomes TRUE, causing a transition from RESPONSE to FAIL). Indicates that the Supplicant has not authenticated to the Authentication Server.

etsysDot1xAuthSessionStatsTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.5

Index: etsysDot1xAuthStationAddress

Reference: IEEE 802.1X-2001 Section 9.4.4

A table that contains the session statistics objects for the Authenticator PAE associated with each supplicant. An entry appears in this table for each supplicant.

etsysDot1xAuthSessionOctetsRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.1

Counter64 (0..18446744073709551615)

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Octets Received

The number of octets received in user data frames from the supplicant PAE during the session.

etsysDot1xAuthSessionOctetsTx

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.2

Counter64 (0..18446744073709551615)

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Octets Transmitted

The number of octets transmitted in user data frames to the supplicant PAE during the session.

etsysDot1xAuthSessionFramesRx

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.3

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Frames Received

The number of user data frames received from the supplicant PAE during the session.

etsysDot1xAuthSessionFramesTx

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.4

Counter32

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Frames Transmitted

The number of user data frames transmitted to the supplicant PAE during the session.

etsysDot1xAuthSessionId

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.5

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Identifier

A unique identifier for the session, in the form of a printable ASCII string of at least three characters.

etsysDot1xAuthSessionAuthenticMethod

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.6

INTEGER1 = remoteAuthServer2 = localAuthServer · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Authentication Method

The authentication method used to establish the session.

etsysDot1xAuthSessionTime

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.7

TimeTicks

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Time

The duration of the session in seconds.

etsysDot1xAuthSessionTerminateCause

1.3.6.1.4.1.5624.1.2.18.1.2.1.5.1.8

INTEGER1 = supplicantLogoff2 = portFailure3 = supplicantRestart4 = reauthFailed5 = authControlForceUnauth6 = portReInit7 = portAdminDisabled999 = notTerminatedYet · Integer32

Reference: IEEE 802.1X-2001 Section 9.4.4, Session Terminate Cause

The reason for the session termination.

etsysDot1xAuthStationWatchTable

1.3.6.1.4.1.5624.1.2.18.1.2.1.12

Index: etsysDot1xAuthInfoStationAddress

A table containing the MAC addresses of stations that statistics, diagnostics, and session statistics will be kept for. This table's existence is due to the realization that devices may not have the resources to keep all of this data for all the authenticated stations; however, there is a need when debugging a network for these statistics. This compromise solution allows the network administrator to pick which stations to collect data for. If the maximum number of stations this device can collect data for is equal to the maximum number of stations the device can authenticate than this table has no effect or meaning. If the maximum number of stations this device can collect data for is 0 then this table has no effect or meaning. Please note: even though a station may be placed into the watch table, the statistics and diagnostic information that is acquired is ultimately determined by the device's capability to acquire that data. The statistics, diagnostics, and session statistics tables all have a read only object that allow the network administrator to determine what information the device can acquire.

etsysDot1xAuthInfoStationAddress

1.3.6.1.4.1.5624.1.2.18.1.2.1.12.1.1

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

The MAC address of a station that statistics, diagnostics, and session statistics will be kept for.

etsysDot1xAuthInfoStationRowStatus

1.3.6.1.4.1.5624.1.2.18.1.2.1.12.1.2

RowStatus1 = active2 = notInService3 = notReady4 = createAndGo5 = createAndWait6 = destroyThe RowStatus textual convention is used to manage the creation and deletion of conceptual rows, and is used as the value of the SYNTAX clause for the status column of a conceptual row (as described in Section 7.7.1 of [2].) The status column has six defined values: - `active', which indicates that the conceptual row is available for use by the managed device; - `notInService', which indicates that the conceptual row exists in the agent, but is unavailable for use by the managed device (see NOTE below); 'notInService' has no implication regarding the internal consistency of the row, availability of resources, or consistency with the current state of the managed device; - `notReady', which indicates that the conceptual row exists in the agent, but is missing information necessary in order to be available for use by the managed device (i.e., one or more required columns in the conceptual row have not been instanciated); - `createAndGo', which is supplied by a management station wishing to create a new instance of a conceptual row and to have its status automatically set to active, making it available for use by the managed device; - `createAndWait', which is supplied by a management station wishing to create a new instance of a conceptual row (but not make it available for use by the managed device); and, - `destroy', which is supplied by a management station wishing to delete all of the instances associated with an existing conceptual row. Whereas five of the six values (all except `notReady') may be specified in a management protocol set operation, only three values will be returned in response to a management protocol retrieval operation: `notReady', `notInService' or `active'. That is, when queried, an existing conceptual row has only three states: it is either available for use by the managed device (the status column has value `active'); it is not available for use by the managed device, though the agent has sufficient information to attempt to make it so (the status column has value `notInService'); or, it is not available for use by the managed device, and an attempt to make it so would fail because the agent has insufficient information (the state column has value `notReady'). NOTE WELL This textual convention may be used for a MIB table, irrespective of whether the values of that table's conceptual rows are able to be modified while it is active, or whether its conceptual rows must be taken out of service in order to be modified. That is, it is the responsibility of the DESCRIPTION clause of the status column to specify whether the status column must not be `active' in order for the value of some other column of the same conceptual row to be modified. If such a specification is made, affected columns may be changed by an SNMP set PDU if the RowStatus would not be equal to `active' either immediately before or after processing the PDU. In other words, if the PDU also contained a varbind that would change the RowStatus value, the column in question may be changed if the RowStatus was not equal to `active' as the PDU was received, or if the varbind sets the status to a value other than 'active'. Also note that whenever any elements of a row exist, the RowStatus column must also exist. To summarize the effect of having a conceptual row with a status column having a SYNTAX clause value of RowStatus, consider the following state diagram: STATE +--------------+-----------+-------------+------------- | A | B | C | D | |status col.|status column| |status column | is | is |status column ACTION |does not exist| notReady | notInService| is active --------------+--------------+-----------+-------------+------------- set status |noError ->D|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndGo |inconsistent- | | | | Value| | | --------------+--------------+-----------+-------------+------------- set status |noError see 1|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndWait |wrongValue | | | --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError column to | Value| entValue| | active | | | | | | or | | | | | | | |see 2 ->D|see 8 ->D| ->D --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError ->C column to | Value| entValue| | notInService | | | | | | or | | or | | | | | |see 3 ->C| ->C|see 6 --------------+--------------+-----------+-------------+------------- set status |noError |noError |noError |noError ->A column to | | | | or destroy | ->A| ->A| ->A|see 7 --------------+--------------+-----------+-------------+------------- set any other |see 4 |noError |noError |see 5 column to some| | | | value | | see 1| ->C| ->D --------------+--------------+-----------+-------------+------------- (1) goto B or C, depending on information available to the agent. (2) if other variable bindings included in the same PDU, provide values for all columns which are missing but required, and all columns have acceptable values, then return noError and goto D. (3) if other variable bindings included in the same PDU, provide legal values for all columns which are missing but required, then return noError and goto C. (4) at the discretion of the agent, the return value may be either: inconsistentName: because the agent does not choose to create such an instance when the corresponding RowStatus instance does not exist, or inconsistentValue: if the supplied value is inconsistent with the state of some other MIB object's value, or noError: because the agent chooses to create the instance. If noError is returned, then the instance of the status column must also be created, and the new state is B or C, depending on the information available to the agent. If inconsistentName or inconsistentValue is returned, the row remains in state A. (5) depending on the MIB definition for the column/table, either noError or inconsistentValue may be returned. (6) the return value can indicate one of the following errors: wrongValue: because the agent does not support notInService (e.g., an agent which does not support createAndWait), or inconsistentValue: because the agent is unable to take the row out of service at this time, perhaps because it is in use and cannot be de-activated. (7) the return value can indicate the following error: inconsistentValue: because the agent is unable to remove the row at this time, perhaps because it is in use and cannot be de-activated. (8) the transition to D can fail, e.g., if the values of the conceptual row are inconsistent, then the error code would be inconsistentValue. NOTE: Other processing of (this and other varbinds of) the set request may result in a response other than noError being returned, e.g., wrongValue, noCreation, etc. Conceptual Row Creation There are four potential interactions when creating a conceptual row: selecting an instance-identifier which is not in use; creating the conceptual row; initializing any objects for which the agent does not supply a default; and, making the conceptual row available for use by the managed device. Interaction 1: Selecting an Instance-Identifier The algorithm used to select an instance-identifier varies for each conceptual row. In some cases, the instance- identifier is semantically significant, e.g., the destination address of a route, and a management station selects the instance-identifier according to the semantics. In other cases, the instance-identifier is used solely to distinguish conceptual rows, and a management station without specific knowledge of the conceptual row might examine the instances present in order to determine an unused instance-identifier. (This approach may be used, but it is often highly sub-optimal; however, it is also a questionable practice for a naive management station to attempt conceptual row creation.) Alternately, the MIB module which defines the conceptual row might provide one or more objects which provide assistance in determining an unused instance-identifier. For example, if the conceptual row is indexed by an integer-value, then an object having an integer-valued SYNTAX clause might be defined for such a purpose, allowing a management station to issue a management protocol retrieval operation. In order to avoid unnecessary collisions between competing management stations, `adjacent' retrievals of this object should be different. Finally, the management station could select a pseudo-random number to use as the index. In the event that this index was already in use and an inconsistentValue was returned in response to the management protocol set operation, the management station should simply select a new pseudo-random number and retry the operation. A MIB designer should choose between the two latter algorithms based on the size of the table (and therefore the efficiency of each algorithm). For tables in which a large number of entries are expected, it is recommended that a MIB object be defined that returns an acceptable index for creation. For tables with small numbers of entries, it is recommended that the latter pseudo-random index mechanism be used. Interaction 2: Creating the Conceptual Row Once an unused instance-identifier has been selected, the management station determines if it wishes to create and activate the conceptual row in one transaction or in a negotiated set of interactions. Interaction 2a: Creating and Activating the Conceptual Row The management station must first determine the column requirements, i.e., it must determine those columns for which it must or must not provide values. Depending on the complexity of the table and the management station's knowledge of the agent's capabilities, this determination can be made locally by the management station. Alternately, the management station issues a management protocol get operation to examine all columns in the conceptual row that it wishes to create. In response, for each column, there are three possible outcomes: - a value is returned, indicating that some other management station has already created this conceptual row. We return to interaction 1. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it should supply a value for this column when the conceptual row is to be created. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. Once the column requirements have been determined, a management protocol set operation is accordingly issued. This operation also sets the new instance of the status column to `createAndGo'. When the agent processes the set operation, it verifies that it has sufficient information to make the conceptual row available for use by the managed device. The information available to the agent is provided by two sources: the management protocol set operation which creates the conceptual row, and, implementation-specific defaults supplied by the agent (note that an agent must provide implementation-specific defaults for at least those objects which it implements as read-only). If there is sufficient information available, then the conceptual row is created, a `noError' response is returned, the status column is set to `active', and no further interactions are necessary (i.e., interactions 3 and 4 are skipped). If there is insufficient information, then the conceptual row is not created, and the set operation fails with an error of `inconsistentValue'. On this error, the management station can issue a management protocol retrieval operation to determine if this was because it failed to specify a value for a required column, or, because the selected instance of the status column already existed. In the latter case, we return to interaction 1. In the former case, the management station can re-issue the set operation with the additional information, or begin interaction 2 again using `createAndWait' in order to negotiate creation of the conceptual row. NOTE WELL Regardless of the method used to determine the column requirements, it is possible that the management station might deem a column necessary when, in fact, the agent will not allow that particular columnar instance to be created or written. In this case, the management protocol set operation will fail with an error such as `noCreation' or `notWritable'. In this case, the management station decides whether it needs to be able to set a value for that particular columnar instance. If not, the management station re-issues the management protocol set operation, but without setting a value for that particular columnar instance; otherwise, the management station aborts the row creation algorithm. Interaction 2b: Negotiating the Creation of the Conceptual Row The management station issues a management protocol set operation which sets the desired instance of the status column to `createAndWait'. If the agent is unwilling to process a request of this sort, the set operation fails with an error of `wrongValue'. (As a consequence, such an agent must be prepared to accept a single management protocol set operation, i.e., interaction 2a above, containing all of the columns indicated by its column requirements.) Otherwise, the conceptual row is created, a `noError' response is returned, and the status column is immediately set to either `notInService' or `notReady', depending on whether it has sufficient information to (attempt to) make the conceptual row available for use by the managed device. If there is sufficient information available, then the status column is set to `notInService'; otherwise, if there is insufficient information, then the status column is set to `notReady'. Regardless, we proceed to interaction 3. Interaction 3: Initializing non-defaulted Objects The management station must now determine the column requirements. It issues a management protocol get operation to examine all columns in the created conceptual row. In the response, for each column, there are three possible outcomes: - a value is returned, indicating that the agent implements the object-type associated with this column and had sufficient information to provide a value. For those columns to which the agent provides read-create access (and for which the agent allows their values to be changed after their creation), a value return tells the management station that it may issue additional management protocol set operations, if it desires, in order to change the value associated with this column. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. However, the agent does not have sufficient information to provide a value, and until a value is provided, the conceptual row may not be made available for use by the managed device. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it must issue additional management protocol set operations, in order to provide a value associated with this column. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. If the value associated with the status column is `notReady', then the management station must first deal with all `noSuchInstance' columns, if any. Having done so, the value of the status column becomes `notInService', and we proceed to interaction 4. Interaction 4: Making the Conceptual Row Available Once the management station is satisfied with the values associated with the columns of the conceptual row, it issues a management protocol set operation to set the status column to `active'. If the agent has sufficient information to make the conceptual row available for use by the managed device, the management protocol set operation succeeds (a `noError' response is returned). Otherwise, the management protocol set operation fails with an error of `inconsistentValue'. NOTE WELL A conceptual row having a status column with value `notInService' or `notReady' is unavailable to the managed device. As such, it is possible for the managed device to create its own instances during the time between the management protocol set operation which sets the status column to `createAndWait' and the management protocol set operation which sets the status column to `active'. In this case, when the management protocol set operation is issued to set the status column to `active', the values held in the agent supersede those used by the managed device. If the management station is prevented from setting the status column to `active' (e.g., due to management station or network failure) the conceptual row will be left in the `notInService' or `notReady' state, consuming resources indefinitely. The agent must detect conceptual rows that have been in either state for an abnormally long period of time and remove them. It is the responsibility of the DESCRIPTION clause of the status column to indicate what an abnormally long period of time would be. This period of time should be long enough to allow for human response time (including `think time') between the creation of the conceptual row and the setting of the status to `active'. In the absence of such information in the DESCRIPTION clause, it is suggested that this period be approximately 5 minutes in length. This removal action applies not only to newly-created rows, but also to previously active rows which are set to, and left in, the notInService state for a prolonged period exceeding that which is considered normal for such a conceptual row. Conceptual Row Suspension When a conceptual row is `active', the management station may issue a management protocol set operation which sets the instance of the status column to `notInService'. If the agent is unwilling to do so, the set operation fails with an error of `wrongValue' or `inconsistentValue'. Otherwise, the conceptual row is taken out of service, and a `noError' response is returned. It is the responsibility of the DESCRIPTION clause of the status column to indicate under what circumstances the status column should be taken out of service (e.g., in order for the value of some other column of the same conceptual row to be modified). Conceptual Row Deletion For deletion of conceptual rows, a management protocol set operation is issued which sets the instance of the status column to `destroy'. This request may be made regardless of the current value of the status column (e.g., it is possible to delete conceptual rows which are either `notReady', `notInService' or `active'.) If the operation succeeds, then all instances associated with the conceptual row are immediately removed. · Integer32

A control that allows entries to be added, activated, deactivated, and removed from this table. When the value of this object is 'active' none of the other objects in this conceptual row can be modified. Setting this object to the 'active' state from the 'notInService' state will cause the collection of the above described statistics. Setting this object to any other valid state from the 'active' state will cause the collection of the above described statistics to stop. Setting this object to the 'active' state from the 'active' state will not have any affect. Conceptual rows that have been in the 'notInService' state for more than a device specific time period MAY be destroyed by the managed entity.

↑ To TOC