EZ5 MIB Catalog

IEEE8021X-PAE-MIB

2017-10-28

Download IEEE8021X-PAE-MIB.txt Open IEEE8021X-PAE-MIB.txt in a new tab

The MIB module for managing the Port Access Entity (PAE) functions of IEEE 802.1X (Revision of 802.1X-2004). The PAE functions managed are summarized in Figure 12-3 of IEEE 802.1X and include EAPOL PACP support for authentication (EAP Supplicant and/or Authenticator), MACsec Key Agreement (MKA), EAPOL, and transmission and reception of network announcements. The following acronyms and definitions are used in this MIB. AN : Association Number, a number that is concatenated with a MACsec Secure Channel Identifier to identify a Secure Association (SA). Announcer : EAPOL-Announcement transmission functionality. Authenticator : An entity that facilitates authentication of other entities attached to the same LAN. CA : secure Connectivity Association: A security relationship, established and maintained by key agreement protocols, that comprises a fully connected subset of the service access points in stations attached to a single LAN that are to be supported by MACsec. CAK : secure Connectivity Association Key, a secret key possessed by members of a given CA. CKN : secure Connectivity Association Key Name (CKN), a text that identifies a CAK. Common Port : An instance of the MAC Internal Sublayer Service used by the SecY or PAC to provide transmission and reception of frames for both the Controlled and Uncontrolled Ports. Controlled Port : The access point used to provide the secure MAC Service to a client of a PAC or SecY. CP state machine : Controlled Port state machine is capable of controlling a SecY or a PAC. The CP supports interoperability with unauthenticated systems that are not port-based network access control capable, or that lack MKA. When the access controlled port is supported by a SecY, the CP is capable of controlling the SecY so as to provide unsecured connectivity to systems that implement a PAC. EAP : Extensible Authentication Protocol, RFC3748. EAPOL : EAP over LANs. KaY : Key Agreement Entity, a PAE entity responsible for MKA. Key Server : Elected by MKA, to transport a succession of SAKs, for use by MACsec, to the other member(s) of a CA. KMD : Key Management Domain, a string identifying systems that share cached CAKs. Listener : The role is to receive the network announcement parameters in the authentication process. Logon Process : The Logon Process is responsible for the managing the use of authentication credentials, for initiating use of the PAE's Supplicant and or Authenticator functionality, for deriving CAK, CKN tuples from PAE results, for maintaining PSKs (Pre-Sharing Keys), and for managing MKA instances. In the absence of successful authentication, key agreement, or support for MAC Security, the Logon Process determines whether the CP state machine should provide unauthenticated connectivity or authenticated but unsecured connectivity. MKA : MACsec Key Agreement protocol allows PAEs, each associated with a port that is an authenticated member of a secure connectivity association (CA) or a potential CA, to discover other PAEs attached to the same LAN, to confirm mutual possession of a CAK and hence to prove a past mutual authentication, to agree the secret keys (SAKs) used by MACsec for symmetric shared key cryptography, and to ensure that the data protected by MACsec has not been delayed. MKPDU : MACsec Key Agreement Protocol Data Unit. MPDU : MAC Protocol Data Unit. NID : Network Identity, a UTF-8 string identifying an network or network service. PAE : Port Access Entity, the protocol entity associated with a Port. It can support the protocol functionality associated with the Authenticator, the Supplicant, or both. PAC : Port Access Controller, a protocol-less shim that provides control over frame transmission and reception by clients attached to its Controlled Port, and uses the MAC Service provided by a Common Port. The access control decision is made by the PAE, typically taking into account the success or failure of mutual authentication and authorization of the PAE's peer(s), and is communicated by the PAE using the LMI to set the PAC's Controlled Port enabled/disable. Two different interfaces 'Controlled Port' and 'Uncontrolled Port', are associated with a PAC, and that for each instance of a PAC, two ifTable rows (one for each interface) run on top of an ifTable row representing the 'Common Port' interface, such as a row with ifType = 'ethernetCsmacd(6)'. For example : ----------------------------------------------------------- | | | | Controlled Port | Uncontrolled Port | | Interface | Interface | | (ifEntry = j) | (ifEntry = k) | | (ifType = | (ifType = | | macSecControlledIF(231)) | macSecUncontrolledIF(232))| | | | |---------------------------------------------------------| | | | Physical Interface | | (ifEntry = i) | | (ifType = ethernetCsmacd(6)) | |_________________________________________________________| i, j, k are ifIndex to indicate an interface stack in the ifTable. Figure : PAC Interface Stack The 'Controlled Port' is the service point to provide one instance of the secure MAC service in a PAC. The 'Uncontrolled Port' is the service point to provide one instance of the insecure MAC service in a PAC. PACP : Port Access Controller Protocol. Port Identifier : A 16-bit identifier that uniquely identifies each of a system's transmit SCs that uses the same MAC address as a component of its SCI. Real Port : Indicates the PAE is for a real port. A port that is not created on demand by the mechanisms specified in this standard, but that can transmit and receive frames for one or more virtual ports. SC : Secure Channel, a security relationship used to provide security guarantees for frames transmitted from one member of a CA to the others. An SC is supported by a sequence of SAs thus allowing the periodic use of fresh keys without terminating the relationship. SA : Secure Association, a security relationship that provides security guarantees for frames transmitted from one member of a CA to the others. Each SA is supported by a single secret key, or a single set of keys where the cryptographic operations used to protect one frame require more than one key. SAK : Secure Association key, the secret key used by an SA. SCI : Secure Channel Identifier, a unique identifier for a secure channel, comprising a MAC Address and a Port Identifier. secured connectivity : Data transfer between two or 'Controlled Ports' that is protected by MACsec. SecY : MAC Security Entity, the entity that operates the MAC Security protocol within a system. Supplicant : An entity at one end of a point-to-point LAN segment that seeks to be authenticated by an Authenticator attached to the other end of that link. Suspension: Temporary suspension of MKA operation to facilitate in-service control plane software upgrades without disrupting existing secure connectivity. Uncontrolled Port : The access point used to provide the insecure MAC Service to a client of a SecY or PAC. Virtual Port : Indicates the PAE is for a virtual port. A MAC Service or Internal Sublayer service access point that is created on demand. Virtual ports can be used to provide separate secure connectivity associations over the same LAN.

SCALARS (4) · TABLES (15)

Scalars (4)

NameOID
ieee8021XPaeSysAccessControl1.3.111.2.802.1.1.15.1.1.1
ieee8021XPaeSysAnnouncements1.3.111.2.802.1.1.15.1.1.2
ieee8021XPaeSysEapolVersion1.3.111.2.802.1.1.15.1.1.3
ieee8021XPaeSysMkaVersion1.3.111.2.802.1.1.15.1.1.4

Tables (15)

NameOID
ieee8021XPaePortTable1.3.111.2.802.1.1.15.1.1.5
ieee8021XPacPortTable1.3.111.2.802.1.1.15.1.1.6
ieee8021XPaePortLogonTable1.3.111.2.802.1.1.15.1.2.1
ieee8021XPaePortSessionTable1.3.111.2.802.1.1.15.1.2.2
ieee8021XLogonNIDTable1.3.111.2.802.1.1.15.1.2.3
ieee8021XAuthenticatorTable1.3.111.2.802.1.1.15.1.3.1
ieee8021XSupplicantTable1.3.111.2.802.1.1.15.1.4.1
ieee8021XEapolStatsTable1.3.111.2.802.1.1.15.1.5.1
ieee8021XKayMkaTable1.3.111.2.802.1.1.15.1.6.1
ieee8021XKayMkaParticipantTable1.3.111.2.802.1.1.15.1.6.2
ieee8021XKayMkaPeerListTable1.3.111.2.802.1.1.15.1.6.3
ieee8021XNidConfigTable1.3.111.2.802.1.1.15.1.7.1
ieee8021XAnnounceTable1.3.111.2.802.1.1.15.1.7.2
ieee8021XAnnouncementTable1.3.111.2.802.1.1.15.1.7.3
ieee8021XAnnouncementCipherSuitesTable1.3.111.2.802.1.1.15.1.7.4

END OF TOC

Scalar details

ieee8021XPaeSysAccessControl

1.3.111.2.802.1.1.15.1.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object enables or disables port-based network access control for all the system's ports. Setting this control object to 'false' causes the following actions : . Deletes any virtual ports previously instantiated. . Terminates authentication exchanges and MKA instances' operation. . Each real port PAE behaves as if no virtual ports created. . All the PAEs' Supplicant, Authenticator, and KaY are disabled. . Logon Process(es) behave as if the object ieee8021XNidUnauthAllowed was 'immediate'. . Announcements can be transmitted, both periodically and in response to announcement requests (conveyed by EAPOL-Starts or EAPOL-Announcement-Reqs) but are sent with a single NULL NID. . Objects announcementAccessStatus and announceAccessStatus have the 'noAccess' value, announcementAccessRequested is 'false', object announcementUnauthAccess has the 'openAccess' value. The control variable settings for each real port PAE in the ieee8021XPaePortTable are unaffected, and will be used once the object is set to 'true'. This configured value for this object shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XPaeSysAnnouncements

1.3.111.2.802.1.1.15.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Setting this control object to 'false' causes each PAE in this system to behave as if the PAE's Announcement functionality is disabled. The independent controls for each PAE apply if this object is 'true'. This configured value for this object shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XPaeSysEapolVersion

1.3.111.2.802.1.1.15.1.1.3

Unsigned32

The EAPOL protocol version for this system.

ieee8021XPaeSysMkaVersion

1.3.111.2.802.1.1.15.1.1.4

Unsigned32

The MKA protocol version for this system.

Table details

ieee8021XPaePortTable

1.3.111.2.802.1.1.15.1.1.5

Index: ieee8021XPaePortNumber

A table of system level information for each port supported by the Port Access Entity. An entry appears in this table for each port of this system. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XPaePortNumber

1.3.111.2.802.1.1.15.1.1.5.1.1

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

An interface index indicates the port number associated with this port. Each PAE is uniquely identified by a port number. The port number used is unique amongst all port numbers for the system, and directly or indirectly identifies the Uncontrolled Port that supports the PAE. If the PAE indicates a real port, ieee8021XPaePortType object in the same row is 'realPort', the port number shall be the same as the ieee8021XPaeCommonPortNumber object in the same row for the associated PAC or SecY. If the PAE indicates a virtual port, ieee8021XPaePortType object in the same row is 'virtualPort', this port number should be the same as the uncontrolledPortNumber object in the same row for the associated PAC or SecY.

ieee8021XPaePortType

1.3.111.2.802.1.1.15.1.1.5.1.2

INTEGER1 = realPort2 = virtualPort · Integer32

The port type of the PAE. realPort(1) : indicates the PAE is for a real port. virtualPort(2) : indicates the PAE is for a virtual port.

ieee8021XPaeControlledPortNumber

1.3.111.2.802.1.1.15.1.1.5.1.3

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

An interface index indicates the port number associated with PAC or SecY's Controlled Port.

ieee8021XPaeUncontrolledPortNumber

1.3.111.2.802.1.1.15.1.1.5.1.4

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

An interface index indicates the port number associated with PAC or SecY's Uncontrolled Port. If the PAE supports a real port, this port number can be the same as the ieee8021XPaeCommonPortNumber object in the same row, otherwise it shall not be the same.

ieee8021XPaeCommonPortNumber

1.3.111.2.802.1.1.15.1.1.5.1.5

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

An interface index indicates the port number associated with PAC or SecY's 'Common Port'. All the virtual ports created for a given real port share the same 'Common Port' and ieee8021XPaeCommonPortNumber in the same row.

ieee8021XPaePortInitialize

1.3.111.2.802.1.1.15.1.1.5.1.6

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The initialization control for this Port. Setting this object 'true' causes the Port to be reinitialized, terminating (and potentially restarting) authentication exchanges and MKA operation. If the port is a real port, any virtual ports previously instantiated are deleted. Virtual ports can be reinstantiated through normal protocol operation. The object value reverts to 'false' once initialization has completed.

ieee8021XPaePortCapabilities

1.3.111.2.802.1.1.15.1.1.5.1.7

BITS

The capabilities of this PAE port. 'suppImplemented' : A PACP EAP supplicant functions are implemented in this PAE if this bit is on. 'authImplemented' : A PACP EAP authenticator functions are implemented in this PAE if this bit is on. 'mkaImplemented' : The KaY MKA functions are implemented in this PAE if this bit is on. 'macsecImplemented' : The MACsec functions in the Controlled Port are implemented in this PAE if this bit is on. 'announcementsImplemented' : The EAPOL announcement can be sent in this PAE if this bit is on. 'listenerImplemented' : This PAE can receive EAPOL announcement if this bit is on. 'virtualPortsImplemented' : Virtual Port functions are implemented in this PAE if this bit is on.

ieee8021XPaePortVirtualPortsEnable

1.3.111.2.802.1.1.15.1.1.5.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Enable or disable to Virtual Ports function for this Real Port PAE, the object ieee8021XPaePortType in the same row has the value 'realPort'. If this PAE is not a Real Port, this object should be read only and returns 'false'. This object will be read only and returns 'false' if the value of the object ieee8021XPaePortCapabilities in the same row has the bit 'virtualPortsImplemented' off.

ieee8021XPaePortMaxVirtualPorts

1.3.111.2.802.1.1.15.1.1.5.1.9

Unsigned32

The maximum number of virtual ports can be supported in this port.

ieee8021XPaePortCurrentVirtualPorts

1.3.111.2.802.1.1.15.1.1.5.1.10

Gauge32

The current number of virtual ports is running in this port.

ieee8021XPaePortVirtualPortStart

1.3.111.2.802.1.1.15.1.1.5.1.11

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the virtual port is created by receipt of an EAPOL-Start packet.

ieee8021XPaePortVirtualPortPeerMAC

1.3.111.2.802.1.1.15.1.1.5.1.12

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

The source MAC address of the received EAPOL-Start if ieee8021XPaePortVirtualPortStart is set 'true'. If ieee8021XPaePortVirtualPortStart is not 'true' in the same row, the value of this object should be 00-00-00-00-00-00.

ieee8021XPaePortLogonEnable

1.3.111.2.802.1.1.15.1.1.5.1.13

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Enable or disable to transmit network announcement information.

ieee8021XPaePortAuthenticatorEnable

1.3.111.2.802.1.1.15.1.1.5.1.14

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

True if the Authenticator is enabled. This object is read only. It returns 'false' if the value of the object ieee8021XPaePortCapabilities in the same row has the bit 'authImplemented' Off, or if the local control variable 'enable' has not been set by the Logon Process.

ieee8021XPaePortSupplicantEnable

1.3.111.2.802.1.1.15.1.1.5.1.15

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

True if the Suppplicant is enabled. This object is read only. It returns 'false' if the PAE lacks supplicant functionality (ieee8021XPaePortCapabilities in the same row has the bit 'suppImplemented' off), or if the local control variable'enable' has not been set by the Logon Process (perhaps because the supplicant is designed to authenticate a human user and that user is not present).

ieee8021XPaePortKayMkaEnable

1.3.111.2.802.1.1.15.1.1.5.1.16

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Enable or disable the MKA protocol function in this PAE. This object will be read only and returns 'false' if the value of the object ieee8021XPaePortCapabilities in the same row has the bit 'mkaImplemented' off.

ieee8021XPaePortAnnouncerEnable

1.3.111.2.802.1.1.15.1.1.5.1.17

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Enable or disable the network Announcer function in this PAE. This object will be read only and returns 'false' if the value of the object ieee8021XPaePortCapabilities in the same row has the bit 'announcementsImplemented' off.

ieee8021XPaePortListenerEnable

1.3.111.2.802.1.1.15.1.1.5.1.18

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Enable or disable the network Listener function in this PAE. This object will be read only and returns 'false' if the value of the object ieee8021XPaePortCapabilities in the same row has the bit 'listenerImplemented' off.

ieee8021XPaeEapolGroupMAC

1.3.111.2.802.1.1.15.1.1.5.1.19

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

The destination Group MAC Address used by this PAE when transmitting EAPOL frames.

ieee8021XPacPortTable

1.3.111.2.802.1.1.15.1.1.6

Index: ieee8021XPacPortControlledPortNumber

A table of system level information for each interface supported by PAC. This table will be instantiated if the value of the object ieee8021XPaePortCapabilities in the corresponding entry of the ieee8021XPaePortTable has the bit 'macsecImplemented' off. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XPacPortControlledPortNumber

1.3.111.2.802.1.1.15.1.1.6.1.1

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The index to identify the 'Controlled Port' interface for a PAC.

ieee8021XPacPortAdminPt2PtMAC

1.3.111.2.802.1.1.15.1.1.6.1.2

INTEGER1 = forceTrue2 = forceFalse3 = auto · Integer32

An object to control the service connectivity to at most one other system. The ieee8021XPacPortOperPt2PtMAC indicates operational status of the service connectivity for this PAC. 'forceTrue' : allows only one service connection to the other system. 'forceFalse' : no restriction on the number of service connections to the other systems. 'auto' : means the service connectivity is determined by the service providing entity.

ieee8021XPacPortOperPt2PtMAC

1.3.111.2.802.1.1.15.1.1.6.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

An object to reflect the current service connectivity status. 'true' : means the service connectivity of this PAC Controlled Port provides at most one other system. 'false' : means the service connectivity of this PAC could provide more than one other system.

ieee8021XPaePortLogonTable

1.3.111.2.802.1.1.15.1.2.1

Index: ieee8021XPaePortNumber

A table of system level information for each port to support the Logon Process(es) status information. This table will be instantiated if the object ieee8021XPaePortLogonEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'.

ieee8021XPaePortLogonConnectStatus

1.3.111.2.802.1.1.15.1.2.1.1.1

INTEGER1 = pending2 = unauthenticated3 = authenticated4 = secure · Integer32

The Logon Process sets this variable to one of the following values, to indicate to the CP state machine if, and how, connectivity is to be provided through the Controlled Port : 'pending' : Prevent connectivity by disabling the Controlled Port of this PAE. 'unauthenticated' : Provide unsecured connectivity, enabling the Controlled Port of this PAE. 'authenticated' : Provide unsecured connectivity but with authentication, enabling Controlled Port of this PAE. 'secure' : Provide secure connectivity, using SAKs provided by the KaY (when available) and enabling Controlled Port when those keys are installed and in use.

ieee8021XPaePortPortValid

1.3.111.2.802.1.1.15.1.2.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' if Controlled Port communication is secured as specified by the MACsec.

ieee8021XPaePortSessionTable

1.3.111.2.802.1.1.15.1.2.2

Index: ieee8021XPaeSessionControlledPortNumber

A table of system level information for each port to support Logon Process(es) session information. This table maintains session statistics for its associated Controlled Port, suitable for communication to a RADIUS or other AAA server at the end of a session for accounting purpose. This table will be instantiated if the object ieee8021XPaePortLogonEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'.

ieee8021XPaeSessionControlledPortNumber

1.3.111.2.802.1.1.15.1.2.2.1.1

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The index to identify the 'Controlled Port' interface's session information for a PAE.

ieee8021XPaePortSessionOctetsRx

1.3.111.2.802.1.1.15.1.2.2.1.2

Counter64 (0..18446744073709551615) · Octets

The number of octets received in this session of this PAE. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by the value of ieee8021XPaePortSessionStartTime.

ieee8021XPaePortSessionOctetsTx

1.3.111.2.802.1.1.15.1.2.2.1.3

Counter64 (0..18446744073709551615) · Octets

The number of octets transmitted in this session of this PAE. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by the value of ieee8021XPaePortSessionStartTime.

ieee8021XPaePortSessionPktsRx

1.3.111.2.802.1.1.15.1.2.2.1.4

Counter64 (0..18446744073709551615) · Packets

The number of packets received in this session of this PAE. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by the value of ieee8021XPaePortSessionStartTime.

ieee8021XPaePortSessionPktsTx

1.3.111.2.802.1.1.15.1.2.2.1.5

Counter64 (0..18446744073709551615) · Packets

The number of packets transmitted in this session of this PAE. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by the value of ieee8021XPaePortSessionStartTime.

ieee8021XPaePortSessionId

1.3.111.2.802.1.1.15.1.2.2.1.6

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (3..253) · OCTET STRING · hint 255t

The session identifier for this session of the PAE. A UTF-8 string, uniquely identifying the session within the context of the PAE's system.

ieee8021XPaePortSessionStartTime

1.3.111.2.802.1.1.15.1.2.2.1.7

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The starting time of this session.

ieee8021XPaePortSessionIntervalTime

1.3.111.2.802.1.1.15.1.2.2.1.8

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The duration time of the session has been last.

ieee8021XPaePortSessionTerminate

1.3.111.2.802.1.1.15.1.2.2.1.9

INTEGER1 = macOperFailed2 = sysAccessDisableOrPortInit3 = receiveEapolLogOff4 = eapReauthFailure5 = mkaFailure6 = newSessionBegin7 = notTerminateYet · Integer32

The reason for the session termination, one of the following : 'macOperFailed' : 'Common Port' for this PAE is not operational. 'sysAccessDisableOrPortInit' : The ieee8021XPaeSysAccessControl object is set to 'false' or initialization process of this PAE is invoked. 'receiveEapolLogOff' : The PAE has received EAPOL-Logoff frame. 'eapReauthFailure' : EAP reauthentication has failed. 'mkaFailure' : MKA failure or other MKA termination. 'newSessionBegin' : New session beginning. 'notTerminateYet' : Not Terminated Yet.

ieee8021XPaePortSessionUserName

1.3.111.2.802.1.1.15.1.2.2.1.10

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..253) · OCTET STRING · hint 255t

The session user name for this session in the PAE. A UTF-8 string, representing the identity of the peer Supplicant. If no such information, zero length string will return.

ieee8021XLogonNIDTable

1.3.111.2.802.1.1.15.1.2.3

Index: ieee8021XPaePortNumber

The Logon Process may use Network Identities (NIDs) to manage its use of authentication credentials, cached CAKs, and announcements. This table provides the NID information for Logon Process. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XLogonNIDConnectedNID

1.3.111.2.802.1.1.15.1.2.3.1.1

Ieee8021XPaeNIDThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (1..100) · OCTET STRING

The NID associated with the current connectivity (possibly unauthenticated) provided by the operation of the CP state machine. This object can differ from both the ieee8021XLogonNIDSelectedNID and the ieee8021XLogonNIDRequestedNID objects in the same row if authenticated connectivity (either secure or unsecured) has already been established, and EAP authentication and MKA operation for both of the latter have not met the necessary conditions (as specified by the control variables unauthAllowed and unsecureAllowed).

ieee8021XLogonNIDRequestedNID

1.3.111.2.802.1.1.15.1.2.3.1.2

Ieee8021XPaeNIDOrNullThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile. If this is a zero length value, then the NULL string for NID information is applicable.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (0..100) · OCTET STRING

The NID marked as access requested in announcements, as determined from EAPOL-Start frames. The default of this object is as the configured value of object ieee8021XLogonNIDSelectedNID. This object information provides context for the PAE's EAP Authenticator. If no EAPOL-Start frame has been received since the PAE's 'Common Port' became operational, or the last EAPOL-Start frame received for the port did not contain a requested NID, the object will take on the value of the object ieee8021XLogonNIDSelectedNID in the same row.

ieee8021XLogonNIDSelectedNID

1.3.111.2.802.1.1.15.1.2.3.1.3

Ieee8021XPaeNIDOrNullThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile. If this is a zero length value, then the NULL string for NID information is applicable.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (0..100) · OCTET STRING

The NID currently configured for use by an access 'Controlled Port' when transmitting EAPOL-Start frames. The default of this object is empty string. This object may be either explicitly configured by management or determined by the PAE using NID selection algorithms. If no authentication is in progress, and the current connectivity is terminated and then starts again, ieee8021XLogonNIDConnectedNID will take on the value of ieee8021XLogonNIDRequestedNID (though a PAE NID's election algorithm, if used, can subsequently select another NID).

ieee8021XAuthenticatorTable

1.3.111.2.802.1.1.15.1.3.1

Index: ieee8021XPaePortNumber

A table that contains the configuration objects for the Authenticator PAE associated with each port. This table will be instantiated if the object ieee8021XPaePortAuthenticatorEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XAuthPaeAuthenticate

1.3.111.2.802.1.1.15.1.3.1.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by the PAE authenticator to request authentication, and if this object is 'true', reauthentication is allowed. This object will be 'false' while the PAE authenticator revokes authentication.

ieee8021XAuthPaeAuthenticated

1.3.111.2.802.1.1.15.1.3.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by PACP if the PAE authenticator currently authenticated, and 'false' if the authentication fails or is revoked.

ieee8021XAuthPaeFailed

1.3.111.2.802.1.1.15.1.3.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by PACP if the authentication has failed or has been terminated. The cause could be a failure returned by EAP, either immediately or following a reauthentication, an excessive number of attempts to authenticate (either immediately or upon reauthentication), or the authenticator deasserting authenticate, the object authPaeAuthenticate in the same row is 'false'. The PACP will set the object authPaeAuthenticated false as well as setting the object 'true'.

ieee8021XAuthPaeReAuthEnabled

1.3.111.2.802.1.1.15.1.3.1.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' if PACP should initiate reauthentication periodically, 'false' otherwise.

ieee8021XAuthPaeQuietPeriod

1.3.111.2.802.1.1.15.1.3.1.1.5

Unsigned32 (0..65535) · seconds

This object indicates a waiting period after a failed authentication attempt, before another attempt is permitted.

ieee8021XAuthPaeReauthPeriod

1.3.111.2.802.1.1.15.1.3.1.1.6

Unsigned32 (0..65535) · seconds

This object indicates the time period of the reauthentication to the supplicant.

ieee8021XAuthPaeRetryMax

1.3.111.2.802.1.1.15.1.3.1.1.7

Unsigned32 · times

The maximum number of authentication attempts before failure is reported to the Logon Process, and the authPaeQuietPeriod timer imposed before further attempts are permitted.

ieee8021XAuthPaeRetryCount

1.3.111.2.802.1.1.15.1.3.1.1.8

Gauge32 · times

The count of the number of authentication attempts.

ieee8021XSupplicantTable

1.3.111.2.802.1.1.15.1.4.1

Index: ieee8021XPaePortNumber

A table that contains the configuration objects for the Supplicant PAE associated with each port. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XSuppPaeAuthenticate

1.3.111.2.802.1.1.15.1.4.1.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by the PAE supplicant to request authentication, and if this object is 'true', reauthentication is allowed. This object will be 'false' while the PAE supplicant revokes authentication.

ieee8021XSuppPaeAuthenticated

1.3.111.2.802.1.1.15.1.4.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by PACP if the PAE supplicant currently authenticated, and 'false' if the authentication fails or is revoked.

ieee8021XSuppPaeFailed

1.3.111.2.802.1.1.15.1.4.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' by PACP if the authentication has failed or has been terminated. The cause could be a failure returned by EAP, either immediately or following a reauthentication, an excessive number of attempts to authenticate (either immediately or upon reauthentication), or the supplicant deasserting authenticate, the object ieee8021XSuppPaeAuthenticate in the same row is 'false'. The PACP will set the object ieee8021XSuppPaeAuthenticated false as well as setting the object 'true'.

ieee8021XSuppPaeHelloPeriod

1.3.111.2.802.1.1.15.1.4.1.1.4

Unsigned32 (0..65535) · seconds

This object indicated a waiting time period after a failed authentication attempt, before another attempt is permitted.

ieee8021XSuppPaeRetryMax

1.3.111.2.802.1.1.15.1.4.1.1.5

Unsigned32 · times

The maximum number of authentication attempts before failure is reported to the Logon Process, and the ieee8021XSuppPaeHelloPeriod timer imposed before further attempts are permitted.

ieee8021XSuppPaeRetryCount

1.3.111.2.802.1.1.15.1.4.1.1.6

Gauge32 · times

The count of the number of authentication attempts.

ieee8021XEapolStatsTable

1.3.111.2.802.1.1.15.1.5.1

Index: ieee8021XPaePortNumber

A table in system level contains the EAPOL statistics and diagnostics information supported by PAE.

ieee8021XEapolInvalidFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.1

Counter32 · Packets

The number of invalid EAPOL frames of any type that have been received by this PAE.

ieee8021XEapolEapLengthErrorFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.2

Counter32 · Packets

The number of EAPOL frames that the Packet Body Length does not match a Packet Body that is contained within the octets of the received EAPOL MPDU in this PAE.

ieee8021XEapolAnnouncementFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.3

Counter32 · Packets

The number of EAPOL-Announcement frames that have been received by this PAE.

ieee8021XEapolAnnouncementReqFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.4

Counter32 · Packets

The number of EAPOL-Announcement-Req frames that have been received by this PAE.

ieee8021XEapolPortUnavailableFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.5

Counter32 · Packets

The number of EAPOL frames that are discarded because their processing would require the creation of a virtual port, for which there are inadequate or constrained resources, or an existing virtual port and no such port currently exists. If virtual port is not supported, this object should be always 0.

ieee8021XEapolStartFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.6

Counter32 · Packets

The number of EAPOL-Start frames that have been received by this PAE.

ieee8021XEapolEapFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.7

Counter32 · Packets

The number of EAPOL-EAP frames that have been received by this PAE.

ieee8021XEapolLogoffFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.8

Counter32 · Packets

The number of EAPOL-Logoff frames that have been received by this PAE.

ieee8021XEapolMkNoCknFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.9

Counter32 · Packets

The number of MKPDUs received with MKA not enabled or CKN not recognized in this PAE.

ieee8021XEapolMkInvalidFramesRx

1.3.111.2.802.1.1.15.1.5.1.1.10

Counter32 · Packets

The number of MKPDUs failing in message authentication on receipt process in this PAE.

ieee8021XEapolLastRxFrameVersion

1.3.111.2.802.1.1.15.1.5.1.1.11

Unsigned32

The version of last received EAPOL frame by this PAE.

ieee8021XEapolLastRxFrameSource

1.3.111.2.802.1.1.15.1.5.1.1.12

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

The source MAC address of last received EAPOL frame by this PAE.

ieee8021XEapolSuppEapFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.13

Counter32 · Packets

The number of EAPOL-EAP frames that have been transmitted by the supplicant of this PAE.

ieee8021XEapolLogoffFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.14

Counter32 · Packets

The number of EAPOL-Logoff frames that have been transmitted by this PAE.

ieee8021XEapolAnnouncementFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.15

Counter32 · Packets

The number of EAPOL-Announcement frames that have been transmitted by this PAE.

ieee8021XEapolAnnouncementReqFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.16

Counter32 · Packets

The number of EAPOL-Announcement-Req frames that have been transmitted by this PAE.

ieee8021XEapolStartFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.17

Counter32 · Packets

The number of EAPOL-Start frames that have been transmitted by this PAE.

ieee8021XEapolAuthEapFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.18

Counter32 · Packets

The number of EAPOL-EAP frames that have been transmitted by the authenticator of this PAE.

ieee8021XEapolMkaFramesTx

1.3.111.2.802.1.1.15.1.5.1.1.19

Counter32 · Packets

The number of EAPOL-MKA frames with no CKN information that have been transmitted by this PAE.

ieee8021XKayMkaTable

1.3.111.2.802.1.1.15.1.6.1

Index: ieee8021XPaePortNumber

A table of system level information for each interface supported by the KaY (Key Agreement Entity). This table will be instantiated if the object ieee8021XPaePortKayMkaEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'. The following terms are used to identify roles within the MKA protocol or protocol scenarios and the MIB description : participant : An instance of MKA, transmitting and receiving frames protected by keys derived from a single CAK, and operating with positive intent, obeying the protocol. member: A participant that possesses the CAK that can be used to prove liveness and to obtain membership in the CA under discussion. actor: The participant under discussion, usually in the KaY being described. partners: Participants or members attached to the same LAN as the actor, excluding the actor. principal actor: The actor controlling the PAC or SecY associated with the KaY. Each participant selects the live participant advertising the highest priority as its key server provided that participant has not selected another as its key server or is unwilling to act as the key server. If a key server cannot be selected SAKs are not distributed. In the event of a tie for highest priority key server, the member with the highest priority SCI is chosen. For consistency with other uses of the SCI's MAC Address component as a priority, numerically lower values of the key server priority and SCI are accorded the highest priority. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XKayMkaActive

1.3.111.2.802.1.1.15.1.6.1.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if there is at least one MKA active actor, transmitting MKPDUs

ieee8021XKayMkaAuthenticated

1.3.111.2.802.1.1.15.1.6.1.1.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the principal actor, i.e. the actor controlling the PAC or SecY associated with the KaY, has determined that Controlled Port communication communication should proceed without MACsec.

ieee8021XKayMkaSecured

1.3.111.2.802.1.1.15.1.6.1.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the principal actor has determined that communication should use MACsec.

ieee8021XKayMkaFailed

1.3.111.2.802.1.1.15.1.6.1.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the object ieee8021XKayMkaSecured in the same row is 'false' and MKA Life Time has elapsed since an MKA participant was last created.

ieee8021XKayMkaActorSCI

1.3.111.2.802.1.1.15.1.6.1.1.5

SecySCITextual convention for a Secure Channel Identifier (SCI). Each SC is identified by an SCI comprising a 48-bit MAC Address, allocated to the transmitting system and a 16-bit Port Identifier.Reference: IEEE 802.1AE Clause 7.1.2 and figure 7.7 SIZE (8) · OCTET STRING

The SCI assigned by the system to the port, applies to all the port's MKA actors.

ieee8021XKayMkaActorsPriority

1.3.111.2.802.1.1.15.1.6.1.1.6

Ieee8021XMkaKeyServerPriorityThis textual convention indicates a Key Server priority information. Each MKA participant encodes a Key Server Priority, an 8-bit integer, in each MKPDU. Each participant selects the live participant advertising the highest priority as its Key Server provided that participant has not selected another as its Key Server or is unwilling to act as the Key Server. If a Key Server cannot be selected SAKs are not distributed. In the event of a tie for highest priority Key Server, the member with the highest priority SCI is chosen. For consistency with other uses of the SCI's MAC Address component as a priority, numerically lower values of the Key Server Priority and SCI are accorded the highest priority. The Table 9-2 contains recommendations for the use of priority values for various system roles. Participants that will never act as a Key Server should advertise priority 0xFF.Reference: IEEE 802.1X Clause 9.5, Table 9-2 SIZE (1) · OCTET STRING

The Key Server priority for all the port's MKA actors. Each participant encodes a key server priority, an 8-bit integer, in each MKPDU.

ieee8021XKayMkaKeyServerPriority

1.3.111.2.802.1.1.15.1.6.1.1.7

Ieee8021XMkaKeyServerPriorityThis textual convention indicates a Key Server priority information. Each MKA participant encodes a Key Server Priority, an 8-bit integer, in each MKPDU. Each participant selects the live participant advertising the highest priority as its Key Server provided that participant has not selected another as its Key Server or is unwilling to act as the Key Server. If a Key Server cannot be selected SAKs are not distributed. In the event of a tie for highest priority Key Server, the member with the highest priority SCI is chosen. For consistency with other uses of the SCI's MAC Address component as a priority, numerically lower values of the Key Server Priority and SCI are accorded the highest priority. The Table 9-2 contains recommendations for the use of priority values for various system roles. Participants that will never act as a Key Server should advertise priority 0xFF.Reference: IEEE 802.1X Clause 9.5, Table 9-2 SIZE (1) · OCTET STRING

The priority of the elected Key Server through MKA in the CA.

ieee8021XKayMkaKeyServerSCI

1.3.111.2.802.1.1.15.1.6.1.1.8

SecySCITextual convention for a Secure Channel Identifier (SCI). Each SC is identified by an SCI comprising a 48-bit MAC Address, allocated to the transmitting system and a 16-bit Port Identifier.Reference: IEEE 802.1AE Clause 7.1.2 and figure 7.7 SIZE (8) · OCTET STRING

The SCI for key server for the MKA principal actor. The length of this object is 0 if there is no principal actor, or that actor has no live peers. This object matches the ieee8021XKayMkaActorSCI object in the same row if the actor is the key server.

ieee8021XKayAllowedJoinGroup

1.3.111.2.802.1.1.15.1.6.1.1.9

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the KaY will accept Group CAKs distributed by MKA protocol.

ieee8021XKayAllowedFormGroup

1.3.111.2.802.1.1.15.1.6.1.1.10

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be 'true' if the KaY will attempt to use point-to-point CAKs to distribute a group CAK, if it is the Key Server for the MKA instances for all the point-to-point CAKs.

ieee8021XKayCreateNewGroup

1.3.111.2.802.1.1.15.1.6.1.1.11

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' if a new Group CAK is to be distributed if the KaY is the Key Server for the MKA instances for all the point-to-point CAKs. This object will be set 'false' by the KaY when distribution is complete.

ieee8021XKayMacSecCapability

1.3.111.2.802.1.1.15.1.6.1.1.12

INTEGER0 = noMACsec1 = macSecCapability12 = macSecCapability23 = macSecCapability3 · Integer32

This object indicates whether MACsec is implemented, and if so whether the implementation provides integrity protection only, integrity and integrity with confidentiality, or integrity and integrity with confidentiality with a selectable confidentiality offset of 0, 30, or 50 octets (see IEEE Std 802.1AE). 'noMACsec' : the MACsec is not implemented. 'macSecCapability1' : capable in 'integrity protection without confidentiality'. 'macSecCapability2' : capable in 'integrity protection without confidentiality' and integrity protection and confidentiali with a confidentiality offset 0',. 'macSecCapability3' : capable in 'integrity protection without confidentiality' and integrity protection and confidentiali with a confidentiality offset 0, 30 or 50'.

ieee8021XKayMacSecDesired

1.3.111.2.802.1.1.15.1.6.1.1.13

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object will be set 'true' if the MKA participants desire the use of MACsec to protect frames with this KaY.

ieee8021XKayMacSecProtect

1.3.111.2.802.1.1.15.1.6.1.1.14

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The status of the MACsec protection function for this KaY. 'true' : then the status of the MACsec protection function will be as object secyIfProtectFramesEnable object configured in the IEEE8021-SECY-MIB. 'false' : then the MACsec protection function is disabled by this KaY.

ieee8021XKayMacSecReplayProtect

1.3.111.2.802.1.1.15.1.6.1.1.15

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The status of the MACsec replay protection function for this KaY. 'true' : then the status of the MACsec replay protection function will be as secyIfReplayProtectEnable object configured in the IEEE8021-SECY-MIB. 'false' : then the MACsec replay protection function is disabled by this KaY.

ieee8021XKayMacSecValidate

1.3.111.2.802.1.1.15.1.6.1.1.16

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The status of the MACsec validation function for this KaY. 'true' : then the status of the MACsec validation function will be as secyIfValidateFrames object configured in the IEEE8021-SECY-MIB. 'false' : then the MACsec validation function is enabled but only for checking without filtering out invalid frames by the SecY.

ieee8021XKayMacSecConfidentialityOffset

1.3.111.2.802.1.1.15.1.6.1.1.17

Integer32 (0 | 30 | 50) · bytes

The confidentiality protection offset options for the selected cipher suite in the MACsec. If the cipher suite does not have this capability, the configured value of the object will not apply to the cipher suite.

ieee8021XKayMkaTxKN

1.3.111.2.802.1.1.15.1.6.1.1.18

Ieee8021XMkaKNThis textual convention indicates a Key Number (KN) used in MKA. The MN is a 32-bit integer assigned by that Key Server (sequentially, beginning with 1).Reference: IEEE 802.1X Clause 9.8 (1..2147483648) · Unsigned32 · hint d

The key number assigned by the key server to the SAK currently being used for transmission. This object will be 0 if MACsec is not being used or the key number is not available yet.

ieee8021XKayMkaTxAN

1.3.111.2.802.1.1.15.1.6.1.1.19

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

The AN assigned by the key server for use with the key number for transmission. This row pointer will point to an entry in the secyTxSATable which the secyTxSCEncodingSA object also points to in the IEEE8021-SECY-MIB. If MACsec is not in use or the AN is not identified yet, the value of this object shall be set to the OBJECT IDENTIFIER { 0 0 }.

ieee8021XKayMkaRxKN

1.3.111.2.802.1.1.15.1.6.1.1.20

Ieee8021XMkaKNThis textual convention indicates a Key Number (KN) used in MKA. The MN is a 32-bit integer assigned by that Key Server (sequentially, beginning with 1).Reference: IEEE 802.1X Clause 9.8 (1..2147483648) · Unsigned32 · hint d

The key number assigned by the key server to the oldest SAK currently being used for reception. It is the same as the key number for transmission if a single SAK is currently in use. This object will be 0 if MACsec is not being used or the key number is not available yet.

ieee8021XKayMkaRxAN

1.3.111.2.802.1.1.15.1.6.1.1.21

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

The AN assigned by the key server for use with the key number for reception. It is the same as AN for transmission if a single SAK is currently in use. This row pointer will point to an entry in the secyRxSATable which the secyRxSCCurrentSA object also points to in the IEEE8021-SECY-MIB. If MACsec is not in use or the AN is not identified yet, the value of this object shall be set to the OBJECT IDENTIFIER { 0 0 }.

ieee8021XKayMkaSuspendFor

1.3.111.2.802.1.1.15.1.6.1.1.22

INTEGER (1..120) · Integer32

Set by management to a non-zero number of seconds between 1 and MKA Suspension Limit to initiate a suspension (9.18) of that duration (if the KaY's principal actor is the Key Server) or to request a suspension (otherwise)

ieee8021XKayMkaSuspendOnRequest

1.3.111.2.802.1.1.15.1.6.1.1.23

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The status of the suspendOnRequest function for this KaY. 'true' : then the KaY's principal actor will initiate a suspension if it is the Key Server and another participant has requested a suspension by transmitting a non-zero value of its suspendFor parameter 'false' : then the KaY will not initiate a suspension on request from another participant.

ieee8021XKayMkaSuspendedWhile

1.3.111.2.802.1.1.15.1.6.1.1.24

INTEGER (1..126) · Integer32

Read by management to determine if a suspension is in progress and to discover the remaining duration of that suspension. May be set directly to coordinate in-service upgrades.

ieee8021XKayMkaParticipantTable

1.3.111.2.802.1.1.15.1.6.2

Index: ieee8021XPaePortNumber · ieee8021XKayMkaPartCKN

A table for each MKA participant supported by the KaY MKA entity. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XKayMkaPartCKN

1.3.111.2.802.1.1.15.1.6.2.1.1

Ieee8021XPaeCKNThis textual convention indicates the CAK name to identify the Connectivity Association Key (CAK) which is the root key in the MACsec Key Agreement key hierarchy. All potential members of the CA use the same CKN.Reference: IEEE 802.1X Clause 5.4, Clause 9.3.1, Clause 6.2 SIZE (1..16) · OCTET STRING

The CKN information for this MKA participant.

ieee8021XKayMkaPartKMD

1.3.111.2.802.1.1.15.1.6.2.1.2

Ieee8021XPaeKMDThis textual convention indicates a Key Management Domain (KMD). KMD is a string of UTF-8 characters that names the transmitting authenticator's key management domain.Reference: IEEE 802.1X Clause 12.6 SIZE (0..253) · OCTET STRING

The KMD information for this MKA participant.

ieee8021XKayMkaPartNID

1.3.111.2.802.1.1.15.1.6.2.1.3

Ieee8021XPaeNIDThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (1..100) · OCTET STRING

The NID information for this MKA participant.

ieee8021XKayMkaPartCached

1.3.111.2.802.1.1.15.1.6.2.1.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' by the KaY if the participant's parameters are cached. If this object is 'true', this object can be set 'false' cleared by management to remove the participant's parameters from the cache.

ieee8021XKayMkaPartActive

1.3.111.2.802.1.1.15.1.6.2.1.5

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' if the participant is active, i.e. is currently transmitting periodic MKPDUs.

ieee8021XKayMkaPartRetain

1.3.111.2.802.1.1.15.1.6.2.1.6

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' to retain the participant in the cache, even if the KaY would normally remove it (due to lack of use for example)

ieee8021XKayMkaPartActivateControl

1.3.111.2.802.1.1.15.1.6.2.1.7

INTEGER1 = default2 = disabled3 = onOperUp4 = always · Integer32

This object is for controlling the participant's behavior when the participant is activated. 'default' : the participant is from cached entries created by the KaY as part of normal operation, without explicit management, and is activated according to the implementation dependent policies of the KaY. 'disabled' : the participant allows the cache information to be retained, but disabled for indefinite period. 'onOperUp' : causing the participant to be activated when the PAE's 'Uncontrolled Port' becomes operational and when the PAE resumes following suspension. 'always' : causing the participant to remain active all the time, even in the continued absence of partners. If the object changed to disabled(1) or onOperUp(3), the participant ceases operation immediately and receipt of MKPDUs with a matching CKN during a subsequent period of twice MKA lifetime will not cause the participant to become active once more.

ieee8021XKayMkaPartPrincipal

1.3.111.2.802.1.1.15.1.6.2.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object is set 'true' if the participant is currently the principal actor.

ieee8021XKayMkaPartDistCKN

1.3.111.2.802.1.1.15.1.6.2.1.9

Ieee8021XPaeCKNOrNullThis textual convention indicates the CAK name to identify the Connectivity Association Key (CAK) which is the root key in the MACsec Key Agreement key hierarchy. All potential members of the CA use the same CKN. If this is a zero length value, then the NULL string means CKN information is applicable.Reference: IEEE 802.1X Clause 5.4, Clause 9.3.1, Clause 6.2 SIZE (0..16) · OCTET STRING

The CKN for the last CAK distributed either by the actor or one of its partners. Empty string for this object will be provided if this participant has not been used to distribute a CAK or the participant is not active, i.e. the object ieee8021XKayMkaPartActive in the same row is 'false'.

ieee8021XKayMkaPartRowStatus

1.3.111.2.802.1.1.15.1.6.2.1.10

RowStatus1 = active2 = notInService3 = notReady4 = createAndGo5 = createAndWait6 = destroyThe RowStatus textual convention is used to manage the creation and deletion of conceptual rows, and is used as the value of the SYNTAX clause for the status column of a conceptual row (as described in Section 7.7.1 of [2].) The status column has six defined values: - `active', which indicates that the conceptual row is available for use by the managed device; - `notInService', which indicates that the conceptual row exists in the agent, but is unavailable for use by the managed device (see NOTE below); 'notInService' has no implication regarding the internal consistency of the row, availability of resources, or consistency with the current state of the managed device; - `notReady', which indicates that the conceptual row exists in the agent, but is missing information necessary in order to be available for use by the managed device (i.e., one or more required columns in the conceptual row have not been instanciated); - `createAndGo', which is supplied by a management station wishing to create a new instance of a conceptual row and to have its status automatically set to active, making it available for use by the managed device; - `createAndWait', which is supplied by a management station wishing to create a new instance of a conceptual row (but not make it available for use by the managed device); and, - `destroy', which is supplied by a management station wishing to delete all of the instances associated with an existing conceptual row. Whereas five of the six values (all except `notReady') may be specified in a management protocol set operation, only three values will be returned in response to a management protocol retrieval operation: `notReady', `notInService' or `active'. That is, when queried, an existing conceptual row has only three states: it is either available for use by the managed device (the status column has value `active'); it is not available for use by the managed device, though the agent has sufficient information to attempt to make it so (the status column has value `notInService'); or, it is not available for use by the managed device, and an attempt to make it so would fail because the agent has insufficient information (the state column has value `notReady'). NOTE WELL This textual convention may be used for a MIB table, irrespective of whether the values of that table's conceptual rows are able to be modified while it is active, or whether its conceptual rows must be taken out of service in order to be modified. That is, it is the responsibility of the DESCRIPTION clause of the status column to specify whether the status column must not be `active' in order for the value of some other column of the same conceptual row to be modified. If such a specification is made, affected columns may be changed by an SNMP set PDU if the RowStatus would not be equal to `active' either immediately before or after processing the PDU. In other words, if the PDU also contained a varbind that would change the RowStatus value, the column in question may be changed if the RowStatus was not equal to `active' as the PDU was received, or if the varbind sets the status to a value other than 'active'. Also note that whenever any elements of a row exist, the RowStatus column must also exist. To summarize the effect of having a conceptual row with a status column having a SYNTAX clause value of RowStatus, consider the following state diagram: STATE +--------------+-----------+-------------+------------- | A | B | C | D | |status col.|status column| |status column | is | is |status column ACTION |does not exist| notReady | notInService| is active --------------+--------------+-----------+-------------+------------- set status |noError ->D|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndGo |inconsistent- | | | | Value| | | --------------+--------------+-----------+-------------+------------- set status |noError see 1|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndWait |wrongValue | | | --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError column to | Value| entValue| | active | | | | | | or | | | | | | | |see 2 ->D|see 8 ->D| ->D --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError ->C column to | Value| entValue| | notInService | | | | | | or | | or | | | | | |see 3 ->C| ->C|see 6 --------------+--------------+-----------+-------------+------------- set status |noError |noError |noError |noError ->A column to | | | | or destroy | ->A| ->A| ->A|see 7 --------------+--------------+-----------+-------------+------------- set any other |see 4 |noError |noError |see 5 column to some| | | | value | | see 1| ->C| ->D --------------+--------------+-----------+-------------+------------- (1) goto B or C, depending on information available to the agent. (2) if other variable bindings included in the same PDU, provide values for all columns which are missing but required, and all columns have acceptable values, then return noError and goto D. (3) if other variable bindings included in the same PDU, provide legal values for all columns which are missing but required, then return noError and goto C. (4) at the discretion of the agent, the return value may be either: inconsistentName: because the agent does not choose to create such an instance when the corresponding RowStatus instance does not exist, or inconsistentValue: if the supplied value is inconsistent with the state of some other MIB object's value, or noError: because the agent chooses to create the instance. If noError is returned, then the instance of the status column must also be created, and the new state is B or C, depending on the information available to the agent. If inconsistentName or inconsistentValue is returned, the row remains in state A. (5) depending on the MIB definition for the column/table, either noError or inconsistentValue may be returned. (6) the return value can indicate one of the following errors: wrongValue: because the agent does not support notInService (e.g., an agent which does not support createAndWait), or inconsistentValue: because the agent is unable to take the row out of service at this time, perhaps because it is in use and cannot be de-activated. (7) the return value can indicate the following error: inconsistentValue: because the agent is unable to remove the row at this time, perhaps because it is in use and cannot be de-activated. (8) the transition to D can fail, e.g., if the values of the conceptual row are inconsistent, then the error code would be inconsistentValue. NOTE: Other processing of (this and other varbinds of) the set request may result in a response other than noError being returned, e.g., wrongValue, noCreation, etc. Conceptual Row Creation There are four potential interactions when creating a conceptual row: selecting an instance-identifier which is not in use; creating the conceptual row; initializing any objects for which the agent does not supply a default; and, making the conceptual row available for use by the managed device. Interaction 1: Selecting an Instance-Identifier The algorithm used to select an instance-identifier varies for each conceptual row. In some cases, the instance- identifier is semantically significant, e.g., the destination address of a route, and a management station selects the instance-identifier according to the semantics. In other cases, the instance-identifier is used solely to distinguish conceptual rows, and a management station without specific knowledge of the conceptual row might examine the instances present in order to determine an unused instance-identifier. (This approach may be used, but it is often highly sub-optimal; however, it is also a questionable practice for a naive management station to attempt conceptual row creation.) Alternately, the MIB module which defines the conceptual row might provide one or more objects which provide assistance in determining an unused instance-identifier. For example, if the conceptual row is indexed by an integer-value, then an object having an integer-valued SYNTAX clause might be defined for such a purpose, allowing a management station to issue a management protocol retrieval operation. In order to avoid unnecessary collisions between competing management stations, `adjacent' retrievals of this object should be different. Finally, the management station could select a pseudo-random number to use as the index. In the event that this index was already in use and an inconsistentValue was returned in response to the management protocol set operation, the management station should simply select a new pseudo-random number and retry the operation. A MIB designer should choose between the two latter algorithms based on the size of the table (and therefore the efficiency of each algorithm). For tables in which a large number of entries are expected, it is recommended that a MIB object be defined that returns an acceptable index for creation. For tables with small numbers of entries, it is recommended that the latter pseudo-random index mechanism be used. Interaction 2: Creating the Conceptual Row Once an unused instance-identifier has been selected, the management station determines if it wishes to create and activate the conceptual row in one transaction or in a negotiated set of interactions. Interaction 2a: Creating and Activating the Conceptual Row The management station must first determine the column requirements, i.e., it must determine those columns for which it must or must not provide values. Depending on the complexity of the table and the management station's knowledge of the agent's capabilities, this determination can be made locally by the management station. Alternately, the management station issues a management protocol get operation to examine all columns in the conceptual row that it wishes to create. In response, for each column, there are three possible outcomes: - a value is returned, indicating that some other management station has already created this conceptual row. We return to interaction 1. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it should supply a value for this column when the conceptual row is to be created. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. Once the column requirements have been determined, a management protocol set operation is accordingly issued. This operation also sets the new instance of the status column to `createAndGo'. When the agent processes the set operation, it verifies that it has sufficient information to make the conceptual row available for use by the managed device. The information available to the agent is provided by two sources: the management protocol set operation which creates the conceptual row, and, implementation-specific defaults supplied by the agent (note that an agent must provide implementation-specific defaults for at least those objects which it implements as read-only). If there is sufficient information available, then the conceptual row is created, a `noError' response is returned, the status column is set to `active', and no further interactions are necessary (i.e., interactions 3 and 4 are skipped). If there is insufficient information, then the conceptual row is not created, and the set operation fails with an error of `inconsistentValue'. On this error, the management station can issue a management protocol retrieval operation to determine if this was because it failed to specify a value for a required column, or, because the selected instance of the status column already existed. In the latter case, we return to interaction 1. In the former case, the management station can re-issue the set operation with the additional information, or begin interaction 2 again using `createAndWait' in order to negotiate creation of the conceptual row. NOTE WELL Regardless of the method used to determine the column requirements, it is possible that the management station might deem a column necessary when, in fact, the agent will not allow that particular columnar instance to be created or written. In this case, the management protocol set operation will fail with an error such as `noCreation' or `notWritable'. In this case, the management station decides whether it needs to be able to set a value for that particular columnar instance. If not, the management station re-issues the management protocol set operation, but without setting a value for that particular columnar instance; otherwise, the management station aborts the row creation algorithm. Interaction 2b: Negotiating the Creation of the Conceptual Row The management station issues a management protocol set operation which sets the desired instance of the status column to `createAndWait'. If the agent is unwilling to process a request of this sort, the set operation fails with an error of `wrongValue'. (As a consequence, such an agent must be prepared to accept a single management protocol set operation, i.e., interaction 2a above, containing all of the columns indicated by its column requirements.) Otherwise, the conceptual row is created, a `noError' response is returned, and the status column is immediately set to either `notInService' or `notReady', depending on whether it has sufficient information to (attempt to) make the conceptual row available for use by the managed device. If there is sufficient information available, then the status column is set to `notInService'; otherwise, if there is insufficient information, then the status column is set to `notReady'. Regardless, we proceed to interaction 3. Interaction 3: Initializing non-defaulted Objects The management station must now determine the column requirements. It issues a management protocol get operation to examine all columns in the created conceptual row. In the response, for each column, there are three possible outcomes: - a value is returned, indicating that the agent implements the object-type associated with this column and had sufficient information to provide a value. For those columns to which the agent provides read-create access (and for which the agent allows their values to be changed after their creation), a value return tells the management station that it may issue additional management protocol set operations, if it desires, in order to change the value associated with this column. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. However, the agent does not have sufficient information to provide a value, and until a value is provided, the conceptual row may not be made available for use by the managed device. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it must issue additional management protocol set operations, in order to provide a value associated with this column. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. If the value associated with the status column is `notReady', then the management station must first deal with all `noSuchInstance' columns, if any. Having done so, the value of the status column becomes `notInService', and we proceed to interaction 4. Interaction 4: Making the Conceptual Row Available Once the management station is satisfied with the values associated with the columns of the conceptual row, it issues a management protocol set operation to set the status column to `active'. If the agent has sufficient information to make the conceptual row available for use by the managed device, the management protocol set operation succeeds (a `noError' response is returned). Otherwise, the management protocol set operation fails with an error of `inconsistentValue'. NOTE WELL A conceptual row having a status column with value `notInService' or `notReady' is unavailable to the managed device. As such, it is possible for the managed device to create its own instances during the time between the management protocol set operation which sets the status column to `createAndWait' and the management protocol set operation which sets the status column to `active'. In this case, when the management protocol set operation is issued to set the status column to `active', the values held in the agent supersede those used by the managed device. If the management station is prevented from setting the status column to `active' (e.g., due to management station or network failure) the conceptual row will be left in the `notInService' or `notReady' state, consuming resources indefinitely. The agent must detect conceptual rows that have been in either state for an abnormally long period of time and remove them. It is the responsibility of the DESCRIPTION clause of the status column to indicate what an abnormally long period of time would be. This period of time should be long enough to allow for human response time (including `think time') between the creation of the conceptual row and the setting of the status to `active'. In the absence of such information in the DESCRIPTION clause, it is suggested that this period be approximately 5 minutes in length. This removal action applies not only to newly-created rows, but also to previously active rows which are set to, and left in, the notInService state for a prolonged period exceeding that which is considered normal for such a conceptual row. Conceptual Row Suspension When a conceptual row is `active', the management station may issue a management protocol set operation which sets the instance of the status column to `notInService'. If the agent is unwilling to do so, the set operation fails with an error of `wrongValue' or `inconsistentValue'. Otherwise, the conceptual row is taken out of service, and a `noError' response is returned. It is the responsibility of the DESCRIPTION clause of the status column to indicate under what circumstances the status column should be taken out of service (e.g., in order for the value of some other column of the same conceptual row to be modified). Conceptual Row Deletion For deletion of conceptual rows, a management protocol set operation is issued which sets the instance of the status column to `destroy'. This request may be made regardless of the current value of the status column (e.g., it is possible to delete conceptual rows which are either `notReady', `notInService' or `active'.) If the operation succeeds, then all instances associated with the conceptual row are immediately removed. · Integer32

The object to create the parameters for the supported participant information in the system. If the participant information is from downloaded policies, this object is 'active'.

ieee8021XKayMkaPeerListTable

1.3.111.2.802.1.1.15.1.6.3

Index: ieee8021XPaePortNumber · ieee8021XKayMkaPartCKN · ieee8021XKayMkaPeerListMI

A table containing the lists of Live Peers and Potential Peers, for all MKA instances for which the KaY is active.

ieee8021XKayMkaPeerListMI

1.3.111.2.802.1.1.15.1.6.3.1.1

Ieee8021XMkaMIThis textual convention indicates a Member Identifier (MI). The MI is a 96-bit random value chosen when the MKA Instance begins, used with a 32-bit MN to protect against replay attacks and to record liveliness in the Live Peer List or potential liveliness in the Potential Peer List. If the MN wraps, a new random MI value is chosen and the MN begins again at 1.Reference: IEEE 802.1X Clause 9.4.2 SIZE (12) · OCTET STRING

The peer entry's MI information in the peer list of this active participant in MKA protocol.

ieee8021XKayMkaPeerListMN

1.3.111.2.802.1.1.15.1.6.3.1.2

Ieee8021XMkaMNThis textual convention indicates a Member Number (MN). The MN is a 32-bit value which begins at 1 and increases for each MKPDU transmitted. It is used with the MI to protect against replay attacks and to record liveliness in the Live Peers List or potential liveliness in the Potential Peer List. If the MN wraps, a new random MI value is chosen and the MN begins again at a value of 1.Reference: IEEE 802.1X Clause 9.4.2 (1..2147483648) · Unsigned32 · hint d

The peer entry's latest MN information in the peer list of this active participant in MKA protocol.

ieee8021XKayMkaPeerListType

1.3.111.2.802.1.1.15.1.6.3.1.3

INTEGER1 = livePeerList2 = potentialPeerList · Integer32

The peer entry's type in the peer list of this active participant in MKA protocol. 'livePeerList' : the peer entry is in the Live Peer List. 'potentialPeerList' : the peer entry is in the Potential Peer List.

ieee8021XKayMkaPeerListSCI

1.3.111.2.802.1.1.15.1.6.3.1.4

SecySCITextual convention for a Secure Channel Identifier (SCI). Each SC is identified by an SCI comprising a 48-bit MAC Address, allocated to the transmitting system and a 16-bit Port Identifier.Reference: IEEE 802.1AE Clause 7.1.2 and figure 7.7 SIZE (8) · OCTET STRING

The SCI information of the peer entry in the peer list of this active participant in MKA protocol.

ieee8021XNidConfigTable

1.3.111.2.802.1.1.15.1.7.1

Index: IMPLIED ieee8021XNidNID

A table that contains the configuration objects for the network announcement information for the Logon Process. The detail operation of the Logon Process can vary depending on the port-based network access control applications, and on the capabilities supported by that implementation including, for example, network discovery and roaming. This table specifies control variables that facilitate behaviors that are potentially useful in a range of applications. Implementations may use and augment the variables specified, or may use variables specific to the implementation. For the writeable objects in this table, the configured value shall be stored in persistent memory and remain unchanged across a re-initialization of the management system of the entity.

ieee8021XNidNID

1.3.111.2.802.1.1.15.1.7.1.1.1

Ieee8021XPaeNIDThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (1..100) · OCTET STRING

The network identifier to identify NID configuration in the PAE.

ieee8021XNidUseEap

1.3.111.2.802.1.1.15.1.7.1.1.2

INTEGER1 = never2 = immediate3 = mkaFail · Integer32

Determines when the Logon Process will initiate EAP, if the Supplicant and or Authenticator are enabled, and takes one of the following values: 'never' : Never. 'immediate' : Immediately, concurrently with the use of MKA with any cached CAK(s). 'mkaFail' : Not until MKA has failed, if a prior CAK has been cached.

ieee8021XNidUnauthAllowed

1.3.111.2.802.1.1.15.1.7.1.1.3

INTEGER1 = never2 = immediate3 = authFail · Integer32

Determines when the Logon Process will tell the CP state machine to provide unauthenticated connectivity, and takes one of the following values: 'never' : Never. 'immediate' : Immediately, independently of any current or future attempts to authenticate using the PAE or MKA. 'authFail' : Not until an attempt has been made to authenticate using EAP, unless neither the Supplicant nor the Authenticator is enabled, and MKA has attempted to use any cached CAK (unless the KaY is not enabled).

ieee8021XNidUnsecuredAllowed

1.3.111.2.802.1.1.15.1.7.1.1.4

INTEGER1 = never2 = immediate3 = mkaFail4 = mkaServer · Integer32

Determines when the Logon Process will tell the CP state machine to provide authenticated but unsecured connectivity, takes one of the following values: 'never' : Never. 'immediate' : Immediately, to provide connectivity concurrently with the use of MKA with any CAK acquired through EAP. 'mkaFail' : Not until MKA has failed, or is not enabled. 'mkaServer' : Only if directed by the MKA server.

ieee8021XNidUnauthenticatedAccess

1.3.111.2.802.1.1.15.1.7.1.1.5

Ieee8021XPaeNIDUnauthenticatedStatus0 = noAccess1 = fallbackAccess2 = limitedAccess3 = openAccessThis textual convention indicates the access capabilities of the port's clients without authentication. 'noAccess' : Other than to authentication services (see Ieee8021XPaeNIDCapabilites information. 'fallbackAccess' : Limited access can be provided after authentication failure. 'limitedAccess' : Immediate limited access is available without authentication. 'openAccess' : Immediate access is available without authentication.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · Integer32

The configured access capability of the port's clients without authentication in this NID.

ieee8021XNidAccessCapabilities

1.3.111.2.802.1.1.15.1.7.1.1.6

Ieee8021XPaeNIDCapabilitesThis textual convention indicates the combinations of authentication and protection capabilities supported for a NID. Any set of these combinations can be supported.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · BITS

The authentication and protection capabilities supported for the NID.

ieee8021XNidKMD

1.3.111.2.802.1.1.15.1.7.1.1.7

Ieee8021XPaeKMDThis textual convention indicates a Key Management Domain (KMD). KMD is a string of UTF-8 characters that names the transmitting authenticator's key management domain.Reference: IEEE 802.1X Clause 12.6 SIZE (0..253) · OCTET STRING

The configured KMD information for this NID.

ieee8021XNidRowStatus

1.3.111.2.802.1.1.15.1.7.1.1.8

RowStatus1 = active2 = notInService3 = notReady4 = createAndGo5 = createAndWait6 = destroyThe RowStatus textual convention is used to manage the creation and deletion of conceptual rows, and is used as the value of the SYNTAX clause for the status column of a conceptual row (as described in Section 7.7.1 of [2].) The status column has six defined values: - `active', which indicates that the conceptual row is available for use by the managed device; - `notInService', which indicates that the conceptual row exists in the agent, but is unavailable for use by the managed device (see NOTE below); 'notInService' has no implication regarding the internal consistency of the row, availability of resources, or consistency with the current state of the managed device; - `notReady', which indicates that the conceptual row exists in the agent, but is missing information necessary in order to be available for use by the managed device (i.e., one or more required columns in the conceptual row have not been instanciated); - `createAndGo', which is supplied by a management station wishing to create a new instance of a conceptual row and to have its status automatically set to active, making it available for use by the managed device; - `createAndWait', which is supplied by a management station wishing to create a new instance of a conceptual row (but not make it available for use by the managed device); and, - `destroy', which is supplied by a management station wishing to delete all of the instances associated with an existing conceptual row. Whereas five of the six values (all except `notReady') may be specified in a management protocol set operation, only three values will be returned in response to a management protocol retrieval operation: `notReady', `notInService' or `active'. That is, when queried, an existing conceptual row has only three states: it is either available for use by the managed device (the status column has value `active'); it is not available for use by the managed device, though the agent has sufficient information to attempt to make it so (the status column has value `notInService'); or, it is not available for use by the managed device, and an attempt to make it so would fail because the agent has insufficient information (the state column has value `notReady'). NOTE WELL This textual convention may be used for a MIB table, irrespective of whether the values of that table's conceptual rows are able to be modified while it is active, or whether its conceptual rows must be taken out of service in order to be modified. That is, it is the responsibility of the DESCRIPTION clause of the status column to specify whether the status column must not be `active' in order for the value of some other column of the same conceptual row to be modified. If such a specification is made, affected columns may be changed by an SNMP set PDU if the RowStatus would not be equal to `active' either immediately before or after processing the PDU. In other words, if the PDU also contained a varbind that would change the RowStatus value, the column in question may be changed if the RowStatus was not equal to `active' as the PDU was received, or if the varbind sets the status to a value other than 'active'. Also note that whenever any elements of a row exist, the RowStatus column must also exist. To summarize the effect of having a conceptual row with a status column having a SYNTAX clause value of RowStatus, consider the following state diagram: STATE +--------------+-----------+-------------+------------- | A | B | C | D | |status col.|status column| |status column | is | is |status column ACTION |does not exist| notReady | notInService| is active --------------+--------------+-----------+-------------+------------- set status |noError ->D|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndGo |inconsistent- | | | | Value| | | --------------+--------------+-----------+-------------+------------- set status |noError see 1|inconsist- |inconsistent-|inconsistent- column to | or | entValue| Value| Value createAndWait |wrongValue | | | --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError column to | Value| entValue| | active | | | | | | or | | | | | | | |see 2 ->D|see 8 ->D| ->D --------------+--------------+-----------+-------------+------------- set status |inconsistent- |inconsist- |noError |noError ->C column to | Value| entValue| | notInService | | | | | | or | | or | | | | | |see 3 ->C| ->C|see 6 --------------+--------------+-----------+-------------+------------- set status |noError |noError |noError |noError ->A column to | | | | or destroy | ->A| ->A| ->A|see 7 --------------+--------------+-----------+-------------+------------- set any other |see 4 |noError |noError |see 5 column to some| | | | value | | see 1| ->C| ->D --------------+--------------+-----------+-------------+------------- (1) goto B or C, depending on information available to the agent. (2) if other variable bindings included in the same PDU, provide values for all columns which are missing but required, and all columns have acceptable values, then return noError and goto D. (3) if other variable bindings included in the same PDU, provide legal values for all columns which are missing but required, then return noError and goto C. (4) at the discretion of the agent, the return value may be either: inconsistentName: because the agent does not choose to create such an instance when the corresponding RowStatus instance does not exist, or inconsistentValue: if the supplied value is inconsistent with the state of some other MIB object's value, or noError: because the agent chooses to create the instance. If noError is returned, then the instance of the status column must also be created, and the new state is B or C, depending on the information available to the agent. If inconsistentName or inconsistentValue is returned, the row remains in state A. (5) depending on the MIB definition for the column/table, either noError or inconsistentValue may be returned. (6) the return value can indicate one of the following errors: wrongValue: because the agent does not support notInService (e.g., an agent which does not support createAndWait), or inconsistentValue: because the agent is unable to take the row out of service at this time, perhaps because it is in use and cannot be de-activated. (7) the return value can indicate the following error: inconsistentValue: because the agent is unable to remove the row at this time, perhaps because it is in use and cannot be de-activated. (8) the transition to D can fail, e.g., if the values of the conceptual row are inconsistent, then the error code would be inconsistentValue. NOTE: Other processing of (this and other varbinds of) the set request may result in a response other than noError being returned, e.g., wrongValue, noCreation, etc. Conceptual Row Creation There are four potential interactions when creating a conceptual row: selecting an instance-identifier which is not in use; creating the conceptual row; initializing any objects for which the agent does not supply a default; and, making the conceptual row available for use by the managed device. Interaction 1: Selecting an Instance-Identifier The algorithm used to select an instance-identifier varies for each conceptual row. In some cases, the instance- identifier is semantically significant, e.g., the destination address of a route, and a management station selects the instance-identifier according to the semantics. In other cases, the instance-identifier is used solely to distinguish conceptual rows, and a management station without specific knowledge of the conceptual row might examine the instances present in order to determine an unused instance-identifier. (This approach may be used, but it is often highly sub-optimal; however, it is also a questionable practice for a naive management station to attempt conceptual row creation.) Alternately, the MIB module which defines the conceptual row might provide one or more objects which provide assistance in determining an unused instance-identifier. For example, if the conceptual row is indexed by an integer-value, then an object having an integer-valued SYNTAX clause might be defined for such a purpose, allowing a management station to issue a management protocol retrieval operation. In order to avoid unnecessary collisions between competing management stations, `adjacent' retrievals of this object should be different. Finally, the management station could select a pseudo-random number to use as the index. In the event that this index was already in use and an inconsistentValue was returned in response to the management protocol set operation, the management station should simply select a new pseudo-random number and retry the operation. A MIB designer should choose between the two latter algorithms based on the size of the table (and therefore the efficiency of each algorithm). For tables in which a large number of entries are expected, it is recommended that a MIB object be defined that returns an acceptable index for creation. For tables with small numbers of entries, it is recommended that the latter pseudo-random index mechanism be used. Interaction 2: Creating the Conceptual Row Once an unused instance-identifier has been selected, the management station determines if it wishes to create and activate the conceptual row in one transaction or in a negotiated set of interactions. Interaction 2a: Creating and Activating the Conceptual Row The management station must first determine the column requirements, i.e., it must determine those columns for which it must or must not provide values. Depending on the complexity of the table and the management station's knowledge of the agent's capabilities, this determination can be made locally by the management station. Alternately, the management station issues a management protocol get operation to examine all columns in the conceptual row that it wishes to create. In response, for each column, there are three possible outcomes: - a value is returned, indicating that some other management station has already created this conceptual row. We return to interaction 1. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it should supply a value for this column when the conceptual row is to be created. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. Once the column requirements have been determined, a management protocol set operation is accordingly issued. This operation also sets the new instance of the status column to `createAndGo'. When the agent processes the set operation, it verifies that it has sufficient information to make the conceptual row available for use by the managed device. The information available to the agent is provided by two sources: the management protocol set operation which creates the conceptual row, and, implementation-specific defaults supplied by the agent (note that an agent must provide implementation-specific defaults for at least those objects which it implements as read-only). If there is sufficient information available, then the conceptual row is created, a `noError' response is returned, the status column is set to `active', and no further interactions are necessary (i.e., interactions 3 and 4 are skipped). If there is insufficient information, then the conceptual row is not created, and the set operation fails with an error of `inconsistentValue'. On this error, the management station can issue a management protocol retrieval operation to determine if this was because it failed to specify a value for a required column, or, because the selected instance of the status column already existed. In the latter case, we return to interaction 1. In the former case, the management station can re-issue the set operation with the additional information, or begin interaction 2 again using `createAndWait' in order to negotiate creation of the conceptual row. NOTE WELL Regardless of the method used to determine the column requirements, it is possible that the management station might deem a column necessary when, in fact, the agent will not allow that particular columnar instance to be created or written. In this case, the management protocol set operation will fail with an error such as `noCreation' or `notWritable'. In this case, the management station decides whether it needs to be able to set a value for that particular columnar instance. If not, the management station re-issues the management protocol set operation, but without setting a value for that particular columnar instance; otherwise, the management station aborts the row creation algorithm. Interaction 2b: Negotiating the Creation of the Conceptual Row The management station issues a management protocol set operation which sets the desired instance of the status column to `createAndWait'. If the agent is unwilling to process a request of this sort, the set operation fails with an error of `wrongValue'. (As a consequence, such an agent must be prepared to accept a single management protocol set operation, i.e., interaction 2a above, containing all of the columns indicated by its column requirements.) Otherwise, the conceptual row is created, a `noError' response is returned, and the status column is immediately set to either `notInService' or `notReady', depending on whether it has sufficient information to (attempt to) make the conceptual row available for use by the managed device. If there is sufficient information available, then the status column is set to `notInService'; otherwise, if there is insufficient information, then the status column is set to `notReady'. Regardless, we proceed to interaction 3. Interaction 3: Initializing non-defaulted Objects The management station must now determine the column requirements. It issues a management protocol get operation to examine all columns in the created conceptual row. In the response, for each column, there are three possible outcomes: - a value is returned, indicating that the agent implements the object-type associated with this column and had sufficient information to provide a value. For those columns to which the agent provides read-create access (and for which the agent allows their values to be changed after their creation), a value return tells the management station that it may issue additional management protocol set operations, if it desires, in order to change the value associated with this column. - the exception `noSuchInstance' is returned, indicating that the agent implements the object-type associated with this column, and that this column in at least one conceptual row would be accessible in the MIB view used by the retrieval were it to exist. However, the agent does not have sufficient information to provide a value, and until a value is provided, the conceptual row may not be made available for use by the managed device. For those columns to which the agent provides read-create access, the `noSuchInstance' exception tells the management station that it must issue additional management protocol set operations, in order to provide a value associated with this column. - the exception `noSuchObject' is returned, indicating that the agent does not implement the object-type associated with this column or that there is no conceptual row for which this column would be accessible in the MIB view used by the retrieval. As such, the management station can not issue any management protocol set operations to create an instance of this column. If the value associated with the status column is `notReady', then the management station must first deal with all `noSuchInstance' columns, if any. Having done so, the value of the status column becomes `notInService', and we proceed to interaction 4. Interaction 4: Making the Conceptual Row Available Once the management station is satisfied with the values associated with the columns of the conceptual row, it issues a management protocol set operation to set the status column to `active'. If the agent has sufficient information to make the conceptual row available for use by the managed device, the management protocol set operation succeeds (a `noError' response is returned). Otherwise, the management protocol set operation fails with an error of `inconsistentValue'. NOTE WELL A conceptual row having a status column with value `notInService' or `notReady' is unavailable to the managed device. As such, it is possible for the managed device to create its own instances during the time between the management protocol set operation which sets the status column to `createAndWait' and the management protocol set operation which sets the status column to `active'. In this case, when the management protocol set operation is issued to set the status column to `active', the values held in the agent supersede those used by the managed device. If the management station is prevented from setting the status column to `active' (e.g., due to management station or network failure) the conceptual row will be left in the `notInService' or `notReady' state, consuming resources indefinitely. The agent must detect conceptual rows that have been in either state for an abnormally long period of time and remove them. It is the responsibility of the DESCRIPTION clause of the status column to indicate what an abnormally long period of time would be. This period of time should be long enough to allow for human response time (including `think time') between the creation of the conceptual row and the setting of the status to `active'. In the absence of such information in the DESCRIPTION clause, it is suggested that this period be approximately 5 minutes in length. This removal action applies not only to newly-created rows, but also to previously active rows which are set to, and left in, the notInService state for a prolonged period exceeding that which is considered normal for such a conceptual row. Conceptual Row Suspension When a conceptual row is `active', the management station may issue a management protocol set operation which sets the instance of the status column to `notInService'. If the agent is unwilling to do so, the set operation fails with an error of `wrongValue' or `inconsistentValue'. Otherwise, the conceptual row is taken out of service, and a `noError' response is returned. It is the responsibility of the DESCRIPTION clause of the status column to indicate under what circumstances the status column should be taken out of service (e.g., in order for the value of some other column of the same conceptual row to be modified). Conceptual Row Deletion For deletion of conceptual rows, a management protocol set operation is issued which sets the instance of the status column to `destroy'. This request may be made regardless of the current value of the status column (e.g., it is possible to delete conceptual rows which are either `notReady', `notInService' or `active'.) If the operation succeeds, then all instances associated with the conceptual row are immediately removed. · Integer32

The object to create the parameters for the supported Network Announcement information in the system. If the Network Announcement information of the entry is from downloaded policies, this object is 'active'.

ieee8021XAnnounceTable

1.3.111.2.802.1.1.15.1.7.2

Index: ieee8021XPaePortNumber · IMPLIED ieee8021XAnnounceNID

A table contains the status information that the Announcers announce in the network announcement of the PAE system. This table will be instantiated if the object ieee8021XPaePortAnnouncerEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'.

ieee8021XAnnounceNID

1.3.111.2.802.1.1.15.1.7.2.1.1

Ieee8021XPaeNIDThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (1..100) · OCTET STRING

The NID information to identify a transmitting network announcement for the PAE.

ieee8021XAnnounceAccessStatus

1.3.111.2.802.1.1.15.1.7.2.1.2

Ieee8021XPaeNIDAccessStatus0 = noAccess1 = remedialAccess2 = restrictedAccess3 = expectedAccessThis textual convention indicates the transmitter's Controlled Port operational status and current level of access resulting from authentication and the consequent authorization controls applied by that port's clients. 'noAccess' : Other than to authentication services, and to services announced as available in the absence of authentication (unauthenticated). 'remedialAccess' : The access granted is severely limited, possibly to remedial services. 'restrictedAccess' : The Controlled Port is operational, but restrictions have been applied by the network that can limit access to some resources. 'expectedAccess' : The Controlled Port is operational, and access provided is as expected for successful authentication and authorization for the NID.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · Integer32

The object information reflects connectivity as a result of authentication attempts of this NID for this Announcer.

ieee8021XAnnouncementTable

1.3.111.2.802.1.1.15.1.7.3

Index: ieee8021XPaePortNumber · IMPLIED ieee8021XAnnouncementNID

A table contains the status information that the Listeners receive in the network announcement of the PAE system. This table will be instantiated if the object ieee8021XPaePortListenerEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'.

ieee8021XAnnouncementNID

1.3.111.2.802.1.1.15.1.7.3.1.1

Ieee8021XPaeNIDThis textual convention indicates a Network Identifier (NID). Each network is identified by a NID, a UTF-8 string used by network attached systems to select a network profile.Reference: IEEE 802.1X Clause 12.6, Clause 10.1 SIZE (1..100) · OCTET STRING

The NID information to identify a received network announcement for the PAE.

ieee8021XAnnouncementKMD

1.3.111.2.802.1.1.15.1.7.3.1.2

Ieee8021XPaeKMDThis textual convention indicates a Key Management Domain (KMD). KMD is a string of UTF-8 characters that names the transmitting authenticator's key management domain.Reference: IEEE 802.1X Clause 12.6 SIZE (0..253) · OCTET STRING

The KMD information for this received network announcement of the PAE.

ieee8021XAnnouncementSpecific

1.3.111.2.802.1.1.15.1.7.3.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object indicates the received announcement information was specific to the receiving PAE, not generic for all systems attached to the LAN.

ieee8021XAnnouncementAccessStatus

1.3.111.2.802.1.1.15.1.7.3.1.4

Ieee8021XPaeNIDAccessStatus0 = noAccess1 = remedialAccess2 = restrictedAccess3 = expectedAccessThis textual convention indicates the transmitter's Controlled Port operational status and current level of access resulting from authentication and the consequent authorization controls applied by that port's clients. 'noAccess' : Other than to authentication services, and to services announced as available in the absence of authentication (unauthenticated). 'remedialAccess' : The access granted is severely limited, possibly to remedial services. 'restrictedAccess' : The Controlled Port is operational, but restrictions have been applied by the network that can limit access to some resources. 'expectedAccess' : The Controlled Port is operational, and access provided is as expected for successful authentication and authorization for the NID.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · Integer32

The object information reflects connectivity as a result of authentication attempts for this received network announcement of the PAE.

ieee8021XAnnouncementAccessRequested

1.3.111.2.802.1.1.15.1.7.3.1.5

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The authenticated access has been requested for this particular NID or not.

ieee8021XAnnouncementUnauthAccess

1.3.111.2.802.1.1.15.1.7.3.1.6

Ieee8021XPaeNIDUnauthenticatedStatus0 = noAccess1 = fallbackAccess2 = limitedAccess3 = openAccessThis textual convention indicates the access capabilities of the port's clients without authentication. 'noAccess' : Other than to authentication services (see Ieee8021XPaeNIDCapabilites information. 'fallbackAccess' : Limited access can be provided after authentication failure. 'limitedAccess' : Immediate limited access is available without authentication. 'openAccess' : Immediate access is available without authentication.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · Integer32

The access capability of the port's clients without authentication in this received network announcement of the PAE. 'openAccess', 'limitedAccess' should not be returned if the object ieee8021XNidUnauthAllowed is 'immediate'.

ieee8021XAnnouncementCapabilities

1.3.111.2.802.1.1.15.1.7.3.1.7

Ieee8021XPaeNIDCapabilitesThis textual convention indicates the combinations of authentication and protection capabilities supported for a NID. Any set of these combinations can be supported.Reference: IEEE 802.1X Clause 10.1, Table 11-8 · BITS

The announcement capabilities of this received network announcement for this PAE.

ieee8021XAnnouncementCipherSuitesTable

1.3.111.2.802.1.1.15.1.7.4

Index: ieee8021XPaePortNumber · ieee8021XAnnouncementNID · ieee8021XAnnouncementCipherSuite

A table contains the Cipher Suites information that the Listeners receive in the network announcement of the PAE system. This table will be instantiated if the object ieee8021XPaePortListenerEnable in the corresponding entry of the ieee8021XPaePortTable is 'true'.

ieee8021XAnnouncementCipherSuite

1.3.111.2.802.1.1.15.1.7.4.1.1

OCTET STRING SIZE (8)

The identifier for the announced cipher suite. This is a global unique 64-bit (EUI-64) identifier to identify a cipher suite.

ieee8021XAnnouncementCipherCapability

1.3.111.2.802.1.1.15.1.7.4.1.2

Unsigned32 (0..65535)

The capability of a Cipher Suite received from the network announcement by the Listener. A 2 octets Cipher Suite dependent implementation capability field precedes each Cipher Suite reference number. If the Cipher Suite, ieee8021XAnnouncementCipherSuite, identifies the Default Cipher Suite (specified in IEEE Std 802.1AE), the two least significant bits of the implementation capability field encode the MACsec Capability parameter specified in Table 11-7 and the fourteen more significant bits are as 0 and ignored on receipt.

↑ To TOC