EZ5 MIB Catalog

JUNIPER-PAE-EXTENSION-MIB

2007-06-07

This is Juniper Networks' implementation of enterprise specific MIB for IEEE802.1x PAE Extension MIB. This MIB Module supports Static MAC Authetication.

Download JUNIPER-PAE-EXTENSION-MIB.txt Open JUNIPER-PAE-EXTENSION-MIB.txt in a new tab

SCALARS (1) · TABLES (3)

Scalars (1)

NameOID
jnxAuthProfileName1.3.6.1.4.1.2636.3.40.1.3.1.1.1

Tables (3)

NameOID
jnxPaeAuthConfigTable1.3.6.1.4.1.2636.3.40.1.3.1.1.2
jnxStaticMacAuthBypassTable1.3.6.1.4.1.2636.3.40.1.3.1.1.3
jnxStaticMacAuthBypassIfTable1.3.6.1.4.1.2636.3.40.1.3.1.1.4

END OF TOC

Scalar details

jnxAuthProfileName

1.3.6.1.4.1.2636.3.40.1.3.1.1.1

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The Authentication Profile Name is given by this object. The access profile with this name is already defined with the radius server ip address, port and secret key.

Table details

jnxPaeAuthConfigTable

1.3.6.1.4.1.2636.3.40.1.3.1.1.2

Index: dot1xPaePortNumber

A table that contains the configuration objects for the Authenticator PAE associated with each port.

jnxPaeAuthConfigMacAuthStatus

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object specifies whether MAC Authentication is enabled on the specified PAE port.

jnxPaeAuthConfigGuestVlan

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

This object specifies the Vlan to which the unauthenticated client moves to. The Vlan should exist on the switch and is user cofigurable per port.

jnxPaeAuthConfigNumberRetries

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.3

Unsigned32

This sets the number of failed authentications on an interface before invoking the quiet period, during which no one can be authenticated on that interface.

jnxPaeAuthConfigSupplicantMode

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.4

INTEGER1 = single2 = single-secure3 = multiple · Integer32

This object specifies the supplicant mode of MAC Authentication enabled on the specified PAE port.

jnxPaeAuthConfigMacRadius

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.5

INTEGER1 = enable2 = disable · Integer32

This object specifies the Mac-Radius mode of MAC Authentication enabled on the specified PAE port.

jnxPaeAuthConfigMacRadiusRestrict

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.6

INTEGER1 = enable2 = disable · Integer32

This object specifies the Mac-Radius mode of MAC Authentication enabled on the specified PAE port.

jnxPaeAuthConfigReAuthenticate

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.7

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object specifies Re-Authentication is enabled or not on the specified PAE port.

jnxPaeAuthConfigQuietPeriod

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.8

Unsigned32 · seconds

This object specifies Time to wait after an authentication failure on the specified PAE port.

jnxPaeAuthConfigMaxRequests

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.9

Unsigned32

This object specifies Number of EAPOL RequestIDs to send before timing out on the specified PAE port.

jnxPaeAuthConfigClientsRejected

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.10

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (1..255) · OCTET STRING · hint 255a

This object specifies VLAN name or 802.1q tag for authentication rejected clients on the specified PAE port.

jnxPaeAuthConfigServerTimeout

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.11

Unsigned32 (1..60) · seconds

This object specifies Authentication server timeout interval on the specified PAE port.

jnxPaeAuthConfigSuppTimeout

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.12

Unsigned32 (1..60) · seconds

This object specifies Time to wait for a client response on the specified PAE port.

jnxPaeAuthConfigTransmitPeriod

1.3.6.1.4.1.2636.3.40.1.3.1.1.2.1.13

Unsigned32

This object specifies Interval before retransmitting initial EAPOL PDUs on the specified PAE port.

jnxStaticMacAuthBypassTable

1.3.6.1.4.1.2636.3.40.1.3.1.1.3

Index: jnxStaticMacAddress

The static MAC list provides an authentication bypass mechanism for clients connected to a port. The MAC address of the clients is first checked in a local database which is a user specified static list of MAC addresses and if a match is found, the client is assumed to be successfully authenticated and the port is opened up for it. No further authentication is done for that client. The VLAN that the client should be moved to or the interfaces on which the MAC address should be allowed from can also be optionally stored in this table. This will enable devices like printers, which do not support 802.1X, to be connected on 802.1X enabled ports. If a match is not found in the static list, 802.1X or MAC authentication is initiated. This table contains the static list of MAC addresses specified by the user.

jnxStaticMacAddress

1.3.6.1.4.1.2636.3.40.1.3.1.1.3.1.1

MacAddressRepresents an 802 MAC address represented in the `canonical' order defined by IEEE 802.1a, i.e., as if it were transmitted least significant bit first, even though 802.5 (in contrast to other 802.x protocols) requires MAC addresses to be transmitted most significant bit first. SIZE (6) · OCTET STRING · hint 1x:

This object specifies the MAC Address of the client connected to the particular PAE port.

jnxStaticMacVlanName

1.3.6.1.4.1.2636.3.40.1.3.1.1.3.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

This object specifies the Vlan to which the client is assigned to.

jnxStaticMacAuthBypassIfTable

1.3.6.1.4.1.2636.3.40.1.3.1.1.4

Index: jnxStaticMacAddress · jnxStaticMacIfIndex

This table provides the list of interfaces on which each MAC Address in the jnxStaticMacAuthBypassTable can be allowed from. If it is detected on any other interface, the authentication is not bypassed.

jnxStaticMacIfIndex

1.3.6.1.4.1.2636.3.40.1.3.1.1.4.1.1

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

This object specifies the list of interfaces from which the MAC Address is allowed from. If it is detected on any other interface, the authentication is bypassed.

↑ To TOC