The MIB module for entities implementing the server side of the Dynamic Authorization Extensions to the Remote Authentication Dial-In User Service (RADIUS) protocol. Copyright (C) The Internet Society (2006). Initial version as published in RFC 4673; for full legal notices see the RFC itself.
The number of Disconnect-Request packets received from unknown addresses. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity.
radiusDynAuthServerCoAInvalidClientAddresses
1.3.6.1.2.1.146.1.1.2
Counter32
The number of CoA-Request packets received from unknown addresses. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity.
radiusDynAuthServerIdentifier
1.3.6.1.2.1.146.1.1.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The NAS-Identifier of the RADIUS Dynamic Authorization Server. This is not necessarily the same as sysName in MIB II. Reference: RFC 2865, Section 5.32, NAS-Identifier.
Table details
radiusDynAuthClientTable
1.3.6.1.2.1.146.1.2
Index: radiusDynAuthClientIndex
The (conceptual) table listing the RADIUS Dynamic Authorization Clients with which the server shares a secret.
radiusDynAuthClientIndex
1.3.6.1.2.1.146.1.2.1.1
Integer32 (1..2147483647)
A number uniquely identifying each RADIUS Dynamic Authorization Client with which this Dynamic Authorization Server communicates. This number is allocated by the agent implementing this MIB module and is unique in this context.
radiusDynAuthClientAddressType
1.3.6.1.2.1.146.1.2.1.2
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The type of IP address of the RADIUS Dynamic Authorization Client referred to in this table entry.
radiusDynAuthClientAddress
1.3.6.1.2.1.146.1.2.1.3
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address value of the RADIUS Dynamic Authorization Client referred to in this table entry, using the version neutral IP address format. The type of this address is determined by the value of the radiusDynAuthClientAddressType object.
radiusDynAuthServDisconRequests
1.3.6.1.2.1.146.1.2.1.4
Counter32 · requests
The number of RADIUS Disconnect-Requests received from this Dynamic Authorization Client. This also includes the RADIUS Disconnect-Requests that have a Service-Type attribute with value 'Authorize Only'. This counter may experience a discontinuity when the DAS module (re)starts as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconAuthOnlyRequests
1.3.6.1.2.1.146.1.2.1.5
Counter32 · requests
The number of RADIUS Disconnect-Requests that include a Service-Type attribute with value 'Authorize Only' received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDupDisconRequests
1.3.6.1.2.1.146.1.2.1.6
Counter32 · requests
The number of duplicate RADIUS Disconnect-Request packets received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconAcks
1.3.6.1.2.1.146.1.2.1.7
Counter32 · replies
The number of RADIUS Disconnect-ACK packets sent to this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconNaks
1.3.6.1.2.1.146.1.2.1.8
Counter32 · replies
The number of RADIUS Disconnect-NAK packets sent to this Dynamic Authorization Client. This includes the RADIUS Disconnect-NAK packets sent with a Service-Type attribute with value 'Authorize Only' and the RADIUS Disconnect-NAK packets sent because no session context was found. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconNakAuthOnlyRequests
1.3.6.1.2.1.146.1.2.1.9
Counter32 · replies
The number of RADIUS Disconnect-NAK packets that include a Service-Type attribute with value 'Authorize Only' sent to this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconNakSessNoContext
1.3.6.1.2.1.146.1.2.1.10
Counter32 · replies
The number of RADIUS Disconnect-NAK packets sent to this Dynamic Authorization Client because no session context was found. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServDisconUserSessRemoved
1.3.6.1.2.1.146.1.2.1.11
Counter32 · sessions
The number of user sessions removed for the Disconnect-Requests received from this Dynamic Authorization Client. Depending on site- specific policies, a single Disconnect request can remove multiple user sessions. In cases where this Dynamic Authorization Server has no knowledge of the number of user sessions that are affected by a single request, each such Disconnect-Request will count as a single affected user session only. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM).
radiusDynAuthServMalformedDisconRequests
1.3.6.1.2.1.146.1.2.1.12
Counter32 · requests
The number of malformed RADIUS Disconnect-Request packets received from this Dynamic Authorization Client. Bad authenticators and unknown types are not included as malformed Disconnect-Requests. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM), and Section 2.3, Packet Format.
radiusDynAuthServDisconBadAuthenticators
1.3.6.1.2.1.146.1.2.1.13
Counter32 · requests
The number of RADIUS Disconnect-Request packets that contained an invalid Authenticator field received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM), and Section 2.3, Packet Format.
radiusDynAuthServDisconPacketsDropped
1.3.6.1.2.1.146.1.2.1.14
Counter32 · requests
The number of incoming Disconnect-Requests from this Dynamic Authorization Client silently discarded by the server application for some reason other than malformed, bad authenticators, or unknown types. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.1, Disconnect Messages (DM), and Section 2.3, Packet Format.
radiusDynAuthServCoARequests
1.3.6.1.2.1.146.1.2.1.15
Counter32 · requests
The number of RADIUS CoA-requests received from this Dynamic Authorization Client. This also includes the CoA requests that have a Service-Type attribute with value 'Authorize Only'. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoAAuthOnlyRequests
1.3.6.1.2.1.146.1.2.1.16
Counter32 · requests
The number of RADIUS CoA-requests that include a Service-Type attribute with value 'Authorize Only' received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServDupCoARequests
1.3.6.1.2.1.146.1.2.1.17
Counter32 · requests
The number of duplicate RADIUS CoA-Request packets received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoAAcks
1.3.6.1.2.1.146.1.2.1.18
Counter32 · replies
The number of RADIUS CoA-ACK packets sent to this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoANaks
1.3.6.1.2.1.146.1.2.1.19
Counter32 · replies
The number of RADIUS CoA-NAK packets sent to this Dynamic Authorization Client. This includes the RADIUS CoA-NAK packets sent with a Service-Type attribute with value 'Authorize Only' and the RADIUS CoA-NAK packets sent because no session context was found. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoANakAuthOnlyRequests
1.3.6.1.2.1.146.1.2.1.20
Counter32 · replies
The number of RADIUS CoA-NAK packets that include a Service-Type attribute with value 'Authorize Only' sent to this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoANakSessNoContext
1.3.6.1.2.1.146.1.2.1.21
Counter32 · replies
The number of RADIUS CoA-NAK packets sent to this Dynamic Authorization Client because no session context was found. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServCoAUserSessChanged
1.3.6.1.2.1.146.1.2.1.22
Counter32 · sessions
The number of user sessions authorization changed for the CoA-Requests received from this Dynamic Authorization Client. Depending on site- specific policies, a single CoA request can change multiple user sessions' authorization. In cases where this Dynamic Authorization Server has no knowledge of the number of user sessions that are affected by a single request, each such CoA-Request will count as a single affected user session only. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA).
radiusDynAuthServMalformedCoARequests
1.3.6.1.2.1.146.1.2.1.23
Counter32 · requests
The number of malformed RADIUS CoA-Request packets received from this Dynamic Authorization Client. Bad authenticators and unknown types are not included as malformed CoA-Requests. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA), and Section 2.3, Packet Format.
radiusDynAuthServCoABadAuthenticators
1.3.6.1.2.1.146.1.2.1.24
Counter32 · requests
The number of RADIUS CoA-Request packets that contained an invalid Authenticator field received from this Dynamic Authorization Client. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA), and Section 2.3, Packet Format.
radiusDynAuthServCoAPacketsDropped
1.3.6.1.2.1.146.1.2.1.25
Counter32 · requests
The number of incoming CoA packets from this Dynamic Authorization Client silently discarded by the server application for some reason other than malformed, bad authenticators, or unknown types. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.2, Change-of-Authorization Messages (CoA), and Section 2.3, Packet Format.
radiusDynAuthServUnknownTypes
1.3.6.1.2.1.146.1.2.1.26
Counter32 · requests
The number of incoming packets of unknown types that were received on the Dynamic Authorization port. This counter may experience a discontinuity when the DAS module (re)starts, as indicated by the value of radiusDynAuthServerCounterDiscontinuity. Reference: RFC 3576, Section 2.3, Packet Format.
radiusDynAuthServerCounterDiscontinuity
1.3.6.1.2.1.146.1.2.1.27
TimeTicks · hundredths of a second
The time (in hundredths of a second) since the last counter discontinuity. A discontinuity may be the result of a reinitialization of the DAS module within the managed entity.