Authentication, Authorization, and Accounting

The following objects are for authorization and accounting functions.

Name, OID, and syntax

Access

Description

snAuthenticationDot1x

1.3.6.1.4.1.1991.1.1.3.15.1.1

Syntax: OCTET STRING (SIZE(0..3))

Read-write

A sequence of authentication methods. Each octet represents a method to authorize the user command. Each octet has the following value:

  • radius(2) - authenticate by requesting radius server
  • none(6) - no authentication

Setting a zero length octet string invalidates all previous authentication methods.

snAuthenticationEnable

1.3.6.1.4.1.1991.1.1.3.15.1.2

Syntax: OCTET STRING (SIZE(0..3))

Read-write

A sequence of authentication methods. Each octet represents a method to authorize the user command. Each octet has the following value:

  • enable(1) - Use enable password for authentication
  • radius(2) - authenticate by requesting radius server
  • local(3) - Use local user for authentication
  • line(4) - Use line (telnet) password for authentication
  • tacplus(5) - authenticate by requesting tacplus server
  • none(6) - no authentication
  • tacacs(7) - Use TACACS authentication

Setting a zero length octet string invalidates all previous authentication methods.

snAuthenticationLogin

1.3.6.1.4.1.1991.1.1.3.15.1.3

Syntax: OCTET STRING (SIZE(0..3))

Read-write

A sequence of authentication methods. Each octet represents a method to authorize the user command. Each octet has the following value:
  • enable(1) - Use enable password for authentication
  • radius(2) - authenticate by requesting radius server
  • local(3) - Use local user for authentication
  • line(4) - Use line (telnet) password for authentication
  • tacplus(5) - authenticate by requesting tacplus server
  • none(6) - no authentication
  • tacacs(7) - Use TACACS authentication

Setting a zero length octet string invalidates all previous authentication methods.

snAuthenticationSnmpserver

1.3.6.1.4.1.1991.1.1.3.15.1.4

Syntax: OCTET STRING (SIZE(0..3))

Read-write

A sequence of authentication methods. Each octet represents a method to authorize the user command. Each octet has the following value:
  • enable(1) - Use enable password for authentication
  • local(3) - Use local user for authentication
  • none(6) - no authentication

Setting a zero length octet string invalidates all previous authentication methods.

snAuthenticationWebserver

1.3.6.1.4.1.1991.1.1.3.15.1.5

Syntax: OCTET STRING (SIZE(0..3))

Read-write

A sequence of authentication methods. Each octet represents a method to authorize the user command. Each octet has the following value:
  • enable(1) - Use enable password for authentication
  • radius(2) - authenticate by requesting radius server
  • local(3) - Use local user for authentication
  • line(4) - Use line (telnet) password for authentication
  • tacplus(5) - authenticate by requesting tacplus server
  • none(6) - no authentication
  • tacacs(7) - Use TACACS authentication

Setting a zero length octet string invalidates all previous authentication methods.

snAuthorizationCommand Methods

1.3.6.1.4.1.1991.1.1.3.15.2.1

Syntax: Octet String

Read-write

Specifies the sequence of authorization methods.

This object can have zero to three octets. Each octet represents a method to authorize the user command. Each octet has the following value:

  • radius(2) - Authorize by the requesting RADIUS server
  • tacplus(5) - Authorize by the requesting TACACS+ server
  • none(6) - Skip authorization

Setting a zero length octet string invalidates all previous authorization methods.

snAuthorizationCommandLevel

1.3.6.1.4.1.1991.1.1.3.15.2.2

Syntax: IpAddress

Read-write

Specifies the commands that must be authorized. Any command that is equal to or less than the selected level will be authorized:

  • level(0) - Privilege level 0
  • level(4) - Privilege level 4
  • level(5) - Privilege level 5
snAuthorizationExec

1.3.6.1.4.1.1991.1.1.3.15.2.3

Syntax: Octet String

Read-write

Shows the sequence of authorization methods for EXEC programs.

This object can have zero to three octets. Each octet represents a method for Telnet or SSH login authorization. Each octet can have one of the following values:

  • radius(2) - Send EXEC authorization request to the RADIUS server .
  • tacplus(5) - Send EXEC authorization request to the TACACS+ server .
  • none(6) - No EXEC authorization method.

Setting a zero length octet string invalidates all authorization methods.

snAuthorizationCoaEnable

1.3.6.1.4.1.1991.1.1.3.15.2.4

Syntax: Integer

Read-write

Enables or disables change of authorization (CoA). Possible values:

  • 1 - Enable CoA
  • 2 - Disable CoA

snAuthorizationCoaIgnore

1.3.6.1.4.1.1991.1.1.3.15.2.5

Syntax: Octet string (size (0...5))

Read-write

For change of Authorization (COA) ignore COA commands. Possible enumeration values:
  • dm-request(1) - Disconnect message request
  • modify-acl(2) - Modify access control list
  • reauth-host(4) - Re-authenticate the host
  • disable-port(8) - Disable the port
  • flip-port(10) - Bounce the port.
snAccountingCommandMethods

1.3.6.1.4.1.1991.1.1.3.15.3.1

Syntax: Octet String

Read-write

Shows a sequence of accounting methods.

This object can have zero to three octets. Each octet represents an accounting method. Each octet can have one of the following values:

  • radius(2) - Send accounting information to the RADIUS server.
  • tacplus(5) - Send accounting information to the TACACS+ server.
  • none(6) - No accounting method.

Setting a zero length octet string invalidates all authorization methods.

snAccountingCommandLevel

1.3.6.1.4.1.1991.1.1.3.15.3.2

Syntax: Integer

Read-write

Specifies the commands that need to be accounted for. Any command that is equal to or less than the selected level will be accounted for:

  • level(0) - Privilege level 0
  • level(4) - Privilege level 4
  • level(5) - Privilege level 5
snAccountingExec

1.3.6.1.4.1.1991.1.1.3.15.3.3

Syntax: Octet String

Read-write

Shows the sequence of accounting methods for EXEC programs.

This object can have zero to three octets. Each octet represents a method for Telnet or SSH login accounting. Each octet can have one of the following values:

  • radius(2) - Send accounting information to the RADIUS server.
  • tacplus(5) - Send accounting information to the TACACS+ server.
  • none(6) - No accounting method.

Setting a zero length octet string invalidates all authorization methods.

snAccountingSystem

1.3.6.1.4.1.1991.1.1.3.15.3.4

Syntax: Octet String

Read-write

A sequence of accounting methods.

This object can have zero to three octets. Each octet represents a method to account for the system-related events. Each octet has the following values:

  • radius(2) - Send accounting information to the RADIUS server.
  • tacplus(5) - Send accounting information to the TACACS+ server.
  • none(6) - No accounting method.

Setting a zero length octet string invalidates all previous accounting methods.