Cisco Catalyst IW9165E Rugged Access Point and Wireless Client Configuration Guide, Cisco IOS XE 26.2.x

PDF

Cisco Catalyst IW9165E Rugged Access Point and Wireless Client Configuration Guide, Cisco IOS XE 26.2.x

SNMP features

Want to summarize with AI?

Log in

Provides a standardized framework for monitoring and managing WGB devices through protocol-based communication between managers and agents. It enables network administrators to assess device health and configure parameters efficiently.


The Simple Network Management Protocol (SNMP) on WGB is a functional element that

  • facilitates monitoring and management of the WGB device through the SNMP protocol,

  • includes roles for information exchange (manager, agent, MIB), and

  • supports network health assessment and parameter configuration.

The SNMP framework on WGB includes:

  • SNMP Manager: Controls and monitors the activities of network devices using SNMP, typically implemented as a network management system (NMS).

  • SNMP Agent: The software component within the managed device that maintains and reports device data.

  • SNMP MIB: A collection of managed objects (variables) which can be queried or set by the SNMP manager.

SNMP process

This illustration shows the SNMP process. When an SNMP manager requests data, the agent receives the request and relays it to the subagent, which responds. The agent then sends an SNMP response packet to the manager.

Figure 1. SNMP Process

SNMP versions

Cisco IOS software supports the following versions of SNMP:

  • SNMPv2c—The community-string-based administrative framework for SNMPv2. SNMPv2c is an update of the protocol operations and data types of SNMPv2p (SNMPv2 classic), and uses the community-based security model of SNMPv1.

  • SNMPv3—Version 3 of SNMP. SNMPv3 uses the following security features to provide secure access to devices:

    • Message integrity—Ensuring that a packet has not been tampered with in transit.

    • Authentication—Determining that the message is from a valid source.

    • Encryption—Scrambling the contents of a packet to prevent it from being learned by an unauthorized source.


Supported SNMP MIB files

The Management Information Base (MIB) is a database containing objects that can be managed on a device. These managed objects, also called variables, can be set or read to provide information about network devices and interfaces. The objects are organized in a hierarchical structure and are grouped in collections identified by object identifiers. Access to MIBs is provided through network management protocols such as SNMP.

The MIB module provides network management information on IEEE 802.11 wireless device association management and data packet forwarding configuration and statistics.

An Object Identifier (OID) uniquely identifies a MIB object on a managed network device. The OID shows the object's location in the MIB hierarchy and provides a way to access the MIB object in a network of managed devices.


Supported OIDs

The list of objects that are supported by the SNMP Management and Information Base (MIB):

  • CISCO-DOT11-ASSOCIATION-MIB OIDs are given here.

Table 1. Supported OIDs

OID Object Name

OID

OID Type

OID Description

cDot11ParentAddress

1.3.6.1.4.1.9.9.273.1.1.1

String

Provides the MAC address of the parent access point.

cDot11ActiveWirelessClients

1.3.6.1.4.1.9.9.273.1.1.2.1.1

Gauge

The device on this interface is currently associating with the number of wireless clients.

cDot11ActiveBridges

1.3.6.1.4.1.9.9.273.1.1.2.1.2

Gauge

The device on this interface is currently associating with the number of bridges.

cDot11ActiveRepeaters

1.3.6.1.4.1.9.9.273.1.1.2.1.3

Gauge

The device on the interface is currently associating with the number of repeaters.

cDot11AssStatsAssociated

1.3.6.1.4.1.9.9.273.1.1.3.1.1

Counter

When device restarts, the object counts the number of stations associated with the device on the interface.

cDot11AssStatsAuthenticated

1.3.6.1.4.1.9.9.273.1.1.3.1.2

Counter

When the device restarted, it currently counts the number of stations authenticated with the device on the interface.

cDot11AssStatsRoamedIn

1.3.6.1.4.1.9.9.273.1.1.3.1.3

Counter

When the device restarted, the object counts the number of stations roamed from another device to the device on the interface.

cDot11AssStatsRoamedAway

1.3.6.1.4.1.9.9.273.1.1.3.1.4

Counter

This object counts the number of stations roamed away from the device on the interface since device re-started.

cDot11AssStatsDeauthenticated

1.3.6.1.4.1.9.9.273.1.1.3.1.5

Counter

This object counts the number of stations deauthenticated with this device on the interface since device re-started

cDot11AssStatsDisassociated

1.3.6.1.4.1.9.9.273.1.1.3.1.6

Counter

This object counts the number of stations disassociated with this device on the interface since device re-started

cd11IfCipherMicFailClientAddress

1.3.6.1.4.1.9.9.273.1.1.4.1.1

String

This is MAC address of the client attached to the radio interface that caused the most recent MIC failure

cd11IfCipherTkipLocalMicFailures

1.3.6.1.4.1.9.9.273.1.1.4.1.2

Counter

When the device restarted, the object counts the number of MIC failures encountered on the radio interface.

cd11IfCipherTkipRemotMicFailures

1.3.6.1.4.1.9.9.273.1.1.4.1.3

Counter

When the device restarted, the object counts the number of MIC failures reported by clients on the radio interface.

cd11IfCipherTkipCounterMeasInvok

1.3.6.1.4.1.9.9.273.1.1.4.1.4

Counter

When the device restarted, the object counts the number of TKIP Counter Measures invoked on the interface.

cd11IfCipherCcmpReplaysDiscarded

1.3.6.1.4.1.9.9.273.1.1.4.1.5

Counter

When the device restarted, the object counts the number of received unicast fragments discarded by replay mechanism on the interface.

cd11IfCipherTkipReplaysDetected

1.3.6.1.4.1.9.9.273.1.1.4.1.6

When the device restarted, the object counts the number of TKIP replay errors detected on this interface.

cDot11ClientRoleClassType

1.3.6.1.4.1.9.9.273.1.2.1.1.3

Counter

The role classification of the client

cDot11ClientDevType

1.3.6.1.4.1.9.9.273.1.2.1.1.4

EnumVal

The device type of the client.

cDot11ClientRadioType

1.3.6.1.4.1.9.9.273.1.2.1.1.5

EnumVal

The radio classification of the client.

cDot11ClientWepEnabled

1.3.6.1.4.1.9.9.273.1.2.1.1.6

EnumVal

Whether WEP key mechanism is used for transmitting frames of data for the client

cDot11ClientWepKeyMixEnabled

1.3.6.1.4.1.9.9.273.1.2.1.1.7

EnumVal

Whether this client is using WEP key mixing

cDot11ClientMicEnabled

1.3.6.1.4.1.9.9.273.1.2.1.1.8

EnumVal

Whether the MIC is enabled for the client

cDot11ClientPowerSaveMode

1.3.6.1.4.1.9.9.273.1.2.1.1.9

EnumVal

The power management mode of the client.

cDot11ClientAid

1.3.6.1.4.1.9.9.273.1.2.1.1.10

Gauge

This is the association identification number of clients or multicast addresses associating with the device.

cDot11ClientDataRateSet

1.3.6.1.4.1.9.9.273.1.2.1.1.11

String

Is a set of data rates at which this client can transmit and receive data

cDot11ClientSoftwareVersion

1.3.6.1.4.1.9.9.273.1.2.1.1.12

String

Cisco IOS software version

cDot11ClientName

1.3.6.1.4.1.9.9.273.1.2.1.1.13

String

Cisco IOS device hostname

cDot11ClientAssociationState

1.3.6.1.4.1.9.9.273.1.2.1.1.14

EnumVal

The object indicates the state of the authentication and association process

cDot11ClientVlanId

1.3.6.1.4.1.9.9.273.1.2.1.1.17

Gauge

The VLAN which the wireless client is assigned to when it is successfully associated to the wireless station.

cDot11ClientSubIfIndex

1.3.6.1.4.1.9.9.273.1.2.1.1.18

Integer

This is the ifIndex of the sub-interface which this wireless client is assigned to when it is successfully associated to the wireless station.

cDot11ClientAuthenAlgorithm

1.3.6.1.4.1.9.9.273.1.2.1.1.19

EnumVal

The IEEE 802.1x authentication methods performed between the wireless station and this client during association

cDot11ClientDot1xAuthenAlgorithm

1.3.6.1.4.1.9.9.273.1.2.1.1.21

Octet String

The IEEE 802.1x authentication methods performed between the wireless client and the authentication server.

cDot11ClientUpTime

1.3.6.1.4.1.9.9.273.1.3.1.1.2

Gauge

The time in seconds that this client has been associated with this device

cDot11ClientSignalStrength

1.3.6.1.4.1.9.9.273.1.3.1.1.3

Integer

The device-dependent measure the signal strength of the most recently received packet from the client.

cDot11ClientSigQuality

1.3.6.1.4.1.9.9.273.1.3.1.1.4

Gauge

The device-dependent measure the signal quality of the most recently received packet from the client.

cDot11ClientPacketsReceived

1.3.6.1.4.1.9.9.273.1.3.1.1.6

Counter

The number of packets received from this client.

cDot11ClientBytesReceived

1.3.6.1.4.1.9.9.273.1.3.1.1.7

Counter

The number of bytes received from the client.

cDot11ClientPacketsSent

1.3.6.1.4.1.9.9.273.1.3.1.1.8

Counter

The number of packets sent to the client.

cDot11ClientBytesSent

1.3.6.1.4.1.9.9.273.1.3.1.1.9

Counter

The number of bytes sent to the client.

cDot11ClientMsduRetries

1.3.6.1.4.1.9.9.273.1.3.1.1.11

Counter

The counter increases when it successfully transmits an MSDU after one or more retransmissions.

cDot11ClientMsduFails

1.3.6.1.4.1.9.9.273.1.3.1.1.12

Counter

The counter increments when the client fails to transmit an MSDU successfully because the number of transmit attempts exceeds a certain limit.


Configure SNMP parameters

This procedure describes how to configure Simple Network Management Protocol (SNMP) on the WGB. You can enable SNMPv2c or SNMPv3 depending on your network requirements. The steps include setting community strings or usernames, defining authentication and encryption methods, and enabling SNMP functionality on the device.

  • Configure all SNMP parameters before enabling the SNMP feature using the CLI command: configure snmp enabled.

  • All SNMP configurations will be automatically removed when the SNMP feature is disabled.

Procedure

  1. Use the configure snmp v2c community-id length length command to enter the SNMP v2c community ID (SNMP v2c only).

    Device#configure snmp v2c community-id 50
  2. Use the configure snmp version {v2c | v3 } command to specify the SNMP protocol version.

    Device# configure snmp version v3
  3. Use the configure snmp auth-method {md5 | sha } command to specify the SNMP v3 authentication protocol (SNMP v3 only).

    Device# configure snmp auth-method md5
  4. Use the configure snmp v3 username length length command to enter the SNMP v3 username (SNMP v3 only).

    Device# configure snmp v3 username length 32
  5. Use the configure snmp v3 password length length command to enter the SNMP v3 user password (SNMP v3 only).

    Device# configure snmp v3 password length 12

    The valid range for length is 8 to 64 characters.

  6. Use the configure snmp encryption {des | aes | none } command to specify the SNMP v3 encryption protocol (SNMP v3 only).

    Device#configure snmp encryption des

    Encryption values are des or aes . Use none if a v3 encryption protocol is not needed.

  7. Use the configure snmp secret length length command to enter the SNMP v3 encryption passphrase (SNMP v3 only).

    Device#configure snmp secret length 12

    The valid range for length is 8 to 64 characters.

  8. Use the configure snmp enabled command to enable SNMP functionality on the WGB.

    Device#configure snmp enabled

    To configure SNMP v2c, repeat Step 1, Step 2 and Step 8.

    To configure SNMP v3, repeat Step 2 through Step 8.

  9. (Optional) Use the configure snmp disabled command to disable SNMP configuration.

    Device# configure snmp disabled

SNMP configuration examples

Configuring SNMP v2c:

Device#configure snmp v2 community-id 25
Device#configure snmp version v2c
Device#configure snmp enabled

Configuring SNMP v3 (security level AuthPriv):

Device#configure snmp auth-method md5
Device#configure snmp v3 username length 32
Device#configure snmp v3 password length 25
Device#configure snmp secret length 12
Device#configure snmp encryption aes
Device#configure snmp version v3
Device#configure snmp enabled

Configuring SNMP v3 (security level AuthNoPriv):

Device#configure snmp auth-method md5
Device#configure snmp v3 username length 32
Device#configure snmp v3 password length 32
Device#configure snmp encryption none
Device#configure snmp version v3
Device#configure snmp enabled

Verifying SNMP

Use the show snmp command to verify the SNMP configuration.

SNMP version v3

Device# show snmp

SNMP: enabled
Version: v3
Community ID: test
Username: username
Password: password
Authentication method: SHA
Encryption: AES
Encryption Passphrase: passphrase
Engine ID: 0x8000000903c0f87fe5f314

SNMP version v2c

Device# show snmp

SNMP: enabled
Version: v2c
Community ID: test
Username: username
Password: password
Authentication method: SHA
Encryption: AES
Encryption Passphrase: passphrase
Engine ID: 0x8000000903c0f87fe5f314