CISCO-ENHANCED-IPSEC-FLOW-MIB
AI MIB Summary
The CISCO-ENHANCED-IPSEC-FLOW-MIB monitors IPsec data plane structures and status on Cisco IOS and VPN platforms, specifically tracking Phase 2 Security Association bundles, tunnel metrics, and traffic flow statistics. It provides granular counters for tunnel establishment failures, key refresh events, and historical data to facilitate troubleshooting of IPsec data tunnels and detection of security violations.
This is a MIB Module for monitoring the structures and status of IPSec-based networks. The MIB has been designed to be adopted as an IETF standard. Hence vendor-specific features of IPSec protocol are excluded from this MIB.
Acronyms The following acronyms are used in this document:
IPsec: Secure IP Protocol
VPN: Virtual Private Network
ISAKMP: Internet Security Association and Key Exchange
Protocol
IKE: Internet Key Exchange Protocol
SA: Security Association
(ref: rfc2408).
SPI: Security Parameter Index is the pointer or
identifier used in accessing SA attributes (ref: rfc2408).
MM: Main Mode - the process of setting up
a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs
QM: Quick Mode - the process of setting up
Phase 2 Security Associations using a Phase 1 SA.
Phase 1 Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document.
Control Tunnel: Another term for a Phase 1 Tunnel.
Phase 2 Tunnel: An instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh).
MTU:
Maximum Transmission Unit (of an IPsec tunnel).
History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. During late 1999, Cisco adopted the MIB and together with Tivoli publised the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt.
With the emergence of multiple IPsec signaling protocols, it became apparent that the signaling aspects of IPsec need to be instrumented separately in their own right. Thus, the IPsec control attributes and metrics were separated out into CISCO-IPSEC-SIGNALING-MIB and CISCO-IKE-FLOW-MIB.
This version of the draft is the version of the draft that models that IPsec data protocol, structures and activity alone.
Overview of MIB
The MIB contains four major groups of objects which are used to manage the IPsec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPsec MIB.
The Phase 2 group models objects pertaining to IPsec data tunnels.
The History group is to aid applications that do trending analysis.
The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid detection of potential security violations.
In addition to the three major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPsec TRAPs.
Main OID:
ciscoEnhancedIpsecFlowMIB.1.3.6.1.4.1.9.9.432
274
Objects
Active
Status
9
Dependencies
Imported Objects
Objects
274 total| Object Name |
|---|
ciscoEnhancedIpsecFlowMIBThis is a MIB Module for monitoring the structures
and status of IPSec-based networks. The MIB has been
designed to be adopted as an IETF standard. Hence
vendor-specific features of IPSec protocol are excluded
from this MIB.
Acronyms
The following acronyms are used in this document:
IPsec: Secure IP Protocol
VPN: Virtual Private Network
ISAKMP: Internet Security Association and Key Exchange
Protocol
IKE: Internet Key Exchange Protocol
SA: Security Association
(ref: rfc2408).
SPI: Security Parameter Index is the pointer or
identifier used in accessing SA attributes
(ref: rfc2408).
MM: Main Mode - the process of setting up
a Phase 1 SA to secure the exchanges
required to setup Phase 2 SAs
QM: Quick Mode - the process of setting up
Phase 2 Security Associations using
a Phase 1 SA.
Phase 1 Tunnel:
An ISAKMP SA can be regarded as representing
a flow of ISAKMP/IKE traffic. Hence an ISAKMP
is referred to as a 'Phase 1 Tunnel' in this
document.
Control Tunnel:
Another term for a Phase 1 Tunnel.
Phase 2 Tunnel:
An instance of a non-ISAKMP SA bundle in which all
the SA share the same proxy identifiers (IDii,IDir)
protect the same stream of application traffic.
Such an SA bundle is termed a 'Phase 2 Tunnel'.
Note that a Phase 2 tunnel may comprise different
SA bundles and different number of SA bundles at
different times (due to key refresh).
MTU:
Maximum Transmission Unit (of an IPsec tunnel).
History of the MIB
A precursor to this MIB was written by Tivoli and implemented
in IBM Nways routers in 1999. During late 1999, Cisco adopted
the MIB and together with Tivoli publised the IPsec Flow
Monitor MIB in IETF IPsec WG in
draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the
MIB was Cisco-ized and implemented this draft as
CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified and
presented to the IPsec WG again in May 2003 in
draft-ietf-ipsec-flow-monitoring-mib-02.txt.
With the emergence of multiple IPsec signaling protocols,
it became apparent that the signaling aspects of IPsec
need to be instrumented separately in their own right.
Thus, the IPsec control attributes and metrics were
separated out into CISCO-IPSEC-SIGNALING-MIB and
CISCO-IKE-FLOW-MIB.
This version of the draft is the version of the draft
that models that IPsec data protocol, structures and
activity alone.
Overview of MIB
The MIB contains four major groups of objects which are
used to manage the IPsec Protocol. These groups include
a Levels Group, a Phase-1 Group, a Phase-2 Group,
a History Group, a Failure Group and a TRAP Control Group.
The following table illustrates the structure of the
IPsec MIB.
The Phase 2 group models objects pertaining to
IPsec data tunnels.
The History group is to aid applications that do
trending analysis.
The Failure group is to enable an operator to
do troubleshooting and debugging of the VPN Router.
Further, counters are supported to aid detection
of potential security violations.
In addition to the three major MIB Groups, there are
a number of Notifications. The following table
illustrates the name and description of the
IPsec TRAPs. MODULE-IDENTITY .1.3.6.1.4.1.9.9.432 |
ciscoEnhancedIpsecFlowMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.0 |
ciscoEnhIpsecFlowTunnelStartThis notification is generated when an IPsec Phase-2
Tunnel becomes active. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.1 |
ciscoEnhIpsecFlowTunnelStopThis notification is generated when an IPsec Phase-2
Tunnel becomes inactive. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.2 |
ciscoEnhIpsecFlowSysFailureThis notification is generated when the processing
for an IPsec Phase-2 Tunnel experiences an internal
or system capacity error. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.3 |
ciscoEnhIpsecFlowSetupFailThis notification is generated when the setup for
an IPsec Phase-2 Tunnel fails. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.4 |
ciscoEnhIpsecFlowBadSaThis notification is generated when the managed
entity receives an IPsec packet with a non-existent
(non-existant in the local Security Association
Database) SPI. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.5 |
ciscoEnhIpsecFlowCertExpiryThis notification is generated to notify that an X.509
certificate is going to expire. The notification is triggered
the time threshold configured on the application for
notification before the certificate is going to expire, which
is when the value of ceipSecCertExpiryStatus is changed from
certOK(1) to certGoingExpired(2). The user should take action
to renew the certificate identified in the notification prior
to the certificate expiration, which is at the validity
notAfter time provided in the notification. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.6 |
ciscoEnhIpsecFlowCertRenewalThis notification is generated to report a status transition
for an X.509 certificate renewal performed by the application.
The notification is generated when the value of
ceipSecCertRenewalStatus is changed from
1. renewalNotNeeded(1) to renewalRequestNeeded(2) or
renewalRequested(3)
2. renewalRequestNeeded(2) to renewalRequested(3)
3. renewalRequested(3) to renewalSuccess(4) or
renewalFailedUpdate(5) or renewalFailedExpired(6)
4. renewalFailedUpdate(5) to renewalFailedExpired(6) NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.432.0.7 |
ciscoEnhancedIpsecFlowMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1 |
ceipSecPhaseTwo OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.1 |
ceipSecGlobalStats OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.1.1 |
ceipSecGlobalActiveTunnelsThe total number of currently active
IPsec Phase-2 Tunnels.ro Gauge32 UNITS "Tunnels" .1.3.6.1.4.1.9.9.432.1.1.1.1 |
ceipSecGlobalPreviousTunnelsThe total number of previously active
IPsec Phase-2 Tunnels.ro Counter64 UNITS "Tunnels" .1.3.6.1.4.1.9.9.432.1.1.1.2 |
ceipSecGlobalInOctetsA high capacity count of the total number of
octets received by all current and previous
IPsec Phase-2 Tunnels. This value is accumulated
BEFORE determining whether or not the packet
should be decompressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.1.3 |
ceipSecGlobalInDecompOctetsA high capacity count of the total number
of decompressed octets received by all current
and previous IPsec Phase-2 Tunnels. This value
is accumulated AFTER the packet is decompressed.
If compression is not being used, this value
will match the value of ceipSecGlobalInOctets.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.1.4 |
ceipSecGlobalInPktsThe total number of packets received
by all current and previous
IPsec Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.5 |
ceipSecGlobalInDropsThe total number of packets dropped
during receive processing by all current and
previous IPsec Phase-2 Tunnels. This count does
NOT include packets dropped due to
Anti-Replay processing.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.6 |
ceipSecGlobalInReplayDropsThe total number of packets dropped during
receive processing due to Anti-Replay
processing by all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.7 |
ceipSecGlobalInAuthsThe total number of inbound authentication's
performed by all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.1.1.8 |
ceipSecGlobalInAuthFailsThe total number of inbound authentication's
which ended in failure by all current and
previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.9 |
ceipSecGlobalInDecryptsThe total number of inbound decryption's
performed by all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.10 |
ceipSecGlobalInDecryptFailsThe total number of inbound decryption's
which ended in failure by all current and
previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.11 |
ceipSecGlobalOutOctetsA high capacity count of the total number
of octets sent by all current and previous
IPsec Phase-2 Tunnels. This value is accumulated
AFTER determining whether or not the packet should
be compressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.1.12 |
ceipSecGlobalOutUncompOctetsA high capacity count of the total number of
uncompressed octets sent by all current and previous
IPsec Phase-2 Tunnels. This value is accumulated
BEFORE the packet is compressed. If compression is
not being used, this value will match the
value of ceipSecGlobalOutOctets.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.1.13 |
ceipSecGlobalOutPktsThe total number of packets sent by all
current and previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.14 |
ceipSecGlobalOutDropsThe total number of packets dropped during send
processing by all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.15 |
ceipSecGlobalOutAuthsThe total number of outbound authentication's
performed by all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.1.1.16 |
ceipSecGlobalOutAuthFailsThe total number of outbound authentication's
which ended in failure
by all current and previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.17 |
ceipSecGlobalOutEncryptsThe total number of outbound encryption's performed
by all current and previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.18 |
ceipSecGlobalOutEncryptFailsThe total number of outbound encryption's
which ended in failure by all current and
previous IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.19 |
ceipSecGlobalProtocolUseFailsThe total number of protocol use failures
which occurred during processing of all current
and previously active IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.20 |
ceipSecGlobalNoSaFailsThe total number of non-existent Security
Association in failures which occurred during
processing of all current and previous IPsec
Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.21 |
ceipSecGlobalSysCapFailsThe total number of system capacity failures
which occurred during processing of all current
and previously active IPsec Phase-2 Tunnels.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.1.22 |
ceipSecGlobalOutCompressedPktsThe cumulative number of outbound packets across all
IPsec flows terminating at this device which were
successfully compressed.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.23 |
ceipSecGlobalOutCompSkippedPktsThe total number of outbound packets across all
IPsec flows terminating at this devices that were
to be compressed but which were skipped due to
the compression hysteresis.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.24 |
ceipSecGlobalOutCompFailPktsThe total number of outbound packets across all IPsec
flows terminating at this device that failed compression
because they grew in size after compression.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.25 |
ceipSecGlobalOutCompTooSmallPktsThe total number of outbound packets across all IPsec
flows terminating at this device that were to be
compressed but were smaller than the compression
threshold size. This number is cumulative since the
last system start.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.1.26 |
ceipSecGlobalThroughputUtilizatioinTimeIntervalThe object is the length of the time interval
to measure the throughtput utilization.ro Unsigned32 UNITS "Seconds" .1.3.6.1.4.1.9.9.432.1.1.1.27 |
ceipSecGlobalThroughputLastUpdatedTimeThe timestamp is the end of the last throughput
utilization time interval.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.1.1.28 |
ceipSecGlobalLastAveragePacketSizeThis object is the average packet size in the
last throughput utilization time interval that
ended at ceipSecGlobalThroughputLastUpdatedTime.ro Unsigned32 UNITS "bytes" .1.3.6.1.4.1.9.9.432.1.1.1.29 |
ceipSecGlobalLastThroughputInMbpsThe object is the total throughput in Mbps in
the last throughput utilization time interval that
ended at ceipSecGlobalThroughputLastUpdatedTime.ro Unsigned32 UNITS "Mbps" .1.3.6.1.4.1.9.9.432.1.1.1.30 |
ceipSecGlobalLastThroughputInKppsThe object is the total throughput in Kpps in
the last throughput utilization time interval that
ended at ceipSecGlobalThroughputLastUpdatedTime.ro Unsigned32 UNITS "Kpps" .1.3.6.1.4.1.9.9.432.1.1.1.31 |
ceipSecGlobalLastThroughputUtilizationThe object is the throughput utilization in
percentage in the last performance utilization
time interval that ended at
ceipSecGlobalThroughputLastUpdatedTime.ro Unsigned32 UNITS "Percent" .1.3.6.1.4.1.9.9.432.1.1.1.32 |
ceipSecGlobalPeakThroughputUtilizationThe object is the peak throughput utilization
in percentage since the managed system is active.
It was observed in the throughput utilization
time interval that ended at
ceipSecGlobalPeakThroughputDateAndTime.ro Unsigned32 UNITS "Percent" .1.3.6.1.4.1.9.9.432.1.1.1.33 |
ceipSecGlobalPeakThroughputDateAndTimeThe date and time when
ceipSecGlobalPeakThroughputUtilization is
updated.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.1.1.34 |
ceipSecGlobalPeakThroughputInMbpsThe object indicates the peak value of throughput
in Mbps.ro Unsigned32 UNITS "Mbps" .1.3.6.1.4.1.9.9.432.1.1.1.35 |
ceipSecGlobalPeakAvgPacketSizeThis object indicates the average packet size in
bytes in the throughput utilization time interval
that ended at ceipSecGlobalPeakThroughputDateAndTime.ro Unsigned32 UNITS "bytes" .1.3.6.1.4.1.9.9.432.1.1.1.36 |
ceipSecTunnelTableThe IPsec Phase-2 Tunnel Table.
There is one entry in this table for
each active IPsec Phase-2 Tunnel. SEQUENCE OF CeipSecTunnelEntry .1.3.6.1.4.1.9.9.432.1.1.2 |
ceipSecTunnelEntryEach entry contains the attributes
associated with an active IPsec Phase-2 Tunnel. CeipSecTunnelEntry .1.3.6.1.4.1.9.9.432.1.1.2.1 |
ceipSecTunIndexThe index of the IPsec Phase-2 Tunnel Table.
The value of the index is a number which begins
at 1 and is incremented with each tunnel that is
created. The value of this object will wrap at
2,147,483,647.
Since this object must correspond to a valid
Phase-2 IPsec tunnel, this object may not assume
the value of 0. CIPsecPhase2TunnelIndex (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.1 |
ceipSecTunLocalAddressTypeThe type of the IP address of the local endpoint
for the IPsec Phase-2 Tunnel.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.2.1.2 |
ceipSecTunLocalAddressThe IP address of the local endpoint
for the IPsec Phase-2 Tunnel.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.2.1.3 |
ceipSecTunRemoteAddressTypeThe type of the IP address of the remote
endpoint for the IPsec Phase-2 Tunnel.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.2.1.4 |
ceipSecTunRemoteAddressThe IP address of the remote endpoint for
the IPsec Phase-2 Tunnel.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.2.1.5 |
ceipSecTunControlProtocolIdentifies the protocol used to setup and
administer this Phase-2 IPsec tunnel.
In case this tunnel was spawned by an IPsec
signaling protocol, this MIB object contains the
value of the object 'cisgIpsSgProtocol' defined
in CISCO-IPSEC-SIGNALING-MIB in the table
'cisgIpsSgTunnelTable' in the row corresponding
to the control tunnel.
A value of 'cpManual' is indicative of a
manually installed and administered Phase-2
tunnel.ro CIPsecControlProtocol (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.6 |
ceipSecTunControlTunnelIndexThe index of the associated IPsec Phase-1
Tunnel. In case this tunnel was spawned by an
IPsec signaling protocol, this MIB object
contains the value of the object 'cisgIpsSgTunIndex'
defined in CISCO-IPSEC-SIGNALING-MIB in the table
'cisgIpsSgTunnelTable' in the row corresponding to
the control tunnel.
A value of 0 identifies that this Phase-2 tunnel
was setup manually.ro CIPsecPhase1TunnelIndexOrZero (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.7 |
ceipSecTunControlTunnelAliveAn indicator which specifies whether or not the
IPsec Phase-1 Tunnel that spawned this Phase-2
tunnel currently exists.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.8 |
ceipSecTunEncapModeThe encapsulation mode used by the
IPsec Phase-2 Tunnel.ro CIPsecEncapMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.9 |
ceipSecTunNATTraversalModeThe encapsulation used by the IPsec Phase-2
tunnel for NAT traversal.
The value of this object is constrained based on
the value of the column 'ceipSecTunEncapMode'. If
the value of 'ceipSecTunEncapMode' is 'encapTransport',
then this object may not assume the values
'natEncapIPsecOverUdp' or 'natEncapIPsecOverTcp'.ro CIPsecNATTraversalMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.10 |
ceipSecTunLifeSizeThe negotiated LifeSize of the
IPsec Phase-2 Tunnel in kilobytes.ro Unsigned32 .1.3.6.1.4.1.9.9.432.1.1.2.1.11 |
ceipSecTunLifeTimeThe negotiated LifeTime of the IPsec Phase-2
Tunnel in seconds.
If the tunnel was setup manually, the value of this
MIB element should be 0.ro Unsigned32 UNITS "Seconds" .1.3.6.1.4.1.9.9.432.1.1.2.1.12 |
ceipSecTunActiveTimeThe length of time the IPsec Phase-2
Tunnel has been active in hundredths of seconds.ro TimeInterval (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.13 |
ceipSecTunSaLifeSizeThresholdThe security association LifeSize refresh
threshold in kilobytes.
If the tunnel was setup manually, the value of this
MIB element should be 0.ro Unsigned32 UNITS "KBytes" .1.3.6.1.4.1.9.9.432.1.1.2.1.14 |
ceipSecTunSaLifeTimeThresholdThe security association LifeTime refresh
threshold in seconds.
If the tunnel was setup manually, the value of this
MIB element should be 0.ro Unsigned32 UNITS "Seconds" .1.3.6.1.4.1.9.9.432.1.1.2.1.15 |
ceipSecTunTotalRefreshesThe total number of security
association refreshes performed.ro Counter32 UNITS "QM Exchanges" .1.3.6.1.4.1.9.9.432.1.1.2.1.16 |
ceipSecTunExpiredSaInstancesThe total number of security associations
which have expired.
If the tunnel was setup manually, the value of this
MIB element should be 0.ro Counter32 UNITS "SAs" .1.3.6.1.4.1.9.9.432.1.1.2.1.17 |
ceipSecTunCurrentSaInstancesThe number of security associations
which are currently active or expiring.ro Gauge32 .1.3.6.1.4.1.9.9.432.1.1.2.1.18 |
ceipSecTunInSaDHGrpThe Diffie Hellman Group used
by the inbound security association of the
IPsec Phase-2 Tunnel.
If the tunnel was setup manually, the value of this
MIB element would be `none'.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.19 |
ceipSecTunInSaEncryptAlgoThe encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecEncryptAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.20 |
ceipSecTunInSaEncryptKeySizeThe key size in bits of the negotiated key to be
used with the algorithm denoted by
'ceipSecTunInSaEncryptAlgo'.
For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the negotiated key size.ro CIPsecEncryptionKeySize UNITS "Bits" .1.3.6.1.4.1.9.9.432.1.1.2.1.21 |
ceipSecTunInSaAhAuthAlgoThe authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.22 |
ceipSecTunInSaEspAuthAlgoThe authentication algorithm used by the inbound
ecapsulation security protocol (ESP) security
association of the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.23 |
ceipSecTunInSaDecompAlgoThe decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.ro CIPsecCompAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.24 |
ceipSecTunOutSaDHGrpThe Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.
If the tunnel was setup manually, the value of this
MIB element would be 'none'.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.25 |
ceipSecTunOutSaEncryptAlgoThe encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecEncryptAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.26 |
ceipSecTunOutSaEncryptKeySizeThe key size in bits of the negotiated key to be
used with the algorithm denoted by
'ceipSecTunOutSaEncryptAlgo'.
For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the negotiated key size.ro CIPsecEncryptionKeySize UNITS "Bits" .1.3.6.1.4.1.9.9.432.1.1.2.1.27 |
ceipSecTunOutSaAhAuthAlgoThe authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.28 |
ceipSecTunOutSaEspAuthAlgoThe authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.29 |
ceipSecTunOutSaCompAlgoThe compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.ro CIPsecCompAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.30 |
ceipSecTunPmtuThe Path MTU for this IPsec Phase-2 tunnel, which has
been either learnt from the network or which has been
specified by the administrator. The lower end of the
range is 68 which is the minimum MTU for IPv4.ro CIPsecPmtu UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.2.1.31 |
ceipSecTunInOctetsA high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value is
accumulated BEFORE determining whether or not the packet
should be decompressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.1.2.1.32 |
ceipSecTunInDecompOctetsA high capacity count of the total number of decompressed
octets received by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will match the
value of ceipSecTunInOctets.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.2.1.33 |
ceipSecTunInPktsThe total number of packets received by this IPsec
Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.34 |
ceipSecTunInDropPktsThe total number of packets dropped
during receive processing by this IPsec Phase-2
Tunnel. This count does NOT include
packets dropped due to Anti-Replay processing.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.35 |
ceipSecTunInReplayDropPktsThe total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.36 |
ceipSecTunInAuthsThe total number of inbound
authentication's performed by this
IPsec Phase-2 Tunnel.ro Counter32 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.1.2.1.37 |
ceipSecTunInAuthFailsThe total number of inbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel .ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.2.1.38 |
ceipSecTunInDecryptsThe total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.39 |
ceipSecTunInDecryptFailsThe total number of inbound decryption's
which ended in failure by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.2.1.40 |
ceipSecTunOutOctetsA high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value is
accumulated AFTER determining whether or not the
packet should be compressed.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.2.1.41 |
ceipSecTunOutUncompOctetsA high capacity count of the total number
of uncompressed octets sent by this IPsec
Phase-2 Tunnel. This value is accumulated BEFORE
the packet is compressed. If compression
is not being used, this value will match the value
of ceipSecTunOutOctets.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.2.1.42 |
ceipSecTunOutPktsThe total number of packets sent by this
IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.43 |
ceipSecTunOutDropPktsThe total number of packets dropped during
send processing by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.44 |
ceipSecTunOutAuthsThe total number of outbound authentication's performed
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.1.2.1.45 |
ceipSecTunOutAuthFailsThe total number of outbound
authentication's which ended in failure
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.2.1.46 |
ceipSecTunOutEncryptsThe total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.47 |
ceipSecTunOutEncryptFailsThe total number of outbound encryption's
which ended in failure by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.1.2.1.48 |
ceipSecTunOutCompressedPktsThe total number of outbound packets
which were successfully compressed.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.49 |
ceipSecTunOutCompSkippedPktsThe total number of outbound packets that were to be
compressed but which were skipped due to the compression
hysteresis.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.50 |
ceipSecTunOutCompFailPktsThe total number of outbound packets that failed
compression because they grew in size after compression.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.51 |
ceipSecTunOutCompTooSmallPktsThe total number of outbound packets that were to be
compressed but were smaller than the compression threshold
size.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.1.2.1.52 |
ceipSecIfIndexThis object represents the ifIndex of an interface
where this tunnel is created.
Multiple IPsec tunnels can be created using the same
interface.ro InterfaceIndex (IF-MIB) .1.3.6.1.4.1.9.9.432.1.1.2.1.53 |
ceipSecTunStatusThe status of the MIB table row.
This object can be used to bring the tunnel down
or force a rekeying.
When the value is set to destroy(5), the SA
bundle is destroyed and this row is deleted
from this table. When the value is set to rekey(6),
then rekeying is forced on this tunnel.
When this MIB value is queried, the value of
active(4) is always returned, if the instance
exists.
This object cannot be used to create a MIB
table row.rw CIPsecTunnelStatus (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.2.1.54 |
ceipSecEndPtTableThe IPsec Phase-2 Tunnel Endpoint Table.
This table contains an entry for each
active endpoint associated with an IPsec
Phase-2 Tunnel. SEQUENCE OF CeipSecEndPtEntry .1.3.6.1.4.1.9.9.432.1.1.3 |
ceipSecEndPtEntryAn IPsec Phase-2 Tunnel Endpoint entry. CeipSecEndPtEntry .1.3.6.1.4.1.9.9.432.1.1.3.1 |
ceipSecEndPtIndexThe number of the Endpoint associated with the
IPsec Phase-2 Tunnel Table. The value of this
index is a number which begins at one and
is incremented with each Endpoint associated
with an IPsec Phase-2 Tunnel.
The value of this object will wrap at 4,294,967,295. Unsigned32 .1.3.6.1.4.1.9.9.432.1.1.3.1.1 |
ceipSecEndPtLocalNameThe DNS name of the local Endpoint.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.2 |
ceipSecEndPtLocalTypeThe type of identity for the local Endpoint.ro CIPsecEndPtType (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.3 |
ceipSecEndPtLocalAddrType1The type of the IP address for this local Endpoint's
first IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.4 |
ceipSecEndPtLocalAddr1The local Endpoint's first IP address specification.
If the local Endpoint type is single IP address,
then this is the value of the IP address.
If the local Endpoint type is IP subnet, then this
is the value of the subnet.
If the local Endpoint type is IP address range,
then this is the value of beginning IP address
of the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
ceipSecEndPtLocalType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.5 |
ceipSecEndPtLocalAddrType2The type of the IP address for this local Endpoint's
second IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.6 |
ceipSecEndPtLocalAddr2The local Endpoint's second IP address specification.
If the local Endpoint type is single IP address,
then this is the value of the IP address.
If the local Endpoint type is IP subnet, then this
is the value of the subnet mask.
If the local Endpoint type is IP address range,
then this is the value of ending IP address
of the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
ceipSecEndPtLocalType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.7 |
ceipSecEndPtLocalProtocolThe protocol number of the local Endpoint's traffic.ro CiscoIpProtocol (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.8 |
ceipSecEndPtLocalPortThe port number of the local Endpoint's traffic.ro CiscoPort (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.9 |
ceipSecEndPtRemoteNameThe DNS name of the remote Endpoint.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.10 |
ceipSecEndPtRemoteTypeThe type of identity for the remote Endpoint.ro CIPsecEndPtType (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.11 |
ceipSecEndPtRemoteAddrType1The type of the IP address for this remote Endpoint's
first IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.12 |
ceipSecEndPtRemoteAddr1The remote Endpoint's first IP address specification.
If the remote Endpoint type is single IP address,
then this is the value of the IP address.
If the remote Endpoint type is IP subnet, then this
is the value of the subnet.
If the remote Endpoint type is IP address range,
then this is the value of beginning IP address
of the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
ceipSecEndPtRemoteType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.13 |
ceipSecEndPtRemoteAddrType2The type of the IP address for this remote Endpoint's
second IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.14 |
ceipSecEndPtRemoteAddr2The remote Endpoint's second IP address specification.
If the remote Endpoint type is single IP address,
then this is the value of the IP address.
If the remote Endpoint type is IP subnet, then this
is the value of the subnet mask.
If the remote Endpoint type is IP address range,
then this is the value of ending IP address of
the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
ceipSecEndPtRemoteType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.1.3.1.15 |
ceipSecEndPtRemoteProtocolThe protocol number of the remote Endpoint's traffic.ro CiscoIpProtocol (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.16 |
ceipSecEndPtRemotePortThe port number of the remote Endpoint's traffic.ro CiscoPort (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.1.3.1.17 |
ceipSecSaTableThe IPsec Phase-2 Security Association Table.
This table identifies the structure (in terms of
component SAs) of each active Phase-2 IPsec tunnel.
This table contains an entry for each active and
expiring security association and maps each entry
in the active Phase-2 tunnel table (ceipSecTunTable)
into a number of entries in this table. The index
of this table reflects the
<destination-address, protocol, spi>
rule for identifying Security Associations. SEQUENCE OF CeipSecSaEntry .1.3.6.1.4.1.9.9.432.1.1.4 |
ceipSecSaEntryEach entry contains the attributes associated with
active and expiring IPsec Phase-2
security associations. CeipSecSaEntry .1.3.6.1.4.1.9.9.432.1.1.4.1 |
ceipSecSaProtocolThis column represents the security protocol (AH,
ESP or IPComp) for which this security association
was setup. CIPsecProtocol (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.4.1.1 |
ceipSecSaIndexThe object, in the context of the IPsec tunnel
'ceipSecTunIndex', is an index of security
associations comprising the Phase-2 IPsec tunnel
represented by the tunnel index 'ceipSecTunIndex'.
The value of this index is a number which begins at
1 and is incremented with each SPI associated with
the corresponding IPsec Phase-2 Tunnel. Unsigned32 .1.3.6.1.4.1.9.9.432.1.1.4.1.2 |
ceipSecSaDirectionPhase-2 IPsec security associations are simplex.
Hence a particular security association is used either
for securing outgoing traffic or decoding incoming
traffic. This column identifies the direction of the
security association represented by this entry.ro CIPsecPhase2SaDirection (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.4.1.3 |
ceipSecSaValueThis is the value of the Security Protection Index
(SPI) assigned by the system to the security
association represented by this entry.ro CIPsecSpi (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.4.1.4 |
ceipSecSaStatusThis column represents the status of the security
association represented by this conceptual row. If
the status of the SA is 'active', the SA is ready
for active use. The status 'expiring' represents any
of the various states that the security association
transitions through before being purged.ro Enumeration .1.3.6.1.4.1.9.9.432.1.1.4.1.5 |
ceipSecTunnelSaTableThe IPsec Phase-2 Tunnel Security Association Table.
This table identifies the SAs that are currently
associated with an active Phase-2 tunnel.
This table contains an entry for each active or
expiring security association (SA) which is
associated with an ceipSecTunnelEntry in 'active' state
and provides statistic information of this SA.
There might be multiple SAs associated with one
ceipSecTunnelEntry. SEQUENCE OF CeipSecTunnelSaEntry .1.3.6.1.4.1.9.9.432.1.1.5 |
ceipSecTunnelSaEntryEach entry contains the attributes and statistics
associated with an active or expiring IPsec Phase-2
security associations. CeipSecTunnelSaEntry .1.3.6.1.4.1.9.9.432.1.1.5.1 |
ceipSecTunSaProtocolThis column represents the security protocol (AH,
ESP or IPComp) for which this security association
was setup. CIPsecProtocol (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.5.1.1 |
ceipSecTunSaIndexThe object, in the context of the IPsec tunnel
'ceipSecTunIndex', is an index of security
associations comprising the Phase-2 IPsec tunnel
represented by the tunnel index 'ceipSecTunIndex'.
The value of this index is a number which begins at
1 and is incremented with each SPI associated with
the corresponding IPsec Phase-2 Tunnel. Unsigned32 .1.3.6.1.4.1.9.9.432.1.1.5.1.2 |
ceipSecTunSaDirectionPhase-2 IPsec security associations are simplex.
Hence a particular security association is used either
for securing outgoing traffic or decoding incoming
traffic. This column identifies the direction of the
security association represented by this entry. CIPsecPhase2SaDirection (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.5.1.3 |
ceipSecTunSaValueThis is the value of the Security Protection Index
(SPI) assigned by the system to the security
association represented by this entry.ro CIPsecSpi (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.5.1.4 |
ceipSecTunSaIfIndexThis object represents the ifIndex of an interface
where a tunnel with ceipSecTunIndex is created.
Multiple IPsec tunnels can be created using the same
interface.ro InterfaceIndex (IF-MIB) .1.3.6.1.4.1.9.9.432.1.1.5.1.5 |
ceipSecTunSaInOctetsA high capacity count of the total number of octets
received by using this SA. This value is
accumulated BEFORE determining whether or not the packet
should be decompressed.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.6 |
ceipSecTunSaInDecompOctetsA high capacity count of the total number of decompressed
octets received by using this SA. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will match the
value of ceipSecTunSaTunInOctets.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.7 |
ceipSecTunSaInPktsThe total number of packets received by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.8 |
ceipSecTunSaInDropPktsThe total number of packets dropped
during receive process by using this SA.
This count does NOT include packets dropped due
to Anti-Replay processing.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.9 |
ceipSecTunSaInReplayDropPktsThe total number of packets dropped during
receive processing due to Anti-Replay processing
by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.10 |
ceipSecTunSaInAuthsThe total number of inbound authentication's
performed by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.11 |
ceipSecTunSaInAuthFailsThe total number of inbound authentication's
which ended in failure by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.12 |
ceipSecTunSaInDecryptsThe total number of inbound decryption's performed
by this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.13 |
ceipSecTunSaInDecryptFailsThe total number of inbound decryption's
which ended in failure by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.14 |
ceipSecTunSaOutOctetsA high capacity count of the total number of octets
sent by using this SA. This value is
accumulated AFTER determining whether or not the packet
should be compressed.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.15 |
ceipSecTunSaOutUncompOctetsA high capacity count of the total number
of uncompressed octets sent by using this SA.
This value is accumulated BEFORE
the packet is compressed. If compression
is not being used, this value will match the value
of ceipSecTunSaTunOutOctets.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.16 |
ceipSecTunSaOutPktsThe total number of packets sent by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.17 |
ceipSecTunSaOutDropPktsThe total number of packets dropped during
send processing by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.18 |
ceipSecTunSaOutAuthsThe total number of outbound authentication's performed
by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.19 |
ceipSecTunSaOutAuthFailsThe total number of outbound
authentication's which ended in failure
by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.20 |
ceipSecTunSaOutEncryptsThe total number of outbound encryption's performed
by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.21 |
ceipSecTunSaOutEncryptFailsThe total number of outbound encryption's
which ended in failure by using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.22 |
ceipSecTunSaOutCompressedPktsThe total number of outbound packets
which were successfully compressed by using this
SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.23 |
ceipSecTunSaOutCompSkippedPktsThe total number of outbound packets that were to be
compressed but which were skipped due to the compression
hysteresis when using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.24 |
ceipSecTunSaOutCompFailPktsThe total number of outbound packets that failed
compression because they grew in size after compression
when using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.25 |
ceipSecTunSaOutCompTooSmallPktsThe total number of outbound packets that were to be
compressed but were smaller than the compression threshold
size when using this SA.ro Counter64 .1.3.6.1.4.1.9.9.432.1.1.5.1.26 |
ceipSecTunSaStatusThis column represents the status of the security
association represented by this conceptual row. If
the status of the SA is 'active', the SA is ready
for active use. The status 'expiring' represents any
of the various states that the security association
transitions through before being purged.ro Enumeration .1.3.6.1.4.1.9.9.432.1.1.5.1.27 |
ceipSecIfTunnelTableThe IPsec Phase-2 Tunnels to Interface association
table. This table contains an entry for each
active IPsec Phase-2 Tunnel created under an interface.
Multiple IPsec Phase-2 Tunnels can be created using the
same interface. SEQUENCE OF CeipSecIfTunnelEntry .1.3.6.1.4.1.9.9.432.1.1.6 |
ceipSecIfTunnelEntryEach entry contains the IPsec Phase-2 Tunnel
associated with an interface. CeipSecIfTunnelEntry .1.3.6.1.4.1.9.9.432.1.1.6.1 |
ceipSecIfTunnelStatusThis object corresponds to the status of
a IPsec Phase-2 Tunnel in ceipSecTunnelTable
indexed by ceipSecTunIndex. The valid status
this object can have are 'active' and
'awaitCommit'.ro CIPsecTunnelStatus (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.1.6.1.1 |
ceipSecHistory OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.2 |
ceipSecHistGlobal OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.2.1 |
ceipSecHistGlobalCntl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.2.1.1 |
ceipSecHistTableSizeThe window size of the IPsec Phase-2 History Tables.
The IPsec Phase-2 History Tables are implemented as
a sliding window in which only the last 'N' entries
are maintained. This object is used specify the number
of entries which will be maintained in the IPsec
Phase-2 History Tables.
An implementation may choose suitable minimum and
maximum values for this element based on the local
policy and available resources. If an SNMP SET request
specifies a value outside this window for this element,
in appropriate SNMP error code should be returned.
Setting this value to zero is equivalent to deleting
all conceptual rows in the archiving tables
('ceipSecHistTable' and 'ceipSecEndPtHistTable') and
disabling the archiving of entries in the tables.rw Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.1.1.1 |
ceipSecTunnelHistTableThe IPsec Phase-2 Tunnel History Table.
This table is conceptually a sliding window in
which only the last 'N' entries are maintained,
where 'N' is the value of the object
'ceipSecHistTableSize'.
If the value of 'ceipSecHistTableSize' is 0,
archiving of entries in this table is disabled. SEQUENCE OF CeipSecTunnelHistEntry .1.3.6.1.4.1.9.9.432.1.2.2 |
ceipSecTunnelHistEntryEach entry contains the attributes associated
with a previously active IPsec Phase-2 Tunnel. CeipSecTunnelHistEntry .1.3.6.1.4.1.9.9.432.1.2.2.1 |
ceipSecTunHistIndexThe index of the IPsec Phase-2 Tunnel History Table.
The value of the index is a number which
begins at one and is incremented with each tunnel
that ends. The value
of this object will wrap at 4,294,967,295. Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.2.1.1 |
ceipSecTunHistTermReasonThe reason the IPsec Phase-2 Tunnel was terminated.
Possible reasons include:
1 = other
2 = normal termination
3 = operator request
4 = peer delete request was received
5 = contact with peer was lost
6 = applicationInitiated (eg: L2TP requesting the
termination)
7 = failure of extended authentication
8 = local failure occurred
9 = operator initiated check point requestro Enumeration .1.3.6.1.4.1.9.9.432.1.2.2.1.2 |
ceipSecTunHistActiveIndexThe index of the previously active IPsec Phase-2
Tunnel.
This object must correspond to an expired IPsec
tunnel; hence this object may not assume the value
of 0.ro CIPsecPhase2TunnelIndex (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.3 |
ceipSecTunHistLocalAddressTypeThe type of the IP address of the local endpoint for
the IPsec Phase-2 Tunnel.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.2.1.4 |
ceipSecTunHistLocalAddressThe IP address of the local endpoint for
the IPsec Phase-2 Tunnel.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.2.1.5 |
ceipSecTunHistRemoteAddressTypeThe type of the IP address of the remote endpoint
for the IPsec Phase-2 Tunnel.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.2.1.6 |
ceipSecTunHistRemoteAddressThe IP address of the remote endpoint for
the IPsec Phase-2 Tunnel.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.2.1.7 |
ceipSecTunHistControlProtocolIdentifies the protocol that was used to setup
and administer Phase-2 IPsec tunnel.ro CIPsecControlProtocol (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.8 |
ceipSecTunHistControlTunnelIndexThe index of the IPsec Phase-1 Tunnel that spawned
this Phase-2 tunnel (in case of IKE, this value
would refer to 'csikeTunIndex' in the 'csikeTunnelTable').
If the IPsec tunnel corresponding to this entry
was setup manually, the value of this object should
be zero.ro CIPsecPhase1TunnelIndexOrZero (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.9 |
ceipSecTunHistEncapModeThe encapsulation mode used by the
IPsec Phase-2 Tunnel.ro CIPsecEncapMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.10 |
ceipSecTunHistNATTraversalModeThe encapsulation used by the IPsec Phase-2
tunnel corresponding to this conceptual row
for NAT traversal.ro CIPsecNATTraversalMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.11 |
ceipSecTunHistLifeSizeThe negotiated LifeSize of the IPsec Phase-2 Tunnel in
kilobytes.ro Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.2.1.12 |
ceipSecTunHistLifeTimeThe negotiated LifeTime of the IPsec Phase-2 Tunnel in
seconds.ro Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.2.1.13 |
ceipSecTunHistStartTimeThe value of sysUpTime in hundredths of seconds
when the IPsec Phase-2 Tunnel was started.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.14 |
ceipSecTunHistActiveTimeThe length of time the IPsec Phase-2 Tunnel has been
active in hundredths of seconds.ro TimeInterval (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.15 |
ceipSecTunHistTotalRefreshesThe total number of security association refreshes
performed.ro Counter32 UNITS "QM Exchanges" .1.3.6.1.4.1.9.9.432.1.2.2.1.16 |
ceipSecTunHistTotalSasThe total number of security associations used
during the life of the IPsec Phase-2 Tunnel.ro Counter32 UNITS "SAs" .1.3.6.1.4.1.9.9.432.1.2.2.1.17 |
ceipSecTunHistInSaDHGrpThe Diffie Hellman Group used by the inbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.18 |
ceipSecTunHistInSaEncryptAlgoThe encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecEncryptAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.19 |
ceipSecTunHistInSaEncryptKeySizeThe size in bits of the key which was negotiated to
be used with the encryption transform used with this
tunnel denoted by ceipSecTunHistInSaEncryptAlgo.
For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the negotiated key size.ro CIPsecEncryptionKeySize UNITS "Bits" .1.3.6.1.4.1.9.9.432.1.2.2.1.20 |
ceipSecTunHistInSaAhAuthAlgoThe authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.21 |
ceipSecTunHistInSaEspAuthAlgoThe authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.22 |
ceipSecTunHistInSaDecompAlgoThe decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.ro CIPsecCompAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.23 |
ceipSecTunHistOutSaDHGrpThe Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.24 |
ceipSecTunHistOutSaEncryptAlgoThe encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.ro CIPsecEncryptAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.25 |
ceipSecTunHistOutSaEncryptKeySzThe size in bits of the key which was negotiated to
be used with the encryption transform used with this
tunnel denoted by ceipSecTunHistOutSaEncryptAlgo.
For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the negotiated key
size.ro CIPsecEncryptionKeySize UNITS "Bits" .1.3.6.1.4.1.9.9.432.1.2.2.1.26 |
ceipSecTunHistOutSaAhAuthAlgoThe authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.27 |
ceipSecTunHistOutSaEspAuthAlgoThe authentication algorithm used by the inbound
ecapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.ro CIPsecAuthAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.28 |
ceipSecTunHistOutSaCompAlgoThe compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.ro CIPsecCompAlgorithm (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.2.1.29 |
ceipSecTunHistPmtuThe Path MTU that was determined for this IPsec
Phase-2 tunnel.ro CIPsecPmtu UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.2.2.1.30 |
ceipSecTunHistInOctetsA high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value
is accumulated BEFORE determining whether or not
the packet should be decompressed.ro Counter64 .1.3.6.1.4.1.9.9.432.1.2.2.1.31 |
ceipSecTunHistInDecompOctetsA high capacity count of the total number of
decompressed octets received by this IPsec Phase-2 Tunnel.
This value is accumulated AFTER the packet is
decompressed.
If compression is not being used, this value will match
the value of ceipSecTunInOctets.ro Counter64 .1.3.6.1.4.1.9.9.432.1.2.2.1.32 |
ceipSecTunHistInPktsThe total number of packets received by this
IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.33 |
ceipSecTunHistInDropPktsThe total number of packets dropped during
receive processing by this IPsec Phase-2 Tunnel.
This count does NOT include packets
dropped due to Anti-Replay processing.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.34 |
ceipSecTunHistInReplayDropPktsThe total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.35 |
ceipSecTunHistInAuthsThe total number of inbound authentication's
performed by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.2.2.1.36 |
ceipSecTunHistInAuthFailsThe total number of inbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel .ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.2.2.1.37 |
ceipSecTunHistInDecryptsThe total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.38 |
ceipSecTunHistInDecryptFailsThe total number of inbound decryption's
which ended in failure by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.2.2.1.39 |
ceipSecTunHistOutOctetsA high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER determining whether or not
the packet should be compressed.ro Counter64 .1.3.6.1.4.1.9.9.432.1.2.2.1.40 |
ceipSecTunHistOutUncompOctetsA high capacity count of the total
number of uncompressed octets sent by this
IPsec Phase-2 Tunnel. This value is accumulated
BEFORE the packet is compressed. If compression
is not being used, this value will match the value
of 'ceipSecTunOutOctets'.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.432.1.2.2.1.41 |
ceipSecTunHistOutPktsThe total number of packets sent by this
IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.42 |
ceipSecTunHistOutDropPktsThe total number of packets dropped during
send processing by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.43 |
ceipSecTunHistOutAuthsThe total number of outbound authentication's
performed by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Events" .1.3.6.1.4.1.9.9.432.1.2.2.1.44 |
ceipSecTunHistOutAuthFailsThe total number of outbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.2.2.1.45 |
ceipSecTunHistOutEncryptsThe total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.46 |
ceipSecTunHistOutEncryptFailsThe total number of outbound encryption's
which ended in failure by this IPsec Phase-2 Tunnel.ro Counter32 UNITS "Failures" .1.3.6.1.4.1.9.9.432.1.2.2.1.47 |
ceipSecTunHistOutCompressedPktsThe total number of outbound packets
which were successfully compressed.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.48 |
ceipSecTunHistOutCompSkippedPktsThe total number of outbound packets that were to be
compressed but which were skipped due to the
compression hysteresis.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.49 |
ceipSecTunHistOutCompFailPktsThe total number of outbound packets that failed
compression because they grew in size after compression.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.50 |
ceipSecTunHistOutCompSmallPktsThe total number of outbound packets that were
to be compressed but were smaller than the
compression threshold size.ro Counter32 UNITS "Packets" .1.3.6.1.4.1.9.9.432.1.2.2.1.51 |
ceipSecEndPtHistTableThe IPsec Phase-2 Tunnel Endpoint History Table.
This table is conceptually a sliding window in
which only the last 'N' entries are maintained,
where 'N' is the value of the object
'ceipSecHistTableSize'.
If the value of 'ceipSecHistTableSize' is 0,
archiving of entries in this table is disabled. SEQUENCE OF CeipSecEndPtHistEntry .1.3.6.1.4.1.9.9.432.1.2.3 |
ceipSecEndPtHistEntryEach entry contains the attributes associated with
a previously active IPsec Phase-2 Tunnel Endpoint. CeipSecEndPtHistEntry .1.3.6.1.4.1.9.9.432.1.2.3.1 |
ceipSecEndPtHistIndexThe number of the previously active Endpoint
associated with a IPsec Phase-2 Tunnel Table.
The value of this index is a number which begins
at one and is incremented with each Endpoint
associated with an IPsec Phase-2 Tunnel.
The value of this object will wrap at 4,294,967,295. Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.3.1.1 |
ceipSecEndPtHistTunIndexThe index of the previously active IPsec
Phase-2 Tunnel Table.ro Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.3.1.2 |
ceipSecEndPtHistActiveIndexThe index of the previously active Endpoint.ro Unsigned32 .1.3.6.1.4.1.9.9.432.1.2.3.1.3 |
ceipSecEndPtHistLocalNameThe DNS name of the local Endpoint.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.4 |
ceipSecEndPtHistLocalTypeThe type of identity for the local Endpoint.ro CIPsecEndPtType (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.5 |
ceipSecEndPtHistLocalAddrType1The type of the IP address for this local Endpoint's
first IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.6 |
ceipSecEndPtHistLocalAddr1The local Endpoint's first IP address specification.
If the local Endpoint type is single IP address,
then this is the value of the IP address.
If the local Endpoint type is IP subnet, then this
is the value of the subnet.
If the local Endpoint type is IP address range,
then this is the value of beginning IP address of
the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
cceipSecEndPtLocalType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.7 |
ceipSecEndPtHistLocalAddrType2The type of the IP address for this local Endpoint's
second IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.8 |
ceipSecEndPtHistLocalAddr2The local Endpoint's second IP address
specification.
If the local Endpoint type is single IP address,
then this is the value of the IP address.
If the local Endpoint type is IP subnet, then this
is the value of the subnet mask.
If the local Endpoint type is IP address range,
then this is the value of ending IP address of
the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
cceipSecEndPtLocalType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.9 |
ceipSecEndPtHistLocalProtocolThe protocol number of the local Endpoint's
traffic.ro CiscoIpProtocol (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.10 |
ceipSecEndPtHistLocalPortThe port number of the local Endpoint's traffic.ro CiscoPort (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.11 |
ceipSecEndPtHistRemoteNameThe DNS name of the remote Endpoint.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.12 |
ceipSecEndPtHistRemoteTypeThe type of identity for the remote Endpoint.ro CIPsecEndPtType (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.13 |
ceipSecEndPtHistRemoteAddrType1The type of the IP address for this remote Endpoint's
first IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.14 |
ceipSecEndPtHistRemoteAddr1The remote Endpoint's first IP address
specification.
If the remote Endpoint type is single IP address,
then this is the value of the IP address.
If the remote Endpoint type is IP subnet, then this
is the value of the subnet.
If the remote Endpoint type is IP address range,
then this is the value of beginning IP address of
the range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
cceipSecEndPtRemoteType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.15 |
ceipSecEndPtHistRemoteAddrType2The type of the IP address for this remote Endpoint's
second IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.16 |
ceipSecEndPtHistRemoteAddr2The remote Endpoint's second IP address
specification.
If the remote Endpoint type is single IP address,
then this is the value of the IP address.
If the remote Endpoint type is IP subnet, then this
is the value of the subnet mask.
If the remote Endpoint type is IP address range,
then this is the value of ending IP address of the
range.
If the type is an IP address, a range or a subnet,
the type of the address can be inferred from
cceipSecEndPtRemoteType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.2.3.1.17 |
ceipSecEndPtHistRemoteProtocolThe protocol number of the remote Endpoint's traffic.ro CiscoIpProtocol (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.18 |
ceipSecEndPtHistRemotePortThe port number of the remote Endpoint's traffic.ro CiscoPort (CISCO-TC) .1.3.6.1.4.1.9.9.432.1.2.3.1.19 |
ceipSecFailures OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.3 |
ceipSecFailGlobal OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.3.1 |
ceipSecFailGlobalCntl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.3.1.1 |
ceipSecFailTableSizeThe window size of the IPsec Phase-2 Failure Table.
The IPsec Phase-2 Failure Tables are implemented as
a sliding window in which only the last N entries are
maintained. This object is used specify the number of
entries which will be maintained in the IPsec Phase-2
Failure Tables.
An implementation may choose suitable minimum and
maximum values for this element based on the local
policy and available resources. If an SNMP SET
request specifies a value outside this window for
this element, an appropriate SNMP error vode must
be returned.
Setting this value to zero is equivalent to deleting
all conceptual rows in the archiving table
'ceipSecFailTable' and disabling the archiving of
entries in these tables.rw Unsigned32 .1.3.6.1.4.1.9.9.432.1.3.1.1.1 |
ceipSecFailTableThe IPsec Phase-2 Failure Table.
This table is implemented as a sliding window
in which only the last n entries are maintained.
The maximum number of entries
is specified by the ceipSecFailTableSize object. SEQUENCE OF CeipSecFailEntry .1.3.6.1.4.1.9.9.432.1.3.2 |
ceipSecFailEntryEach entry contains the attributes associated with
an IPsec Phase-1 failure. CeipSecFailEntry .1.3.6.1.4.1.9.9.432.1.3.2.1 |
ceipSecFailIndexThe IPsec Phase-2 Failure Table index.
The value of the index is a number which
begins at one and is incremented with each
IPsec Phase-1 failure. The value of this
object will wrap at 4,294,967,295. Unsigned32 .1.3.6.1.4.1.9.9.432.1.3.2.1.1 |
ceipSecFailReasonThe reason for the failure. Possible reasons
include:
1 = other
2 = internal error occurred
3 = peer encoding error
4 = proposal failure
5 = protocol use failure
6 = non-existent security association
7 = decryption failure
8 = encryption failure
9 = inbound authentication failure
10 = outbound authentication failure
11 = compression failure
12 = system capacity failure
13 = peer delete request was received
14 = contact with peer was lost
15 = sequence number rolled over
16 = operator requested termination
17 = performance utilization exceeding the threshold.ro Enumeration .1.3.6.1.4.1.9.9.432.1.3.2.1.2 |
ceipSecFailTimeThe value of sysUpTime in hundredths of seconds
at the time of the failure.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.3.2.1.3 |
ceipSecFailTunnelIndexThe Phase-2 Tunnel index (ceipSecTunIndex).
If this conceptual row corresponds to an operation
failure (that is, the failure of an established
Phase-2 IPsec tunnel), then the value of this object
may not be zero.ro CIPsecPhase2TunnelIndex (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.3.2.1.4 |
ceipSecFailSaSpiThe security association SPI value.
If this conceptual row corresponds to a setup
failure (failure to establish the tunnel), the
value of this MIB object is undefined.ro CIPsecSpi (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.432.1.3.2.1.5 |
ceipSecFailPktSrcAddressTypeThe type of the packet's source IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.3.2.1.6 |
ceipSecFailPktSrcAddressThe packet's source IP address.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.3.2.1.7 |
ceipSecFailPktDstAddressTypeThe type of the packet's destination IP address.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.3.2.1.8 |
ceipSecFailPktDstAddressThe packet's destination IP address.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.432.1.3.2.1.9 |
ceipSecNotificationCntl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.5 |
ceipSecNotiCntlIpSecAllNotifsThis object
sending any notification
defined in this MIB module. That is, a particular
notification 'foo' defined in this MIB module is
enabled if and only if the expression
(ceipSecNotiCntlIpSecAllNotifs && ceipSecNotiCntl<foo>)
evaluates to 'true', where ceipSecNotiCntl<foo> is a
notification defined in this MIB module.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.1 |
ceipSecNotifCntlIpSecTunnelStartThis object defines the administrative state
of sending the IPsec Phase-2 Tunnel Start TRAP.
If the value of this object is 'true', the issuing
of the notification 'ciscoEnhIpsecFlowTunnelStart'
is enabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.2 |
ceipSecNotifCntlIpSecTunnelStopThis object defines the administrative state of
sending the IPsec Phase-2 Tunnel Stop TRAP.
If the value of this object is 'true', the issuing
of the notification 'ciscoEnhIpsecFlowTunnelStop'
is enabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.3 |
ceipSecNotifCntlIpSecSysFailureThis object defines the administrative state
of sending the IPsec Phase-2 System Failure TRAP.
If the value of this object is 'true', the issuing
of the notification 'ciscoEnhIpsecFlowSysFailure'
is enabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.4 |
ceipSecNotifCntlIpSecSetUpFailThis object defines the administrative state
of sending the IPsec Phase-2 Set Up Failure TRAP.
If the value of this object is 'true', the issuing
of the notification 'ciscoEnhIpsecFlowSetupFail'
is enabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.5 |
ceipSecNotifCntlIpSecBadSaThis object defines the administrative state of
sending the IPsec Phase-2 No Security Association
trap.
If the value of this object is 'true', the issuing
of the notification 'ciscoEnhIpsecFlowBadSa' is
enabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.6 |
ceipSecNotifCntlCertExpiryThis object defines the administrative state of sending the
IPSec certificate expiry notification.
If the value of this object is 'true', the issuing of the
notification 'ciscoEnhIpsecFlowCertExpiry' is enabled,
otherwise notification 'ciscoEnhIpsecFlowCertExpiry' is
disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.7 |
ceipSecNotifCntlCertRenewalThis object defines the administrative state of sending the
IPSec X.509 certificate renewal status notification.
If the value of this object is 'true', the issuing of the
notification 'ciscoEnhIpsecFlowCertRenewal' is enabled,
otherwise notification 'ciscoEnhIpsecFlowCertRenewal' is
disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.432.1.5.8 |
ceipSecCertNotification OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.1.6 |
ceipSecCertSubjectNameThis object provides the subject name from the X.509
certificate, or the alternate subject name if it is available.
The subject name is formatted as a character string matching the
output of a ssh-certview command-line application, except that
the application sending the notification may limit the string
length.
Example Subject Name: C=US, OU=DEV, CN=Test-01
Example Subject Alternative Name:
2001:0022:0022:0020:0000:0000:0000:0102ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.6.1 |
ceipSecCertSerialNumberThis object provides the serial number from the X.509
certificate. The serial number is formatted as a character
string matching the output of a ssh-certview command-line
application. The issuer name and the serial number identify a
unique certificate.
Example: 1000655533ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.6.2 |
ceipSecCertIssuerNameThis object provides the issuer name from the X.509
certificate. The issuer name is formatted as a character string
matching the output of a ssh-certview command-line application,
except that the application sending the notification may limit
the string length. The issuer name and the serial number
identify a unique certificate.
Example: C=US, O=Cisco, OU=MITG, CN=Lnx-Insta-RootCA-1ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.6.3 |
ceipSecCertExpiryTimeThis object provides the validity notAfter time from the X.509
certificate. The notAfter time is the time after which the
certificate is not valid. The time is formatted as a character
string matching the output of a ssh-certview command-line
application.
Example: 2012 Apr 14th, 19:01:45 GMTro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.432.1.6.4 |
ceipSecCertRenewalStatusThis object provides the renewal status of the X.509
certificate on the application sending the notification.
renewalNotNeeded(1) = certificate is OK and does not need to
be renewed renewalRequestNeeded(2) = certificate renewal request
is needed
renewalRequested(3) = certificate renewal has been requested
and the renewal process is proceeding
renewalSuccess(4) = certificate has been renewed and will
be OK (renewalNotNeeded)
renewalFailedUpdate(5) = certificate renewal failed, but
certificate is still usable until the validity expiration time
provided in the notification, or otherwise restricted by the
application
renewalFailedExpired(6) = certificate is no longer valid, the
current time is after the certificate's validity notAfter time,
which is provided in this notificationro Enumeration .1.3.6.1.4.1.9.9.432.1.6.5 |
ceipSecCertExpiryStatusThis object provides the expiration status of the X.509
certificate on the application sending the notification.
The notification is sent when the value of this object is
changed from certOK(1) to certGoingExpired(2).
certOK(1) = certificate is OK and is not within the
configured time threshold for going to expire
certGoingExpired(2) = certificate is within the configured time
threshold for going to expire
certExpired(3) = certificate has expired, the current time
is after the certificate's validity notAfter timero Enumeration .1.3.6.1.4.1.9.9.432.1.6.6 |
ciscoEnhancedIpsecFlowMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.2 |
ciscoEnhIPsecFlowMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.2.1 |
ciscoIPsecFlowMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.432.2.2 |