CISCO-IKE-FLOW-MIB
AI MIB Summary
The CISCO-IKE-FLOW-MIB monitors Cisco IOS and VPN platform devices to track the status, performance, and failures of Internet Key Exchange (IKEv1 and IKEv2) signaling flows, specifically providing granular visibility into Phase 1 Main Mode negotiations, Phase 2 Quick Mode exchanges, and Security Association (SA) lifecycle events. This module augments generic IPsec signaling data by exposing specific tunnel table entries, global statistics, and historical event logs required for troubleshooting IPsec VPN control plane connectivity.
This is a MIB module for monitoring the structures and status of IPsec control flows based on Internet Key Exchange protocol. The MIB models standard aspects of the IKE protocol.
Synopsis
This MIB module models status, performance and failures of the IKEv1- and IKEv2-based signaling in IPsec, FC-SP(and similar) protocols. In practice, the security protocols such as IPsec, FC-SP and CTS use a signaling protocol such as IKE, KINK, or some such. A number of characteristics of these signaling protocols are generic. The generic attributes and status of signaling activity has been modeled in CISCO-IPSEC-SIGNALING-MIB. This MIB module augments CISCO-IPSEC-SIGNALING-MIB with IKE-specific MIB objects. (Signaling protocols are also referred to this document as 'Control Protocols', since they perform session control.)
History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. That MIB instrumented both IKE(v1) and IPsec in a single module. During late 1999, Cisco adopted the MIB and together with Tivoli published the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt.
This version of the draft is a Cisco-ized version that culls out the IKE-specific aspects of the IPsec Flow Monitor MIB.
Overview of MIB The MIB contains five major groups of objects which are used to manage the IKE protocol activity. These groups include the global statistics, IKE tunnel table, IKE History Group and a notification Group.
The tunnel table and the history table have a sparse-table relationship with the corresponding tables in the CISCO-IPSEC-SIGNALING-MIB (details in the DESCRIPTION of the respective tables).
Acronyms The following acronyms are used in this document:
Flow, Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document.
IPsec:
Secure IP Protocol
ISAKMP:
Internet Security Association and Key Management Protocol
IKE:
Internet Key Exchange Protocol
MM:
Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs
Phase 2 Tunnel: AN instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh).
QM:
Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA.
SA:
Security Association (ref: rfc2408).
VPN:
Virtual Private Network.
Main OID:
ciscoIkeFlowMIB.1.3.6.1.4.1.9.9.429
69
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
69 total| Object Name |
|---|
ciscoIkeFlowMIBThis is a MIB module for monitoring the structures
and status of IPsec control flows based on Internet
Key Exchange protocol. The MIB models standard
aspects of the IKE protocol.
Synopsis
This MIB module models status, performance and
failures of the IKEv1- and IKEv2-based signaling in
IPsec, FC-SP(and similar) protocols. In practice,
the security protocols such as IPsec, FC-SP and
CTS use a signaling protocol such as IKE, KINK,
or some such. A number of characteristics of these
signaling protocols are generic.
The generic attributes and status of signaling
activity has been modeled in
CISCO-IPSEC-SIGNALING-MIB. This MIB module augments
CISCO-IPSEC-SIGNALING-MIB with IKE-specific
MIB objects.
(Signaling protocols are also referred to this
document as 'Control Protocols', since they perform
session control.)
History of the MIB
A precursor to this MIB was written by Tivoli and
implemented in IBM Nways routers in 1999. That
MIB instrumented both IKE(v1) and IPsec in a
single module. During late 1999, Cisco adopted
the MIB and together with Tivoli published the
IPsec Flow Monitor MIB in IETF IPsec WG in
draft-ietf-ipsec-flow-monitoring-mib-00.txt.
In 2000, the MIB was Cisco-ized and implemented
this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in
IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified
and presented to the IPsec WG again in May 2003
in draft-ietf-ipsec-flow-monitoring-mib-02.txt.
This version of the draft is a Cisco-ized version
that culls out the IKE-specific aspects of the
IPsec Flow Monitor MIB.
Overview of MIB
The MIB contains five major groups of objects which
are used to manage the IKE protocol activity. These
groups include the global statistics, IKE tunnel
table, IKE History Group and a notification Group.
The tunnel table and the history table have a
sparse-table relationship with the corresponding
tables in the CISCO-IPSEC-SIGNALING-MIB
(details in the DESCRIPTION of the respective
tables).
Acronyms
The following acronyms are used in this document:
Flow, Tunnel:
An ISAKMP SA can be regarded as representing
a flow of ISAKMP/IKE traffic. Hence an ISAKMP
is referred to as a 'Phase 1 Tunnel' in this
document.
IPsec:
Secure IP Protocol
ISAKMP:
Internet Security Association and Key
Management Protocol
IKE:
Internet Key Exchange Protocol
MM:
Main Mode - the process of setting up
a Phase 1 SA to secure the exchanges
required to setup Phase 2 SAs
Phase 2 Tunnel:
AN instance of a non-ISAKMP SA bundle in
which all the SA share the same proxy
identifiers (IDii,IDir) protect the same
stream of application traffic.
Such an SA bundle is termed a 'Phase 2 Tunnel'.
Note that a Phase 2 tunnel may comprise
different SA bundles and different number of
SA bundles at different
times (due to key refresh).
QM:
Quick Mode - the process of setting up
Phase 2 Security Associations using a
Phase 1 SA.
SA:
Security Association (ref: rfc2408).
VPN:
Virtual Private Network. MODULE-IDENTITY .1.3.6.1.4.1.9.9.429 |
ciscoIkeFlowMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.0 |
ciscoIkeFlowInNewGrpRejectedThis notification is generated when the managed
entity receives and rejects an incoming new group
proposal from an IKE peer identified by
'cisgIpsSgFailRemoteAddress'.
'cisgIpsSgFailLocalAddress' identifies the address of
the local peer.
The ISAKMP context of the exchange can be obtained
from the IKE tunnel index which is contained in the
index of the varbind objects of this trap. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.429.0.1 |
ciscoIkeFlowOutNewGrpRejectedThis notification is generated when the managed entity
issues a new group proposal to the remote peer identified
by 'cisgIpsSgFailRemoteAddress' and the peer rejects the
proposal. 'cisgIpsSgFailLocalAddress' identifies the
address of the local peer.
The ISAKMP context of the exchange can be
obtained from the IKE tunnel index which is contained
in the index of the varbind objects of this trap. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.429.0.2 |
ciscoIkeFlowMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.1 |
cifIkeCurrentActivity OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.1.1 |
cifIkeGlobalStatsTableThe Phase-1 IKE Global Statistics Table.
There is one entry in this table for each Phase-1 IKE,
protocol('cpIkev1' and 'cpIkev2') implemented by the
managed entity.
For all the counter objects in the table below, initially when
the IKE Tunnel becomes active and appears in this
table, they would contain a value of zero. SEQUENCE OF CifIkeGlobalStatsEntry .1.3.6.1.4.1.9.9.429.1.1.1 |
cifIkeGlobalStatsEntryEach entry contains the global statistics pertaining
to the specific IKE protocol. CifIkeGlobalStatsEntry .1.3.6.1.4.1.9.9.429.1.1.1.1 |
cifIkeGlobalInP2ExchgsThe total number of Phase-2 exchanges
received by all currently and previously
active Phase-1 Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.1 |
cifIkeGlobalInP2ExchgInvalidsThe total number of Phase-2 exchanges which were
received and found to be invalid by all currently and
previously active Phase-1 Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.2 |
cifIkeGlobalInP2ExchgRejectsThe total number of Phase-2 exchanges
which were received and rejected by all
currently and previously active Phase-1 Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.3 |
cifIkeGlobalOutP2ExchgsThe total number of Phase-2 exchanges which were
sent by all currently and previously active IPsec
Phase-1 Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.4 |
cifIkeGlobalOutP2ExchgInvalidsThe total number of Phase-2 exchanges which were
sent and found to be invalid by all currently and
previously active Phase-1 Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.5 |
cifIkeGlobalOutP2ExchgRejectsThe total number of Phase-2 exchanges
which were sent and rejected by all currently and
previously active Phase-1 IKE Tunnels.ro Counter64 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.1.1.6 |
cifIkeGlobalInXauthsThe number of times the extended authentication
requests was received by the managed entity
from a peer.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.429.1.1.1.1.7 |
cifIkeGlobalInXauthFailuresThe number of times the extended authentication
information supplied by an IKE peer was found
to be invalid by the local entity.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.429.1.1.1.1.8 |
cifIkeGlobalOutXauthFailuresThe number of times the extended authentication
information supplied by the managed entity to an
IKE peer was found to be invalid by the remote peer.ro Counter64 UNITS "Failures" .1.3.6.1.4.1.9.9.429.1.1.1.1.9 |
cifIkeGlobalInNewGrpReqsThe total number of New Group exchanges initiated
remotely.ro Counter64 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.1.1.10 |
cifIkeGlobalOutNewGrpReqsThe total number of New Group exchanges initiated
locally.ro Counter64 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.1.1.11 |
cifIkeGlobalInNewGrpRejectReqsThe total number of New Group exchanges initiated
remotely that ended in reject.ro Counter64 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.1.1.12 |
cifIkeGlobalOutNewGrpRejectReqsThe total number of New Group exchanges initiated
locally that ended in reject.ro Counter64 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.1.1.13 |
cifIkeTunnelTableThe Phase-1 Internet Key Exchange Tunnel Table.
There is one entry in this table for each active IPsec
Phase-1 IKE Tunnel. SEQUENCE OF CifIkeTunnelEntry .1.3.6.1.4.1.9.9.429.1.1.3 |
cifIkeTunnelEntryEach entry contains the attributes associated with
an active Phase-1 IKE Tunnel.
The rows in this table correspond 1-to-1 with a subset of
the rows in cisgIpsSgTunnelTable, specifically the subset
which represent Phase-1 IKE Tunnels.
Hence, the value of the index 'cisgIpsSgProtocol'
in this table is always 'cpIkev1' or 'cpIkev2'.
For all the counter objects in the table below, initially when
the Phase-1 IKE Tunnel becomes active and appears in this
table, they would contain a value of zero. CifIkeTunnelEntry .1.3.6.1.4.1.9.9.429.1.1.3.1 |
cifIkeTunNegoModeThe negotiation mode of the Phase-1 IKE Tunnel.ro CIPsecIkeNegoMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.429.1.1.3.1.1 |
cifIkeTunDHGrpThe Diffie Hellman Group used in Phase-1 IKE
negotiations.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.429.1.1.3.1.2 |
cifIkeTunSaRefreshThresholdThe security association refresh threshold in seconds.
If the tunnel does not refresh its security associations,
the value of this MIB object is zero.ro Unsigned32 .1.3.6.1.4.1.9.9.429.1.1.3.1.3 |
cifIkeTunTotalRefreshesThe total number of security associations refreshes
performed. If the tunnel does not refresh its security
associations, the value of this MIB object is never
incremented.ro Counter32 UNITS "QM Exchanges" .1.3.6.1.4.1.9.9.429.1.1.3.1.4 |
cifIkeTunInP2ExchgsThe total number of Phase-2 exchanges received by
this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.5 |
cifIkeTunInP2ExchgInvalidsThe total number of Phase-2 exchanges received and
found to be invalid by this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.6 |
cifIkeTunInP2ExchgRejectsThe total number of Phase-2 exchanges received and
rejected by this Phase-1 Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.7 |
cifIkeTunInP2SaDelRequestsThe total number of Phase-2 security association
delete requests received by this Phase-1 IKE Tunnel.ro Counter32 UNITS "Notification Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.8 |
cifIkeTunOutP2ExchgsThe total number of Phase-2 exchanges sent by
this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.9 |
cifIkeTunOutP2ExchgInvalidsThe total number of Phase-2 exchanges sent and
found to be invalid by this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.10 |
cifIkeTunOutP2ExchgRejectsThe total number of Phase-2 exchanges sent and
rejected by this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.11 |
cifIkeTunInNewGrpReqsThe total number of New Group exchanges initiated
remotely using this IKE tunnel.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.3.1.12 |
cifIkeTunOutNewGrpReqsThe total number of New Group exchanges initiated
locally using this IKE tunnel.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.3.1.13 |
cifIkeTunInNewGrpRejectedReqsThe total number of New Group exchanges initiated
remotely using this IKE tunnel that ended in reject.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.3.1.14 |
cifIkeTunOutNewGrpRejectedReqsThe total number of New Group exchanges initiated
locally using this IKE tunnel that ended in reject.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.1.3.1.15 |
cifIkeTunInConfigsThe total number of Mode Configuration settings
received (either CFG_REPLY or CFG_SET payloads)
by the local entity on the ISAKMP SA represented by
this IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.16 |
cifIkeTunOutConfigsThe total number of Mode Configuration settings
dispatched (either CFG_REPLY or CFG_SET payloads)
by the local entity on the ISAKMP SA represented by
this IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.17 |
cifIkeTunInConfigRejectsThe total number of Mode Configuration settings
which were received (either CFG_REPLY or CFG_SET
payloads) and rejected by this entity using the ISAKMP
SA represented by this IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.18 |
cifIkeTunOutConfigRejectsThe total number of Mode Configuration settings
which were dispatched (either CFG_REPLY or CFG_SET
payloads) by this entity and were rejected by the
peer (client) using the ISAKMP SA represented by
this IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.1.3.1.19 |
cifIkeHistory OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.1.2 |
cifIkeTunnelHistTableThe Phase-1 Internet Key Exchange Tunnel
history table.
This table is conceptually a sliding window in
which only the last 'N' entries are maintained,
where 'N' is the value of the object
'cisgIpsSgHistTableSize' (defined in
defined in CISCO-IPSEC-SIGNALING-MIB).
If the value of 'cisgIpsSgHistTableSize' is 0,
then this table will be empty.
For all the counter objects in the table below, initially
when the Tunnel entry appears in this table, they would
contain a value of zero. SEQUENCE OF CifIkeTunnelHistEntry .1.3.6.1.4.1.9.9.429.1.2.1 |
cifIkeTunnelHistEntryEach entry contains the attributes associated with
a previously active Phase-1 IKE Tunnel.
This table has a sparse table relationship with the
generic Phase-1 Tunnel history table
'cisgIpsSgTunnelHistTable' defined in
CISCO-IPSEC-SIGNALING-MIB. However, the value of the
index column in this table will always be either
'cpIkev1' or 'cpIkev2'. CifIkeTunnelHistEntry .1.3.6.1.4.1.9.9.429.1.2.1.1 |
cifIkeTunHistNegoModeThe negotiation mode of the Phase-1 IKE Tunnel.ro CIPsecIkeNegoMode (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.429.1.2.1.1.1 |
cifIkeTunHistDHGrpThe Diffie Hellman Group used in Phase-1 IKE
negotiations.ro CIPsecDiffHellmanGrp (CISCO-IPSEC-TC) .1.3.6.1.4.1.9.9.429.1.2.1.1.2 |
cifIkeTunHistTotalRefreshesThe total number of security associations
refreshes performed.ro Counter32 UNITS "QM Exchanges" .1.3.6.1.4.1.9.9.429.1.2.1.1.3 |
cifIkeTunHistTotalSasThe total number of security associations used
during the life of the Phase-1 IKE Tunnel.ro Counter32 UNITS "SAs" .1.3.6.1.4.1.9.9.429.1.2.1.1.4 |
cifIkeTunHistInP2ExchgsThe total number of Phase-2 exchanges received
by this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.5 |
cifIkeTunHistInP2ExchgInvalidsThe total number of Phase-2 exchanges
received on this tunnel that were found to
contain references to unrecognized security
parameters.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.6 |
cifIkeTunHistInP2ExchgRejectsThe total number of Phase-2 exchanges
received on this tunnel that were validated but were
rejected by the local policy.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.7 |
cifIkeTunHistOutP2ExchgsThe total number of Phase-2 security association
delete requests received by this Phase-1 IKE Tunnel.ro Counter32 UNITS "Notification Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.8 |
cifIkeTunHistOutP2ExchgInvalidsThe total number of Phase-2 exchanges sent by
this Phase-1 IKE Tunnel.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.9 |
cifIkeTunHistOutP2ExchgRejectsThe total number of Phase-2 exchanges
sent on this tunnel that were rejected by the
peer, because it contained references to security
parameters not recognized by the peer.ro Counter32 UNITS "SA Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.10 |
cifIkeTunHistInNewGrpReqsThe total number of New Group exchanges initiated
remotely using this IKE tunnel during its lifetime.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.2.1.1.11 |
cifIkeTunHistOutNewGrpReqsThe total number of New Group exchanges initiated
locally using this IKE tunnel during its lifetime.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.2.1.1.12 |
cifIkeTunHistInNewGrpRejectReqsThe total number of New Group exchanges initiated
remotely using this IKE tunnel during its lifetime
that ended in reject.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.2.1.1.13 |
cifIkeTunHistOutNewGrpRejectReqsThe total number of New Group exchanges initiated
locally using this IKE tunnel during its lifetime
that ended in reject.ro Counter32 UNITS "Negotiations" .1.3.6.1.4.1.9.9.429.1.2.1.1.14 |
cifIkeTunHistInConfigsThe total number of Mode Configuration settings
received (either CFG_REPLY or CFG_SET payloads)
by the local entity on the ISAKMP SA represented by this
IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.15 |
cifIkeTunHistOutConfigsThe total number of Mode Configuration settings
dispatched (either CFG_REPLY or CFG_SET payloads)
by the local entity on the ISAKMP SA represented by this
IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.16 |
cifIkeTunHistInConfigsRejectsThe total number of Mode Configuration settings
which were received (either CFG_REPLY or CFG_SET
payloads) and rejected by this entity using the ISAKMP
SA represented by this IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.17 |
cifIkeTunHistOutConfigsRejectsThe total number of Mode Configuration settings
which were dispatched (either CFG_REPLY or CFG_SET
payloads) by this entity and were rejected by the
peer (client) using the ISAKMP SA represented by this
IKE tunnel.ro Counter32 UNITS "Mode Configuration Setting Payloads" .1.3.6.1.4.1.9.9.429.1.2.1.1.18 |
cifIkeNotifControl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.1.3 |
cifIkeNotifCntlInNewGrpRejectedThe generation of the 'ciscoIkeFlowInNewGrpRejected'
notification is enabled if and only if this object has the
value 'true'.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.429.1.3.1 |
cifIkeNotifCntlOutNewGrpRejectedThe generation of the 'ciscoIkeFlowOutNewGrpRejected'
notification is enabled if and only if this object has the
value 'true'.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.429.1.3.2 |
ciscoIkeFlowMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.2 |
ciscoIkeFlowMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.2.1 |
ciscoIkeFlowMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.429.2.2 |