Home/Catalog/CISCO-IPSEC-FLOW-MONITOR-MIB

CISCO-IPSEC-FLOW-MONITOR-MIB

This is a MIB Module for monitoring the structures in IPSec-based Virtual Private Networks. The MIB has been designed to be adopted as an IETF standard. Hence Cisco-specific features of IPSec protocol are excluded from this MIB. Acronyms The following acronyms are used in this document: IPSec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol SA: Security Association MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. Overview of IPsec MIB The MIB contains six major groups of objects which are used to manage the IPSec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPSec MIB. The Phase 1 group models objects pertaining to IKE negotiations and tunnels. The Phase 2 group models objects pertaining to IPSec data tunnels. The History group is to aid applications that do trending analysis. The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid Intrusion Detection. In addition to the five major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPSec TRAPs. For a detailed discussion, please refer to the IETF draft draft-ietf-ipsec-flow-monitoring-mib-00.txt.
Main OID:
ciscoIpSecFlowMonitorMIB.1.3.6.1.4.1.9.9.171
425
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

425 total
Object Name
ciscoIpSecFlowMonitorMIBThis is a MIB Module for monitoring the structures in IPSec-based Virtual Private Networks. The MIB has been designed to be adopted as an IETF standard. Hence Cisco-specific features of IPSec protocol are excluded from this MIB. Acronyms The following acronyms are used in this document: IPSec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol SA: Security Association MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. Overview of IPsec MIB The MIB contains six major groups of objects which are used to manage the IPSec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPSec MIB. The Phase 1 group models objects pertaining to IKE negotiations and tunnels. The Phase 2 group models objects pertaining to IPSec data tunnels. The History group is to aid applications that do trending analysis. The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid Intrusion Detection. In addition to the five major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPSec TRAPs. For a detailed discussion, please refer to the IETF draft draft-ietf-ipsec-flow-monitoring-mib-00.txt.
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.171
cipSecMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1
cipSecLevels
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.1
cipSecMibLevelThe level of the IPsec MIB.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.1.1
cipSecPhaseOne
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.2
cikeGlobalStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.2.1
cikeGlobalActiveTunnelsThe number of currently active IPsec Phase-1 IKE Tunnels.ro
Gauge32
.1.3.6.1.4.1.9.9.171.1.2.1.1
cikeGlobalPreviousTunnelsThe total number of previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.1.2
cikeGlobalInOctetsThe total number of octets received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.1.3
cikeGlobalInPktsThe total number of packets received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.1.4
cikeGlobalInDropPktsThe total number of packets which were dropped during receive processing by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.1.5
cikeGlobalInNotifysThe total number of notifys received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.6
cikeGlobalInP2ExchgsThe total number of IPsec Phase-2 exchanges received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.7
cikeGlobalInP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges which were received and found to be invalid by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.8
cikeGlobalInP2ExchgRejectsThe total number of IPsec Phase-2 exchanges which were received and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.9
cikeGlobalInP2SaDelRequestsThe total number of IPsec Phase-2 security association delete requests received by all currently and previously active and IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.10
cikeGlobalOutOctetsThe total number of octets sent by all currently and previously active and IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.1.11
cikeGlobalOutPktsThe total number of packets sent by all currently and previously active and IPsec Phase-1 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.1.12
cikeGlobalOutDropPktsThe total number of packets which were dropped during send processing by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.1.13
cikeGlobalOutNotifysThe total number of notifys sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.14
cikeGlobalOutP2ExchgsThe total number of IPsec Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.15
cikeGlobalOutP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges which were sent and found to be invalid by all currently and previously active IPsec Phase-1 Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.16
cikeGlobalOutP2ExchgRejectsThe total number of IPsec Phase-2 exchanges which were sent and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.17
cikeGlobalOutP2SaDelRequestsThe total number of IPsec Phase-2 SA delete requests sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.1.18
cikeGlobalInitTunnelsThe total number of IPsec Phase-1 IKE Tunnels which were locally initiated.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.1.19
cikeGlobalInitTunnelFailsThe total number of IPsec Phase-1 IKE Tunnels which were locally initiated and failed to activate.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.1.20
cikeGlobalRespTunnelFailsThe total number of IPsec Phase-1 IKE Tunnels which were remotely initiated and failed to activate.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.1.21
cikeGlobalSysCapFailsThe total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.1.22
cikeGlobalAuthFailsThe total number of authentications which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.1.23
cikeGlobalDecryptFailsThe total number of decryptions which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.1.24
cikeGlobalHashValidFailsThe total number of hash validations which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.1.25
cikeGlobalNoSaFailsThe total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.1.26
cikePeerTableThe IPsec Phase-1 Internet Key Exchange Peer Table. There is one entry in this table for each IPsec Phase-1 IKE peer association which is currently associated with an active IPsec Phase-1 Tunnel. The IPsec Phase-1 IKE Tunnel associated with this IPsec Phase-1 IKE peer association may or may not be currently active.
SEQUENCE OF CikePeerEntry
.1.3.6.1.4.1.9.9.171.1.2.2
cikePeerEntryEach entry contains the attributes associated with an IPsec Phase-1 IKE peer association.
CikePeerEntry
.1.3.6.1.4.1.9.9.171.1.2.2.1
cikePeerLocalTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.2.1.1
cikePeerLocalValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.2.1.2
cikePeerRemoteTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.2.1.3
cikePeerRemoteValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.2.1.4
cikePeerIntIndexThe internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.
Integer32
.1.3.6.1.4.1.9.9.171.1.2.2.1.5
cikePeerLocalAddrThe IP address of the local peer.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.2.2.1.6
cikePeerRemoteAddrThe IP address of the remote peer.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.2.2.1.7
cikePeerActiveTimeThe length of time that the peer association has existed in hundredths of a second.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.2.1.8
cikePeerActiveTunnelIndexThe index of the active IPsec Phase-1 IKE Tunnel (cikeTunIndex in the cikeTunnelTable) for this peer association. If an IPsec Phase-1 IKE Tunnel is not currently active, then the value of this object will be zero.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.2.2.1.9
cikeTunnelTableThe IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
SEQUENCE OF CikeTunnelEntry
.1.3.6.1.4.1.9.9.171.1.2.3
cikeTunnelEntryEach entry contains the attributes associated with an active IPsec Phase-1 IKE Tunnel.
CikeTunnelEntry
.1.3.6.1.4.1.9.9.171.1.2.3.1
cikeTunIndexThe index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.2.3.1.1
cikeTunLocalTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.3.1.2
cikeTunLocalValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.3.1.3
cikeTunLocalAddrThe IP address of the local endpoint for the IPsec Phase-1 IKE Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.2.3.1.4
cikeTunLocalNameThe DNS name of the local IP address for the IPsec Phase-1 IKE Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a NULL string.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.3.1.5
cikeTunRemoteTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.3.1.6
cikeTunRemoteValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.3.1.7
cikeTunRemoteAddrThe IP address of the remote endpoint for the IPsec Phase-1 IKE Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.2.3.1.8
cikeTunRemoteNameThe DNS name of the remote IP address of IPsec Phase-1 IKE Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a NULL string.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.3.1.9
cikeTunNegoModeThe negotiation mode of the IPsec Phase-1 IKE Tunnel.ro
IkeNegoMode
.1.3.6.1.4.1.9.9.171.1.2.3.1.10
cikeTunDiffHellmanGrpThe Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.2.3.1.11
cikeTunEncryptAlgoThe encryption algorithm used in IPsec Phase-1 IKE negotiations.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.2.3.1.12
cikeTunHashAlgoThe hash algorithm used in IPsec Phase-1 IKE negotiations.ro
IkeHashAlgo
.1.3.6.1.4.1.9.9.171.1.2.3.1.13
cikeTunAuthMethodThe authentication method used in IPsec Phase-1 IKE negotiations.ro
IkeAuthMethod
.1.3.6.1.4.1.9.9.171.1.2.3.1.14
cikeTunLifeTimeThe negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.2.3.1.15
cikeTunActiveTimeThe length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.3.1.16
cikeTunSaRefreshThresholdThe security association refresh threshold in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.2.3.1.17
cikeTunTotalRefreshesThe total number of security associations refreshes performed.ro
Counter32 UNITS "QM Exchanges"
.1.3.6.1.4.1.9.9.171.1.2.3.1.18
cikeTunInOctetsThe total number of octets received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.19
cikeTunInPktsThe total number of packets received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.20
cikeTunInDropPktsThe total number of packets dropped by this IPsec Phase-1 IKE Tunnel during receive processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.21
cikeTunInNotifysThe total number of notifys received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.22
cikeTunInP2ExchgsThe total number of IPsec Phase-2 exchanges received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.23
cikeTunInP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges received and found to be invalid by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.24
cikeTunInP2ExchgRejectsThe total number of IPsec Phase-2 exchanges received and rejected by this IPsec Phase-1 Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.25
cikeTunInP2SaDelRequestsThe total number of IPsec Phase-2 security association delete requests received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.26
cikeTunOutOctetsThe total number of octets sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.27
cikeTunOutPktsThe total number of packets sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.28
cikeTunOutDropPktsThe total number of packets dropped by this IPsec Phase-1 IKE Tunnel during send processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.3.1.29
cikeTunOutNotifysThe total number of notifys sent by this IPsec Phase-1 Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.30
cikeTunOutP2ExchgsThe total number of IPsec Phase-2 exchanges sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.31
cikeTunOutP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges sent and found to be invalid by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.32
cikeTunOutP2ExchgRejectsThe total number of IPsec Phase-2 exchanges sent and rejected by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.33
cikeTunOutP2SaDelRequestsThe total number of IPsec Phase-2 security association delete requests sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.3.1.34
cikeTunStatusThe status of the MIB table row. This object can be used to bring the tunnel down by setting value of this object to destroy(2). This object cannot be used to create a MIB table row.rw
TunnelStatus
.1.3.6.1.4.1.9.9.171.1.2.3.1.35
cikePeerCorrTableThe IPsec Phase-1 Internet Key Exchange Peer Association to IPsec Phase-2 Tunnel Correlation Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
SEQUENCE OF CikePeerCorrEntry
.1.3.6.1.4.1.9.9.171.1.2.4
cikePeerCorrEntryEach entry contains the attributes of an IPsec Phase-1 IKE Peer Association to IPsec Phase-2 Tunnel Correlation.
CikePeerCorrEntry
.1.3.6.1.4.1.9.9.171.1.2.4.1
cikePeerCorrLocalTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.4.1.1
cikePeerCorrLocalValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.4.1.2
cikePeerCorrRemoteTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.
IkePeerType
.1.3.6.1.4.1.9.9.171.1.2.4.1.3
cikePeerCorrRemoteValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.2.4.1.4
cikePeerCorrIntIndexThe internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.
Integer32
.1.3.6.1.4.1.9.9.171.1.2.4.1.5
cikePeerCorrSeqNumThe sequence number of the local-remote peer association. This sequence number is used to uniquely identify multiple instances of an unique association between the local and remote peer.
Integer32
.1.3.6.1.4.1.9.9.171.1.2.4.1.6
cikePeerCorrIpSecTunIndexThe index of the active IPsec Phase-2 Tunnel (cipSecTunIndex in the cipSecTunnelTable) for this IPsec Phase-1 IKE Peer Association.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.2.4.1.7
cikePhase1GWStatsTablePhase-1 IKE stats information is included in this table. Each entry is related to a specific gateway which is identified by 'cmgwIndex'.
SEQUENCE OF CikePhase1GWStatsEntry
.1.3.6.1.4.1.9.9.171.1.2.5
cikePhase1GWStatsEntryEach entry contains the attributes of an Phase-1 IKE stats information for the related gateway. There is only one entry for each gateway. The entry is created when a gateway up and cannot be deleted.
CikePhase1GWStatsEntry
.1.3.6.1.4.1.9.9.171.1.2.5.1
cikePhase1GWActiveTunnelsThe number of currently active IPsec Phase-1 IKE Tunnels.ro
Gauge32
.1.3.6.1.4.1.9.9.171.1.2.5.1.1
cikePhase1GWPreviousTunnelsThe total number of previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.5.1.2
cikePhase1GWInOctetsThe total number of octets received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.3
cikePhase1GWInPktsThe total number of packets received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.4
cikePhase1GWInDropPktsThe total number of packets which were dropped during receive processing by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.5
cikePhase1GWInNotifysThe total number of notifys received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.6
cikePhase1GWInP2ExchgsThe total number of IPsec Phase-2 exchanges received by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.7
cikePhase1GWInP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges which were received and found to be invalid by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.8
cikePhase1GWInP2ExchgRejectsThe total number of IPsec Phase-2 exchanges which were received and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.9
cikePhase1GWInP2SaDelRequestsThe total number of IPsec Phase-2 'Security Association' delete requests received by all currently and previously active and IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.10
cikePhase1GWOutOctetsThe total number of octets sent by all currently and previously active and IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.11
cikePhase1GWOutPktsThe total number of packets sent by all currently and previously active and IPsec Phase-1 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.12
cikePhase1GWOutDropPktsThe total number of packets which were dropped during send processing by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.2.5.1.13
cikePhase1GWOutNotifysThe total number of notifys sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.14
cikePhase1GWOutP2ExchgsThe total number of IPsec Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.15
cikePhase1GWOutP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges which were sent and found to be invalid by all currently and previously active IPsec Phase-1 Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.16
cikePhase1GWOutP2ExchgRejectsThe total number of IPsec Phase-2 exchanges which were sent and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.17
cikePhase1GWOutP2SaDelRequestsThe total number of IPsec Phase-2 SA delete requests sent by all currently and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.2.5.1.18
cikePhase1GWInitTunnelsThe total number of IPsec Phase-1 IKE Tunnels which were locally initiated.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.5.1.19
cikePhase1GWInitTunnelFailsThe total number of IPsec Phase-1 IKE Tunnels which were locally initiated and failed to activate.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.5.1.20
cikePhase1GWRespTunnelFailsThe total number of IPsec Phase-1 IKE Tunnels which were remotely initiated and failed to activate.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.2.5.1.21
cikePhase1GWSysCapFailsThe total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.5.1.22
cikePhase1GWAuthFailsThe total number of authentications which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.5.1.23
cikePhase1GWDecryptFailsThe total number of decryptions which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.5.1.24
cikePhase1GWHashValidFailsThe total number of hash validations which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.5.1.25
cikePhase1GWNoSaFailsThe total number of non-existent 'Security Association' failures occurred during processing of current and previous IPsec Phase-1 IKE Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.2.5.1.26
cipSecPhaseTwo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.3
cipSecGlobalStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.3.1
cipSecGlobalActiveTunnelsThe total number of currently active IPsec Phase-2 Tunnels.ro
Gauge32
.1.3.6.1.4.1.9.9.171.1.3.1.1
cipSecGlobalPreviousTunnelsThe total number of previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Phase-2 Tunnels"
.1.3.6.1.4.1.9.9.171.1.3.1.2
cipSecGlobalInOctetsThe total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecGlobalInOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.1.3
cipSecGlobalHcInOctetsA high capacity count of the total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.1.4
cipSecGlobalInOctWrapsThe number of times the global octets received counter (cipSecGlobalInOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.1.5
cipSecGlobalInDecompOctetsThe total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalInOctets. See also cipSecGlobalInDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.1.6
cipSecGlobalHcInDecompOctetsA high capacity count of the total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalHcInOctets.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.1.7
cipSecGlobalInDecompOctWrapsThe number of times the global decompressed octets received counter (cipSecGlobalInDecompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.1.8
cipSecGlobalInPktsThe total number of packets received by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.9
cipSecGlobalInDropsThe total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.10
cipSecGlobalInReplayDropsThe total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.11
cipSecGlobalInAuthsThe total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.1.12
cipSecGlobalInAuthFailsThe total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.13
cipSecGlobalInDecryptsThe total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.14
cipSecGlobalInDecryptFailsThe total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.15
cipSecGlobalOutOctetsThe total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecGlobalOutOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.1.16
cipSecGlobalHcOutOctetsA high capacity count of the total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.1.17
cipSecGlobalOutOctWrapsThe number of times the global octets sent counter (cipSecGlobalOutOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.1.18
cipSecGlobalOutUncompOctetsThe total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalOutOctets. See also cipSecGlobalOutDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.1.19
cipSecGlobalHcOutUncompOctetsA high capacity count of the total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalHcOutOctets.ro
Counter64 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.1.20
cipSecGlobalOutUncompOctWrapsThe number of times the global uncompressed octets sent counter (cipSecGlobalOutUncompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.1.21
cipSecGlobalOutPktsThe total number of packets sent by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.22
cipSecGlobalOutDropsThe total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.23
cipSecGlobalOutAuthsThe total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.1.24
cipSecGlobalOutAuthFailsThe total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.25
cipSecGlobalOutEncryptsThe total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.1.26
cipSecGlobalOutEncryptFailsThe total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.27
cipSecGlobalProtocolUseFailsThe total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.28
cipSecGlobalNoSaFailsThe total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.29
cipSecGlobalSysCapFailsThe total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.1.30
cipSecTunnelTableThe IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
SEQUENCE OF CipSecTunnelEntry
.1.3.6.1.4.1.9.9.171.1.3.2
cipSecTunnelEntryEach entry contains the attributes associated with an active IPsec Phase-2 Tunnel.
CipSecTunnelEntry
.1.3.6.1.4.1.9.9.171.1.3.2.1
cipSecTunIndexThe index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.1
cipSecTunIkeTunnelIndexThe index of the associated IPsec Phase-1 IKE Tunnel. (cikeTunIndex in the cikeTunnelTable)ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.2
cipSecTunIkeTunnelAliveAn indicator which specifies whether or not the IPsec Phase-1 IKE Tunnel currently exists.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.3.2.1.3
cipSecTunLocalAddrThe IP address of the local endpoint for the IPsec Phase-2 Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.2.1.4
cipSecTunRemoteAddrThe IP address of the remote endpoint for the IPsec Phase-2 Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.2.1.5
cipSecTunKeyTypeThe type of key used by the IPsec Phase-2 Tunnel.ro
KeyType
.1.3.6.1.4.1.9.9.171.1.3.2.1.6
cipSecTunEncapModeThe encapsulation mode used by the IPsec Phase-2 Tunnel.ro
EncapMode
.1.3.6.1.4.1.9.9.171.1.3.2.1.7
cipSecTunLifeSizeThe negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.8
cipSecTunLifeTimeThe negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.9
cipSecTunActiveTimeThe length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.3.2.1.10
cipSecTunSaLifeSizeThresholdThe security association LifeSize refresh threshold in kilobytes.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.11
cipSecTunSaLifeTimeThresholdThe security association LifeTime refresh threshold in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.2.1.12
cipSecTunTotalRefreshesThe total number of security association refreshes performed.ro
Counter32 UNITS "QM Exchanges"
.1.3.6.1.4.1.9.9.171.1.3.2.1.13
cipSecTunExpiredSaInstancesThe total number of security associations which have expired.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.3.2.1.14
cipSecTunCurrentSaInstancesThe number of security associations which are currently active or expiring.ro
Gauge32
.1.3.6.1.4.1.9.9.171.1.3.2.1.15
cipSecTunInSaDiffHellmanGrpThe Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.3.2.1.16
cipSecTunInSaEncryptAlgoThe encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.17
cipSecTunInSaAhAuthAlgoThe authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.18
cipSecTunInSaEspAuthAlgoThe authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.19
cipSecTunInSaDecompAlgoThe decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
CompAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.20
cipSecTunOutSaDiffHellmanGrpThe Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.3.2.1.21
cipSecTunOutSaEncryptAlgoThe encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.22
cipSecTunOutSaAhAuthAlgoThe authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.23
cipSecTunOutSaEspAuthAlgoThe authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.24
cipSecTunOutSaCompAlgoThe compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
CompAlgo
.1.3.6.1.4.1.9.9.171.1.3.2.1.25
cipSecTunInOctetsThe total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecTunInOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.26
cipSecTunHcInOctetsA high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.ro
Counter64 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.27
cipSecTunInOctWrapsThe number of times the octets received counter (cipSecTunInOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.2.1.28
cipSecTunInDecompOctetsThe total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunInOctets. See also cipSecTunInDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.29
cipSecTunHcInDecompOctetsA high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunHcInOctets.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.2.1.30
cipSecTunInDecompOctWrapsThe number of times the decompressed octets received counter (cipSecTunInDecompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.2.1.31
cipSecTunInPktsThe total number of packets received by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.32
cipSecTunInDropPktsThe total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.33
cipSecTunInReplayDropPktsThe total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.34
cipSecTunInAuthsThe total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.2.1.35
cipSecTunInAuthFailsThe total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.2.1.36
cipSecTunInDecryptsThe total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.37
cipSecTunInDecryptFailsThe total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.2.1.38
cipSecTunOutOctetsThe total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecTunOutOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.39
cipSecTunHcOutOctetsA high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.2.1.40
cipSecTunOutOctWrapsThe number of times the out octets counter (cipSecTunOutOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.2.1.41
cipSecTunOutUncompOctetsThe total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunOutOctets. See also cipSecTunOutDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.42
cipSecTunHcOutUncompOctetsA high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunHcOutOctets.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.3.2.1.43
cipSecTunOutUncompOctWrapsThe number of times the uncompressed octets sent counter (cipSecTunOutUncompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.2.1.44
cipSecTunOutPktsThe total number of packets sent by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.45
cipSecTunOutDropPktsThe total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.46
cipSecTunOutAuthsThe total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.2.1.47
cipSecTunOutAuthFailsThe total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.2.1.48
cipSecTunOutEncryptsThe total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.2.1.49
cipSecTunOutEncryptFailsThe total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.2.1.50
cipSecTunStatusThe status of the MIB table row. This object can be used to bring the tunnel down by setting value of this object to destroy(2). When the value is set to destroy(2), the SA bundle is destroyed and this row is deleted from this table. When this MIB value is queried, the value of active(1) is always returned, if the instance exists. This object cannot be used to create a MIB table row.rw
TunnelStatus
.1.3.6.1.4.1.9.9.171.1.3.2.1.51
cipSecEndPtTableThe IPsec Phase-2 Tunnel Endpoint Table. This table contains an entry for each active endpoint associated with an IPsec Phase-2 Tunnel.
SEQUENCE OF CipSecEndPtEntry
.1.3.6.1.4.1.9.9.171.1.3.3
cipSecEndPtEntryAn IPsec Phase-2 Tunnel Endpoint entry.
CipSecEndPtEntry
.1.3.6.1.4.1.9.9.171.1.3.3.1
cipSecEndPtIndexThe number of the Endpoint associated with the IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.3.3.1.1
cipSecEndPtLocalNameThe DNS name of the local Endpoint.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.3.3.1.2
cipSecEndPtLocalTypeThe type of identity for the local Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.ro
EndPtType
.1.3.6.1.4.1.9.9.171.1.3.3.1.3
cipSecEndPtLocalAddr1The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.3.1.4
cipSecEndPtLocalAddr2The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.3.1.5
cipSecEndPtLocalProtocolThe protocol number of the local Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.3.1.6
cipSecEndPtLocalPortThe port number of the local Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.3.1.7
cipSecEndPtRemoteNameThe DNS name of the remote Endpoint.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.3.3.1.8
cipSecEndPtRemoteTypeThe type of identity for the remote Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.ro
EndPtType
.1.3.6.1.4.1.9.9.171.1.3.3.1.9
cipSecEndPtRemoteAddr1The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.3.1.10
cipSecEndPtRemoteAddr2The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.3.3.1.11
cipSecEndPtRemoteProtocolThe protocol number of the remote Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.3.1.12
cipSecEndPtRemotePortThe port number of the remote Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.3.3.1.13
cipSecSpiTableThe IPsec Phase-2 Security Protection Index Table. This table contains an entry for each active and expiring security association.
SEQUENCE OF CipSecSpiEntry
.1.3.6.1.4.1.9.9.171.1.3.4
cipSecSpiEntryEach entry contains the attributes associated with active and expiring IPsec Phase-2 security associations.
CipSecSpiEntry
.1.3.6.1.4.1.9.9.171.1.3.4.1
cipSecSpiIndexThe number of the SPI associated with the Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.3.4.1.1
cipSecSpiDirectionThe direction of the SPI.ro
Enumeration
.1.3.6.1.4.1.9.9.171.1.3.4.1.2
cipSecSpiValueThe value of the SPI.ro
Unsigned32
.1.3.6.1.4.1.9.9.171.1.3.4.1.3
cipSecSpiProtocolThe protocol of the SPI.ro
Enumeration
.1.3.6.1.4.1.9.9.171.1.3.4.1.4
cipSecSpiStatusThe status of the SPI.ro
Enumeration
.1.3.6.1.4.1.9.9.171.1.3.4.1.5
cipSecPhase2GWStatsTablePhase-2 IPsec stats information is included in this table. Each entry is related to a specific gateway which is identified by 'cmgwIndex'
SEQUENCE OF CipSecPhase2GWStatsEntry
.1.3.6.1.4.1.9.9.171.1.3.5
cipSecPhase2GWStatsEntryEach entry contains the attributes of an Phase-2 IPsec stats information for the related gateway. There is only one entry for each gateway. The entry is created when a gateway up and cannot be deleted.
CipSecPhase2GWStatsEntry
.1.3.6.1.4.1.9.9.171.1.3.5.1
cipSecPhase2GWActiveTunnelsThe total number of currently active IPsec Phase-2 Tunnels.ro
Gauge32
.1.3.6.1.4.1.9.9.171.1.3.5.1.1
cipSecPhase2GWPreviousTunnelsThe total number of previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Phase-2 Tunnels"
.1.3.6.1.4.1.9.9.171.1.3.5.1.2
cipSecPhase2GWInOctetsThe total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecGlobalInOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.3
cipSecPhase2GWInOctWrapsThe number of times the global octets received counter (cipSecGlobalInOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.5.1.4
cipSecPhase2GWInDecompOctetsThe total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalInOctets. See also cipSecGlobalInDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.5
cipSecPhase2GWInDecompOctWrapsThe number of times the global decompressed octets received counter (cipSecGlobalInDecompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.5.1.6
cipSecPhase2GWInPktsThe total number of packets received by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.7
cipSecPhase2GWInDropsThe total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.8
cipSecPhase2GWInReplayDropsThe total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.9
cipSecPhase2GWInAuthsThe total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.5.1.10
cipSecPhase2GWInAuthFailsThe total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.11
cipSecPhase2GWInDecryptsThe total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.12
cipSecPhase2GWInDecryptFailsThe total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.13
cipSecPhase2GWOutOctetsThe total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecGlobalOutOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.14
cipSecPhase2GWOutOctWrapsThe number of times the global octets sent counter (cipSecGlobalOutOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.5.1.15
cipSecPhase2GWOutUncompOctetsThe total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalOutOctets. See also cipSecGlobalOutDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.16
cipSecPhase2GWOutUncompOctWrapsThe number of times the global uncompressed octets sent counter (cipSecGlobalOutUncompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.3.5.1.17
cipSecPhase2GWOutPktsThe total number of packets sent by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.18
cipSecPhase2GWOutDropsThe total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.19
cipSecPhase2GWOutAuthsThe total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.3.5.1.20
cipSecPhase2GWOutAuthFailsThe total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.21
cipSecPhase2GWOutEncryptsThe total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.3.5.1.22
cipSecPhase2GWOutEncryptFailsThe total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.23
cipSecPhase2GWProtocolUseFailsThe total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.24
cipSecPhase2GWNoSaFailsThe total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.25
cipSecPhase2GWSysCapFailsThe total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.3.5.1.26
cipSecHistory
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.4
cipSecHistGlobal
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.4.1
cipSecHistGlobalCntl
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.4.1.1
cipSecHistTableSizeThe window size of the IPsec Phase-1 and Phase-2 History Tables. The IPsec Phase-1 and Phase-2 History Tables are implemented as a sliding window in which only the last n entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-1 and Phase-2 History Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, a BAD VALUE may be returned.rw
Integer32
.1.3.6.1.4.1.9.9.171.1.4.1.1.1
cipSecHistCheckPointThe current state of check point processing. This object will return ready when the agent is ready to create on-demand history entries for active IPsec Tunnels or checkPoint when the agent is currently creating on-demand history entries for active IPsec Tunnels. By setting this value to checkPoint, the agent will create: a) an entry in the IPsec Phase-1 Tunnel History for each active IPsec Phase-1 Tunnel and b) an entry in the IPsec Phase-2 Tunnel History Table and an entry in the IPsec Phase-2 Tunnel EndPoint History Table for each active IPsec Phase-2 Tunnel.rw
Enumeration
.1.3.6.1.4.1.9.9.171.1.4.1.1.2
cipSecHistPhaseOne
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.4.2
cikeTunnelHistTableThe IPsec Phase-1 Internet Key Exchange Tunnel History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.
SEQUENCE OF CikeTunnelHistEntry
.1.3.6.1.4.1.9.9.171.1.4.2.1
cikeTunnelHistEntryEach entry contains the attributes associated with a previously active IPsec Phase-1 IKE Tunnel.
CikeTunnelHistEntry
.1.3.6.1.4.1.9.9.171.1.4.2.1.1
cikeTunHistIndexThe index of the IPsec Phase-1 IKE Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.1
cikeTunHistTermReasonThe reason the IPsec Phase-1 IKE Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = local failure occurred. 7 = operator initiated check point requestro
Enumeration
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.2
cikeTunHistActiveIndexThe index of the previously active IPsec Phase-1 IKE Tunnel.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.3
cikeTunHistPeerLocalTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.4
cikeTunHistPeerLocalValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.5
cikeTunHistPeerIntIndexThe internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.6
cikeTunHistPeerRemoteTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.7
cikeTunHistPeerRemoteValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.8
cikeTunHistLocalAddrThe IP address of the local endpoint for the IPsec Phase-1 IKE Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.9
cikeTunHistLocalNameThe DNS name of the local IP address for the IPsec Phase-1 IKE Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a NULL string.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.10
cikeTunHistRemoteAddrThe IP address of the remote endpoint for the IPsec Phase-1 IKE Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.11
cikeTunHistRemoteNameThe DNS name of the remote IP address of IPsec Phase-1 IKE Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a NULL string.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.12
cikeTunHistNegoModeThe negotiation mode of the IPsec Phase-1 IKE Tunnel.ro
IkeNegoMode
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.13
cikeTunHistDiffHellmanGrpThe Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.14
cikeTunHistEncryptAlgoThe encryption algorithm used in IPsec Phase-1 IKE negotiations.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.15
cikeTunHistHashAlgoThe hash algorithm used in IPsec Phase-1 IKE negotiations.ro
IkeHashAlgo
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.16
cikeTunHistAuthMethodThe authentication method used in IPsec Phase-1 IKE negotiations.ro
IkeAuthMethod
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.17
cikeTunHistLifeTimeThe negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.18
cikeTunHistStartTimeThe value of sysUpTime in hundredths of seconds when the IPsec Phase-1 IKE tunnel was started.ro
TimeStamp (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.19
cikeTunHistActiveTimeThe length of time the IPsec Phase-1 IKE tunnel was been active in hundredths of seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.20
cikeTunHistTotalRefreshesThe total number of security associations refreshes performed.ro
Counter32 UNITS "QM Exchanges"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.21
cikeTunHistTotalSasThe total number of security associations used during the life of the IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.22
cikeTunHistInOctetsThe total number of octets received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.23
cikeTunHistInPktsThe total number of packets received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.24
cikeTunHistInDropPktsThe total number of packets dropped by this IPsec Phase-1 IKE Tunnel during receive processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.25
cikeTunHistInNotifysThe total number of notifys received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.26
cikeTunHistInP2ExchgsThe total number of IPsec Phase-2 exchanges received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.27
cikeTunHistInP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges received and found to be invalid by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.28
cikeTunHistInP2ExchgRejectsThe total number of IPsec Phase-2 exchanges received and rejected by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.29
cikeTunHistInP2SaDelRequestsThe total number of IPsec Phase-2 security association delete requests received by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.30
cikeTunHistOutOctetsThe total number of octets sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.31
cikeTunHistOutPktsThe total number of packets sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.32
cikeTunHistOutDropPktsThe total number of packets dropped by this IPsec Phase-1 IKE Tunnel during send processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.33
cikeTunHistOutNotifysThe total number of notifys sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.34
cikeTunHistOutP2ExchgsThe total number of IPsec Phase-2 exchanges sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.35
cikeTunHistOutP2ExchgInvalidsThe total number of IPsec Phase-2 exchanges sent and found to be invalid by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.36
cikeTunHistOutP2ExchgRejectsThe total number of IPsec Phase-2 exchanges sent and rejected by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "SA Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.37
cikeTunHistOutP2SaDelRequestsThe total number of IPsec Phase-2 security association delete requests sent by this IPsec Phase-1 IKE Tunnel.ro
Counter32 UNITS "Notification Payloads"
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.38
cipSecHistPhaseTwo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.4.3
cipSecTunnelHistTableThe IPsec Phase-2 Tunnel History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.
SEQUENCE OF CipSecTunnelHistEntry
.1.3.6.1.4.1.9.9.171.1.4.3.1
cipSecTunnelHistEntryEach entry contains the attributes associated with a previously active IPsec Phase-2 Tunnel.
CipSecTunnelHistEntry
.1.3.6.1.4.1.9.9.171.1.4.3.1.1
cipSecTunHistIndexThe index of the IPsec Phase-2 Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.1
cipSecTunHistTermReasonThe reason the IPsec Phase-2 Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = local failure occurred 7 = operator initiated check point requestro
Enumeration
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.2
cipSecTunHistActiveIndexThe index of the previously active IPsec Phase-2 Tunnel.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.3
cipSecTunHistIkeTunnelIndexThe index of the associated IPsec Phase-1 Tunnel (cikeTunIndex in the cikeTunnelTable).ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.4
cipSecTunHistLocalAddrThe IP address of the local endpoint for the IPsec Phase-2 Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.5
cipSecTunHistRemoteAddrThe IP address of the remote endpoint for the IPsec Phase-2 Tunnel.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.6
cipSecTunHistKeyTypeThe type of key used by the IPsec Phase-2 Tunnel.ro
KeyType
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.7
cipSecTunHistEncapModeThe encapsulation mode used by the IPsec Phase-2 Tunnel.ro
EncapMode
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.8
cipSecTunHistLifeSizeThe negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.9
cipSecTunHistLifeTimeThe negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.10
cipSecTunHistStartTimeThe value of sysUpTime in hundredths of seconds when the IPsec Phase-2 Tunnel was started.ro
TimeStamp (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.11
cipSecTunHistActiveTimeThe length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.12
cipSecTunHistTotalRefreshesThe total number of security association refreshes performed.ro
Counter32 UNITS "QM Exchanges"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.13
cipSecTunHistTotalSasThe total number of security associations used during the life of the IPsec Phase-2 Tunnel.ro
Counter32 UNITS "SAs"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.14
cipSecTunHistInSaDiffHellmanGrpThe Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.15
cipSecTunHistInSaEncryptAlgoThe encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.16
cipSecTunHistInSaAhAuthAlgoThe authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.17
cipSecTunHistInSaEspAuthAlgoThe authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.18
cipSecTunHistInSaDecompAlgoThe decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
CompAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.19
cipSecTunHistOutSaDiffHellmanGrpThe Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.ro
DiffHellmanGrp
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.20
cipSecTunHistOutSaEncryptAlgoThe encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.ro
EncryptAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.21
cipSecTunHistOutSaAhAuthAlgoThe authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.22
cipSecTunHistOutSaEspAuthAlgoThe authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.ro
AuthAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.23
cipSecTunHistOutSaCompAlgoThe compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.ro
CompAlgo
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.24
cipSecTunHistInOctetsThe total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecTunInOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.25
cipSecTunHistHcInOctetsA high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.26
cipSecTunHistInOctWrapsThe number of times the octets received counter (cipSecTunInOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.27
cipSecTunHistInDecompOctetsThe total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunInOctets. See also cipSecTunInDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.28
cipSecTunHistHcInDecompOctetsA high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunHcInOctets.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.29
cipSecTunHistInDecompOctWrapsThe number of times the decompressed octets received counter (cipSecTunInDecompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.30
cipSecTunHistInPktsThe total number of packets received by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.31
cipSecTunHistInDropPktsThe total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.32
cipSecTunHistInReplayDropPktsThe total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.33
cipSecTunHistInAuthsThe total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.34
cipSecTunHistInAuthFailsThe total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.35
cipSecTunHistInDecryptsThe total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.36
cipSecTunHistInDecryptFailsThe total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.37
cipSecTunHistOutOctetsThe total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecTunOutOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.38
cipSecTunHistHcOutOctetsA high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.ro
Counter64
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.39
cipSecTunHistOutOctWrapsThe number of times the octets sent counter (cipSecTunOutOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.40
cipSecTunHistOutUncompOctetsThe total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunOutOctets. See also cipSecTunOutDecompOctWraps for the number of times this counter has wrapped.ro
Counter32 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.41
cipSecTunHistHcOutUncompOctetsA high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunHcOutOctets.ro
Counter64 UNITS "Octets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.42
cipSecTunHistOutUncompOctWrapsThe number of times the uncompressed octets sent counter (cipSecTunOutUncompOctets) has wrapped.ro
Counter32 UNITS "Integral units"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.43
cipSecTunHistOutPktsThe total number of packets sent by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.44
cipSecTunHistOutDropPktsThe total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.45
cipSecTunHistOutAuthsThe total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Events"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.46
cipSecTunHistOutAuthFailsThe total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.47
cipSecTunHistOutEncryptsThe total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.48
cipSecTunHistOutEncryptFailsThe total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.ro
Counter32 UNITS "Failures"
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.49
cipSecEndPtHistTableThe IPsec Phase-2 Tunnel Endpoint History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.
SEQUENCE OF CipSecEndPtHistEntry
.1.3.6.1.4.1.9.9.171.1.4.3.2
cipSecEndPtHistEntryEach entry contains the attributes associated with a previously active IPsec Phase-2 Tunnel Endpoint.
CipSecEndPtHistEntry
.1.3.6.1.4.1.9.9.171.1.4.3.2.1
cipSecEndPtHistIndexThe number of the previously active Endpoint associated with a IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.1
cipSecEndPtHistTunIndexThe index of the previously active IPsec Phase-2 Tunnel Table.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.2
cipSecEndPtHistActiveIndexThe index of the previously active Endpoint.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.3
cipSecEndPtHistLocalNameThe DNS name of the local Endpoint.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.4
cipSecEndPtHistLocalTypeThe type of identity for the local Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.ro
EndPtType --INTEGER { --singleIpAddr(1), --ipAddrRange(2), --ipSubnet(3) --}
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.5
cipSecEndPtHistLocalAddr1The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.6
cipSecEndPtHistLocalAddr2The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.7
cipSecEndPtHistLocalProtocolThe protocol number of the local Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.8
cipSecEndPtHistLocalPortThe port number of the local Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.9
cipSecEndPtHistRemoteNameThe DNS name of the remote Endpoint.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.10
cipSecEndPtHistRemoteTypeThe type of identity for the remote Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.ro
EndPtType --INTEGER { --singleIpAddr(1), --ipAddrRange(2), --ipSubnet(3) --}
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.11
cipSecEndPtHistRemoteAddr1The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.12
cipSecEndPtHistRemoteAddr2The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.13
cipSecEndPtHistRemoteProtocolThe protocol number of the remote Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.14
cipSecEndPtHistRemotePortThe port number of the remote Endpoint's traffic.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.15
cipSecFailures
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.5
cipSecFailGlobal
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.5.1
cipSecFailGlobalCntl
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.5.1.1
cipSecFailTableSizeThe window size of the IPsec Phase-1 and Phase-2 Failure Tables. The IPsec Phase-1 and Phase-2 Failure Tables are implemented as a sliding window in which only the last n entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-1 and Phase-2 Failure Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, a BAD VALUE may be returned.rw
Integer32
.1.3.6.1.4.1.9.9.171.1.5.1.1.1
cipSecFailPhaseOne
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.5.2
cikeFailTableThe IPsec Phase-1 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecFailTableSize object.
SEQUENCE OF CikeFailEntry
.1.3.6.1.4.1.9.9.171.1.5.2.1
cikeFailEntryEach entry contains the attributes associated with an IPsec Phase-1 failure.
CikeFailEntry
.1.3.6.1.4.1.9.9.171.1.5.2.1.1
cikeFailIndexThe IPsec Phase-1 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.1
cikeFailReasonThe reason for the failure. Possible reasons include: 1 = other 2 = peer delete request was received 3 = contact with peer was lost 4 = local failure occurred 5 = authentication failure 6 = hash validation failure 7 = encryption failure 8 = internal error occurred 9 = system capacity failure 10 = proposal failure 11 = peer's certificate is unavailable 12 = peer's certificate was found invalid 13 = local certificate expired 14 = certificate revoke list (crl) failure 15 = peer encoding error 16 = non-existent security association 17 = operator requested termination.ro
Enumeration
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.2
cikeFailTimeThe value of sysUpTime in hundredths of seconds at the time of the failure.ro
TimeStamp (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.3
cikeFailLocalTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.4
cikeFailLocalValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.5
cikeFailRemoteTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.ro
IkePeerType
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.6
cikeFailRemoteValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.7
cikeFailLocalAddrThe IP address of the local peer.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.8
cikeFailRemoteAddrThe IP address of the remote peer.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.9
cipSecFailPhaseTwo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.5.3
cipSecFailTableThe IPsec Phase-2 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecFailTableSize object.
SEQUENCE OF CipSecFailEntry
.1.3.6.1.4.1.9.9.171.1.5.3.1
cipSecFailEntryEach entry contains the attributes associated with an IPsec Phase-1 failure.
CipSecFailEntry
.1.3.6.1.4.1.9.9.171.1.5.3.1.1
cipSecFailIndexThe IPsec Phase-2 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.1
cipSecFailReasonThe reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination.ro
Enumeration
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.2
cipSecFailTimeThe value of sysUpTime in hundredths of seconds at the time of the failure.ro
TimeStamp (SNMPv2-TC)
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.3
cipSecFailTunnelIndexThe Phase-2 Tunnel index (cipSecTunIndex).ro
Integer32
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.4
cipSecFailSaSpiThe security association SPI value.ro
Integer32
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.5
cipSecFailPktSrcAddrThe packet's source IP address.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.6
cipSecFailPktDstAddrThe packet's destination IP address.ro
IPSIpAddress
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.7
cipSecTrapCntl
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.1.6
cipSecTrapCntlIkeTunnelStartThis object defines the administrative state of sending the IPsec IKE Phase-1 Tunnel Start TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.1
cipSecTrapCntlIkeTunnelStopThis object defines the administrative state of sending the IPsec IKE Phase-1 Tunnel Stop TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.2
cipSecTrapCntlIkeSysFailureThis object defines the administrative state of sending the IPsec IKE Phase-1 System Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.3
cipSecTrapCntlIkeCertCrlFailureThis object defines the administrative state of sending the IPsec IKE Phase-1 Certificate/CRL Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.4
cipSecTrapCntlIkeProtocolFailThis object defines the administrative state of sending the IPsec IKE Phase-1 Protocol Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.5
cipSecTrapCntlIkeNoSaThis object defines the administrative state of sending the IPsec IKE Phase-1 No Security Association TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.6
cipSecTrapCntlIpSecTunnelStartThis object defines the administrative state of sending the IPsec Phase-2 Tunnel Start TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.7
cipSecTrapCntlIpSecTunnelStopThis object defines the administrative state of sending the IPsec Phase-2 Tunnel Stop TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.8
cipSecTrapCntlIpSecSysFailureThis object defines the administrative state of sending the IPsec Phase-2 System Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.9
cipSecTrapCntlIpSecSetUpFailureThis object defines the administrative state of sending the IPsec Phase-2 Set Up Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.10
cipSecTrapCntlIpSecEarlyTunTermThis object defines the administrative state of sending the IPsec Phase-2 Early Tunnel Termination TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.11
cipSecTrapCntlIpSecProtocolFailThis object defines the administrative state of sending the IPsec Phase-2 Protocol Failure TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.12
cipSecTrapCntlIpSecNoSaThis object defines the administrative state of sending the IPsec Phase-2 No Security Association TRAPrw
TrapStatus
.1.3.6.1.4.1.9.9.171.1.6.13
cipSecMIBNotificationPrefix
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.2
cipSecMIBNotifications
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.2.0
cikeTunnelStartThis notification is generated when an IPsec Phase-1 IKE Tunnel becomes active.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.1
cikeTunnelStopThis notification is generated when an IPsec Phase-1 IKE Tunnel becomes inactive.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.2
cikeSysFailureThis notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences an internal or system capacity error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.3
cikeCertCrlFailureThis notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a Certificate or a Certificate Revoke List (CRL) related error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.4
cikeProtocolFailureThis notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a protocol related error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.5
cikeNoSaThis notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a non-existent security association error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.6
cipSecTunnelStartThis notification is generated when an IPsec Phase-2 Tunnel becomes active.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.7
cipSecTunnelStopThis notification is generated when an IPsec Phase-2 Tunnel becomes inactive.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.8
cipSecSysFailureThis notification is generated when the processing for an IPsec Phase-2 Tunnel experiences an internal or system capacity error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.9
cipSecSetUpFailureThis notification is generated when the setup for an IPsec Phase-2 Tunnel fails.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.10
cipSecEarlyTunTermThis notification is generated when an an IPsec Phase-2 Tunnel is terminated earily or before expected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.11
cipSecProtocolFailureThis notification is generated when the processing for an IPsec Phase-2 Tunnel experiences a protocol related error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.12
cipSecNoSaThis notification is generated when the processing for an IPsec Phase-2 Tunnel experiences a non-existent security association error.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.171.2.0.13
cipSecMIBConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.3
cipSecMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.3.1
cipSecMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.171.3.2