CISCO-IPSEC-MIB
AI MIB Summary
Standard SNMP MIB module defining data structures for CISCO-IPSEC-MIB.
90
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
90 total| Object Name |
|---|
ciscoIPsecMIB OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62 |
SNMPv2-SMI-v1 Unknown .1.3.6.1.4.1.9.10.62 |
ciscoIPsecMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1 |
cipsIsakmpGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.1 |
cipsIsakmpEnabledThe value of this object is TRUE if ISAKMP
has been enabled on the managed entity. Otherise
the value of this object is FALSE.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.10.62.1.1.1 |
cipsIsakmpIdentityThe value of this object is shows the type of
identity used by the managed entity in ISAKMP
negotiations with another peer.ro IkeIdentityType -- Rsyntax INTEGER { -- isakmpIdTypeUNKNOWN(0), -- isakmpIdTypeADDRESS(1), -- isakmpIdTypeHOSTNAME(2) -- } .1.3.6.1.4.1.9.10.62.1.1.2 |
cipsIsakmpKeepaliveIntervalThe value of this object is time interval in
seconds between successive ISAKMP keepalive
heartbeats issued to the peers to which IKE
tunnels have been setup.ro Integer32 .1.3.6.1.4.1.9.10.62.1.1.3 |
cipsNumIsakmpPoliciesThe value of this object is the number of
ISAKMP policies that have been configured on the
managed entity.ro Integer32 .1.3.6.1.4.1.9.10.62.1.1.4 |
cipsIsakmpPolicyTableThe table containing the list of all
ISAKMP policy entries configured by the operator. SEQUENCE OF CipsIsakmpPolicyEntry .1.3.6.1.4.1.9.10.62.1.1.5 |
cipsIsakmpPolicyEntryEach entry contains the attributes
associated with a single ISAKMP
Policy entry. CipsIsakmpPolicyEntry .1.3.6.1.4.1.9.10.62.1.1.5.1 |
cipsIsakmpPolPriorityThe priotity of this ISAKMP Policy entry.
This is also the index of this table. Integer32 .1.3.6.1.4.1.9.10.62.1.1.5.1.1 |
cipsIsakmpPolEncrThe encryption transform specified by this
ISAKMP policy specification. The Internet Key Exchange
(IKE) tunnels setup using this policy item would
use the specified encryption transform to protect the
ISAKMP PDUs.ro EncryptAlgo -- Rsyntax INTEGER { -- none(1), -- des(2), -- des3(3) -- } .1.3.6.1.4.1.9.10.62.1.1.5.1.2 |
cipsIsakmpPolHashThe hash transform specified by this
ISAKMP policy specification. The IKE tunnels
setup using this policy item would use the
specified hash transform to protect the
ISAKMP PDUs.ro IkeHashAlgo -- Rsyntax INTEGER { -- none(1), -- md5(2), -- sha(3) -- } .1.3.6.1.4.1.9.10.62.1.1.5.1.3 |
cipsIsakmpPolAuthThe peer authentication mthod specified by
this ISAKMP policy specification. If this policy
entity is selected for negotiation with a peer,
the local entity would authenticate the peer using
the method specified by this object.ro IkeAuthMethod -- Rsyntax INTEGER { -- none(1), -- preSharedKey(2), -- rsaSig(3), -- rsaEncrypt(4), -- revPublicKey(5) -- } .1.3.6.1.4.1.9.10.62.1.1.5.1.4 |
cipsIsakmpPolGroupThis object specifies the Oakley group used
for Diffie Hellman exchange in the Main Mode.
If this policy item is selected to negotiate
Main Mode with an IKE peer, the local entity
chooses the group specified by this object to
perform Diffie Hellman exchange with the
peer.ro DiffHellmanGrp -- Rsyntax INTEGER { -- none(1), -- dhGroup1(2), -- dhGroup2(3) -- } .1.3.6.1.4.1.9.10.62.1.1.5.1.5 |
cipsIsakmpPolLifetimeThis object specifies the lifetime in seconds
of the IKE tunnels generated using this
policy specification.ro Integer32 .1.3.6.1.4.1.9.10.62.1.1.5.1.6 |
cipsIPsecGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.2 |
cipsIPsecGlobals OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.2.1 |
cipsSALifetimeThe default lifetime (in seconds) assigned
to an SA as a global policy (maybe overridden
in specific cryptomap definitions).ro CIPsecLifetime -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.1 |
cipsSALifesizeThe default lifesize in KBytes assigned to an SA
as a global policy (unless overridden in cryptomap
definition)ro CIPsecLifesize -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.2 |
cipsNumStaticCryptomapSetsThe number of Cryptomap Sets that are are fully
configured. Statically defined cryptomap sets
are ones where the operator has fully specified
all the parameters required set up IPSec
Virtual Private Networks (VPNs).ro CIPsecNumCryptoMaps -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.3 |
cipsNumCETCryptomapSetsThe number of static Cryptomap Sets that have
at least one CET cryptomap element
as a member of the set.ro CIPsecNumCryptoMaps -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.4 |
cipsNumDynamicCryptomapSetsThe number of dynamic IPSec Policy templates
(called 'dynamic cryptomap templates') configured
on the managed entity.ro CIPsecNumCryptoMaps -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.5 |
cipsNumTEDCryptomapSetsThe number of static Cryptomap Sets that have
at least one dynamic cryptomap template
bound to them which has the Tunnel Endpoint Discovery
(TED) enabled.ro CIPsecNumCryptoMaps -- Rsyntax Gauge32 .1.3.6.1.4.1.9.10.62.1.2.1.6 |
cipsIPsecStatistics OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.2.2 |
cipsNumTEDProbesReceivedThe number of TED probes that were received by this
managed entity since bootup. Not affected by any
CLI operation.ro Counter32 -- Units -- Integral Units .1.3.6.1.4.1.9.10.62.1.2.2.1 |
cipsNumTEDProbesSentThe number of TED probes that were dispatched by all
the dynamic cryptomaps in this managed entity since
bootup. Not affected by any CLI operation.ro Counter32 -- Units -- Integral Units .1.3.6.1.4.1.9.10.62.1.2.2.2 |
cipsNumTEDFailuresThe number of TED probes that were dispatched by
the local entity and that failed to locate crypto
endpoint. Not affected by any CLI operation.ro Counter32 -- Units -- Integral Units .1.3.6.1.4.1.9.10.62.1.2.2.3 |
cipsCryptomapGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.2.3 |
cipsStaticCryptomapSetTableThe table containing the list of all
cryptomap sets that are fully specified
and are not wild-carded.
The operator may include different types of
cryptomaps in such a set - manual, CET,
ISAKMP or dynamic. SEQUENCE OF CipsStaticCryptomapSetEntry .1.3.6.1.4.1.9.10.62.1.2.3.1 |
cipsStaticCryptomapSetEntryEach entry contains the attributes
associated with a single static
cryptomap set. CipsStaticCryptomapSetEntry .1.3.6.1.4.1.9.10.62.1.2.3.1.1 |
cipsStaticCryptomapSetNameThe index of the static cryptomap table. The value
of the string is the name string assigned by the
operator in defining the cryptomap set. DisplayString -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.10.62.1.2.3.1.1.1 |
cipsStaticCryptomapSetSizeThe total number of cryptomap entries contained in
this cryptomap set.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.2 |
cipsStaticCryptomapSetNumIsakmpThe number of cryptomaps associated with this
cryptomap set that use ISAKMP protocol to do key
exchange.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.3 |
cipsStaticCryptomapSetNumManualThe number of cryptomaps associated with this
cryptomap set that require the operator to manually
setup the keys and SPIs.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.4 |
cipsStaticCryptomapSetNumCETThe number of cryptomaps of type 'ipsec-cisco'
associated with this cryptomap set. Such
cryptomap elements implement Cisco Encryption Technology
based Virtual Private Networks.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.5 |
cipsStaticCryptomapSetNumDynamicThe number of dynamic cryptomap templates
linked to this cryptomap set.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.6 |
cipsStaticCryptomapSetNumDiscThe number of dynamic cryptomap templates
linked to this cryptomap set that have Tunnel Endpoint
Discovery (TED) enabled.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.7 |
cipsStaticCryptomapSetNumSAsThe number of and IPsec Security Associations
that are active and were setup using this cryptomap.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.1.1.8 |
cipsDynamicCryptomapSetTableThe table containing the list of all dynamic
cryptomaps that use IKE, defined on
the managed entity. SEQUENCE OF CipsDynamicCryptomapSetEntry .1.3.6.1.4.1.9.10.62.1.2.3.2 |
cipsDynamicCryptomapSetEntryEach entry contains the attributes associated
with a single dynamic cryptomap template. CipsDynamicCryptomapSetEntry .1.3.6.1.4.1.9.10.62.1.2.3.2.1 |
cipsDynamicCryptomapSetNameThe index of the dynamic cryptomap table.
The value of the string is the one assigned
by the operator in defining the cryptomap set. DisplayString -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.10.62.1.2.3.2.1.1 |
cipsDynamicCryptomapSetSizeThe number of cryptomap entries in this cryptomap.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.2.1.2 |
cipsDynamicCryptomapSetNumAssocThe number of static cryptomap sets with which
this dynamic cryptomap is associated.ro Gauge32 .1.3.6.1.4.1.9.10.62.1.2.3.2.1.3 |
cipsStaticCryptomapTableThe table ilisting the member cryptomaps
of the cryptomap sets that are configured
on the managed entity. SEQUENCE OF CipsStaticCryptomapEntry .1.3.6.1.4.1.9.10.62.1.2.3.3 |
cipsStaticCryptomapEntryEach entry contains the attributes
associated with a single static
(fully specified) cryptomap entry.
This table does not include the members
of dynamic cryptomap sets that may be
linked with the parent static cryptomap set. CipsStaticCryptomapEntry .1.3.6.1.4.1.9.10.62.1.2.3.3.1 |
cipsStaticCryptomapPriorityThe priority of the cryptomap entry in the
cryptomap set. This is the second index component
of this table. Integer32 .1.3.6.1.4.1.9.10.62.1.2.3.3.1.1 |
cipsStaticCryptomapTypeThe type of the cryptomap entry. This can be an ISAKMP
cryptomap, CET or manual. Dynamic cryptomaps are not
counted in this table.ro CryptomapType -- Rsyntax INTEGER { -- cryptomapTypeNONE(0), -- cryptomapTypeMANUAL(1), -- cryptomapTypeISAKMP(2), -- cryptomapTypeCET(3), -- cryptomapTypeDYNAMIC(4), -- cryptomapTypeDYNAMICDISCOVERY(5) -- } .1.3.6.1.4.1.9.10.62.1.2.3.3.1.2 |
cipsStaticCryptomapDescrThe description string entered by the operatoir
while creating this cryptomap. The string generally
identifies a description and the purpose of this
policy.ro DisplayString -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.10.62.1.2.3.3.1.3 |
cipsStaticCryptomapPeerThe IP address of the current peer associated with
this IPSec policy item. Traffic that is protected by
this cryptomap is protected by a tunnel that terminates
at the device whose IP address is specified by this
object.ro IPSIpAddress -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.10.62.1.2.3.3.1.4 |
cipsStaticCryptomapNumPeersThe number of peers associated with this cryptomap
entry. The peers other than the one identified by
'cipsStaticCryptomapPeer' are backup peers.
Manual cryptomaps may have only one peer.ro Integer32 .1.3.6.1.4.1.9.10.62.1.2.3.3.1.5 |
cipsStaticCryptomapPfsThis object identifies if the tunnels instantiated
due to this policy item should use Perfect Forward Secrecy
(PFS) and if so, what group of Oakley they should use.ro DiffHellmanGrp -- Rsyntax INTEGER { -- none(1), -- dhGroup1(2), -- dhGroup2(3) -- } .1.3.6.1.4.1.9.10.62.1.2.3.3.1.6 |
cipsStaticCryptomapLifetimeThis object identifies the lifetime of the IPSec
Security Associations (SA) created using this IPSec policy
entry. If this value is zero, the lifetime assumes the
value specified by the global lifetime parameter.ro Integer32(0 | 120..86400) .1.3.6.1.4.1.9.10.62.1.2.3.3.1.7 |
cipsStaticCryptomapLifesizeThis object identifies the lifesize (maximum traffic
in bytes that may be carried) of the IPSec SAs
created using this IPSec policy entry.
If this value is zero, the lifetime assumes the
value specified by the global lifesize parameter.ro Integer32(0 | 2560..536870912) .1.3.6.1.4.1.9.10.62.1.2.3.3.1.8 |
cipsStaticCryptomapLevelHostThis object identifies the granularity of the
IPSec SAs created using this IPSec policy entry.
If this value is TRUE, distinct SA bundles are created
for distinct hosts at the end of the application traffic.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.10.62.1.2.3.3.1.9 |
cipsCryptomapSetIfTableThe table lists the binding of cryptomap sets
to the interfaces of the managed entity. SEQUENCE OF CipsCryptomapSetIfEntry .1.3.6.1.4.1.9.10.62.1.2.3.4 |
cipsCryptomapSetIfEntryEach entry contains the record of
the association between an interface
and a cryptomap set (static) that is defined
on the managed entity.
Note that the cryptomap set identified in
this binding must static. Dynamic cryptomaps cannot
be bound to interfaces. CipsCryptomapSetIfEntry .1.3.6.1.4.1.9.10.62.1.2.3.4.1 |
cipsCryptomapSetIfVirtualThe value of this object identifies if the
interface to which the cryptomap set is attached
is a tunnel (such as a GRE or PPTP tunnel).ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.10.62.1.2.3.4.1.1 |
cipsCryptomapSetIfStatusThis object identifies the status of the binding
of the specified cryptomap set with the specified
interface. The value when queried is always 'attached'.
When set to 'detached', the cryptomap set if detached
from the specified interface. The effect of this is same
as the CLI command
config-if# no crypto map cryptomapSetName
Setting the value to 'attached' will result in
SNMP General Error.rw CryptomapSetBindStatus -- Rsyntax INTEGER { -- unknown(0), -- attached(1), -- detached(2) -- } .1.3.6.1.4.1.9.10.62.1.2.3.4.1.2 |
cipsSysCapacityGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.3 |
cipsMaxSAsThe maximum number of IPsec Security Associations
that can be established on this managed entity.
If no theoretical limit exists, this
returns value 0.
Not affected by any CLI operation.ro INTEGER .1.3.6.1.4.1.9.10.62.1.3.1 |
cips3DesCapableThe value of this object is TRUE if the
managed entity has the hardware nad software
features to support 3DES encryption algorithm.
Not affected by any CLI operation.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.10.62.1.3.2 |
cipsTrapCntlGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.1.4 |
cipsCntlIsakmpPolicyAddedThis object defines the administrative state of
sending the IOS IPsec ISAKMP Policy Add trap.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.1 |
cipsCntlIsakmpPolicyDeletedThis object defines the administrative state of
sending the IOS IPsec ISAKMP Policy Delete trap.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.2 |
cipsCntlCryptomapAddedThis object defines the administrative state of
sending the IOS IPsec Cryptomap Add trap.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.3 |
cipsCntlCryptomapDeletedThis object defines the administrative state of
sending the IOS IPsec Cryptomap Delete trap.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.4 |
cipsCntlCryptomapSetAttachedThis object defines the administrative state of
sending the IOS IPsec trap that is issued
when a cryptomap set is attached to an interface.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.5 |
cipsCntlCryptomapSetDetachedThis object defines the administrative state of
sending the IOS IPsec trap that is issued
when a cryptomap set is detached from an interface.
to which it was earlier bound.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.6 |
cipsCntlTooManySAsThis object defines the administrative state of
sending the IOS IPsec trap that is issued
when the number of SAs crosses the maximum
number of SAs that may be supported on
the managed entity.rw TrapStatus -- Rsyntax INTEGER { -- enabled(1), -- disabled(2) -- } .1.3.6.1.4.1.9.10.62.1.4.7 |
ciscoIPsecMIBNotificationPrefix OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.2 |
cipsMIBNotifications OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.2.0 |
cipsIsakmpPolicyAddedThis trap is generated when a new ISAKMP
policy element is defined on the managed entity.
The context of the event includes the updated
number of ISAKMP policy elements currently available. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.1 |
cipsIsakmpPolicyDeletedThis trap is generated when an existing ISAKMP
policy element is deleted on the managed entity.
The context of the event includes the updated
number of ISAKMP policy elements currently available. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.2 |
cipsCryptomapAddedThis trap is generated when a new cryptomap is
added to the specified cryptomap set. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.3 |
cipsCryptomapDeletedThis trap is generated when a cryptomap is
removed from the specified cryptomap set. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.4 |
cipsCryptomapSetAttachedA cryptomap set must be attached to an interface
of the device in order for it to be operational.
This trap is generated when the cryptomap set
attached to an active interface of the managed entity.
The context of the notification includes:
Size of the attached cryptomap set,
Number of ISAKMP cryptomaps in the set and
Number of Dynamic cryptomaps in the set. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.5 |
cipsCryptomapSetDetachedThis trap is generated when a cryptomap set is
detached from an interafce to which it was
bound earlier. The context of the event identifies the
size of the cryptomap set. TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.6 |
cipsTooManySAsThis trap is generated when a new SA is attempted
to be setup while the number of currently active SAs
equals the maximum configurable. The variables are:
cipsMaxSAs TRAP-TYPE .1.3.6.1.4.1.9.10.62.2.0.7 |
ciscoIPsecMIBConformance OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3 |
cipsMIBConformances OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.1 |
cipsMIBCompliance OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.1.1 |
cipsMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2 |
cipsMIBConfIsakmpGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.1 |
cipsMIBConfIPSecGlobalsGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.2 |
cipsMIBConfCapacityGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.3 |
cipsMIBStaticCryptomapGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.4 |
cipsMIBManualCryptomapGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.5 |
cipsMIBDynamicCryptomapGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.6 |
cipsMIBMandatoryNotifCntlGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.10.62.3.2.7 |