Home/Catalog/HUAWEI-SECURITY-IPSEC-MIB

HUAWEI-SECURITY-IPSEC-MIB

AI MIB Summary

The HUAWEI-SECURITY-IPSEC-MIB provides SNMP-based management and monitoring of IPsec security associations, tunnel states, and cryptographic parameters specifically for Huawei Eudemon and USG firewall series. It enables the collection of operational metrics such as active tunnel counts, negotiation failures, and security policy enforcement status to facilitate real-time troubleshooting and compliance auditing.

V1.00 The IPSec mib is for Eudemon and USG product series.
Main OID:
hwIpsec.1.3.6.1.4.1.2011.6.122.26
120
Objects
Active
Status
3
Dependencies

Imported Objects

Objects

120 total
Object Name
huawei
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011
huaweiUtility
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6
hwSecurity
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122
hwIpsecV1.00 The IPSec mib is for Eudemon and USG product series.
MODULE-IDENTITY
.1.3.6.1.4.1.2011.6.122.26
hwIPSecGlobalStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.1
hwIPSecGlobalTotalTotal number of IPSec tunnels.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.1.1
hwIPSecGlobalPacketInputNumber of received security packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.2
hwIPSecGlobalPacketOutputNumber of sent security packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.3
hwIPSecGlobalByteInputNumber of bytes of received security packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.4
hwIPSecGlobalByteOutputNumber of bytes of sent security packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.5
hwIPSecGlobalDroppedPacketInputNumber of discarded packets that are received.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.6
hwIPSecGlobalDroppedPacketOutputNumber of discarded packets that are sent.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.7
hwIPSecGlobalEncIntactPacketNumber of packets that do not need to be fragmented.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.8
hwIPSecGlobalEncPacketFirstSliceNumber of initial packets to be encrypted.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.9
hwIPSecGlobalEncPacketAfterSliceNumber of follow-up packets to be encrypted.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.10
hwIPSecGlobalDecPacketReassFirstSliceNumber of initial packets that are fragmented and assembled.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.11
hwIPSecGlobalDecPacketReassAfterSliceNumber of follow-up packets that are fragmented and assembled.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.12
hwIPSecGlobalDecPacketReassLenErrNumber of packets with incorrect length during reassembling.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.13
hwIPSecGlobalPacketHeaderWrongNumber of discarded packets caused by the packet header error.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.14
hwIPSecGlobalMemoryApplyFailNumber of discarded packets caused by memory applying failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.15
hwIPSecGlobalCannotFindSANumber of discarded packets caused by no matched security associations.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.16
hwIPSecGlobalWrongSANumber of discarded packets caused by incorrect security associations.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.17
hwIPSecGlobalBadAuthenticationNumber of discarded packets caused by the authentication failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.18
hwIPSecGlobalReplayNumber of discarded packets caused by the packet replay.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.19
hwIPSecGlobalPreRecheckErrNumber of discarded packets caused by the pre-check failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.20
hwIPSecGlobalPostRecheckErrNumber of discarded packets caused by the post-check failurero
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.21
hwIPSecGlobalExceedByteLimitNumber of discarded packets caused by the exceeding of the byte limit.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.22
hwIPSecGlobalExceedPacketLimitNumber of discarded packets caused by the exceeding of the packet limit.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.23
hwIPSecGlobalProcessIpv4ErrNumber of discarded packets caused by the plain-text forwarding failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.24
hwIPSecGlobalFibSearchErrNumber of discarded packets caused by the route check failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.25
hwIPSecGlobalIKEInboundOKNumber of received IKE negotiation packets that successfully enter the queue.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.26
hwIPSecGlobalIKEInboundErrNumber of received IKE negotiation packets that fail to enter the queue.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.27
hwIPSecGlobalIKEOutboundOKNumber of sent IKE negotiation packets that successfully enter the queue.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.28
hwIPSecGlobalIKEOutboundErrNumber of sent IKE negotiation packets that fail to enter the queue.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.29
hwIPSecGlobalSoftExprSoft timeout times.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.30
hwIPSecGlobalHardExprHard timeout times.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.31
hwIPSecGlobalDPDOperDPD operation and detection times.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.32
hwIPSecGlobalModpCntModular exponentiation calculation.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.33
hwIPSecGlobalSaeSuccSAE computing success.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.34
hwIPSecGlobalSoftwareSuccSoftware computing success.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.1.35
hwIPSecTunnelConfigTableThis table specifies the configuration attributes for Huawei IPSec tunnel.
SEQUENCE OF HwIPSecTunnelConfigEntry
.1.3.6.1.4.1.2011.6.122.26.2
hwIPSecTunnelConfigEntryEach entry in the hwIPSecTunnelConfigTable holds a set of monitoring configuration parameters associated with an instance of IPSec tunnel.
HwIPSecTunnelConfigEntry
.1.3.6.1.4.1.2011.6.122.26.2.1
hwIPSecIfIndexIndex of the router interface corresponding to the IPSec tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.1
hwIPSecTunnelPolicyNumID of the ACL rule in the current IPSec policy.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.2
hwIPSecTunnelIndexIndex of the IPSec tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.3
hwIPSecTunnelRuleIdID of the ACL rule in the current IPSec policy.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.4
hwIPSecTunnelDstIPDestination IP address of the tunnel (peer end).ro
IpAddress
.1.3.6.1.4.1.2011.6.122.26.2.1.5
hwIPSecTunnelInsideIPIntranet IP address of the peer end during remote access.ro
IpAddress
.1.3.6.1.4.1.2011.6.122.26.2.1.6
hwIPSecTunnelRemotePortPort number of the peer end of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.7
hwIPSecTunnelCpuIDCPU ID of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.8
hwIPSecTunnelEncapModeEncapsulation mode of the tunnel (tunneling mode or transmission mode).ro
Enumeration
.1.3.6.1.4.1.2011.6.122.26.2.1.9
hwIPSecTunnelNatTraverWhether the tunnel needs NAT traversal (If yes, the value is 1.).ro
Enumeration
.1.3.6.1.4.1.2011.6.122.26.2.1.10
hwIPSecTunnelFromIKEV2Whether the tunnel adopts IKEv2 (If yes, the value is 1.).ro
Enumeration
.1.3.6.1.4.1.2011.6.122.26.2.1.11
hwIPSecTunnelEncryptModeEncryption mode of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.12
hwIPSecTunnelESPDigestModeESP check mode of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.13
hwIPSecTunnelAHDigestModeAH check mode of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.14
hwIPSecTunnelProtoProtocol of the tunnel (ESP or AH, or both).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.15
hwIPSecTunnelOutPortIndexIndex of the egress of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.16
hwIPSecTunnelSrcPortIndicates the source port number if NAT traversal is adopted.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.17
hwIPSecTunnelDstPortIndicates the destination port number if NAT traversal is adopted.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.18
hwIPSecTunnelVrfIndexVPN ID protected by the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.19
hwIPSecTunnelIfVrfIndexVPN ID of the sending interface of the tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.20
hwIPSecTunnelSrcIPSource IP address of the tunnel (local end).ro
IpAddress
.1.3.6.1.4.1.2011.6.122.26.2.1.21
hwIPSecTunnelSpeedLimitInRate limiting pre-configured in the incoming direction.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.22
hwIPSecTunnelSpeedLimitOutRate limiting pre-configured in the outgoing direction.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.23
hwIPSecTunnelInitiatorInitiator or responder of the IPSec tunnel.ro
Enumeration
.1.3.6.1.4.1.2011.6.122.26.2.1.24
hwIPSecTunnelLifeSizeLife cycle of the IPSec tunnel (in kbytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.25
hwIPSecTunnelLifeTimeLife cycle of the IPSec tunnel (in seconds).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.2.1.26
hwIPSecTunnelPolicyNameSecurity policy for the IPSec tunnel.ro
OCTET STRING
.1.3.6.1.4.1.2011.6.122.26.2.1.27
hwIPSecTunnelSaStatusStatus of the SA.ro
Enumeration
.1.3.6.1.4.1.2011.6.122.26.2.1.28
hwIPSecTunnelStatsTableThis table specifies the status attributes for Huawei IPSec tunnel.
SEQUENCE OF HwIPSecTunnelStatsEntry
.1.3.6.1.4.1.2011.6.122.26.3
hwIPSecTunnelStatsEntryEach entry in the hwIPSecTunnelConfigTable holds a set of monitoring status parameters associated with an instance of IPSec tunnel.
HwIPSecTunnelStatsEntry
.1.3.6.1.4.1.2011.6.122.26.3.1
hwIPSecTunnelSaIDInIndex of the incoming IPSec tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.1
hwIPSecTunnelSaIDOutIndex of the outgoing IPSec tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.2
hwIPSecTunnelFlowSoftExpireInIncoming soft timeout traffic (in bytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.3
hwIPSecTunnelFlowSoftExpireOutOutgoing soft timeout traffic (in bytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.4
hwIPSecTunnelFlowHardExpireInIncoming hard timeout traffic (in bytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.5
hwIPSecTunnelFlowHardExpireOutOutgoing hard timeout traffic (in bytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.6
hwIPSecTunnelRemainTimeRemaining time of the IPSec tunnel (in seconds).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.7
hwIPSecTunnelRemainSizeRemaining bytes of the IPSec tunnel (in kbytes).ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.8
hwIPSecTunnelSpiInIncoming SPI.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.9
hwIPSecTunnelSpiOutOutgoing SPI.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.10
hwIPSecTunnelInSideSpiInSPI of the internal ESP header when both AH and ESP are adopted in the incoming direction.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.11
hwIPSecTunnelInSideSpiOutSPI of the internal ESP header when both AH and ESP are adopted in the outgoing direction.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.12
hwIPSecTunnelESPSequenceNumberInSerial number of the incoming ESP protocol.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.13
hwIPSecTunnelESPSequenceNumberOutSerial number of the outgoing ESP protocol.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.14
hwIPSecTunnellAHSequenceNumberInSerial number of the incoming AH protocol.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.15
hwIPSecTunnellAHSequenceNumberOutSerial number of the outgoing AH protocol.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.3.1.16
hwIPSecTunnelMemApplyFailNumber of discarded packets because packets to be encrypted are too long.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.17
hwIPSecTunnelBadAuthNumber of discarded packets caused by the authentication failure of received packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.18
hwIPSecTunnelReplayNumber of discarded packets caused by receiving replayed packets.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.19
hwIPSecTunnelAfterReCheckErrNumber of discarded packets caused by the decryption post-check failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.20
hwIPSecTunnelPktDropByteLimitInNumber of discarded packets caused by the exceeding the byte limit in the incoming direction.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.21
hwIPSecTunnelPktDropByteLimitOutNumber of discarded packets caused by the exceeding of the byte limit in the outgoing direction.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.22
hwIPSecTunnelFIBSearchErrNumber of discarded packets caused by the route check failure.ro
Counter64
.1.3.6.1.4.1.2011.6.122.26.3.1.23
hwIPSecSaStatisticTableThis table specifies the SA numbers of policies which have been bound with interfaces.
SEQUENCE OF HwIPSecSaStatisticEntry
.1.3.6.1.4.1.2011.6.122.26.4
hwIPSecSaStatisticEntry.
HwIPSecSaStatisticEntry
.1.3.6.1.4.1.2011.6.122.26.4.1
hwIPSecSaStatisticTunnelPolicyNameSecurity policy for the IPSec tunnel.ro
OCTET STRING
.1.3.6.1.4.1.2011.6.122.26.4.1.1
hwIPSecSaStatisticSaInCntIncoming SA number.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.4.1.2
hwIPSecSaStatisticSaOutCntOutgoing SA number.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.4.1.3
hwIPSecTrapObject
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.5
hwIPSecTrapTunnelPolicyNumID of the ACL rule in the current IPSec policy.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.5.1
hwIPSecTrapIfIndexIndex of the router interface corresponding to the IPSec tunnel.ro
Gauge32
.1.3.6.1.4.1.2011.6.122.26.5.2
hwIPSecTrapTunnelPolicyNameSecurity policy for the IPSec tunnel.ro
OCTET STRING
.1.3.6.1.4.1.2011.6.122.26.5.3
hwIPSecNotifications
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.6
hwIPSecTunnelStartSend the message when the IPSec tunnel is established.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.1
hwIPSecTunnelStopSend the message when the IPSec tunnel is deleted.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.2
hwIPSecPolicyAddSend the message when an IPSec policy is added.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.3
hwIPSecPolicyDelSend the message when an IPSec policy is deleted.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.4
hwIPSecPolicyAttachSend the message when an IPSec policy is applied to an interface.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.5
hwIPSecPolicyDetachSend the message when an IPSec policy is cancelled on an interface.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.6
hwIPSecIKEResetSend the message when an IKE SA is reset .
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.7
hwIPSecIPSecResetSend the message when an IPSec SA is reset .
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.8
hwIPSecSaReachMaxSend the message when IPSec SA Number will Be Reach Max .
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.9
hwIPSecSaReachMaxAtOnceSend the message when IPSec SA Number Reach Max At Once.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.10
hwIKESaReachMaxSend the message when IKE SA Number will Be Reach Max .
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.11
hwIKESaReachMaxAtOnceSend the message when IKE SA Number will Be Reach Max .
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.6.122.26.6.12
hwIPSecMibConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.7
hwIPSecMibCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.7.1
hwIPSecMibGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.6.122.26.7.2
HUAWEI-SECURITY-IPSEC-MIB - SNMP MIB Reference | MIBs Explorer