Home/Catalog/JNX-IPSEC-MONITOR-MIB

JNX-IPSEC-MONITOR-MIB

Updated May 31, 2016
AI MIB Summary

Standard SNMP MIB module defining data structures for JNX-IPSEC-MONITOR-MIB.

Main OID:
jnxIpSecMonitorMIB.1.3.6.1.4.1.2636.3.22
80
Objects
Active
Status
6
Dependencies

Imported Objects

Objects

80 total
Object Name
jnxIpSecMonitorMIB
MODULE-IDENTITY
.1.3.6.1.4.1.2636.3.22
jnxIpSecMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.22.1
jnxIpSecLevels
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.22.1.1
jnxIpSecMibLevelThe version of the IPsec MIB.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.1.1
jnxIpSecPhaseOne
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.22.1.2
jnxIkeTunnelTableThe IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
SEQUENCE OF JnxIkeTunnelEntry
.1.3.6.1.4.1.2636.3.22.1.2.1
jnxIkeTunnelEntryEach entry contains the attributes associated with an active IPsec Phase-1 IKE Tunnel.
JnxIkeTunnelEntry
.1.3.6.1.4.1.2636.3.22.1.2.1.1
jnxIkeTunIndexThe index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.2636.3.22.1.2.1.1.1
jnxIkeTunLocalRoleThe role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder.ro
JnxIkePeerRole (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.2
jnxIkeTunNegStateThe state of the current negotiation , It can be 1. matured 2. not maturedro
JnxIkeNegState
.1.3.6.1.4.1.2636.3.22.1.2.1.1.3
jnxIkeTunInitiatorCookieCookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.4
jnxIkeTunResponderCookieCookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.5
jnxIkeTunLocalIdTypeThe type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.ro
JnxIkePeerType (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.6
jnxIkeTunLocalIdValueThe value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.7
jnxIkeTunLocalGwAddrTypeThe IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.8
jnxIkeTunLocalGwAddrThe IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.9
jnxIkeTunLocalCertNameName of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.10
jnxIkeTunRemoteIdTypeThe type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.ro
JnxIkePeerType (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.11
jnxIkeTunRemoteIdValueThe value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.12
jnxIkeTunRemoteGwAddrTypeThe IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.13
jnxIkeTunRemoteGwAddrThe IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.14
jnxIkeTunNegoModeThe negotiation mode of the IPsec Phase-1 IKE Tunnel.ro
JnxIkeNegoMode (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.15
jnxIkeTunDiffHellmanGrpThe Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.ro
JnxDiffHellmanGrp (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.16
jnxIkeTunEncryptAlgoThe encryption algorithm used in IPsec Phase-1 IKE negotiations.ro
JnxEncryptAlgo (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.17
jnxIkeTunHashAlgoThe hash algorithm used in IPsec Phase-1 IKE negotiations.ro
JnxIkeHashAlgo (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.18
jnxIkeTunAuthMethodThe authentication method used in IPsec Phase-1 IKE negotiations.ro
JnxIkeAuthMethod (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.19
jnxIkeTunLifeTimeThe negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.2.1.1.20
jnxIkeTunActiveTimeThe length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.2.1.1.21
jnxIkeTunInOctetsThe total number of octets received by this IPsec Phase-1 IKE security association.ro
Counter64 UNITS "Octets"
.1.3.6.1.4.1.2636.3.22.1.2.1.1.22
jnxIkeTunInPktsThe total number of packets received by this IPsec Phase-1 IKE security association.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.2636.3.22.1.2.1.1.23
jnxIkeTunOutOctetsThe total number of octets sent by this IPsec Phase-1 IKE security association.ro
Counter64 UNITS "Octets"
.1.3.6.1.4.1.2636.3.22.1.2.1.1.24
jnxIkeTunOutPktsThe total number of packets sent by this IPsec Phase-1 IKE security association.ro
Counter32 UNITS "Packets"
.1.3.6.1.4.1.2636.3.22.1.2.1.1.25
jnxIpSecPhaseTwo
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.22.1.3
jnxIpSecTunnelTableThe IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
SEQUENCE OF JnxIpSecTunnelEntry
.1.3.6.1.4.1.2636.3.22.1.3.1
jnxIpSecTunnelEntryEach entry contains the attributes associated with an active IPsec Phase-2 Tunnel.
JnxIpSecTunnelEntry
.1.3.6.1.4.1.2636.3.22.1.3.1.1
jnxIpSecTunIndexThe index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.1.1.1
jnxIpSecRuleNameName of the rule configured in IPSec configuration.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.2
jnxIpSecTermNameName of the term configured under IPSec rule.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.3
jnxIpSecTunLocalGwAddrTypeThe IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.4
jnxIpSecTunLocalGwAddrThe IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.5
jnxIpSecTunRemoteGwAddrTypeThe IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.6
jnxIpSecTunRemoteGwAddrThe IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.7
jnxIpSecTunLocalProxyIdIdentifier for the local end.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.8
jnxIpSecTunRemoteProxyIdIdentifier for the remote end.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.9
jnxIpSecTunKeyTypeThe type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installedro
JnxKeyType (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.10
jnxIpSecRemotePeerTypeThe type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand)ro
JnxRemotePeerType (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.1.1.11
jnxIpSecTunMtuMTU value of this Phase-2 tunnel.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.1.1.12
jnxIpSecTunOutEncryptedBytesNumber of bytes encrypted by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.13
jnxIpSecTunOutEncryptedPktsNumber of packets encrypted by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.14
jnxIpSecTunInDecryptedBytesNumber of bytes decrypted by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.15
jnxIpSecTunInDecryptedPktsNumber of packets decrypted by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.16
jnxIpsSecTunAHInBytesNumber of incoming bytes authenticated using AH by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.17
jnxIpsSecTunAHInPktsNumber of incoming packets authenticated using AH by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.18
jnxIpsSecTunAHOutBytesNumber of outgoing bytes applied AH by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.19
jnxIpsSecTunAHOutPktsNumber of outgoing packets applied AH by this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.20
jnxIpSecTunReplayDropPktsNumber of packets dropped by this Phase-2 tunnel due to anti replay check failure.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.21
jnxIpSecTunAhAuthFailsNumber of packets received by this Phase-2 tunnel that failed AH authentication.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.22
jnxIpSecTunEspAuthFailsNumber of packets received by this Phase-2 tunnel that failed ESP authentication.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.23
jnxIpSecTunDecryptFailsNumber of packets received by this Phase-2 tunnel that failed decryption.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.24
jnxIpSecTunBadHeadersNumber of packets received by this Phase-2 tunnel that failed due to bad headers.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.25
jnxIpSecTunBadTrailersNumber of packets received by this Phase-2 tunnel that failed due to bad ESP trailers.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.26
jnxIpSecTunDroppedPktsTotal number of dropped packets for this Phase-2 tunnel.ro
Counter64
.1.3.6.1.4.1.2636.3.22.1.3.1.1.27
jnxIpSecSaTableThe IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations.
SEQUENCE OF JnxIpSecSaEntry
.1.3.6.1.4.1.2636.3.22.1.3.2
jnxIpSecSaEntryEach entry contains the attributes associated with active and expiring IPsec Phase-2 security associations.
JnxIpSecSaEntry
.1.3.6.1.4.1.2636.3.22.1.3.2.1
jnxIpSecSaProtocolThe index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
Enumeration
.1.3.6.1.4.1.2636.3.22.1.3.2.1.1
jnxIpSecSaIndexThe index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.2.1.2
jnxIpSecSaInSpiThe value of the incoming SPI.ro
JnxSpi
.1.3.6.1.4.1.2636.3.22.1.3.2.1.3
jnxIpSecSaOutSpiThe value of the outgoing SPI.ro
JnxSpi
.1.3.6.1.4.1.2636.3.22.1.3.2.1.4
jnxIpSecSaInAuxSpiThe value of the incoming auxiliary SPI. This is valid for AH and ESP bundles.ro
JnxSpi
.1.3.6.1.4.1.2636.3.22.1.3.2.1.5
jnxIpSecSaOutAuxSpiThe value of the outgoing auxiliary SPI. This is valid for AH and ESP bundles.ro
JnxSpi
.1.3.6.1.4.1.2636.3.22.1.3.2.1.6
jnxIpSecSaTypeThis field represents the type of security associations which can be either manual or dynamicro
JnxSAType (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.2.1.7
jnxIpSecSaEncapModeThe encapsulation mode used by an IPsec Phase-2 Tunnel.ro
JnxEncapMode (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.2.1.8
jnxIpSecSaLifeSizeThe negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.2.1.9
jnxIpSecSaLifeTimeThe negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.2.1.10
jnxIpSecSaActiveTimeThe length of time the IPsec Phase-2 Tunnel has been active in seconds.ro
TimeInterval (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.22.1.3.2.1.11
jnxIpSecSaLifeSizeThresholdThe security association LifeSize refresh threshold in kilobytes.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.2.1.12
jnxIpSecSaLifeTimeThresholdThe security association LifeTime refresh threshold in seconds.ro
Integer32
.1.3.6.1.4.1.2636.3.22.1.3.2.1.13
jnxIpSecSaEncryptAlgoThe Encryption algorithm used to encrypt the packets which can be either es-cbc or 3des-cbc.ro
JnxEncryptAlgo (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.2.1.14
jnxIpSecSaAuthAlgoThe algorithm used for authentication of packets which can be hmac-md5-96 or hmac-sha1-96ro
JnxAuthAlgo (JUNIPER-IPSEC-FLOW-MON-MIB)
.1.3.6.1.4.1.2636.3.22.1.3.2.1.15
jnxIpSecSaStateThis column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.ro
Enumeration
.1.3.6.1.4.1.2636.3.22.1.3.2.1.16
JNX-IPSEC-MONITOR-MIB - SNMP MIB Reference | MIBs Explorer