Home/Catalog/ONEACCESS-GDOI-MIB

ONEACCESS-GDOI-MIB

AI MIB Summary

ONEACCESS-GDOI-MIB enables the monitoring and management of Group Domain of Interpretation (GDOI) protocol parameters, specifically tracking IPsec Security Association (SA) establishment states, group key distribution events, and cryptographic policy configurations within OneAccess network security gateways.

This MIB module defines objects for managing the GDOI protocol
Main OID:
oacExpIMGdoiMIB.1.3.6.1.4.1.13191.10.3.4.1224
28
Objects
Active
Status
4
Dependencies

Imported Objects

Objects

28 total
Object Name
oacExpIMGdoiMIBThis MIB module defines objects for managing the GDOI protocol
MODULE-IDENTITY
.1.3.6.1.4.1.13191.10.3.4.1224
oacGdoiMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.13191.10.3.4.1224.1
oacGdoiGroupTableA table of information regarding GDOI Groups in use on the network device being queried.
SEQUENCE OF OacGdoiGroupEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.1
oacGdoiGroupEntryAn entry containing GDOI Group information, uniquely identified by the GDOI Group ID.
OacGdoiGroupEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1
oacGdoiGroupNameThe string-readable name configured for or given to a GDOI Group.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.1
oacGdoiGroupIdTypeThe Identification Type Value used to parse a GDOI Group ID. The GDOI RFC 3547 defines the types that can be used as a GDOI Group ID, and RFC 4306 defines all valid types that can be used as an identifier.ro
OacGdoiIdentificationType
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.2
oacGdoiGroupIdValueThe value of a Group ID with its type indicated by the oacGdoiGroupIdType. Use the oacGdoiGroupIdType to parse the Group ID correctly. This Group ID value is sent as the 'Identification Data' field of the Identification Payload for a GDOI GROUPKEY-PULL exchange.ro
OacGdoiIdentificationValue
.1.3.6.1.4.1.13191.10.3.4.1224.1.1.1.3
oacGdoiGm
OBJECT IDENTIFIER
.1.3.6.1.4.1.13191.10.3.4.1224.1.2
oacGdoiGmTableA table of information regarding GDOI Group Members (GMs) locally configured on the network device being queried. Note that Local Group Members may or may not be registered to a Key Server in its GDOI Group on the same network device being queried.
SEQUENCE OF OacGdoiGmEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2
oacGdoiGmEntryAn entry containing Local GDOI Group Member information, uniquely identified by Group & GM IDs. Because the Group Member is Local to the network device being queried, TEKs installed for this Group Member can be queried as well.
OacGdoiGmEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1
oacGdoiGmIdTypeThe Identification Type Value used to parse the identity information for a Initiator or Group Member. RFC 4306 defines all valid types that can be used as an identifier. These identification types are sent as the 'SRC ID Type' and 'DST ID Type' of the KEK and TEK payloads for GDOI GROUPKEY-PULL and GROUPKEY-PUSH exchanges.ro
OacGdoiIdentificationType
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.1
oacGdoiGmIdValueThe value of the identity information for a Group Member with its type indicated by the oacGdoiGmIdType. Use the oacGdoiGmIdType to parse the Group Member ID correctly. This Group Member ID value is sent as the 'SRC Identification Data' and 'DST Identification Data' of the KEK and TEK payloads for GDOI GROUPKEY-PULL and GROUPKEY-PUSH exchanges.ro
OacGdoiIdentificationValue
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.2
oacGdoiGmRegKeyServerIdValueThe value of the identity information for this Group Member's registered Key Server with its type indicated by the oacGdoiGmRegKeyServerIdType. Use the oacGdoiGmRegKeyServerIdType to parse the registered Key Server's ID correctly. This Key Server ID value is sent as the 'SRC Identification Data' and 'DST Identification Data' of the KEK and TEK payloads for GDOI GROUPKEY-PULL and GROUPKEY-PUSH exchanges.ro
OacGdoiIdentificationValue
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.3
oacGdoiGmActiveKEKThe SPI of the Key Encryption Key (KEK) that is currently being used by the Group Member to authenticate & decrypt a rekey from a GROUPKEY-PUSH message.ro
OacGdoiSPI
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.4
oacGdoiGmRekeysReceivedThe sequence number of the last rekey successfully received from this Group Member's registered Key Server.ro
Counter32 UNITS "GROUPKEY-PUSH Messages"
.1.3.6.1.4.1.13191.10.3.4.1224.1.2.2.1.5
oacGdoiPolicy
OBJECT IDENTIFIER
.1.3.6.1.4.1.13191.10.3.4.1224.1.3
oacGdoiGmKekTableA table of information regarding GDOI Key Encryption Key (KEK) Security Associations (SAs) currently installed for GDOI entities acting as Group Members on the network device being queried. There is one entry in this table for each KEK SA that has been installed and not yet deleted. Each KEK SA is uniquely identified by a SPI at any given time.
SEQUENCE OF OacGdoiGmKekEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2
oacGdoiGmKekEntryAn entry containing the attributes associated with a GDOI KEK SA, uniquely identified by the Group ID, Group Member (GM) ID, & SPI value assigned by the GM's registered Key Server to the KEK. There will be at least one KEK SA entry for each GM & two KEK SA entries for a given GM only during a KEK rekey when a new KEK is received & installed. The KEK SPI is unique for every KEK for a given Group Member.
OacGdoiGmKekEntry
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1
oacGdoiGmKekSPIThe value of the Security Parameter Index (SPI) of a KEK SA. The SPI must be the ISAKMP Header cookie pair where the first 8 octets become the 'Initiator Cookie' field of the GROUPKEY-PUSH message ISAKMP HDR, and the second 8 octets become the 'Responder Cookie' in the same HDR. As described above, these cookies are assigned by the GCKS.ro
OacGdoiSPI
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.1
oacGdoiGmKekSrcIdValueThe value of the identity information for the source of a KEK SA with its type indicated by the oacGdoiGmKekSrcIdType. Use the oacGdoiGmKekSrcIdType to parse the KEK Source ID correctly. This ID value is sent as the 'SRC Identification Data' of a KEK payload.ro
OacGdoiIdentificationValue
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.2
oacGdoiGmKekDstIdValueThe value of the identity information for the destination of a KEK SA (multicast rekey address) with its type indicated by oacGdoiGmKekDstIdType. Use the oacGdoiGmKekDstIdType to parse the KEK Dest. ID correctly. This ID value is sent as the 'DST Identification Data' of a KEK payload.ro
OacGdoiIdentificationValue
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.3
oacGdoiGmKekEncryptAlgThe value of the KEK_ALGORITHM which specifies the encryption algorithm used with the KEK SA. A GDOI implementaiton must support KEK_ALG_3DES. Following are the KEK encryption algoritm values defined in the GDOI RFC 3547, however the oacGdoiEncryptionAlgorithm TC defines all possible values. Algorithm Type Value -------------- ----- KEK_ALG_DES 1 KEK_ALG_3DES 2 KEK_ALG_AES 3ro
OacGdoiKEKEncryptionAlgorithm
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.4
oacGdoiGmKekEncryptKeyLengthThe value of the KEK_KEY_LENGTH which specifies the KEK Algorithm key length (in bits).ro
Unsigned32 UNITS "Bits"
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.5
oacGdoiGmKekSigHashAlgThe value of the SIG_HASH_ALGORITHM which specifies the SIG payload hash algorithm. This is not required (i.e. could have a value of zero) if the SIG_ALGORITHM is SIG_ALG_DSS or SIG_ALG_ECDSS, which imply SIG_HASH_SHA1 (i.e. must have a value of zero or SIG_HASH_SHA1)ro
OacGdoiHashAlogrithm
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.6
oacGdoiGmKekSigAlgThe value of the SIG_ALGORITHM which specifies the SIG payload signature algorithm. A GDOI implementation must support SIG_ALG_RSAro
OacGdoiSignatureMethod
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.7
oacGdoiGmKekSigKeyLengthThe value of the SIG_KEY_LENGTH which specifies the length of the SIG payload key.ro
Unsigned32 UNITS "Bits"
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.8
oacGdoiGmKekOriginalLifetimeThe value of the KEK_KEY_LIFETIME which specifies the maximum time for which a KEK is valid. The GCKS may refresh the KEK at any time before the end of the valid period. The value is a four (4) octet (32-bit) number defining a valid time period in seconds.ro
Unsigned32 UNITS "Seconds"
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.9
oacGdoiGmKekRemainingLifetimeThe value of the remaining time for which a KEK is valid. The value is a four (4) octet (32-bit) number which begins at the value of oacGdoiGmKekOriginalLifetime and counts down to 0 in seconds. If the lifetime has already expired, this value should remain at zero (0) until the GCKS refreshes the KEK.ro
Unsigned32 UNITS "Seconds"
.1.3.6.1.4.1.13191.10.3.4.1224.1.3.2.1.10
ONEACCESS-GDOI-MIB - SNMP MIB Reference | MIBs Explorer