RAPID-IPSEC-SA-MON-MIB-EXT
AI MIB Summary
RAPID-IPSEC-SA-MON-MIB-EXT enables the monitoring of IPsec Security Association (SA) states and traffic statistics on RapidStream hardware or software appliances, extending the IETF IPsec MIB standard with vendor-specific attributes for SA lifecycle and performance tracking.
The MIB module describes generic IPSec objects defined in IETF working draft 'draft-ieft-ipsec-monitor-mib-01' and RapidStream's extension.
Main OID:
rsIpsecSaMonModule.1.3.6.1.4.1.4355.3
179
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
179 total| Object Name |
|---|
rsIpsecSaMonModuleThe MIB module describes generic IPSec objects
defined in IETF working draft
'draft-ieft-ipsec-monitor-mib-01' and RapidStream's
extension. MODULE-IDENTITY .1.3.6.1.4.1.4355.3 |
rsIpsecSaMonitorMIBThis is the base object identifier for all IPSec branches. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1 |
rsSaTablesThis is the base object identifier for all SA tables. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.1 |
rsIpsecSaEspInTableThe (conceptual) table containing information on IPSec
inbound ESP SAs.
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaEspInEntry .1.3.6.1.4.1.4355.3.1.1.1 |
rsIpsecSaEspInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaEspInEntry .1.3.6.1.4.1.4355.3.1.1.1.1 |
rsIpsecSaEspInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.1.1.1 |
rsIpsecSaEspInSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.1.1.2 |
rsIpsecSaEspInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchanged during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.1.1.3 |
rsIpsecSaEspInDestIdTypeThe type of identifier presented by 'rsIpsecSaEspInDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.1.1.4 |
rsIpsecSaEspInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.1.1.5 |
rsIpsecSaEspInSourceIdTypeThe type of identifier presented by 'rsIpsecSaEspInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.1.1.6 |
rsIpsecSaEspInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.1.1.7 |
rsIpsecSaEspInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.1.1.8 |
rsIpsecSaEspInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.1.1.9 |
rsIpsecSaEspInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.1.1.10 |
rsIpsecSaEspInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.1.1.11 |
rsIpsecSaEspInEncAlgA unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.ro IpsecDoiEspTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.1.1.12 |
rsIpsecSaEspInEncKeyLengthThe length of the encryption key in bits used for the
algorithm specified in the 'rsIpsecSaEspInEncAlg' object, or 0
if the key length is implicit in the specified algorithm or
there is no encryption specified.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.1.1.13 |
rsIpsecSaEspInAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAuthAlgorithm (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.1.1.14 |
rsIpsecSaEspInLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.1.1.15 |
rsIpsecSaEspInLimitKbytesThe maximum traffic in kilobytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.1.1.16 |
rsIpsecSaEspInAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.1.1.17 |
rsIpsecSaEspInAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.1.1.18 |
rsIpsecSaEspInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.1.1.19 |
rsIpsecSaEspInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.20 |
rsIpsecSaEspInDecryptErrorsThe number of packets discarded by the SA due to decryption
errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.21 |
rsIpsecSaEspInAuthErrorsThe number of packets discarded by the SA due to
authentication errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.22 |
rsIpsecSaEspInReplayErrorsThe number of packets discarded by the SA due to replay
errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.23 |
rsIpsecSaEspInPolicyErrorsThe number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.24 |
rsIpsecSaEspInPadErrorsThe number of packets discarded by the SA due to pad value
errors.
Implementations that do not check this must not support this
object.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.25 |
rsIpsecSaEspInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to congestion
at the decryption element.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.1.1.26 |
rsIpsecSaAhInTableThe (conceptual) table containing information on IPSec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaAhInEntry .1.3.6.1.4.1.4355.3.1.1.2 |
rsIpsecSaAhInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaAhInEntry .1.3.6.1.4.1.4355.3.1.1.2.1 |
rsIpsecSaAhInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.2.1.1 |
rsIpsecSaAhInSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.2.1.2 |
rsIpsecSaAhInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.2.1.3 |
rsIpsecSaAhInDestIdTypeThe type of identifier presented by 'rsIpsecSaAhInDestId', or
0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.2.1.4 |
rsIpsecSaAhInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.2.1.5 |
rsIpsecSaAhInSourceIdTypeThe type of identifier presented by 'rsIpsecSaAhInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.2.1.6 |
rsIpsecSaAhInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.2.1.7 |
rsIpsecSaAhInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.2.1.8 |
rsIpsecSaAhInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.2.1.9 |
rsIpsecSaAhInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.2.1.10 |
rsIpsecSaAhInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.2.1.11 |
rsIpsecSaAhInAuthAlgA unique value representing the hash algorithm applied to
traffic carried by this SA if it uses ESP or 0 if there is
no authentication applied by ESP.ro IpsecDoiAhTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.2.1.12 |
rsIpsecSaAhInLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.2.1.13 |
rsIpsecSaAhInLimitKbytesThe maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.2.1.14 |
rsIpsecSaAhInAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.2.1.15 |
rsIpsecSaAhInAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.2.1.16 |
rsIpsecSaAhInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.2.1.17 |
rsIpsecSaAhInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.2.1.18 |
rsIpsecSaAhInAuthErrorsThe number of packets discarded by the SA due to
authentication errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.2.1.19 |
rsIpsecSaAhInReplayErrorsThe number of packets discarded by the SA due to replay
errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.2.1.20 |
rsIpsecSaAhInPolicyErrorsThe number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.2.1.21 |
rsIpsecSaAhInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to congestion
at the authentication element.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.2.1.22 |
rsIpsecSaIpcompInTableThe (conceptual) table containing information on IPSec
inbound IPCOMP SAs.
There should be one row for every inbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaIpcompInEntry .1.3.6.1.4.1.4355.3.1.1.3 |
rsIpsecSaIpcompInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaIpcompInEntry .1.3.6.1.4.1.4355.3.1.1.3.1 |
rsIpsecSaIpcompInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.3.1.1 |
rsIpsecSaIpcompInCpiThe CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.3.1.2 |
rsIpsecSaIpcompInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode, or 0 if this SA is used with
multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during SA creation
negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.3.1.3 |
rsIpsecSaIpcompInDestIdTypeThe type of identifier presented by
'rsIpsecSaIpcompInDestId', or 0 if unknown or if the SA uses
transport mode, or 0 if this SA is used with multiple SAs in
protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.3.1.4 |
rsIpsecSaIpcompInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during SA creation
negotiation.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.3.1.5 |
rsIpsecSaIpcompInSourceIdTypeThe type of identifier presented by
'rsIpsecSaIpcompInSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.3.1.6 |
rsIpsecSaIpcompInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.3.1.7 |
rsIpsecSaIpcompInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.3.1.8 |
rsIpsecSaIpcompInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.3.1.9 |
rsIpsecSaIpcompInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.3.1.10 |
rsIpsecSaIpcompInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.3.1.11 |
rsIpsecSaIpcompInDecompAlgA unique value representing the decompression algorithm
applied to traffic.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.3.1.12 |
rsIpsecSaIpcompInSecondsThe number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.3.1.13 |
rsIpsecSaIpcompInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.3.1.14 |
rsIpsecSaIpcompInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.3.1.15 |
rsIpsecSaIpcompInDecompErrorsThe number of packets discarded by the SA due to
decompression errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.3.1.16 |
rsIpsecSaIpcompInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decompression errors. This may include packets
dropped due to a lack of receive buffers, and packets
dropped due to congestion at the decompression element.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.3.1.17 |
rsIpsecSaEspOutTableThe (conceptual) table containing information on IPSec
Outbound ESP SAs.
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaEspOutEntry .1.3.6.1.4.1.4355.3.1.1.4 |
rsIpsecSaEspOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaEspOutEntry .1.3.6.1.4.1.4355.3.1.1.4.1 |
rsIpsecSaEspOutAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.4.1.1 |
rsIpsecSaEspOutSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.4.1.2 |
rsIpsecSaEspOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.4.1.3 |
rsIpsecSaEspOutSourceIdTypeThe type of identifier presented by
'rsIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.4.1.4 |
rsIpsecSaEspOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.4.1.5 |
rsIpsecSaEspOutDestIdTypeThe type of identifier presented by 'rsIpsecSaEspOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.4.1.6 |
rsIpsecSaEspOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.4.1.7 |
rsIpsecSaEspOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.4.1.8 |
rsIpsecSaEspOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.4.1.9 |
rsIpsecSaEspOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.4.1.10 |
rsIpsecSaEspOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.4.1.11 |
rsIpsecSaEspOutEncAlgA unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.ro IpsecDoiEspTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.4.1.12 |
rsIpsecSaEspOutEncKeyLengthThe length of the encryption key in bits used for the
algorithm specified in the 'rsIpsecSaEspOutEncAlg' object, or
0 if the key length is implicit in the specified algorithm
or there is no encryption specified.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.4.1.13 |
rsIpsecSaEspOutAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAuthAlgorithm (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.4.1.14 |
rsIpsecSaEspOutLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.4.1.15 |
rsIpsecSaEspOutLimitKbytesThe maximum traffic in kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.4.1.16 |
rsIpsecSaEspOutAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.4.1.17 |
rsIpsecSaEspOutAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.4.1.18 |
rsIpsecSaEspOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.4.1.19 |
rsIpsecSaEspOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.4.1.20 |
rsIpsecSaEspOutSendErrorsThe number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.4.1.21 |
rsIpsecSaAhOutTableThe (conceptual) table containing information on IPSec
Outbound AH SAs.
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaAhOutEntry .1.3.6.1.4.1.4355.3.1.1.5 |
rsIpsecSaAhOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaAhOutEntry .1.3.6.1.4.1.4355.3.1.1.5.1 |
rsIpsecSaAhOutAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.5.1.1 |
rsIpsecSaAhOutSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.5.1.2 |
rsIpsecSaAhOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.5.1.3 |
rsIpsecSaAhOutSourceIdTypeThe type of identifier presented by 'rsIpsecSaAhOutSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.5.1.4 |
rsIpsecSaAhOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.5.1.5 |
rsIpsecSaAhOutDestIdTypeThe type of identifier presented by 'rsIpsecSaAhOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.5.1.6 |
rsIpsecSaAhOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.5.1.7 |
rsIpsecSaAhOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.5.1.8 |
rsIpsecSaAhOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.5.1.9 |
rsIpsecSaAhOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.5.1.10 |
rsIpsecSaAhOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.5.1.11 |
rsIpsecSaAhOutAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAhTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.5.1.12 |
rsIpsecSaAhOutLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.5.1.13 |
rsIpsecSaAhOutLimitKbytesThe maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.5.1.14 |
rsIpsecSaAhOutAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.5.1.15 |
rsIpsecSaAhOutAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.4355.3.1.1.5.1.16 |
rsIpsecSaAhOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.5.1.17 |
rsIpsecSaAhOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.5.1.18 |
rsIpsecSaAhOutSendErrorsThe number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.5.1.19 |
rsIpsecSaIpcompOutTableThe (conceptual) table containing information on IPSec
Outbound IPCOMP SAs.
There should be one row for every outbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF RSIpsecSaIpcompOutEntry .1.3.6.1.4.1.4355.3.1.1.6 |
rsIpsecSaIpcompOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. RSIpsecSaIpcompOutEntry .1.3.6.1.4.1.4355.3.1.1.6.1 |
rsIpsecSaIpcompOutAddressThe destination address of the SA.
If the IPCOMP SA is shared across multiple SAs in protection
suites, this value may be 0.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.4355.3.1.1.6.1.1 |
rsIpsecSaIpcompOutCpiThe CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.6.1.2 |
rsIpsecSaIpcompOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.6.1.3 |
rsIpsecSaIpcompOutSourceIdTypeThe type of identifier presented by
'rsIpsecSaIpcompOutSourceId', or 0 if unknown or if the SA
uses transport mode encapsulation, or 0 if this SA is used
with multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.6.1.4 |
rsIpsecSaIpcompOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.4355.3.1.1.6.1.5 |
rsIpsecSaIpcompOutDestIdTypeThe type of identifier presented by
'rsIpsecSaIpcompOutDestId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.6.1.6 |
rsIpsecSaIpcompOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.4355.3.1.1.6.1.7 |
rsIpsecSaIpcompOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.6.1.8 |
rsIpsecSaIpcompOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.4355.3.1.1.6.1.9 |
rsIpsecSaIpcompOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.4355.3.1.1.6.1.10 |
rsIpsecSaIpcompOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.6.1.11 |
rsIpsecSaIpcompOutCompAlgA unique value representing the compression algorithm
applied to traffic.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.1.6.1.12 |
rsIpsecSaIpcompOutSecondsThe number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.4355.3.1.1.6.1.13 |
rsIpsecSaIpcompOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.4355.3.1.1.6.1.14 |
rsIpsecSaIpcompOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.4355.3.1.1.6.1.15 |
rsSaStatisticsThis is the base object identifier for all objects which
are global counters for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.2 |
rsIpsecEspCurrentInboundSAsThe current number of inbound ESP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.1 |
rsIpsecEspTotalInboundSAsThe total number of inbound ESP SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.2 |
rsIpsecEspCurrentOutboundSAsThe current number of outbound ESP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.3 |
rsIpsecEspTotalOutboundSAsThe total number of outbound ESP SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.4 |
rsIpsecAhCurrentInboundSAsThe current number of inbound AH SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.5 |
rsIpsecAhTotalInboundSAsThe total number of inbound AH SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.6 |
rsIpsecAhCurrentOutboundSAsThe current number of outbound AH SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.7 |
rsIpsecAhTotalOutboundSAsThe total number of outbound AH SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.8 |
rsIpsecIpcompCurrentInboundSAsThe current number of inbound IPCOMP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.9 |
rsIpsecIpcompTotalInboundSAsThe total number of inbound IPCOMP SAs created in the
entity since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.10 |
rsIpsecIpcompCurrentOutboundSAsThe current number of outbound IPCOMP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.4355.3.1.2.11 |
rsIpsecIpcompTotalOutboundSAsThe total number of outbound IPCOMP SAs created in the
entity since boot time.ro Counter32 .1.3.6.1.4.1.4355.3.1.2.12 |
rsSaErrorsThis is the base object identifier for all objects which
are global error counters for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.3 |
rsIpsecDecryptionErrorsThe total number of packets received by the entity in SAs
since boot time with decryption errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.1 |
rsIpsecAuthenticationErrorsThe total number of packets received by the entity in SAs
since boot time with authentication errors.
This includes all packets in which the hash value is
determined to be invalid, for both ESP and AH SAs.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.2 |
rsIpsecReplayErrorsThe total number of packets received by the entity in SAs
since boot time with replay errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.3 |
rsIpsecPolicyErrorsThe total number of packets received by the entity in SAs
since boot time and discarded due to policy errors. This
includes packets that had selectors that were invalid for
the SA that carried them.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.4 |
rsIpsecOtherReceiveErrorsThe total number of packets received by the entity in SAs
since boot time and discarded due to errors not due to
decryption, authentication, replay or policy.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.5 |
rsIpsecSendErrorsThe total number of packets to be sent by the entity in SAs
since boot time and discarded due to errors.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.6 |
rsIpsecUnknownSpiErrorsThe total number of packets received by the entity since
boot time with SPIs or CPIs that were not valid.ro Counter32 .1.3.6.1.4.1.4355.3.1.3.7 |
rsSaTrapsThis is the base object identifier for all objects which
are traps for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.4 |
rsEspAuthFailureTrapIPSec packets with invalid hashes were found in an inbound
ESP SA. The total number of authentication errors
accumulated is sent for the specific row of the
'rsIpsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.1 |
rsAhAuthFailureTrapIPSec packets with invalid hashes were found in an inbound
AH SA. The total number of authentication errors accumulated
is sent for the specific row of the 'rsIpsecSaAhInTable' table
for the SA; this provides the identity of the SA in which
the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.2 |
rsEspReplayFailureTrapIPSec packets with invalid sequence numbers were found in
an inbound ESP SA. The total number of replay errors
accumulated is sent for the specific row of the
'rsIpsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.3 |
rsAhReplayFailureTrapIPSec packets with invalid sequence numbers were found in
the specified AH SA. The total number of replay errors
accumulated is sent for the specific row of the
'rsIpsecSaAhInTable' table for the SA; this provides the
identity of the SA in which the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.4 |
rsEspPolicyFailureTrapIPSec packets carrying packets with invalid selectors for
the specified ESP SA were found. The total number of policy
errors accumulated is sent for the specific row of the
'rsIpsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.5 |
rsAhPolicyFailureTrapIPSec packets carrying packets with invalid selectors for
the specified AH SA were found. The total number of policy
errors accumulated is sent for the specific row of the
'rsIpsecSaAhInTable' table for the SA; this provides the
identity of the SA in which the error occurred.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.6 |
rsInvalidSpiTrapA packet with an unknown SPI was detected from the
specified peer with the specified SPI using the specified
protocol. The destination address of the received packet is
specified by 'ipsecLocalAddress'.
The value 'ifIndex' may be 0 if this optional linkage is
unsupported.
If the object 'ipsecSecurityProtocol' has the value for
IPCOMP, then the 'ipsecSPI' object is the CPI of the packet.
Implementations SHOULD send one trap per peer (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.4355.3.1.4.0.7 |
rsSaTrapObjectsThis is the base object identifier for objects which are
used as part of traps. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.5 |
rsIpsecSecurityProtocolA security protocol associated with the trap.ro IpsecDoiSecProtocolId (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.4355.3.1.5.1 |
rsIpsecSPIAn SPI associated with a trap. Where the security protocol
associated with the trap is IPCOMP, this value has a maximum
of 65535.ro Integer32 .1.3.6.1.4.1.4355.3.1.5.2 |
rsIpsecLocalAddressA local IP address associated with the trap.ro IpAddress .1.3.6.1.4.1.4355.3.1.5.3 |
rsIpsecPeerAddressA peer IP address associated with the trap.ro IpAddress .1.3.6.1.4.1.4355.3.1.5.4 |
rsSaTrapControlThis is the base object identifier for all objects which
are trap controls for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.6 |
rsEspAuthFailureTrapEnableIndicates whether espAuthFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.1 |
rsAhAuthFailureTrapEnableIndicates whether ahAuthFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.2 |
rsEspReplayFailureTrapEnableIndicates whether espReplayFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.3 |
rsAhReplayFailureTrapEnableIndicates whether ahReplayFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.4 |
rsEspPolicyFailureTrapEnableIndicates whether espPolicyFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.5 |
rsAhPolicyFailureTrapEnableIndicates whether ahPolicyFailureTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.6 |
rsInvalidSpiTrapEnableIndicates whether invalidSpiTrap traps should be
generated.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.4355.3.1.6.7 |
rsSaGroupsThis is the base object identifier for all objects which
describe the groups in this MIB. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.7 |
rsSaConformanceThis is the base object identifier for all objects which
describe the conformance for this MIB. OBJECT IDENTIFIER .1.3.6.1.4.1.4355.3.1.8 |