WATCHGUARD-IPSEC-SA-MON-MIB-EXT
AI MIB Summary
The WATCHGUARD-IPSEC-SA-MON-MIB-EXT module enables monitoring of IPSec Security Association states and statistics on WatchGuard firewalls, extending the IETF IPsec Monitor MIB to track SA establishment, termination, and traffic volume counters.
The MIB module describes generic IPSec objects defined in IETF working draft 'draft-ieft-ipsec-monitor-mib-01' and WatchGuard's extension.
Main OID:
wgIpsecSaMonModule.1.3.6.1.4.1.3097.3
156
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
156 total| Object Name |
|---|
wgIpsecSaMonModuleThe MIB module describes generic IPSec objects
defined in IETF working draft
'draft-ieft-ipsec-monitor-mib-01' and WatchGuard's
extension. MODULE-IDENTITY .1.3.6.1.4.1.3097.3 |
wgIpsecSaMonitorMIBThis is the base object identifier for all IPSec branches. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.3.1 |
wgSaTablesThis is the base object identifier for all SA tables. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.3.1.1 |
wgIpsecSaEspInTableThe (conceptual) table containing information on IPSec
inbound ESP SAs.
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaEspInEntry .1.3.6.1.4.1.3097.3.1.1.1 |
wgIpsecSaEspInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaEspInEntry .1.3.6.1.4.1.3097.3.1.1.1.1 |
wgIpsecSaEspInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.1.1.1 |
wgIpsecSaEspInSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.1.1.2 |
wgIpsecSaEspInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchanged during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.1.1.3 |
wgIpsecSaEspInDestIdTypeThe type of identifier presented by 'wgIpsecSaEspInDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.1.1.4 |
wgIpsecSaEspInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.1.1.5 |
wgIpsecSaEspInSourceIdTypeThe type of identifier presented by 'wgIpsecSaEspInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.1.1.6 |
wgIpsecSaEspInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.1.1.7 |
wgIpsecSaEspInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.1.1.8 |
wgIpsecSaEspInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.1.1.9 |
wgIpsecSaEspInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.1.1.10 |
wgIpsecSaEspInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.1.1.11 |
wgIpsecSaEspInEncAlgA unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.ro IpsecDoiEspTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.1.1.12 |
wgIpsecSaEspInEncKeyLengthThe length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspInEncAlg' object, or 0
if the key length is implicit in the specified algorithm or
there is no encryption specified.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.1.1.13 |
wgIpsecSaEspInAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAuthAlgorithm (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.1.1.14 |
wgIpsecSaEspInLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.1.1.15 |
wgIpsecSaEspInLimitKbytesThe maximum traffic in kilobytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.1.1.16 |
wgIpsecSaEspInAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.1.1.17 |
wgIpsecSaEspInAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.1.1.18 |
wgIpsecSaEspInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.1.1.19 |
wgIpsecSaEspInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.20 |
wgIpsecSaEspInDecryptErrorsThe number of packets discarded by the SA due to decryption
errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.21 |
wgIpsecSaEspInAuthErrorsThe number of packets discarded by the SA due to
authentication errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.22 |
wgIpsecSaEspInReplayErrorsThe number of packets discarded by the SA due to replay
errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.23 |
wgIpsecSaEspInPolicyErrorsThe number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.24 |
wgIpsecSaEspInPadErrorsThe number of packets discarded by the SA due to pad value
errors.
Implementations that do not check this must not support this
object.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.25 |
wgIpsecSaEspInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to congestion
at the decryption element.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.1.1.26 |
wgIpsecSaAhInTableThe (conceptual) table containing information on IPSec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaAhInEntry .1.3.6.1.4.1.3097.3.1.1.2 |
wgIpsecSaAhInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaAhInEntry .1.3.6.1.4.1.3097.3.1.1.2.1 |
wgIpsecSaAhInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.2.1.1 |
wgIpsecSaAhInSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.2.1.2 |
wgIpsecSaAhInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.2.1.3 |
wgIpsecSaAhInDestIdTypeThe type of identifier presented by 'wgIpsecSaAhInDestId', or
0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.2.1.4 |
wgIpsecSaAhInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.2.1.5 |
wgIpsecSaAhInSourceIdTypeThe type of identifier presented by 'wgIpsecSaAhInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.2.1.6 |
wgIpsecSaAhInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.2.1.7 |
wgIpsecSaAhInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.2.1.8 |
wgIpsecSaAhInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.2.1.9 |
wgIpsecSaAhInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.2.1.10 |
wgIpsecSaAhInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.2.1.11 |
wgIpsecSaAhInAuthAlgA unique value representing the hash algorithm applied to
traffic carried by this SA if it uses ESP or 0 if there is
no authentication applied by ESP.ro IpsecDoiAhTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.2.1.12 |
wgIpsecSaAhInLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.2.1.13 |
wgIpsecSaAhInLimitKbytesThe maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.2.1.14 |
wgIpsecSaAhInAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.2.1.15 |
wgIpsecSaAhInAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.2.1.16 |
wgIpsecSaAhInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.2.1.17 |
wgIpsecSaAhInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.2.1.18 |
wgIpsecSaAhInAuthErrorsThe number of packets discarded by the SA due to
authentication errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.2.1.19 |
wgIpsecSaAhInReplayErrorsThe number of packets discarded by the SA due to replay
errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.2.1.20 |
wgIpsecSaAhInPolicyErrorsThe number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.2.1.21 |
wgIpsecSaAhInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to congestion
at the authentication element.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.2.1.22 |
wgIpsecSaIpcompInTableThe (conceptual) table containing information on IPSec
inbound IPCOMP SAs.
There should be one row for every inbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaIpcompInEntry .1.3.6.1.4.1.3097.3.1.1.3 |
wgIpsecSaIpcompInEntryAn entry (conceptual row) containing the information on a
particular IPSec inbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaIpcompInEntry .1.3.6.1.4.1.3097.3.1.1.3.1 |
wgIpsecSaIpcompInAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.3.1.1 |
wgIpsecSaIpcompInCpiThe CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.3.1.2 |
wgIpsecSaIpcompInDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode, or 0 if this SA is used with
multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during SA creation
negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.3.1.3 |
wgIpsecSaIpcompInDestIdTypeThe type of identifier presented by
'wgIpsecSaIpcompInDestId', or 0 if unknown or if the SA uses
transport mode, or 0 if this SA is used with multiple SAs in
protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.3.1.4 |
wgIpsecSaIpcompInSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during SA creation
negotiation.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.3.1.5 |
wgIpsecSaIpcompInSourceIdTypeThe type of identifier presented by
'wgIpsecSaIpcompInSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.3.1.6 |
wgIpsecSaIpcompInProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.3.1.7 |
wgIpsecSaIpcompInDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.3.1.8 |
wgIpsecSaIpcompInSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.3.1.9 |
wgIpsecSaIpcompInCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.3.1.10 |
wgIpsecSaIpcompInEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.3.1.11 |
wgIpsecSaIpcompInDecompAlgA unique value representing the decompression algorithm
applied to traffic.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.3.1.12 |
wgIpsecSaIpcompInSecondsThe number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.3.1.13 |
wgIpsecSaIpcompInUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.3.1.14 |
wgIpsecSaIpcompInPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.3.1.15 |
wgIpsecSaIpcompInDecompErrorsThe number of packets discarded by the SA due to
decompression errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.3.1.16 |
wgIpsecSaIpcompInOtherReceiveErrorsThe number of packets discarded by the SA due to errors
other than decompression errors. This may include packets
dropped due to a lack of receive buffers, and packets
dropped due to congestion at the decompression element.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.3.1.17 |
wgIpsecSaEspOutTableThe (conceptual) table containing information on IPSec
Outbound ESP SAs.
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaEspOutEntry .1.3.6.1.4.1.3097.3.1.1.4 |
wgIpsecSaEspOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaEspOutEntry .1.3.6.1.4.1.3097.3.1.1.4.1 |
wgIpsecSaEspOutAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.4.1.1 |
wgIpsecSaEspOutSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.4.1.2 |
wgIpsecSaEspOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.4.1.3 |
wgIpsecSaEspOutSourceIdTypeThe type of identifier presented by
'wgIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.4.1.4 |
wgIpsecSaEspOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.4.1.5 |
wgIpsecSaEspOutDestIdTypeThe type of identifier presented by 'wgIpsecSaEspOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.4.1.6 |
wgIpsecSaEspOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.4.1.7 |
wgIpsecSaEspOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.4.1.8 |
wgIpsecSaEspOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.4.1.9 |
wgIpsecSaEspOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.4.1.10 |
wgIpsecSaEspOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.4.1.11 |
wgIpsecSaEspOutEncAlgA unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.ro IpsecDoiEspTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.4.1.12 |
wgIpsecSaEspOutEncKeyLengthThe length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspOutEncAlg' object, or
0 if the key length is implicit in the specified algorithm
or there is no encryption specified.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.4.1.13 |
wgIpsecSaEspOutAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAuthAlgorithm (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.4.1.14 |
wgIpsecSaEspOutLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.4.1.15 |
wgIpsecSaEspOutLimitKbytesThe maximum traffic in kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.4.1.16 |
wgIpsecSaEspOutAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.4.1.17 |
wgIpsecSaEspOutAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.4.1.18 |
wgIpsecSaEspOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.4.1.19 |
wgIpsecSaEspOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.4.1.20 |
wgIpsecSaEspOutSendErrorsThe number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.4.1.21 |
wgIpsecSaAhOutTableThe (conceptual) table containing information on IPSec
Outbound AH SAs.
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaAhOutEntry .1.3.6.1.4.1.3097.3.1.1.5 |
wgIpsecSaAhOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaAhOutEntry .1.3.6.1.4.1.3097.3.1.1.5.1 |
wgIpsecSaAhOutAddressThe destination address of the SA.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.5.1.1 |
wgIpsecSaAhOutSpiThe security parameters index of the SA.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.5.1.2 |
wgIpsecSaAhOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.5.1.3 |
wgIpsecSaAhOutSourceIdTypeThe type of identifier presented by 'wgIpsecSaAhOutSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.5.1.4 |
wgIpsecSaAhOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.
This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.5.1.5 |
wgIpsecSaAhOutDestIdTypeThe type of identifier presented by 'wgIpsecSaAhOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.5.1.6 |
wgIpsecSaAhOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.5.1.7 |
wgIpsecSaAhOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.5.1.8 |
wgIpsecSaAhOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.5.1.9 |
wgIpsecSaAhOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.5.1.10 |
wgIpsecSaAhOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.5.1.11 |
wgIpsecSaAhOutAuthAlgA unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.ro IpsecDoiAhTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.5.1.12 |
wgIpsecSaAhOutLimitSecondsThe maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncated.ro Integer32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.5.1.13 |
wgIpsecSaAhOutLimitKbytesThe maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.
The display value is limited to 4294967295 kilobytes; values
greater than that value will be truncated.ro Integer32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.5.1.14 |
wgIpsecSaAhOutAccSecondsThe number of seconds accumulated against the SA's
expiration by time.
This is also the number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.5.1.15 |
wgIpsecSaAhOutAccKbytesThe amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.ro Counter32 UNITS "kilobytes" .1.3.6.1.4.1.3097.3.1.1.5.1.16 |
wgIpsecSaAhOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.5.1.17 |
wgIpsecSaAhOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.5.1.18 |
wgIpsecSaAhOutSendErrorsThe number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.5.1.19 |
wgIpsecSaIpcompOutTableThe (conceptual) table containing information on IPSec
Outbound IPCOMP SAs.
There should be one row for every outbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent. SEQUENCE OF WGIpsecSaIpcompOutEntry .1.3.6.1.4.1.3097.3.1.1.6 |
wgIpsecSaIpcompOutEntryAn entry (conceptual row) containing the information on a
particular IPSec Outbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table. WGIpsecSaIpcompOutEntry .1.3.6.1.4.1.3097.3.1.1.6.1 |
wgIpsecSaIpcompOutAddressThe destination address of the SA.
If the IPCOMP SA is shared across multiple SAs in protection
suites, this value may be 0.
For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is
used for IPv4 only nodes, while the prefix
'0000:0000:0000:0000:0000:0000:' is used for bi-lingual
nodes.ro IpAddress .1.3.6.1.4.1.3097.3.1.1.6.1.1 |
wgIpsecSaIpcompOutCpiThe CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.6.1.2 |
wgIpsecSaIpcompOutSourceIdThe source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.6.1.3 |
wgIpsecSaIpcompOutSourceIdTypeThe type of identifier presented by
'wgIpsecSaIpcompOutSourceId', or 0 if unknown or if the SA
uses transport mode encapsulation, or 0 if this SA is used
with multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.6.1.4 |
wgIpsecSaIpcompOutDestIdThe destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.
This value, if non-zero, is taken directly from the optional
ID payloads that are exchange during phase 2 negotiations.ro OCTET STRING .1.3.6.1.4.1.3097.3.1.1.6.1.5 |
wgIpsecSaIpcompOutDestIdTypeThe type of identifier presented by
'wgIpsecSaIpcompOutDestId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.ro IpsecDoiIdentType (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.6.1.6 |
wgIpsecSaIpcompOutProtocolThe transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.3097.3.1.1.6.1.7 |
wgIpsecSaIpcompOutSourcePortThe source port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.6.1.8 |
wgIpsecSaIpcompOutDestPortThe destination port number of the protocol that this SA
carries, or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.3097.3.1.1.6.1.9 |
wgIpsecSaIpcompOutCreatorThe creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.ro IpsecSaCreatorIdent .1.3.6.1.4.1.3097.3.1.1.6.1.10 |
wgIpsecSaIpcompOutEncapsulationThe type of encapsulation used by this SA.ro IpsecDoiEncapsulationMode (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.6.1.11 |
wgIpsecSaIpcompOutCompAlgA unique value representing the compression algorithm
applied to traffic.ro IpsecDoiIpcompTransform (IPSEC-ISAKMP-IKE-DOI-TC) .1.3.6.1.4.1.3097.3.1.1.6.1.12 |
wgIpsecSaIpcompOutSecondsThe number of seconds that the SA has existed.ro Counter32 UNITS "seconds" .1.3.6.1.4.1.3097.3.1.1.6.1.13 |
wgIpsecSaIpcompOutUserOctetsThe amount of user level traffic measured in bytes handled
by the SA.
This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.ro Counter32 UNITS "bytes" .1.3.6.1.4.1.3097.3.1.1.6.1.14 |
wgIpsecSaIpcompOutPacketsThe number of packets handled by the SA.ro Counter32 .1.3.6.1.4.1.3097.3.1.1.6.1.15 |
wgSaStatisticsThis is the base object identifier for all objects which
are global counters for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.3.1.2 |
wgIpsecEspCurrentInboundSAsThe current number of inbound ESP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.1 |
wgIpsecEspTotalInboundSAsThe total number of inbound ESP SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.2 |
wgIpsecEspCurrentOutboundSAsThe current number of outbound ESP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.3 |
wgIpsecEspTotalOutboundSAsThe total number of outbound ESP SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.4 |
wgIpsecAhCurrentInboundSAsThe current number of inbound AH SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.5 |
wgIpsecAhTotalInboundSAsThe total number of inbound AH SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.6 |
wgIpsecAhCurrentOutboundSAsThe current number of outbound AH SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.7 |
wgIpsecAhTotalOutboundSAsThe total number of outbound AH SAs created in the entity
since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.8 |
wgIpsecIpcompCurrentInboundSAsThe current number of inbound IPCOMP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.9 |
wgIpsecIpcompTotalInboundSAsThe total number of inbound IPCOMP SAs created in the
entity since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.10 |
wgIpsecIpcompCurrentOutboundSAsThe current number of outbound IPCOMP SAs in the entity.ro Gauge32 .1.3.6.1.4.1.3097.3.1.2.11 |
wgIpsecIpcompTotalOutboundSAsThe total number of outbound IPCOMP SAs created in the
entity since boot time.ro Counter32 .1.3.6.1.4.1.3097.3.1.2.12 |
wgSaErrorsThis is the base object identifier for all objects which
are global error counters for IPSec security associations. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.3.1.3 |
wgIpsecDecryptionErrorsThe total number of packets received by the entity in SAs
since boot time with decryption errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.1 |
wgIpsecAuthenticationErrorsThe total number of packets received by the entity in SAs
since boot time with authentication errors.
This includes all packets in which the hash value is
determined to be invalid, for both ESP and AH SAs.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.2 |
wgIpsecReplayErrorsThe total number of packets received by the entity in SAs
since boot time with replay errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.3 |
wgIpsecPolicyErrorsThe total number of packets received by the entity in SAs
since boot time and discarded due to policy errors. This
includes packets that had selectors that were invalid for
the SA that carried them.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.4 |
wgIpsecOtherReceiveErrorsThe total number of packets received by the entity in SAs
since boot time and discarded due to errors not due to
decryption, authentication, replay or policy.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.5 |
wgIpsecSendErrorsThe total number of packets to be sent by the entity in SAs
since boot time and discarded due to errors.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.6 |
wgIpsecUnknownSpiErrorsThe total number of packets received by the entity since
boot time with SPIs or CPIs that were not valid.ro Counter32 .1.3.6.1.4.1.3097.3.1.3.7 |