WATCHGUARD-IPSEC-TUNNEL-MIB
The WATCHGUARD-IPSEC-TUNNEL-MIB enables monitoring and management of IPsec tunnel interface states, traffic counters, and security association parameters on WatchGuard firewalls. It provides granular visibility into tunnel establishment status, packet throughput, and error statistics for troubleshooting encrypted site-to-site or remote access connections.
Imported Objects
Objects
48 total| Object Name |
|---|
wgInfoModuleThe MIB module describes various tunnel objects of WatchGuard system. MODULE-IDENTITY .1.3.6.1.4.1.3097.6 |
wgIpsecTunnelMIBThis is the base object identifier for all tunnel branches. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.6.5 |
wgIpsecTunnelThis is the base object identifier for all tunnel information. OBJECT IDENTIFIER .1.3.6.1.4.1.3097.6.5.1 |
wgIpsecTunnelNumThe total number of entries in the wgIpsecTunnelTable.ro Unsigned32 .1.3.6.1.4.1.3097.6.5.1.1 |
wgIpsecTunnelTableThis is the connection table describing all current tunnels exist on this entity. SEQUENCE OF WGIpsecTunnelEntry .1.3.6.1.4.1.3097.6.5.1.2 |
wgIpsecTunnelEntryAn entry (conceptual row) containing the information on a tunnel between two security gateways. WGIpsecTunnelEntry .1.3.6.1.4.1.3097.6.5.1.2.1 |
wgIpsecTunnelIDThe running index of this tunnel.ro Integer32 .1.3.6.1.4.1.3097.6.5.1.2.1.1 |
wgIpsecTunnelLocalAddrThe local IP address of the current tunnel.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.2 |
wgIpsecTunnelPeerAddrThe remote IP address of the current tunnel.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.3 |
wgIpsecTunnelInSpiThe security parameters index of inbound SA's within this tunnel.ro Integer32 .1.3.6.1.4.1.3097.6.5.1.2.1.4 |
wgIpsecTunnelOutSpiThe security parameters index of outbound SA's within this tunnel.ro Integer32 .1.3.6.1.4.1.3097.6.5.1.2.1.5 |
wgIpsecTunnelCreateTimeThe date and time when the tunnel is created.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.3097.6.5.1.2.1.6 |
wgIpsecTunnelDeviceIDThe identifier of target device where the SA resides.ro Unsigned32 .1.3.6.1.4.1.3097.6.5.1.2.1.7 |
wgIpsecTunnelEspEncryptAlgThe encryption algorithm used in the tunnel. It's 0 if ESP is not used.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.8 |
wgIpsecTunnelEspAuthAlgThe authentication algorithm used in the tunnel. It's 0 if ESP is not used.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.9 |
wgIpsecTunnelAhAuthAlgThe AH authentication algorithm used in the tunnel. It's 0 if AH is not used.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.10 |
wgIpsecTunnelModeThe tunnel/transport mode of the tunnel.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.11 |
wgIpsecTunnelKeyModeThe key mode of the tunnel.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.12 |
wgIpsecTunnelLifeTimeThe life time (in hundredths of a second) of the tunnel.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.3097.6.5.1.2.1.13 |
wgIpsecTunnelLifeLengthThe maximum traffic in bytes that the tunnel is allowed to support.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.14 |
wgIpsecTunnelInSaBytesCurrent active inbound SA bytes of the tunnel.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.15 |
wgIpsecTunnelOutSaBytesCurrent active outbound SA bytes of the tunnel.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.16 |
wgIpsecTunnelAccSecsThe number of seconds that the tunnel has existed.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.17 |
wgIpsecTunnelSelectorProtocolThe ip protocol number that this SA selector carries, or 0 if it carries any protocol.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.18 |
wgIpsecTunnelSelectorRemoteIPTypeThe type of remote IP address of the SA selector in the entity.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.19 |
wgIpsecTunnelSelectorRemoteIPOneThe first remote IP address of the SA selector in the entity. It's IP address if remote IP of this selector only has one address. It's IP address of subnet if the remote IP of this selector is IP subnet. It's the start IP address if the remote IP of this selector has a range of addresses.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.20 |
wgIpsecTunnelSelectorRemoteIPTwoThe second remote IP address of the SA selector in the entity. It's 0 if remote IP of this selector only has one address. It's netmask of subnet if the remote IP of this selector is IP subnet. It's the end IP address if the remote IP of this selector has a range of addresses.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.21 |
wgIpsecTunnelSelectorRemotePortThe remote port used by this selector in the entity.ro INTEGER .1.3.6.1.4.1.3097.6.5.1.2.1.22 |
wgIpsecTunnelSelectorLocalIPTypeThe type of local IP address of the SA selector in the entity.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.23 |
wgIpsecTunnelSelectorLocalIPOneThe first local IP address of the SA selector in the entity. It's IP address if local IP of this selector only has one address. It's IP address of subnet if the local IP of this selector is IP subnet. It's the start IP address if the local IP of this selector has a range of IP addresses.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.24 |
wgIpsecTunnelSelectorLocalIPTwoThe second local IP address of the SA selector in the entity. It's 0 if local IP of this selector only has one address. It's netmask of subnet if the local IP of this selector is IP subnet. It's the end IP address if the local IP of this selector has a range of IP addresses.ro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.25 |
wgIpsecTunnelSelectorLocalPortThe local port used by this selector in the entity.ro INTEGER .1.3.6.1.4.1.3097.6.5.1.2.1.26 |
wgIpsecTunnelNumRekeyThe number of rekeys of the tunnel.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.27 |
wgIpsecTunnelInKbytesTotal inbound traffic in Kbytes since the establish of this tunnel.ro Counter32 UNITS "Kbytes" .1.3.6.1.4.1.3097.6.5.1.2.1.28 |
wgIpsecTunnelOutKbytesTotal outound traffic in Kbytes since the establish of this connection.ro Counter32 UNITS "Kbytes" .1.3.6.1.4.1.3097.6.5.1.2.1.29 |
wgIpsecTunnelInPacketsTotal number of inbound packets since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.30 |
wgIpsecTunnelOutPacketsTotal number of outound packets since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.31 |
wgIpsecTunnelInDecryptErrorsTotal number of packets discarded due to decryption error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.32 |
wgIpsecTunnelInAuthErrorsTotal number of packets discarded due to authentication error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.33 |
wgIpsecTunnelInReplayErrorsTotal number of packets discarded due to replay error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.34 |
wgIpsecTunnelInOtherErrorsThe number of packets discarded due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the decryption element.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.35 |
wgIpsecTunnelOutDecryptErrorsTotal number of packets discarded due to decryption error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.36 |
wgIpsecTunnelOutAuthErrorsTotal number of packets discarded due to authentication error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.37 |
wgIpsecTunnelOutReplayErrorsTotal number of packets discarded due to replay error since the establish of this connection.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.38 |
wgIpsecTunnelOutOtherErrorsThe number of packets discarded due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the decryption element.ro Counter32 .1.3.6.1.4.1.3097.6.5.1.2.1.39 |
wgIpsecTunnelUdpEncapIndicates whether if UDP encapsulated IPSec has been enabled.ro Enumeration .1.3.6.1.4.1.3097.6.5.1.2.1.40 |
wgIpsecTunnelPeerUdpPortThe peer's UDP port of current tunnel when UDP encapsulated IPSec is enabled.ro INTEGER .1.3.6.1.4.1.3097.6.5.1.2.1.41 |
wgIpsecTunnelOrigPeerAddrThe original peer ip address of current tunnel when UDP encapsulated IPSec is enabledro IpAddress .1.3.6.1.4.1.3097.6.5.1.2.1.42 |
More MIBs from Watchguard
Browse all WatchguardMIBs →The WATCHGUARD-IPSEC-SA-MON-MIB-EXT module enables monitoring of IPSec Security Association states and statistics on WatchGuard firewalls, extending the IETF IPsec Monitor MIB to track SA establishment, termination, and traffic volume counters.
The WATCHGUARD-IPSEC-ENDPOINT-PAIR-MIB monitors WatchGuard security gateways to aggregate and report the status of IPSec Security Associations (SAs) between specific pairs of gateway IP addresses. It provides the data required to construct a topological view of IPSec tunnels by tracking the count and state of tunnel-mode SAs established between any two external IP endpoints.
The WATCHGUARD-PRODUCTS-MIB provides object identifiers for monitoring and managing WatchGuard firewall hardware, enabling the collection of critical performance metrics such as interface traffic counters, session states, CPU utilization, memory usage, and system health status via SNMP.
The WATCHGUARD-CLIENT-MIB facilitates the monitoring and management of endpoint client status, connection states, and security posture data within WatchGuard Firebox and XTM appliance environments via SNMP. This module enables administrators to track active client sessions, authentication states, and client-specific policy enforcement metrics for centralized network visibility.
The WATCHGUARD-HA-MIB module facilitates the monitoring of high availability cluster states and failover events on WatchGuard firewalls, specifically tracking HA synchronization status, node roles, and link health to ensure continuous service availability.
The WATCHGUARD-POLICY-MIB enables SNMP-based monitoring and management of WatchGuard firewall policy configurations, including rule definitions, policy states, and associated traffic control parameters. This module facilitates the retrieval of specific policy objects to verify rule enforcement and audit security settings on WatchGuard network security appliances.