snmpV2
The MIB module to describe generic IPSec objects, transient and permanent virtual tunnels created by IPSec SAs, and entity level IPSec objects and events.
Main OID:
ipsecMIB.1.3.6.1.4.1.1022.10
144
Objects
Active
Status
3
Dependencies
Imported Objects
Objects
144 total| Object Name |
|---|
ipsecMIBThe MIB module to describe generic IPSec objects,
transient and permanent virtual tunnels created by IPSec
SAs, and entity level IPSec objects and events. MODULE-IDENTITY .1.3.6.1.4.1.1022.10 |
ipsecMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1 |
ipsec OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1 |
ipsecIkeSaTableThe (conceptual) table containing information on IPSec's
IKE SAs. SEQUENCE OF IpsecIkeSaEntry .1.3.6.1.4.1.1022.10.1.1.1 |
ipsecIkeSaEntryAn entry (conceptual row) containing the information on
a particular IKE SA. IpsecIkeSaEntry .1.3.6.1.4.1.1022.10.1.1.1.1 |
ipsecIkeSaIndexA unique value, greater than zero, for each tunnel
interface. It is recommended that values are assigned
contiguously starting from 1.
The value for each tunnel interface must remain constant
at least from one re-initialization of entity's network
management system to the next re-initialization.
Further, the value for tunnel interfaces that are marked
as permanent must remain constant across all re-
initializations of the network management system.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.1 |
ipsecIkeSaPeerIpAddressThe IP address of the peer that this SA was negotiated
with, or 0 if unknown.ro IpAddress .1.3.6.1.4.1.1022.10.1.1.1.1.2 |
ipsecIkeSaPeerPortNumberThe port number of the peer that this SA was negotiated
with, or 0 if the default ISAKMP port number (500).ro INTEGER .1.3.6.1.4.1.1022.10.1.1.1.1.3 |
ipsecIkeSaAuthMethodThe authentication method used to authenticate the
peers.
Note that this does not include the specific method of
authentication if extended authenticated is used.
Specific values are used as described in the ISAKMP Class
Values of Authentication Method from Appendix A of
[IKE].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.4 |
ipsecIkeSaPeerIdTypeThe type of ID used by the peer.
Specific values are used as described in Section 4.6.2.1
of [IPDOI].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.5 |
ipsecIkeSaPeerIdThe ID of the peer this SA was negotiated with.
The length may require truncation under some conditions.ro OCTET STRING .1.3.6.1.4.1.1022.10.1.1.1.1.6 |
ipsecIkeSaPeerCertSerialNumThe serial number of the certificate of the peer this SA
was negotiated with.
This object has no meaning if a certificate was not used
in authenticating the peer.ro OCTET STRING .1.3.6.1.4.1.1022.10.1.1.1.1.7 |
ipsecIkeSaPeerCertIssuerThe serial number of the certificate of the peer this SA
was negotiated with.
This object has no meaning if a certificate was not used
in authenticating the peer.ro OCTET STRING .1.3.6.1.4.1.1022.10.1.1.1.1.8 |
ipsecIkeSaTypeThe type of virtual tunnel represented by this row.
A transient link will disappear from the table when
the SAs needed for it cannot be established. A
permanent link will shows its status in the
ipsecIkeSaStatus object.ro Enumeration .1.3.6.1.4.1.1022.10.1.1.1.1.9 |
ipsecIkeSaStatusThe status of the virtual tunnel represented by this
row, if the tunnel is configured as permanent.
'neverTried' means that no attempt to set-up the link
has been done. 'linkUp' means that the link is up and
operating normally. 'linkDown' means that the link was
up, but has gone down.ro Enumeration .1.3.6.1.4.1.1022.10.1.1.1.1.10 |
ipsecIkeSaEncAlgA unique value representing the encryption algorithm
applied to traffic carried by this SA or 0 if there
is no encryption applied.
Specific values are used as described in the ISAKMP
Class Values of Encryption Algorithms from Appendix A
of [IKE].ro INTEGER .1.3.6.1.4.1.1022.10.1.1.1.1.11 |
ipsecIkeSaEncKeyLengthThe length of the encryption key in bits used for
algorithm specified in the ipsecIkeSaEncAlg object or 0
if the key length is implicit in the specified
algorithm or there is no encryption specified.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.12 |
ipsecIkeSaHashAlgA unique value representing the hash algorithm applied
to traffic carried by this SA or 0 if there is no
encryption applied.
Specific values are used as described in the ISAKMP Class
Values of Hash Algorithms from Appendix A of [IKE].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.13 |
ipsecIkeSaDifHelGroupDescA unique value representing the Diffie-Hellman group
description used or 0 if the group is unknown.
Specific values are used as described in the ISAKMP Class
Values of Group Description from Appendix A of [IKE].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.14 |
ipsecIkeSaDifHelGroupTypeA unique value representing the Diffie-Hellman group
type used or 0 if the group is unknown.
Specific values are used as described in the ISAKMP Class
Values of Group Type from Appendix A of [IKE].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.15 |
ipsecIkeSaDifHelFieldSizeThe field size, in bits, of a Diffie-Hellman group.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.16 |
ipsecIkeSaPRFThe pseudo-random functions used, or 0 if not used or if
unknown.
Specific values are used as described in the ISAKMP Class
Values of PRF from Appendix A of [IKE] (which specifies
none at the present time).ro Integer32 .1.3.6.1.4.1.1022.10.1.1.1.1.17 |
ipsecIkeSaPFSA value that indicates that perfect forward secrecy is
used for all IPSec SAs created by this IKE SA.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.1022.10.1.1.1.1.18 |
ipsecIkeSaInitiatorCookieThe value of the cookie used by the initiator for the
current phase 1 SA.ro OCTET STRING .1.3.6.1.4.1.1022.10.1.1.1.1.19 |
ipsecIkeSaResponderCookieThe value of the cookie used by the responder for the
current phase 1 SA.ro OCTET STRING .1.3.6.1.4.1.1022.10.1.1.1.1.20 |
ipsecIkeSaTimeStartThe date and time that the current SA within the link
was set up.
It is not the date and time that the virtual tunnel was
set up.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.1022.10.1.1.1.1.21 |
ipsecIkeSaTimeLimitThe maximum lifetime in seconds of the current SA
supporting the virtual tunnel, or 0 if there is no time
constraint on its expiration.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.1.1.22 |
ipsecIkeSaTrafficLimitThe maximum traffic in 1024-byte blocks that the current
SA supporting the virtual tunnel is allowed to support,
or 0 if there is no traffic constraint on its
expiration.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.1.1.23 |
ipsecIkeSaInboundTrafficThe amount traffic measured in bytes handled in the
current SA in the inbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.24 |
ipsecIkeSaOutboundTrafficThe amount traffic measured in bytes handled in the
current SA in the outbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.25 |
ipsecIkeSaInboundPacketsThe number of packets handled in the current SA in the
inbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.26 |
ipsecIkeSaOutboundPacketsThe number of packets handled in the current SA in the
outbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.27 |
ipsecIkeSaTotalSaNumThe total number of SAs, including the current SA, that
have been set up to support this virtual tunnel.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.28 |
ipsecIkeSaFirstTimeStartThe data and time that this virtual tunnel was
originally set up.
It is not the time that the current SA was set up.
If this is a permanent virtual tunnel, it is reset when
the tunnel goes to the 'linkUp' state.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.1022.10.1.1.1.1.29 |
ipsecIkeSaTotalInboundTrafficThe total amount of traffic measured in bytes handled in
the tunnel in the inbound direction. In other words, it
is the aggregate value of all inbound traffic carried by
all SAs ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.30 |
ipsecIkeSaTotalOutboundTrafficThe total amount of traffic measured in bytes handled in
the tunnel in the outbound direction. In other words, it
is the aggregate value of all inbound traffic carried by
all SAs ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.31 |
ipsecIkeSaTotalInboundPacketsThe total number of packets handled by the virtual
tunnel since it became active in the inbound direction.
In other words, it is the aggregate value of the number
of inbound packets carried by all SAs ever set up to
support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.32 |
ipsecIkeSaTotalOutboundPacketsThe total number of packets handled by the virtual
tunnel since it became active in the outbound direction.
In other words, it is the aggregate value of the number
of outbound packets carried by all SAs ever set up to
support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.33 |
ipsecIkeSaDecryptErrorsThe total number of inbound packets to this SA discarded
due to decryption errors.
Note that this refers to IKE protocol packets, and not to
packets carried by SAs set up by the SAs supporting this
tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.34 |
ipsecIkeSaHashErrorsThe total number of inbound packets to this SA discarded
due to hash errors.
Note that this refers to IKE protocol packets, and not to
packets carried by SAs set up by the SAs supporting this
tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.35 |
ipsecIkeSaOtherReceiveErrorsThe total number of inbound packets to this SA discarded
for reasons other than bad hashes or decryption errors.
This may include packets dropped to a lack of receive
buffer space.
Note that this refers to IKE protocol packets, and not to
packets carried by SAs set up by the SAs supporting this
tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.36 |
ipsecIkeSaSendErrorsThe total number of outbound packets from this SA
discarded for any reason. This may include packets
dropped to a lack of transmit buffer space.
Note that this refers to IKE protocol packets, and not to
packets carried by SAs set up by the SAs supporting this
tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.37 |
ipsecIkeSaIpsecInboundTrafficThe total amount of inbound traffic measured in bytes
handled by all IPSec SAs set up by phase 1 SAs supporting
this tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.38 |
ipsecIkeSaIpsecOutboundTrafficThe total amount of outbound traffic measured in bytes
handled by all IPSec SAs set up by phase 1 SAs supporting
this tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.39 |
ipsecIkeSaIpsecInboundPacketsThe total number of inbound packets handled by all IPSec
SAs set up by phase 1 SAs supporting this tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.40 |
ipsecIkeSaIpsecOutboundPacketsThe total number of outbound packets handled by all
IPSec SAs set up by phase 1 SAs supporting this tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.41 |
ipsecIkeSaIpsecDecryptErrorsThe total number of inbound packets discarded by all
IPSec SAs due to decryption errors.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.42 |
ipsecIkeSaIpsecAuthErrorsThe total number of inbound packets discarded by all
IPSec SAs due to authentication errors. This includes
hash failures in IPSec SAs using ESP and AH.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.43 |
ipsecIkeSaIpsecReplayErrorsThe total number of inbound packets discarded by all
IPSec SAs due to replay errors.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.44 |
ipsecIkeSaIpsecOtherReceiveErrorsThe total number of inbound packets discarded by all
IPSec SAs due to errors other than authentication,
decryption or replay errors. This may include packets
dropped due to lack of receive buffers.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.45 |
ipsecIkeSaIpsecSendErrorsThe total number of outbound packets discarded by all
IPSec SAs due to any error. This may include packets
dropped due to lack of receive buffers.
If this is a permanent virtual tunnel, it is not reset to
zero when the tunnel goes to the 'linkUp' state.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.1.1.46 |
ipsecTunnelTableThe (conceptual) table containing information on IPSec
SA-based tunnels. SEQUENCE OF IpsecTunnelEntry .1.3.6.1.4.1.1022.10.1.1.2 |
ipsecTunnelEntryAn entry (conceptual row) containing the information on
a particular configured tunnel. IpsecTunnelEntry .1.3.6.1.4.1.1022.10.1.1.2.1 |
ipsecTunnelIndexA unique value, greater than zero, for each tunnel
interface. It is recommended that values are assigned
contiguously starting from 1.
The value for each tunnel interface must remain constant
at least from one re-initialization of the entity's
network management system to the next re-initialization.
Further, the value for tunnel interfaces that are marked
as permanent must remain constant across all re-
initializations of the network management system.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.1 |
ipsecTunnelIkeSaThe value of the index into the IKE SA tunnel table that
created this tunnel (ipsecIkeSaIndex), or 0 if the tunnel
is created by a static IPSec SA.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.2 |
ipsecTunnelTypeThe type of the virtual tunnel represented by this row.
'static' means that the tunnel is supported by a single
static IPSec SA that was setup by configuration, and not
by using a key exchange protocol. In this case, the value
of ipsecTunnelIkeSa must be 0.ro Enumeration .1.3.6.1.4.1.1022.10.1.1.2.1.3 |
ipsecTunnelLocalAddressOrStartThe address of or the start address (if an address
range) of the local endpoint of the tunnel, or 0.0.0.0 if
unknown or if the SA uses transport mode encapsulation.ro IpAddress .1.3.6.1.4.1.1022.10.1.1.2.1.4 |
ipsecTunnelLocalAddressMaskOrEndThe mask of or the end address (if an address range) of
the local endpoint of the tunnel, or 0.0.0.0 if unknown
or if the SA uses transport mode encapsulation.ro IpAddress .1.3.6.1.4.1.1022.10.1.1.2.1.5 |
ipsecTunnelRemoteAddressOrStartThe address of or the start address (if an address
range) of the remote endpoint of the tunnel, or 0.0.0.0
if unknown or if the SA uses transport mode
encapsulation.ro IpAddress .1.3.6.1.4.1.1022.10.1.1.2.1.6 |
ipsecTunnelRemoteAddressMaskOrEndThe mask of or the end address (if an address range) of
the remote endpoint of the tunnel, or 0.0.0.0 if unknown
or if the SA uses transport mode encapsulation.ro IpAddress .1.3.6.1.4.1.1022.10.1.1.2.1.7 |
ipsecTunnelProtocolThe number of the protocol that this tunnel carries, or
0 if it carries any protocol.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.8 |
ipsecTunnelLocalPortThe number of the local port that this tunnel carries,
or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.1022.10.1.1.2.1.9 |
ipsecTunnelRemotePortThe number of the remote port that this tunnel carries,
or 0 if it carries any port number.ro Integer32 (0.. 65535) .1.3.6.1.4.1.1022.10.1.1.2.1.10 |
ipsecTunnelModeThe type of encapsulation used by this virtual tunnel.ro Enumeration .1.3.6.1.4.1.1022.10.1.1.2.1.11 |
ipsecTunnelEspEncAlgA unique value representing the encryption algorithm
applied to traffic carried by this SA if it uses ESP or 0
if there is no encryption applied by ESP or if ESP is not
used.
Specific values are taken from section 4.4.4 of [IPDOI].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.12 |
ipsecTunnelEspEncKeyLengthThe length of the encryption key in bits used for the
algorithm specified in the ipsecTunnelEspEncAlg object,
or 0 if the key length is implicit in the specified
algorithm or there is no encryption specified.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.13 |
ipsecTunnelEspAuthAlgA unique value representing the hash algorithm applied
to traffic carried by this SA if it uses ESP or 0 if
there is no authentication applied by ESP or if ESP is
not used.
Specific values are taken from the Authentication
Algorithm attribute values of Section 4.5 of [IPDOI].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.14 |
ipsecTunnelAhAuthAlgA unique value representing the hash algorithm applied
to traffic carried by this SA if it uses AH or 0 if AH is
not used.
Specific values are taken from Section 4.4.3 of [IPDOI].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.15 |
ipsecTunnelCompAlgA unique value representing the compression algorithm
applied to traffic carried by this SA if it uses IPCOMP.
Specific values are taken from Section 4.4.5 of [IPDOI].ro Integer32 .1.3.6.1.4.1.1022.10.1.1.2.1.16 |
ipsecTunnelStartTimeThe date and time that this virtual tunnel was set up.
If this is a permanent virtual tunnel, it is reset when
the number of current SAs (ipsecTunnelCurrentSaNum)
changes from 0 to 1.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.1022.10.1.1.2.1.17 |
ipsecTunnelCurrentSaNumThe number of current SAs set up to support this virtual
tunnel.
If this number is 0, the tunnel must be considered down.
Also if this number is 0, the tunnel must a permanent
tunnel, since transient tunnels that are down do not
appear in the table.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.2.1.18 |
ipsecTunnelTotalSaNumThe total number of SAs, including all current SAs, that
have been set up to support this virtual tunnel.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.19 |
ipsecTunnelTotalInboundTrafficThe total amount of traffic measured in bytes handled in
the tunnel in the inbound direction. In other words, it
is the aggregate value of all inbound traffic carried by
all IPSec SAs ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.20 |
ipsecTunnelTotalOutboundTrafficThe total amount of traffic measured in bytes handled in
the tunnel in the outbound direction. In other words, it
is the aggregate value of all inbound traffic carried by
all IPSec SAs ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.21 |
ipsecTunnelTotalInboundPacketsThe total number of packets handled in the tunnel in the
inbound direction. In other words, it is the aggregate
value of all inbound packets carried by all IPSec SAs
ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.22 |
ipsecTunnelTotalOutboundPacketsThe total number of packets handled in the tunnel in the
outbound direction. In other words, it is the aggregate
value of all outbound packets carried by all IPSec SAs
ever set up to support the virtual tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.23 |
ipsecTunnelDecryptErrorsThe total number of inbound packets discarded by this
virtual tunnel due to decryption errors in ESP.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.24 |
ipsecTunnelAuthErrorsThe total number of inbound packets discarded by this
virtual tunnel due to authentication errors. This
includes hash failures in IPSec SA bundles using both ESP
and AH.
If this is a permanent virtual tunnel, it is not resetto
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.25 |
ipsecTunnelReplayErrorsThe total number of inbound packets discarded by this
virtual tunnel due to replay errors. This includes replay
failures in IPSec SA bundles using both ESP and AH.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.26 |
ipsecTunnelPolicyErrorsThe total number of inbound packets discarded by this
virtual tunnel due to policy errors. This includes errors
in all transforms if SA bundles are used.
Policy errors are due to the detection of a packet that
was inappropriately sent into this tunnel.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.27 |
ipsecTunnelOtherReceiveErrorsThe total number of inbound packets discarded by this
virtual tunnel due to errors other than decryption,
authentication or replay errors. This may include packets
dropped due to a lack of receive buffers.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.28 |
ipsecTunnelSendErrorsThe total number of outbound packets discarded by this
virtual tunnel due to any error. This may include packets
dropped due to a lack of transmit buffers.
If this is a permanent virtual tunnel, it is not reset to
zero when the number of current SAs
(ipsecTunnelCurrentSaNum) changes from 0 to 1.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.2.1.29 |
ipsecSaTableThe (conceptual) table containing information on IPSec
SAs. SEQUENCE OF IpsecSaEntry .1.3.6.1.4.1.1022.10.1.1.3 |
ipsecSaEntryAn entry (conceptual row) containing the information on
a particular IPSec SA. IpsecSaEntry .1.3.6.1.4.1.1022.10.1.1.3.1 |
ipsecSaIndexA unique value, greater than zero, for each IPSec SA. It
is recommended that values are assigned contiguously
starting from 1.ro Integer32 .1.3.6.1.4.1.1022.10.1.1.3.1.1 |
ipsecSaTunnelThe value of the index into the IPSec SA tunnel table
that this SA supports (ipsecTunnelIndex).ro Integer32 .1.3.6.1.4.1.1022.10.1.1.3.1.2 |
ipsecSaInboundEspSpiThe value of the SPI for the inbound SA that provides
the ESP security service, or zero if ESP is not used.ro Unsigned32 .1.3.6.1.4.1.1022.10.1.1.3.1.3 |
ipsecSaOutboundEspSpiThe value of the SPI for the outbound SA that provides
the ESP security service, or zero if ESP is not used.ro Unsigned32 .1.3.6.1.4.1.1022.10.1.1.3.1.4 |
ipsecSaInboundAhSpiThe value of the SPI for the inbound SA that provides
the AH security service, or zero if AH is not used.ro Unsigned32 .1.3.6.1.4.1.1022.10.1.1.3.1.5 |
ipsecSaOutboundAhSpiThe value of the SPI for the outbound SA that provides
the AH security service, or zero if AH is not used.ro Unsigned32 .1.3.6.1.4.1.1022.10.1.1.3.1.6 |
ipsecSaInboundCompCpiThe value of the CPI for the inbound SA that provides IP
compression, or zero if IPCOMP is not used.ro INTEGER .1.3.6.1.4.1.1022.10.1.1.3.1.7 |
ipsecSaOutboundCompCpiThe value of the CPI for the outbound SA that provides
IP compression, or zero if IPCOMP is not used.ro INTEGER .1.3.6.1.4.1.1022.10.1.1.3.1.8 |
ipsecSaCreationTimeThe date and time that the current SA was set up.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.1022.10.1.1.3.1.9 |
ipsecSaTimeLimitThe maximum lifetime in seconds of the SA, or 0 if there
is no time constraint on its expiration.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.3.1.10 |
ipsecSaTrafficLimitThe maximum traffic in 1024-byte blocks that the SA is
allowed to support, or 0 if there is no traffic
constraint on its expiration.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.3.1.11 |
ipsecSaInboundTrafficThe amount traffic measured in bytes handled by the SA
in the inbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.12 |
ipsecSaOutboundTrafficThe amount traffic measured in bytes handled by the SA
in the outbound direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.13 |
ipsecSaInboundPacketsThe number of packets handled by the SA in the inbound
direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.14 |
ipsecSaOutboundPacketsThe number of packets handled by the SA in the outbound
direction.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.15 |
ipsecSaDecryptErrorsThe number of inbound packets discarded by the SA due to
decryption errors.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.16 |
ipsecSaAuthErrorsThe number of inbound packets discarded by the SA due to
authentication errors. This includes hash failures in
both ESP and AH.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.17 |
ipsecSaReplayErrorsThe number of inbound packets discarded by the SA due to
replay errors. This includes replay failures both ESP and
AH.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.18 |
ipsecSaOtherReceiveErrorsThe number of inbound packets discarded by the SA due to
errors other than decryption, authentication or replay
errors. This may include decompression errors or errors
due to a lack of receive buffers.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.19 |
ipsecSaSendErrorsThe number of outbound packets discarded by the SA due
to any error. This may include compression errors or
errors due to a lack of transmit buffers.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.3.1.20 |
ipsecTraps OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.4 |
ipsecTrapsObjects OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.4.0 |
ipsecTrapPermIkeNegFailureAn attempt to negotiate a phase 1 SA for the specified
permanent IKE tunnel failed. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.1 |
ipsecTrapTransIkeNegFailureAn attempt to negotiate a phase 1 SA for a transient IKE
tunnel failed.
This trap is different from the
'ipsecTrapPermIkeNegFailure' trap, since this one will
likely result in the removal of this entry from the IKE
SA tunnel table. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.2 |
ipsecTrapInvalidCookieIKE packets with invalid cookies were detected from the
specified peer.
Implementations SHOULD send one trap per peer (within a
reasonable time period, rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.3 |
ipsecTrapIpsecNegFailureAn attempt to negotiate a phase 2 SA within the
specified IKE tunnel failed. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.4 |
ipsecTrapIpsecAuthFailureIPSec packets with invalid hashes were found in the
specified SA.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.5 |
ipsecTrapIpsecReplayFailureIPSec packets with invalid sequence numbers were found
in the specified SA.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.6 |
ipsecTrapIpsecPolicyFailureIPSec packets carrying packets with invalid selectors
for the specified SA were found.
Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.7 |
ipsecTrapInvalidSpiESP, AH or IPCOMP packets with unknown SPIs (or CPIs)
were detected from the specified peer.
Implementations SHOULD send one trap per peer (within a
reasonable time period), rather than sending one trap per
packet. NOTIFICATION-TYPE .1.3.6.1.4.1.1022.10.1.1.4.0.8 |
ipsecSaCounts OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.5 |
ipsecTotalIkeSAsThe total number of phase 1 SAs established by the
entity since boot time. It is not the total number of
tunnels established by the entity since boot time. It
does include SAs established to support both permanent
and transient tunnels.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.5.1 |
ipsecTotalIpsecSAsThe total number of phase 2 SAs established by the
entity since boot time. It is not the total number of
IPSec virtual tunnels established by the entity since
boot time. It does include SAs established to support
permanent and transient tunnels.
It is recommended that SA bundles or security suites be
considered a single SA for the purposes of this
statistic.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.5.2 |
ipsecPermTunStats OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.6 |
ipsecCnfgPermIkeTunnelsThe total number of phase 1 tunnels in the entity that
are configured as permanent.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.6.1 |
ipsecUpPermIkeTunnelsThe total number of phase 1 tunnels in the entity that
are configured as permanent and are up and available for
use.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.6.2 |
ipsecCnfgPermIpsecTunnelsThe total number of phase 2 tunnels in the entity that
are configured as permanent.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.6.3 |
ipsecUpPermIpsecTunnelsThe total number of phase 2 tunnels in the entity that
are configured as permanent and are up and available for
use.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.6.4 |
ipsecTransTunStats OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.7 |
ipsecTotalTransIkeTunnelsThe total number of transient phase 1 tunnels
established by the entity since boot time.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.1 |
ipsecCurrentTransIkeTunnelsThe number of transient phase 1 tunnels in the entity
that are up and available for use at this moment in
time.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.7.2 |
ipsecTotalTransIpsecTunnelsThe total number of transient phase 2 tunnels
established by the entity since boot time.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.3 |
ipsecCurrentTransIpsecTunnelsThe number of phase 2 tunnels in the entity that are up
and available for use at this moment in time.ro Gauge32 .1.3.6.1.4.1.1022.10.1.1.7.4 |
ipsecTotalTransInboundPacketsThe total number of inbound packets carried on transient
IPSec tunnels since boot time.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.5 |
ipsecTotalTransOutboundPacketsThe total number of outbound packets carried on
transient IPSec tunnels since boot time.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.6 |
ipsecTotalTransInboundTrafficThe total amount of inbound traffic carried on transient
IPSec tunnels since boot time, measured in 1024-octet
blocks.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.7 |
ipsecTotalTransOutboundTrafficThe total amount of outbound traffic carried on
transient IPSec tunnels since boot time, measured in
1024-octet blocks.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.8 |
ipsecTotalTransIkeSetupFailuresThe total number of IKE SA set up attempts that have
failed since entity boot time. This includes SAs
associated with transient tunnels only.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.7.9 |
ipsecNotifications OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.8 |
ipsecNotifyMessageTotalCountThe total number of all types of notify messages sent or
received by the entity since boot time.
It is the sum of all occurrences in the
'ipsecNotifyCountTable'.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.8.1 |
ipsecNotifyCountTableThe (conceptual) table containing information on IPSec
notify message counts.
This table MAY be sparsely populated; that is, rows for
which the count is 0 may be absent. SEQUENCE OF IpsecNotifyCountEntry .1.3.6.1.4.1.1022.10.1.1.8.2 |
ipsecNotifyCountEntryAn entry (conceptual row) containing the total number of
occurrences of a notify message. IpsecNotifyCountEntry .1.3.6.1.4.1.1022.10.1.1.8.2.1 |
ipsecNotifyMessageThe value representing a specific IPSec notify message,
or 0 if unknown.
Values are assigned from the set of notify message types
as defined in Section 3.14.1 of [ISAKMP]. In addition,
the value 0 may be used for this object when the object
is used as a trap cause, and the cause is unknown.ro INTEGER .1.3.6.1.4.1.1022.10.1.1.8.2.1.1 |
ipsecNotifyMessageCountThe total number of times the specific notify message
has been received or sent by the entity since system
boot.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.8.2.1.2 |
ipsecErrorStats OBJECT IDENTIFIER .1.3.6.1.4.1.1022.10.1.1.9 |
ipsecUnknownSpiErrorsThe total number of packets received by the entity since
boot time with SPIs or CPIs that were not valid.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.9.1 |
ipsecIkeProtocolErrorsThe total number of packets received by the entity since
boot time with IKE protocol errors.
This includes packets with invalid cookies, but does not
include errors that could be associated with specific IKE
SAs.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.9.2 |
ipsecIpsecAuthenticationErrorsThe total number of packets received by the entity since
boot time with authentication errors in the IPSec SAs.
This includes all packets in which the hash value is
determined to be invalid.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.9.3 |
ipsecIpsecReplayErrorsThe total number of packets received by the entity since
boot time with replay errors in the IPSec SAs.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.9.4 |
ipsecIpsecPolicyErrorsThe total number of packets received by the entity since
boot time and discarded due to policy errors. This
includes packets that had selectors that were invalid for
the SA that carried them.ro Counter32 .1.3.6.1.4.1.1022.10.1.1.9.5 |