MIBs Depot

CISCO-ENHANCED-IPSEC-FLOW-MIB

Registered at
1.3.6.1.4.1.9.9.432
Last updated
2013-06-28 00:00
Organization
Cisco Systems, Inc.
Revisions
2013-06-28 00:00, 2011-07-19 00:00, 2005-01-12 00:00, 2004-08-31 00:00
Namespace
cisco
Source file
CISCO-ENHANCED-IPSEC-FLOW-MIB
Digest
sha256:8779a540b85b33eeec1a6d765796dd2570f814fa00acb25dd5282ca24f976426

Description

This is a MIB Module for monitoring the structures and status of IPSec-based networks. The MIB has been designed to be adopted as an IETF standard. Hence vendor-specific features of IPSec protocol are excluded from this MIB. Acronyms The following acronyms are used in this document: IPsec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol SA: Security Association (ref: rfc2408). SPI: Security Parameter Index is the pointer or identifier used in accessing SA attributes (ref: rfc2408). MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. Phase 1 Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document. Control Tunnel: Another term for a Phase 1 Tunnel. Phase 2 Tunnel: An instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh). MTU: Maximum Transmission Unit (of an IPsec tunnel). History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. During late 1999, Cisco adopted the MIB and together with Tivoli publised the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms. With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt. With the emergence of multiple IPsec signaling protocols, it became apparent that the signaling aspects of IPsec need to be instrumented separately in their own right. Thus, the IPsec control attributes and metrics were separated out into CISCO-IPSEC-SIGNALING-MIB and CISCO-IKE-FLOW-MIB. This version of the draft is the version of the draft that models that IPsec data protocol, structures and activity alone. Overview of MIB The MIB contains four major groups of objects which are used to manage the IPsec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPsec MIB. The Phase 2 group models objects pertaining to IPsec data tunnels. The History group is to aid applications that do trending analysis. The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid detection of potential security violations. In addition to the three major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPsec TRAPs.

Contact

Cisco Systems Customer Service Postal: 170 W Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS E-mail: cs-ipsecmib@external.cisco.com

Imports

FromSymbols
CISCO-IPSEC-TCCIPsecAuthAlgorithm, CIPsecCompAlgorithm, CIPsecControlProtocol, CIPsecDiffHellmanGrp, CIPsecEncapMode, CIPsecEncryptAlgorithm, CIPsecEncryptionKeySize, CIPsecEndPtType, CIPsecNATTraversalMode, CIPsecPhase1TunnelIndexOrZero, CIPsecPhase2SaDirection, CIPsecPhase2TunnelIndex, CIPsecPmtu, CIPsecProtocol, CIPsecSpi, CIPsecTunnelStatus
CISCO-SMIciscoMgmt
CISCO-TCCiscoIpProtocol, CiscoPort
IF-MIBInterfaceIndex, ifIndex
INET-ADDRESS-MIBInetAddress, InetAddressType
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP, OBJECT-GROUP
SNMPv2-SMICounter32, Counter64, Gauge32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDateAndTime, DisplayString, TEXTUAL-CONVENTION, TimeInterval, TimeStamp, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

CISCO-ENHANCED-IPSEC-FLOW-MIB
CISCO-IPSEC-TC
CISCO-SMI
CISCO-TC
IANAifType-MIB
IF-MIB
INET-ADDRESS-MIB
SNMP-FRAMEWORK-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC

Objects

NameOIDSyntaxAccessStatus
ciscoEnhancedIpsecFlowMIBNotifs
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.0
ciscoEnhancedIpsecFlowMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1
ceipSecPhaseTwo
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.1
ceipSecGlobalStats
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.1.1
ceipSecGlobalActiveTunnels
OBJECT-TYPE
The total number of currently active IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.1Gauge32read-onlycurrent
ceipSecGlobalPreviousTunnels
OBJECT-TYPE
The total number of previously active IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.2Counter64read-onlycurrent
ceipSecGlobalInOctets
OBJECT-TYPE
A high capacity count of the total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed.
1.3.6.1.4.1.9.9.432.1.1.1.3Counter64read-onlycurrent
ceipSecGlobalInDecompOctets
OBJECT-TYPE
A high capacity count of the total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecGlobalInOctets.
1.3.6.1.4.1.9.9.432.1.1.1.4Counter64read-onlycurrent
ceipSecGlobalInPkts
OBJECT-TYPE
The total number of packets received by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.5Counter64read-onlycurrent
ceipSecGlobalInDrops
OBJECT-TYPE
The total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.
1.3.6.1.4.1.9.9.432.1.1.1.6Counter64read-onlycurrent
ceipSecGlobalInReplayDrops
OBJECT-TYPE
The total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.7Counter64read-onlycurrent
ceipSecGlobalInAuths
OBJECT-TYPE
The total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.8Counter64read-onlycurrent
ceipSecGlobalInAuthFails
OBJECT-TYPE
The total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.9Counter64read-onlycurrent
ceipSecGlobalInDecrypts
OBJECT-TYPE
The total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.10Counter64read-onlycurrent
ceipSecGlobalInDecryptFails
OBJECT-TYPE
The total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.11Counter64read-onlycurrent
ceipSecGlobalOutOctets
OBJECT-TYPE
A high capacity count of the total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed.
1.3.6.1.4.1.9.9.432.1.1.1.12Counter64read-onlycurrent
ceipSecGlobalOutUncompOctets
OBJECT-TYPE
A high capacity count of the total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecGlobalOutOctets.
1.3.6.1.4.1.9.9.432.1.1.1.13Counter64read-onlycurrent
ceipSecGlobalOutPkts
OBJECT-TYPE
The total number of packets sent by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.14Counter64read-onlycurrent
ceipSecGlobalOutDrops
OBJECT-TYPE
The total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.15Counter64read-onlycurrent
ceipSecGlobalOutAuths
OBJECT-TYPE
The total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.16Counter64read-onlycurrent
ceipSecGlobalOutAuthFails
OBJECT-TYPE
The total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.17Counter64read-onlycurrent
ceipSecGlobalOutEncrypts
OBJECT-TYPE
The total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.18Counter64read-onlycurrent
ceipSecGlobalOutEncryptFails
OBJECT-TYPE
The total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.19Counter64read-onlycurrent
ceipSecGlobalProtocolUseFails
OBJECT-TYPE
The total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.20Counter64read-onlycurrent
ceipSecGlobalNoSaFails
OBJECT-TYPE
The total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.21Counter64read-onlycurrent
ceipSecGlobalSysCapFails
OBJECT-TYPE
The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.
1.3.6.1.4.1.9.9.432.1.1.1.22Counter64read-onlycurrent
ceipSecGlobalOutCompressedPkts
OBJECT-TYPE
The cumulative number of outbound packets across all IPsec flows terminating at this device which were successfully compressed.
1.3.6.1.4.1.9.9.432.1.1.1.23Counter64read-onlycurrent
ceipSecGlobalOutCompSkippedPkts
OBJECT-TYPE
The total number of outbound packets across all IPsec flows terminating at this devices that were to be compressed but which were skipped due to the compression hysteresis.
1.3.6.1.4.1.9.9.432.1.1.1.24Counter64read-onlycurrent
ceipSecGlobalOutCompFailPkts
OBJECT-TYPE
The total number of outbound packets across all IPsec flows terminating at this device that failed compression because they grew in size after compression.
1.3.6.1.4.1.9.9.432.1.1.1.25Counter64read-onlycurrent
ceipSecGlobalOutCompTooSmallPkts
OBJECT-TYPE
The total number of outbound packets across all IPsec flows terminating at this device that were to be compressed but were smaller than the compression threshold size. This number is cumulative since the last system start.
1.3.6.1.4.1.9.9.432.1.1.1.26Counter64read-onlycurrent
ceipSecGlobalThroughputUtilizatioinTimeInterval
OBJECT-TYPE
The object is the length of the time interval to measure the throughtput utilization.
1.3.6.1.4.1.9.9.432.1.1.1.27Unsigned32read-onlycurrent
ceipSecGlobalThroughputLastUpdatedTime
OBJECT-TYPE
The timestamp is the end of the last throughput utilization time interval.
1.3.6.1.4.1.9.9.432.1.1.1.28TimeStampread-onlycurrent
ceipSecGlobalLastAveragePacketSize
OBJECT-TYPE
This object is the average packet size in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.
1.3.6.1.4.1.9.9.432.1.1.1.29Unsigned32read-onlycurrent
ceipSecGlobalLastThroughputInMbps
OBJECT-TYPE
The object is the total throughput in Mbps in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.
1.3.6.1.4.1.9.9.432.1.1.1.30Unsigned32read-onlycurrent
ceipSecGlobalLastThroughputInKpps
OBJECT-TYPE
The object is the total throughput in Kpps in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.
1.3.6.1.4.1.9.9.432.1.1.1.31Unsigned32read-onlycurrent
ceipSecGlobalLastThroughputUtilization
OBJECT-TYPE
The object is the throughput utilization in percentage in the last performance utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.
1.3.6.1.4.1.9.9.432.1.1.1.32Unsigned32read-onlycurrent
ceipSecGlobalPeakThroughputUtilization
OBJECT-TYPE
The object is the peak throughput utilization in percentage since the managed system is active. It was observed in the throughput utilization time interval that ended at ceipSecGlobalPeakThroughputDateAndTime.
1.3.6.1.4.1.9.9.432.1.1.1.33Unsigned32read-onlycurrent
ceipSecGlobalPeakThroughputDateAndTime
OBJECT-TYPE
The date and time when ceipSecGlobalPeakThroughputUtilization is updated.
1.3.6.1.4.1.9.9.432.1.1.1.34DateAndTimeread-onlycurrent
ceipSecGlobalPeakThroughputInMbps
OBJECT-TYPE
The object indicates the peak value of throughput in Mbps.
1.3.6.1.4.1.9.9.432.1.1.1.35Unsigned32read-onlycurrent
ceipSecGlobalPeakAvgPacketSize
OBJECT-TYPE
This object indicates the average packet size in bytes in the throughput utilization time interval that ended at ceipSecGlobalPeakThroughputDateAndTime.
1.3.6.1.4.1.9.9.432.1.1.1.36Unsigned32read-onlycurrent
ceipSecTunnelTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2not-accessiblecurrent
ceipSecTunnelEntry
OBJECT-TYPE
Each entry contains the attributes associated with an active IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1not-accessiblecurrent
ceipSecTunIndex
OBJECT-TYPE
The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. Since this object must correspond to a valid Phase-2 IPsec tunnel, this object may not assume the value of 0.
1.3.6.1.4.1.9.9.432.1.1.2.1.1CIPsecPhase2TunnelIndexnot-accessiblecurrent
ceipSecTunLocalAddressType
OBJECT-TYPE
The type of the IP address of the local endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.2InetAddressTyperead-onlycurrent
ceipSecTunLocalAddress
OBJECT-TYPE
The IP address of the local endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.3InetAddressread-onlycurrent
ceipSecTunRemoteAddressType
OBJECT-TYPE
The type of the IP address of the remote endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.4InetAddressTyperead-onlycurrent
ceipSecTunRemoteAddress
OBJECT-TYPE
The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.5InetAddressread-onlycurrent
ceipSecTunControlProtocol
OBJECT-TYPE
Identifies the protocol used to setup and administer this Phase-2 IPsec tunnel. In case this tunnel was spawned by an IPsec signaling protocol, this MIB object contains the value of the object 'cisgIpsSgProtocol' defined in CISCO-IPSEC-SIGNALING-MIB in the table 'cisgIpsSgTunnelTable' in the row corresponding to the control tunnel. A value of 'cpManual' is indicative of a manually installed and administered Phase-2 tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.6CIPsecControlProtocolread-onlycurrent
ceipSecTunControlTunnelIndex
OBJECT-TYPE
The index of the associated IPsec Phase-1 Tunnel. In case this tunnel was spawned by an IPsec signaling protocol, this MIB object contains the value of the object 'cisgIpsSgTunIndex' defined in CISCO-IPSEC-SIGNALING-MIB in the table 'cisgIpsSgTunnelTable' in the row corresponding to the control tunnel. A value of 0 identifies that this Phase-2 tunnel was setup manually.
1.3.6.1.4.1.9.9.432.1.1.2.1.7CIPsecPhase1TunnelIndexOrZeroread-onlycurrent
ceipSecTunControlTunnelAlive
OBJECT-TYPE
An indicator which specifies whether or not the IPsec Phase-1 Tunnel that spawned this Phase-2 tunnel currently exists.
1.3.6.1.4.1.9.9.432.1.1.2.1.8TruthValueread-onlycurrent
ceipSecTunEncapMode
OBJECT-TYPE
The encapsulation mode used by the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.9CIPsecEncapModeread-onlycurrent
ceipSecTunNATTraversalMode
OBJECT-TYPE
The encapsulation used by the IPsec Phase-2 tunnel for NAT traversal. The value of this object is constrained based on the value of the column 'ceipSecTunEncapMode'. If the value of 'ceipSecTunEncapMode' is 'encapTransport', then this object may not assume the values 'natEncapIPsecOverUdp' or 'natEncapIPsecOverTcp'.
1.3.6.1.4.1.9.9.432.1.1.2.1.10CIPsecNATTraversalModeread-onlycurrent
ceipSecTunLifeSize
OBJECT-TYPE
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
1.3.6.1.4.1.9.9.432.1.1.2.1.11Unsigned32 (1..4294967295)read-onlycurrent
ceipSecTunLifeTime
OBJECT-TYPE
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds. If the tunnel was setup manually, the value of this MIB element should be 0.
1.3.6.1.4.1.9.9.432.1.1.2.1.12Unsigned32read-onlycurrent
ceipSecTunActiveTime
OBJECT-TYPE
The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.
1.3.6.1.4.1.9.9.432.1.1.2.1.13TimeIntervalread-onlycurrent
ceipSecTunSaLifeSizeThreshold
OBJECT-TYPE
The security association LifeSize refresh threshold in kilobytes. If the tunnel was setup manually, the value of this MIB element should be 0.
1.3.6.1.4.1.9.9.432.1.1.2.1.14Unsigned32read-onlycurrent
ceipSecTunSaLifeTimeThreshold
OBJECT-TYPE
The security association LifeTime refresh threshold in seconds. If the tunnel was setup manually, the value of this MIB element should be 0.
1.3.6.1.4.1.9.9.432.1.1.2.1.15Unsigned32read-onlycurrent
ceipSecTunTotalRefreshes
OBJECT-TYPE
The total number of security association refreshes performed.
1.3.6.1.4.1.9.9.432.1.1.2.1.16Counter32read-onlycurrent
ceipSecTunExpiredSaInstances
OBJECT-TYPE
The total number of security associations which have expired. If the tunnel was setup manually, the value of this MIB element should be 0.
1.3.6.1.4.1.9.9.432.1.1.2.1.17Counter32read-onlycurrent
ceipSecTunCurrentSaInstances
OBJECT-TYPE
The number of security associations which are currently active or expiring.
1.3.6.1.4.1.9.9.432.1.1.2.1.18Gauge32read-onlycurrent
ceipSecTunInSaDHGrp
OBJECT-TYPE
The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel. If the tunnel was setup manually, the value of this MIB element would be `none'.
1.3.6.1.4.1.9.9.432.1.1.2.1.19CIPsecDiffHellmanGrpread-onlycurrent
ceipSecTunInSaEncryptAlgo
OBJECT-TYPE
The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.20CIPsecEncryptAlgorithmread-onlycurrent
ceipSecTunInSaEncryptKeySize
OBJECT-TYPE
The key size in bits of the negotiated key to be used with the algorithm denoted by 'ceipSecTunInSaEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.
1.3.6.1.4.1.9.9.432.1.1.2.1.21CIPsecEncryptionKeySizeread-onlycurrent
ceipSecTunInSaAhAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.22CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunInSaEspAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound ecapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.23CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunInSaDecompAlgo
OBJECT-TYPE
The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.24CIPsecCompAlgorithmread-onlycurrent
ceipSecTunOutSaDHGrp
OBJECT-TYPE
The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel. If the tunnel was setup manually, the value of this MIB element would be 'none'.
1.3.6.1.4.1.9.9.432.1.1.2.1.25CIPsecDiffHellmanGrpread-onlycurrent
ceipSecTunOutSaEncryptAlgo
OBJECT-TYPE
The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.26CIPsecEncryptAlgorithmread-onlycurrent
ceipSecTunOutSaEncryptKeySize
OBJECT-TYPE
The key size in bits of the negotiated key to be used with the algorithm denoted by 'ceipSecTunOutSaEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.
1.3.6.1.4.1.9.9.432.1.1.2.1.27CIPsecEncryptionKeySizeread-onlycurrent
ceipSecTunOutSaAhAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.28CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunOutSaEspAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.29CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunOutSaCompAlgo
OBJECT-TYPE
The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.30CIPsecCompAlgorithmread-onlycurrent
ceipSecTunPmtu
OBJECT-TYPE
The Path MTU for this IPsec Phase-2 tunnel, which has been either learnt from the network or which has been specified by the administrator. The lower end of the range is 68 which is the minimum MTU for IPv4.
1.3.6.1.4.1.9.9.432.1.1.2.1.31CIPsecPmturead-onlycurrent
ceipSecTunInOctets
OBJECT-TYPE
A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.
1.3.6.1.4.1.9.9.432.1.1.2.1.32Counter64read-onlycurrent
ceipSecTunInDecompOctets
OBJECT-TYPE
A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunInOctets.
1.3.6.1.4.1.9.9.432.1.1.2.1.33Counter64read-onlycurrent
ceipSecTunInPkts
OBJECT-TYPE
The total number of packets received by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.34Counter32read-onlycurrent
ceipSecTunInDropPkts
OBJECT-TYPE
The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.
1.3.6.1.4.1.9.9.432.1.1.2.1.35Counter32read-onlycurrent
ceipSecTunInReplayDropPkts
OBJECT-TYPE
The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.36Counter32read-onlycurrent
ceipSecTunInAuths
OBJECT-TYPE
The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.37Counter32read-onlycurrent
ceipSecTunInAuthFails
OBJECT-TYPE
The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .
1.3.6.1.4.1.9.9.432.1.1.2.1.38Counter32read-onlycurrent
ceipSecTunInDecrypts
OBJECT-TYPE
The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.39Counter32read-onlycurrent
ceipSecTunInDecryptFails
OBJECT-TYPE
The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.40Counter32read-onlycurrent
ceipSecTunOutOctets
OBJECT-TYPE
A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.
1.3.6.1.4.1.9.9.432.1.1.2.1.41Counter64read-onlycurrent
ceipSecTunOutUncompOctets
OBJECT-TYPE
A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecTunOutOctets.
1.3.6.1.4.1.9.9.432.1.1.2.1.42Counter64read-onlycurrent
ceipSecTunOutPkts
OBJECT-TYPE
The total number of packets sent by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.43Counter32read-onlycurrent
ceipSecTunOutDropPkts
OBJECT-TYPE
The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.44Counter32read-onlycurrent
ceipSecTunOutAuths
OBJECT-TYPE
The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.45Counter32read-onlycurrent
ceipSecTunOutAuthFails
OBJECT-TYPE
The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.46Counter32read-onlycurrent
ceipSecTunOutEncrypts
OBJECT-TYPE
The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.47Counter32read-onlycurrent
ceipSecTunOutEncryptFails
OBJECT-TYPE
The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.2.1.48Counter32read-onlycurrent
ceipSecTunOutCompressedPkts
OBJECT-TYPE
The total number of outbound packets which were successfully compressed.
1.3.6.1.4.1.9.9.432.1.1.2.1.49Counter32read-onlycurrent
ceipSecTunOutCompSkippedPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis.
1.3.6.1.4.1.9.9.432.1.1.2.1.50Counter32read-onlycurrent
ceipSecTunOutCompFailPkts
OBJECT-TYPE
The total number of outbound packets that failed compression because they grew in size after compression.
1.3.6.1.4.1.9.9.432.1.1.2.1.51Counter32read-onlycurrent
ceipSecTunOutCompTooSmallPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but were smaller than the compression threshold size.
1.3.6.1.4.1.9.9.432.1.1.2.1.52Counter32read-onlycurrent
ceipSecIfIndex
OBJECT-TYPE
This object represents the ifIndex of an interface where this tunnel is created. Multiple IPsec tunnels can be created using the same interface.
1.3.6.1.4.1.9.9.432.1.1.2.1.53InterfaceIndexread-onlycurrent
ceipSecTunStatus
OBJECT-TYPE
The status of the MIB table row. This object can be used to bring the tunnel down or force a rekeying. When the value is set to destroy(5), the SA bundle is destroyed and this row is deleted from this table. When the value is set to rekey(6), then rekeying is forced on this tunnel. When this MIB value is queried, the value of active(4) is always returned, if the instance exists. This object cannot be used to create a MIB table row.
1.3.6.1.4.1.9.9.432.1.1.2.1.54CIPsecTunnelStatusread-writecurrent
ceipSecEndPtTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel Endpoint Table. This table contains an entry for each active endpoint associated with an IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.3not-accessiblecurrent
ceipSecEndPtEntry
OBJECT-TYPE
An IPsec Phase-2 Tunnel Endpoint entry.
1.3.6.1.4.1.9.9.432.1.1.3.1not-accessiblecurrent
ceipSecEndPtIndex
OBJECT-TYPE
The number of the Endpoint associated with the IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 4,294,967,295.
1.3.6.1.4.1.9.9.432.1.1.3.1.1Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecEndPtLocalName
OBJECT-TYPE
The DNS name of the local Endpoint.
1.3.6.1.4.1.9.9.432.1.1.3.1.2SnmpAdminStringread-onlycurrent
ceipSecEndPtLocalType
OBJECT-TYPE
The type of identity for the local Endpoint.
1.3.6.1.4.1.9.9.432.1.1.3.1.3CIPsecEndPtTyperead-onlycurrent
ceipSecEndPtLocalAddrType1
OBJECT-TYPE
The type of the IP address for this local Endpoint's first IP address.
1.3.6.1.4.1.9.9.432.1.1.3.1.4InetAddressTyperead-onlycurrent
ceipSecEndPtLocalAddr1
OBJECT-TYPE
The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtLocalType.
1.3.6.1.4.1.9.9.432.1.1.3.1.5InetAddressread-onlycurrent
ceipSecEndPtLocalAddrType2
OBJECT-TYPE
The type of the IP address for this local Endpoint's second IP address.
1.3.6.1.4.1.9.9.432.1.1.3.1.6InetAddressTyperead-onlycurrent
ceipSecEndPtLocalAddr2
OBJECT-TYPE
The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtLocalType.
1.3.6.1.4.1.9.9.432.1.1.3.1.7InetAddressread-onlycurrent
ceipSecEndPtLocalProtocol
OBJECT-TYPE
The protocol number of the local Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.1.3.1.8CiscoIpProtocolread-onlycurrent
ceipSecEndPtLocalPort
OBJECT-TYPE
The port number of the local Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.1.3.1.9CiscoPortread-onlycurrent
ceipSecEndPtRemoteName
OBJECT-TYPE
The DNS name of the remote Endpoint.
1.3.6.1.4.1.9.9.432.1.1.3.1.10SnmpAdminStringread-onlycurrent
ceipSecEndPtRemoteType
OBJECT-TYPE
The type of identity for the remote Endpoint.
1.3.6.1.4.1.9.9.432.1.1.3.1.11CIPsecEndPtTyperead-onlycurrent
ceipSecEndPtRemoteAddrType1
OBJECT-TYPE
The type of the IP address for this remote Endpoint's first IP address.
1.3.6.1.4.1.9.9.432.1.1.3.1.12InetAddressTyperead-onlycurrent
ceipSecEndPtRemoteAddr1
OBJECT-TYPE
The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtRemoteType.
1.3.6.1.4.1.9.9.432.1.1.3.1.13InetAddressread-onlycurrent
ceipSecEndPtRemoteAddrType2
OBJECT-TYPE
The type of the IP address for this remote Endpoint's second IP address.
1.3.6.1.4.1.9.9.432.1.1.3.1.14InetAddressTyperead-onlycurrent
ceipSecEndPtRemoteAddr2
OBJECT-TYPE
The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtRemoteType.
1.3.6.1.4.1.9.9.432.1.1.3.1.15InetAddressread-onlycurrent
ceipSecEndPtRemoteProtocol
OBJECT-TYPE
The protocol number of the remote Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.1.3.1.16CiscoIpProtocolread-onlycurrent
ceipSecEndPtRemotePort
OBJECT-TYPE
The port number of the remote Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.1.3.1.17CiscoPortread-onlycurrent
ceipSecSaTable
OBJECT-TYPE
The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ceipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations.
1.3.6.1.4.1.9.9.432.1.1.4not-accessiblecurrent
ceipSecSaEntry
OBJECT-TYPE
Each entry contains the attributes associated with active and expiring IPsec Phase-2 security associations.
1.3.6.1.4.1.9.9.432.1.1.4.1not-accessiblecurrent
ceipSecSaProtocol
OBJECT-TYPE
This column represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
1.3.6.1.4.1.9.9.432.1.1.4.1.1CIPsecProtocolnot-accessiblecurrent
ceipSecSaIndex
OBJECT-TYPE
The object, in the context of the IPsec tunnel 'ceipSecTunIndex', is an index of security associations comprising the Phase-2 IPsec tunnel represented by the tunnel index 'ceipSecTunIndex'. The value of this index is a number which begins at 1 and is incremented with each SPI associated with the corresponding IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.4.1.2Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecSaDirection
OBJECT-TYPE
Phase-2 IPsec security associations are simplex. Hence a particular security association is used either for securing outgoing traffic or decoding incoming traffic. This column identifies the direction of the security association represented by this entry.
1.3.6.1.4.1.9.9.432.1.1.4.1.3CIPsecPhase2SaDirectionread-onlycurrent
ceipSecSaValue
OBJECT-TYPE
This is the value of the Security Protection Index (SPI) assigned by the system to the security association represented by this entry.
1.3.6.1.4.1.9.9.432.1.1.4.1.4CIPsecSpiread-onlycurrent
ceipSecSaStatus
OBJECT-TYPE
This column represents the status of the security association represented by this conceptual row. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.
1.3.6.1.4.1.9.9.432.1.1.4.1.5INTEGER {unknown(1), active(2), expiring(3)}read-onlycurrent
ceipSecTunnelSaTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel Security Association Table. This table identifies the SAs that are currently associated with an active Phase-2 tunnel. This table contains an entry for each active or expiring security association (SA) which is associated with an ceipSecTunnelEntry in 'active' state and provides statistic information of this SA. There might be multiple SAs associated with one ceipSecTunnelEntry.
1.3.6.1.4.1.9.9.432.1.1.5not-accessiblecurrent
ceipSecTunnelSaEntry
OBJECT-TYPE
Each entry contains the attributes and statistics associated with an active or expiring IPsec Phase-2 security associations.
1.3.6.1.4.1.9.9.432.1.1.5.1not-accessiblecurrent
ceipSecTunSaProtocol
OBJECT-TYPE
This column represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
1.3.6.1.4.1.9.9.432.1.1.5.1.1CIPsecProtocolnot-accessiblecurrent
ceipSecTunSaIndex
OBJECT-TYPE
The object, in the context of the IPsec tunnel 'ceipSecTunIndex', is an index of security associations comprising the Phase-2 IPsec tunnel represented by the tunnel index 'ceipSecTunIndex'. The value of this index is a number which begins at 1 and is incremented with each SPI associated with the corresponding IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.1.5.1.2Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecTunSaDirection
OBJECT-TYPE
Phase-2 IPsec security associations are simplex. Hence a particular security association is used either for securing outgoing traffic or decoding incoming traffic. This column identifies the direction of the security association represented by this entry.
1.3.6.1.4.1.9.9.432.1.1.5.1.3CIPsecPhase2SaDirectionnot-accessiblecurrent
ceipSecTunSaValue
OBJECT-TYPE
This is the value of the Security Protection Index (SPI) assigned by the system to the security association represented by this entry.
1.3.6.1.4.1.9.9.432.1.1.5.1.4CIPsecSpiread-onlycurrent
ceipSecTunSaIfIndex
OBJECT-TYPE
This object represents the ifIndex of an interface where a tunnel with ceipSecTunIndex is created. Multiple IPsec tunnels can be created using the same interface.
1.3.6.1.4.1.9.9.432.1.1.5.1.5InterfaceIndexread-onlycurrent
ceipSecTunSaInOctets
OBJECT-TYPE
A high capacity count of the total number of octets received by using this SA. This value is accumulated BEFORE determining whether or not the packet should be decompressed.
1.3.6.1.4.1.9.9.432.1.1.5.1.6Counter64read-onlycurrent
ceipSecTunSaInDecompOctets
OBJECT-TYPE
A high capacity count of the total number of decompressed octets received by using this SA. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunSaTunInOctets.
1.3.6.1.4.1.9.9.432.1.1.5.1.7Counter64read-onlycurrent
ceipSecTunSaInPkts
OBJECT-TYPE
The total number of packets received by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.8Counter64read-onlycurrent
ceipSecTunSaInDropPkts
OBJECT-TYPE
The total number of packets dropped during receive process by using this SA. This count does NOT include packets dropped due to Anti-Replay processing.
1.3.6.1.4.1.9.9.432.1.1.5.1.9Counter64read-onlycurrent
ceipSecTunSaInReplayDropPkts
OBJECT-TYPE
The total number of packets dropped during receive processing due to Anti-Replay processing by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.10Counter64read-onlycurrent
ceipSecTunSaInAuths
OBJECT-TYPE
The total number of inbound authentication's performed by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.11Counter64read-onlycurrent
ceipSecTunSaInAuthFails
OBJECT-TYPE
The total number of inbound authentication's which ended in failure by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.12Counter64read-onlycurrent
ceipSecTunSaInDecrypts
OBJECT-TYPE
The total number of inbound decryption's performed by this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.13Counter64read-onlycurrent
ceipSecTunSaInDecryptFails
OBJECT-TYPE
The total number of inbound decryption's which ended in failure by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.14Counter64read-onlycurrent
ceipSecTunSaOutOctets
OBJECT-TYPE
A high capacity count of the total number of octets sent by using this SA. This value is accumulated AFTER determining whether or not the packet should be compressed.
1.3.6.1.4.1.9.9.432.1.1.5.1.15Counter64read-onlycurrent
ceipSecTunSaOutUncompOctets
OBJECT-TYPE
A high capacity count of the total number of uncompressed octets sent by using this SA. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecTunSaTunOutOctets.
1.3.6.1.4.1.9.9.432.1.1.5.1.16Counter64read-onlycurrent
ceipSecTunSaOutPkts
OBJECT-TYPE
The total number of packets sent by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.17Counter64read-onlycurrent
ceipSecTunSaOutDropPkts
OBJECT-TYPE
The total number of packets dropped during send processing by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.18Counter64read-onlycurrent
ceipSecTunSaOutAuths
OBJECT-TYPE
The total number of outbound authentication's performed by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.19Counter64read-onlycurrent
ceipSecTunSaOutAuthFails
OBJECT-TYPE
The total number of outbound authentication's which ended in failure by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.20Counter64read-onlycurrent
ceipSecTunSaOutEncrypts
OBJECT-TYPE
The total number of outbound encryption's performed by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.21Counter64read-onlycurrent
ceipSecTunSaOutEncryptFails
OBJECT-TYPE
The total number of outbound encryption's which ended in failure by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.22Counter64read-onlycurrent
ceipSecTunSaOutCompressedPkts
OBJECT-TYPE
The total number of outbound packets which were successfully compressed by using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.23Counter64read-onlycurrent
ceipSecTunSaOutCompSkippedPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis when using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.24Counter64read-onlycurrent
ceipSecTunSaOutCompFailPkts
OBJECT-TYPE
The total number of outbound packets that failed compression because they grew in size after compression when using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.25Counter64read-onlycurrent
ceipSecTunSaOutCompTooSmallPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but were smaller than the compression threshold size when using this SA.
1.3.6.1.4.1.9.9.432.1.1.5.1.26Counter64read-onlycurrent
ceipSecTunSaStatus
OBJECT-TYPE
This column represents the status of the security association represented by this conceptual row. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.
1.3.6.1.4.1.9.9.432.1.1.5.1.27INTEGER {unknown(1), active(2), expiring(3)}read-onlycurrent
ceipSecIfTunnelTable
OBJECT-TYPE
The IPsec Phase-2 Tunnels to Interface association table. This table contains an entry for each active IPsec Phase-2 Tunnel created under an interface. Multiple IPsec Phase-2 Tunnels can be created using the same interface.
1.3.6.1.4.1.9.9.432.1.1.6not-accessiblecurrent
ceipSecIfTunnelEntry
OBJECT-TYPE
Each entry contains the IPsec Phase-2 Tunnel associated with an interface.
1.3.6.1.4.1.9.9.432.1.1.6.1not-accessiblecurrent
ceipSecIfTunnelStatus
OBJECT-TYPE
This object corresponds to the status of a IPsec Phase-2 Tunnel in ceipSecTunnelTable indexed by ceipSecTunIndex. The valid status this object can have are 'active' and 'awaitCommit'.
1.3.6.1.4.1.9.9.432.1.1.6.1.1CIPsecTunnelStatusread-onlycurrent
ceipSecHistory
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.2
ceipSecHistGlobal
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.2.1
ceipSecHistGlobalCntl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.2.1.1
ceipSecHistTableSize
OBJECT-TYPE
The window size of the IPsec Phase-2 History Tables. The IPsec Phase-2 History Tables are implemented as a sliding window in which only the last 'N' entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-2 History Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, in appropriate SNMP error code should be returned. Setting this value to zero is equivalent to deleting all conceptual rows in the archiving tables ('ceipSecHistTable' and 'ceipSecEndPtHistTable') and disabling the archiving of entries in the tables.
1.3.6.1.4.1.9.9.432.1.2.1.1.1Unsigned32read-writecurrent
ceipSecTunnelHistTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel History Table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'ceipSecHistTableSize'. If the value of 'ceipSecHistTableSize' is 0, archiving of entries in this table is disabled.
1.3.6.1.4.1.9.9.432.1.2.2not-accessiblecurrent
ceipSecTunnelHistEntry
OBJECT-TYPE
Each entry contains the attributes associated with a previously active IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1not-accessiblecurrent
ceipSecTunHistIndex
OBJECT-TYPE
The index of the IPsec Phase-2 Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 4,294,967,295.
1.3.6.1.4.1.9.9.432.1.2.2.1.1Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecTunHistTermReason
OBJECT-TYPE
The reason the IPsec Phase-2 Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = applicationInitiated (eg: L2TP requesting the termination) 7 = failure of extended authentication 8 = local failure occurred 9 = operator initiated check point request
1.3.6.1.4.1.9.9.432.1.2.2.1.2INTEGER {other(1), normal(2), operRequest(3), peerDelRequest(4), peerLost(5), applicationInitiated(6), xauthFailure(7), seqNumRollOver(8), checkPointReq(9)}read-onlycurrent
ceipSecTunHistActiveIndex
OBJECT-TYPE
The index of the previously active IPsec Phase-2 Tunnel. This object must correspond to an expired IPsec tunnel; hence this object may not assume the value of 0.
1.3.6.1.4.1.9.9.432.1.2.2.1.3CIPsecPhase2TunnelIndexread-onlycurrent
ceipSecTunHistLocalAddressType
OBJECT-TYPE
The type of the IP address of the local endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.4InetAddressTyperead-onlycurrent
ceipSecTunHistLocalAddress
OBJECT-TYPE
The IP address of the local endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.5InetAddressread-onlycurrent
ceipSecTunHistRemoteAddressType
OBJECT-TYPE
The type of the IP address of the remote endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.6InetAddressTyperead-onlycurrent
ceipSecTunHistRemoteAddress
OBJECT-TYPE
The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.7InetAddressread-onlycurrent
ceipSecTunHistControlProtocol
OBJECT-TYPE
Identifies the protocol that was used to setup and administer Phase-2 IPsec tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.8CIPsecControlProtocolread-onlycurrent
ceipSecTunHistControlTunnelIndex
OBJECT-TYPE
The index of the IPsec Phase-1 Tunnel that spawned this Phase-2 tunnel (in case of IKE, this value would refer to 'csikeTunIndex' in the 'csikeTunnelTable'). If the IPsec tunnel corresponding to this entry was setup manually, the value of this object should be zero.
1.3.6.1.4.1.9.9.432.1.2.2.1.9CIPsecPhase1TunnelIndexOrZeroread-onlycurrent
ceipSecTunHistEncapMode
OBJECT-TYPE
The encapsulation mode used by the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.10CIPsecEncapModeread-onlycurrent
ceipSecTunHistNATTraversalMode
OBJECT-TYPE
The encapsulation used by the IPsec Phase-2 tunnel corresponding to this conceptual row for NAT traversal.
1.3.6.1.4.1.9.9.432.1.2.2.1.11CIPsecNATTraversalModeread-onlycurrent
ceipSecTunHistLifeSize
OBJECT-TYPE
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
1.3.6.1.4.1.9.9.432.1.2.2.1.12Unsigned32 (1..4294967295)read-onlycurrent
ceipSecTunHistLifeTime
OBJECT-TYPE
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
1.3.6.1.4.1.9.9.432.1.2.2.1.13Unsigned32 (1..4294967295)read-onlycurrent
ceipSecTunHistStartTime
OBJECT-TYPE
The value of sysUpTime in hundredths of seconds when the IPsec Phase-2 Tunnel was started.
1.3.6.1.4.1.9.9.432.1.2.2.1.14TimeStampread-onlycurrent
ceipSecTunHistActiveTime
OBJECT-TYPE
The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.
1.3.6.1.4.1.9.9.432.1.2.2.1.15TimeIntervalread-onlycurrent
ceipSecTunHistTotalRefreshes
OBJECT-TYPE
The total number of security association refreshes performed.
1.3.6.1.4.1.9.9.432.1.2.2.1.16Counter32read-onlycurrent
ceipSecTunHistTotalSas
OBJECT-TYPE
The total number of security associations used during the life of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.17Counter32read-onlycurrent
ceipSecTunHistInSaDHGrp
OBJECT-TYPE
The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.18CIPsecDiffHellmanGrpread-onlycurrent
ceipSecTunHistInSaEncryptAlgo
OBJECT-TYPE
The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.19CIPsecEncryptAlgorithmread-onlycurrent
ceipSecTunHistInSaEncryptKeySize
OBJECT-TYPE
The size in bits of the key which was negotiated to be used with the encryption transform used with this tunnel denoted by ceipSecTunHistInSaEncryptAlgo. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.
1.3.6.1.4.1.9.9.432.1.2.2.1.20CIPsecEncryptionKeySizeread-onlycurrent
ceipSecTunHistInSaAhAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.21CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunHistInSaEspAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.22CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunHistInSaDecompAlgo
OBJECT-TYPE
The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.23CIPsecCompAlgorithmread-onlycurrent
ceipSecTunHistOutSaDHGrp
OBJECT-TYPE
The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.24CIPsecDiffHellmanGrpread-onlycurrent
ceipSecTunHistOutSaEncryptAlgo
OBJECT-TYPE
The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.25CIPsecEncryptAlgorithmread-onlycurrent
ceipSecTunHistOutSaEncryptKeySz
OBJECT-TYPE
The size in bits of the key which was negotiated to be used with the encryption transform used with this tunnel denoted by ceipSecTunHistOutSaEncryptAlgo. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.
1.3.6.1.4.1.9.9.432.1.2.2.1.26CIPsecEncryptionKeySizeread-onlycurrent
ceipSecTunHistOutSaAhAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.27CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunHistOutSaEspAuthAlgo
OBJECT-TYPE
The authentication algorithm used by the inbound ecapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.28CIPsecAuthAlgorithmread-onlycurrent
ceipSecTunHistOutSaCompAlgo
OBJECT-TYPE
The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.29CIPsecCompAlgorithmread-onlycurrent
ceipSecTunHistPmtu
OBJECT-TYPE
The Path MTU that was determined for this IPsec Phase-2 tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.30CIPsecPmturead-onlycurrent
ceipSecTunHistInOctets
OBJECT-TYPE
A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.
1.3.6.1.4.1.9.9.432.1.2.2.1.31Counter64read-onlycurrent
ceipSecTunHistInDecompOctets
OBJECT-TYPE
A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunInOctets.
1.3.6.1.4.1.9.9.432.1.2.2.1.32Counter64read-onlycurrent
ceipSecTunHistInPkts
OBJECT-TYPE
The total number of packets received by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.33Counter32read-onlycurrent
ceipSecTunHistInDropPkts
OBJECT-TYPE
The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.
1.3.6.1.4.1.9.9.432.1.2.2.1.34Counter32read-onlycurrent
ceipSecTunHistInReplayDropPkts
OBJECT-TYPE
The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.35Counter32read-onlycurrent
ceipSecTunHistInAuths
OBJECT-TYPE
The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.36Counter32read-onlycurrent
ceipSecTunHistInAuthFails
OBJECT-TYPE
The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .
1.3.6.1.4.1.9.9.432.1.2.2.1.37Counter32read-onlycurrent
ceipSecTunHistInDecrypts
OBJECT-TYPE
The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.38Counter32read-onlycurrent
ceipSecTunHistInDecryptFails
OBJECT-TYPE
The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.39Counter32read-onlycurrent
ceipSecTunHistOutOctets
OBJECT-TYPE
A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.
1.3.6.1.4.1.9.9.432.1.2.2.1.40Counter64read-onlycurrent
ceipSecTunHistOutUncompOctets
OBJECT-TYPE
A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of 'ceipSecTunOutOctets'.
1.3.6.1.4.1.9.9.432.1.2.2.1.41Counter64read-onlycurrent
ceipSecTunHistOutPkts
OBJECT-TYPE
The total number of packets sent by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.42Counter32read-onlycurrent
ceipSecTunHistOutDropPkts
OBJECT-TYPE
The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.43Counter32read-onlycurrent
ceipSecTunHistOutAuths
OBJECT-TYPE
The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.44Counter32read-onlycurrent
ceipSecTunHistOutAuthFails
OBJECT-TYPE
The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.45Counter32read-onlycurrent
ceipSecTunHistOutEncrypts
OBJECT-TYPE
The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.46Counter32read-onlycurrent
ceipSecTunHistOutEncryptFails
OBJECT-TYPE
The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.
1.3.6.1.4.1.9.9.432.1.2.2.1.47Counter32read-onlycurrent
ceipSecTunHistOutCompressedPkts
OBJECT-TYPE
The total number of outbound packets which were successfully compressed.
1.3.6.1.4.1.9.9.432.1.2.2.1.48Counter32read-onlycurrent
ceipSecTunHistOutCompSkippedPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis.
1.3.6.1.4.1.9.9.432.1.2.2.1.49Counter32read-onlycurrent
ceipSecTunHistOutCompFailPkts
OBJECT-TYPE
The total number of outbound packets that failed compression because they grew in size after compression.
1.3.6.1.4.1.9.9.432.1.2.2.1.50Counter32read-onlycurrent
ceipSecTunHistOutCompSmallPkts
OBJECT-TYPE
The total number of outbound packets that were to be compressed but were smaller than the compression threshold size.
1.3.6.1.4.1.9.9.432.1.2.2.1.51Counter32read-onlycurrent
ceipSecEndPtHistTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel Endpoint History Table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'ceipSecHistTableSize'. If the value of 'ceipSecHistTableSize' is 0, archiving of entries in this table is disabled.
1.3.6.1.4.1.9.9.432.1.2.3not-accessiblecurrent
ceipSecEndPtHistEntry
OBJECT-TYPE
Each entry contains the attributes associated with a previously active IPsec Phase-2 Tunnel Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1not-accessiblecurrent
ceipSecEndPtHistIndex
OBJECT-TYPE
The number of the previously active Endpoint associated with a IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 4,294,967,295.
1.3.6.1.4.1.9.9.432.1.2.3.1.1Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecEndPtHistTunIndex
OBJECT-TYPE
The index of the previously active IPsec Phase-2 Tunnel Table.
1.3.6.1.4.1.9.9.432.1.2.3.1.2Unsigned32 (1..4294967295)read-onlycurrent
ceipSecEndPtHistActiveIndex
OBJECT-TYPE
The index of the previously active Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1.3Unsigned32 (1..4294967295)read-onlycurrent
ceipSecEndPtHistLocalName
OBJECT-TYPE
The DNS name of the local Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1.4SnmpAdminStringread-onlycurrent
ceipSecEndPtHistLocalType
OBJECT-TYPE
The type of identity for the local Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1.5CIPsecEndPtTyperead-onlycurrent
ceipSecEndPtHistLocalAddrType1
OBJECT-TYPE
The type of the IP address for this local Endpoint's first IP address.
1.3.6.1.4.1.9.9.432.1.2.3.1.6InetAddressTyperead-onlycurrent
ceipSecEndPtHistLocalAddr1
OBJECT-TYPE
The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtLocalType.
1.3.6.1.4.1.9.9.432.1.2.3.1.7InetAddressread-onlycurrent
ceipSecEndPtHistLocalAddrType2
OBJECT-TYPE
The type of the IP address for this local Endpoint's second IP address.
1.3.6.1.4.1.9.9.432.1.2.3.1.8InetAddressTyperead-onlycurrent
ceipSecEndPtHistLocalAddr2
OBJECT-TYPE
The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtLocalType.
1.3.6.1.4.1.9.9.432.1.2.3.1.9InetAddressread-onlycurrent
ceipSecEndPtHistLocalProtocol
OBJECT-TYPE
The protocol number of the local Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.2.3.1.10CiscoIpProtocolread-onlycurrent
ceipSecEndPtHistLocalPort
OBJECT-TYPE
The port number of the local Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.2.3.1.11CiscoPortread-onlycurrent
ceipSecEndPtHistRemoteName
OBJECT-TYPE
The DNS name of the remote Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1.12SnmpAdminStringread-onlycurrent
ceipSecEndPtHistRemoteType
OBJECT-TYPE
The type of identity for the remote Endpoint.
1.3.6.1.4.1.9.9.432.1.2.3.1.13CIPsecEndPtTyperead-onlycurrent
ceipSecEndPtHistRemoteAddrType1
OBJECT-TYPE
The type of the IP address for this remote Endpoint's first IP address.
1.3.6.1.4.1.9.9.432.1.2.3.1.14InetAddressTyperead-onlycurrent
ceipSecEndPtHistRemoteAddr1
OBJECT-TYPE
The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtRemoteType.
1.3.6.1.4.1.9.9.432.1.2.3.1.15InetAddressread-onlycurrent
ceipSecEndPtHistRemoteAddrType2
OBJECT-TYPE
The type of the IP address for this remote Endpoint's second IP address.
1.3.6.1.4.1.9.9.432.1.2.3.1.16InetAddressTyperead-onlycurrent
ceipSecEndPtHistRemoteAddr2
OBJECT-TYPE
The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtRemoteType.
1.3.6.1.4.1.9.9.432.1.2.3.1.17InetAddressread-onlycurrent
ceipSecEndPtHistRemoteProtocol
OBJECT-TYPE
The protocol number of the remote Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.2.3.1.18CiscoIpProtocolread-onlycurrent
ceipSecEndPtHistRemotePort
OBJECT-TYPE
The port number of the remote Endpoint's traffic.
1.3.6.1.4.1.9.9.432.1.2.3.1.19CiscoPortread-onlycurrent
ceipSecFailures
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.3
ceipSecFailGlobal
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.3.1
ceipSecFailGlobalCntl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.3.1.1
ceipSecFailTableSize
OBJECT-TYPE
The window size of the IPsec Phase-2 Failure Table. The IPsec Phase-2 Failure Tables are implemented as a sliding window in which only the last N entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-2 Failure Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, an appropriate SNMP error vode must be returned. Setting this value to zero is equivalent to deleting all conceptual rows in the archiving table 'ceipSecFailTable' and disabling the archiving of entries in these tables.
1.3.6.1.4.1.9.9.432.1.3.1.1.1Unsigned32read-writecurrent
ceipSecFailTable
OBJECT-TYPE
The IPsec Phase-2 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the ceipSecFailTableSize object.
1.3.6.1.4.1.9.9.432.1.3.2not-accessiblecurrent
ceipSecFailEntry
OBJECT-TYPE
Each entry contains the attributes associated with an IPsec Phase-1 failure.
1.3.6.1.4.1.9.9.432.1.3.2.1not-accessiblecurrent
ceipSecFailIndex
OBJECT-TYPE
The IPsec Phase-2 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 4,294,967,295.
1.3.6.1.4.1.9.9.432.1.3.2.1.1Unsigned32 (1..4294967295)not-accessiblecurrent
ceipSecFailReason
OBJECT-TYPE
The reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination 17 = performance utilization exceeding the threshold.
1.3.6.1.4.1.9.9.432.1.3.2.1.2INTEGER {other(1), internalError(2), peerEncodingError(3), proposalFailure(4), protocolUseFail(5), nonExistentSa(6), decryptFailure(7), encryptFailure(8), inAuthFailure(9), outAuthFailure(10), compression(11), sysCapExceeded(12), peerDelRequest(13), peerLost(14), seqNumRollOver(15), operRequest(16), performanceUtilization(17)}read-onlycurrent
ceipSecFailTime
OBJECT-TYPE
The value of sysUpTime in hundredths of seconds at the time of the failure.
1.3.6.1.4.1.9.9.432.1.3.2.1.3TimeStampread-onlycurrent
ceipSecFailTunnelIndex
OBJECT-TYPE
The Phase-2 Tunnel index (ceipSecTunIndex). If this conceptual row corresponds to an operation failure (that is, the failure of an established Phase-2 IPsec tunnel), then the value of this object may not be zero.
1.3.6.1.4.1.9.9.432.1.3.2.1.4CIPsecPhase2TunnelIndexread-onlycurrent
ceipSecFailSaSpi
OBJECT-TYPE
The security association SPI value. If this conceptual row corresponds to a setup failure (failure to establish the tunnel), the value of this MIB object is undefined.
1.3.6.1.4.1.9.9.432.1.3.2.1.5CIPsecSpiread-onlycurrent
ceipSecFailPktSrcAddressType
OBJECT-TYPE
The type of the packet's source IP address.
1.3.6.1.4.1.9.9.432.1.3.2.1.6InetAddressTyperead-onlycurrent
ceipSecFailPktSrcAddress
OBJECT-TYPE
The packet's source IP address.
1.3.6.1.4.1.9.9.432.1.3.2.1.7InetAddressread-onlycurrent
ceipSecFailPktDstAddressType
OBJECT-TYPE
The type of the packet's destination IP address.
1.3.6.1.4.1.9.9.432.1.3.2.1.8InetAddressTyperead-onlycurrent
ceipSecFailPktDstAddress
OBJECT-TYPE
The packet's destination IP address.
1.3.6.1.4.1.9.9.432.1.3.2.1.9InetAddressread-onlycurrent
ceipSecNotificationCntl
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.5
ceipSecNotiCntlIpSecAllNotifs
OBJECT-TYPE
This object sending any notification defined in this MIB module. That is, a particular notification 'foo' defined in this MIB module is enabled if and only if the expression (ceipSecNotiCntlIpSecAllNotifs && ceipSecNotiCntl<foo>) evaluates to 'true', where ceipSecNotiCntl<foo> is a notification defined in this MIB module.
1.3.6.1.4.1.9.9.432.1.5.1TruthValueread-writecurrent
ceipSecNotifCntlIpSecTunnelStart
OBJECT-TYPE
This object defines the administrative state of sending the IPsec Phase-2 Tunnel Start TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowTunnelStart' is enabled.
1.3.6.1.4.1.9.9.432.1.5.2TruthValueread-writecurrent
ceipSecNotifCntlIpSecTunnelStop
OBJECT-TYPE
This object defines the administrative state of sending the IPsec Phase-2 Tunnel Stop TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowTunnelStop' is enabled.
1.3.6.1.4.1.9.9.432.1.5.3TruthValueread-writecurrent
ceipSecNotifCntlIpSecSysFailure
OBJECT-TYPE
This object defines the administrative state of sending the IPsec Phase-2 System Failure TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowSysFailure' is enabled.
1.3.6.1.4.1.9.9.432.1.5.4TruthValueread-writecurrent
ceipSecNotifCntlIpSecSetUpFail
OBJECT-TYPE
This object defines the administrative state of sending the IPsec Phase-2 Set Up Failure TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowSetupFail' is enabled.
1.3.6.1.4.1.9.9.432.1.5.5TruthValueread-writecurrent
ceipSecNotifCntlIpSecBadSa
OBJECT-TYPE
This object defines the administrative state of sending the IPsec Phase-2 No Security Association trap. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowBadSa' is enabled.
1.3.6.1.4.1.9.9.432.1.5.6TruthValueread-writecurrent
ceipSecNotifCntlCertExpiry
OBJECT-TYPE
This object defines the administrative state of sending the IPSec certificate expiry notification. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowCertExpiry' is enabled, otherwise notification 'ciscoEnhIpsecFlowCertExpiry' is disabled.
1.3.6.1.4.1.9.9.432.1.5.7TruthValueread-writecurrent
ceipSecNotifCntlCertRenewal
OBJECT-TYPE
This object defines the administrative state of sending the IPSec X.509 certificate renewal status notification. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowCertRenewal' is enabled, otherwise notification 'ciscoEnhIpsecFlowCertRenewal' is disabled.
1.3.6.1.4.1.9.9.432.1.5.8TruthValueread-writecurrent
ceipSecCertNotification
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.1.6
ceipSecCertSubjectName
OBJECT-TYPE
This object provides the subject name from the X.509 certificate, or the alternate subject name if it is available. The subject name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. Example Subject Name: C=US, OU=DEV, CN=Test-01 Example Subject Alternative Name: 2001:0022:0022:0020:0000:0000:0000:0102
1.3.6.1.4.1.9.9.432.1.6.1SnmpAdminStringread-onlycurrent
ceipSecCertSerialNumber
OBJECT-TYPE
This object provides the serial number from the X.509 certificate. The serial number is formatted as a character string matching the output of a ssh-certview command-line application. The issuer name and the serial number identify a unique certificate. Example: 1000655533
1.3.6.1.4.1.9.9.432.1.6.2SnmpAdminStringread-onlycurrent
ceipSecCertIssuerName
OBJECT-TYPE
This object provides the issuer name from the X.509 certificate. The issuer name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. The issuer name and the serial number identify a unique certificate. Example: C=US, O=Cisco, OU=MITG, CN=Lnx-Insta-RootCA-1
1.3.6.1.4.1.9.9.432.1.6.3SnmpAdminStringread-onlycurrent
ceipSecCertExpiryTime
OBJECT-TYPE
This object provides the validity notAfter time from the X.509 certificate. The notAfter time is the time after which the certificate is not valid. The time is formatted as a character string matching the output of a ssh-certview command-line application. Example: 2012 Apr 14th, 19:01:45 GMT
1.3.6.1.4.1.9.9.432.1.6.4SnmpAdminStringread-onlycurrent
ceipSecCertRenewalStatus
OBJECT-TYPE
This object provides the renewal status of the X.509 certificate on the application sending the notification. renewalNotNeeded(1) = certificate is OK and does not need to be renewed renewalRequestNeeded(2) = certificate renewal request is needed renewalRequested(3) = certificate renewal has been requested and the renewal process is proceeding renewalSuccess(4) = certificate has been renewed and will be OK (renewalNotNeeded) renewalFailedUpdate(5) = certificate renewal failed, but certificate is still usable until the validity expiration time provided in the notification, or otherwise restricted by the application renewalFailedExpired(6) = certificate is no longer valid, the current time is after the certificate's validity notAfter time, which is provided in this notification
1.3.6.1.4.1.9.9.432.1.6.5INTEGER {renewalNotNeeded(1), renewalRequestNeeded(2), renewalRequested(3), renewalSuccess(4), renewalFailedUpdate(5), renewalFailedExpired(6)}read-onlycurrent
ceipSecCertExpiryStatus
OBJECT-TYPE
This object provides the expiration status of the X.509 certificate on the application sending the notification. The notification is sent when the value of this object is changed from certOK(1) to certGoingExpired(2). certOK(1) = certificate is OK and is not within the configured time threshold for going to expire certGoingExpired(2) = certificate is within the configured time threshold for going to expire certExpired(3) = certificate has expired, the current time is after the certificate's validity notAfter time
1.3.6.1.4.1.9.9.432.1.6.6INTEGER {certOK(1), certGoingExpired(2), certExpired(3)}read-onlycurrent
ciscoEnhancedIpsecFlowMIBConform
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.2
ciscoEnhIPsecFlowMIBCompliances
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.2.1
ciscoIPsecFlowMIBGroups
OBJECT-IDENTITY
1.3.6.1.4.1.9.9.432.2.2

Notifications

NameOIDStatus
ciscoEnhIpsecFlowTunnelStart
NOTIFICATION-TYPE
This notification is generated when an IPsec Phase-2 Tunnel becomes active.
1.3.6.1.4.1.9.9.432.0.1current
ciscoEnhIpsecFlowTunnelStop
NOTIFICATION-TYPE
This notification is generated when an IPsec Phase-2 Tunnel becomes inactive.
1.3.6.1.4.1.9.9.432.0.2current
ciscoEnhIpsecFlowSysFailure
NOTIFICATION-TYPE
This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences an internal or system capacity error.
1.3.6.1.4.1.9.9.432.0.3current
ciscoEnhIpsecFlowSetupFail
NOTIFICATION-TYPE
This notification is generated when the setup for an IPsec Phase-2 Tunnel fails.
1.3.6.1.4.1.9.9.432.0.4current
ciscoEnhIpsecFlowBadSa
NOTIFICATION-TYPE
This notification is generated when the managed entity receives an IPsec packet with a non-existent (non-existant in the local Security Association Database) SPI.
1.3.6.1.4.1.9.9.432.0.5current
ciscoEnhIpsecFlowCertExpiry
NOTIFICATION-TYPE
This notification is generated to notify that an X.509 certificate is going to expire. The notification is triggered the time threshold configured on the application for notification before the certificate is going to expire, which is when the value of ceipSecCertExpiryStatus is changed from certOK(1) to certGoingExpired(2). The user should take action to renew the certificate identified in the notification prior to the certificate expiration, which is at the validity notAfter time provided in the notification.
1.3.6.1.4.1.9.9.432.0.6current
ciscoEnhIpsecFlowCertRenewal
NOTIFICATION-TYPE
This notification is generated to report a status transition for an X.509 certificate renewal performed by the application. The notification is generated when the value of ceipSecCertRenewalStatus is changed from 1. renewalNotNeeded(1) to renewalRequestNeeded(2) or renewalRequested(3) 2. renewalRequestNeeded(2) to renewalRequested(3) 3. renewalRequested(3) to renewalSuccess(4) or renewalFailedUpdate(5) or renewalFailedExpired(6) 4. renewalFailedUpdate(5) to renewalFailedExpired(6)
1.3.6.1.4.1.9.9.432.0.7current

Conformance

NameOIDStatus
ciscoEnhIPsecFlowMIBCompliance
MODULE-COMPLIANCE
The compliance statement for SNMP entities pertaining to Phase-2 of IP Security Protocol.
1.3.6.1.4.1.9.9.432.2.1.1deprecated
ciscoEnhIPsecFlowMIBComplianceRev1
MODULE-COMPLIANCE
The compliance statement for SNMP entities pertaining to Phase-2 of IP Security Protocol.
1.3.6.1.4.1.9.9.432.2.1.2deprecated
ciscoEnhIPsecFlowMIBComplianceRev2
MODULE-COMPLIANCE
The compliance statement for SNMP entities pertaining to Phase-2 of IP Security Protocol.
1.3.6.1.4.1.9.9.432.2.1.3current
ciscoEnhIPsecFlowActivityGroup
OBJECT-GROUP
This group consists of: 1) IPsec Phase-2 Global Statistics 2) IPsec Phase-2 Tunnel Table 3) IPsec Phase-2 Endpoint Table 4) IPsec Phase-2 Security Association Table
1.3.6.1.4.1.9.9.432.2.2.1current
ciscoEnhIPsecFlowCoreHistGroup
OBJECT-GROUP
This group consists of the core (mandatory) objects pertaining to maintaining history of IPsec activity.
1.3.6.1.4.1.9.9.432.2.2.2current
ciscoEnhIPsecFlowHistoryGroup
OBJECT-GROUP
This group consists of objects that pertain to maintenance of history of IPsec Phase 2 activity.
1.3.6.1.4.1.9.9.432.2.2.3current
ciscoEnhIPsecFlowCoreFailGroup
OBJECT-GROUP
This group consists of the core (mandatory) objects pertaining to maintaining history of failure IPsec activity.
1.3.6.1.4.1.9.9.432.2.2.4current
ciscoEnhIPsecFlowFailureGroup
OBJECT-GROUP
This group consists of objects that pertain to maintenance of history of failures associated with Phase 2 IPsec activity.
1.3.6.1.4.1.9.9.432.2.2.5current
ciscoEnhIPsecFlowNotifCntlGroup
OBJECT-GROUP
This group of objects controls the sending of notifications pertaining to IPsec Phase-2 processing.
1.3.6.1.4.1.9.9.432.2.2.6current
ciscoEnhIPsecFlowNotifGroup
NOTIFICATION-GROUP
This group contains the notifications pertaining to Phase-2 operations and data transfer.
1.3.6.1.4.1.9.9.432.2.2.7current
ciscoEnhIPsecFlowTunnelSaGroup
OBJECT-GROUP
This group consists of the Phase-2 IPsec tunnel Security Association and traffic information.
1.3.6.1.4.1.9.9.432.2.2.8current
ciscoEnhIPsecFlowNotifCntlGroupSup01
OBJECT-GROUP
This supplement group of objects controls the sending of X.509 certificate IPSec notifications.
1.3.6.1.4.1.9.9.432.2.2.9current
ciscoEnhIPsecFlowNotifGroupSup01
NOTIFICATION-GROUP
This supplement group contains the X.509 certificate notifications for the IPSec MIB.
1.3.6.1.4.1.9.9.432.2.2.10current
ciscoEnhIPsecFlowCertObjectGroup
OBJECT-GROUP
This group consists of objects to support X.509 certificates.
1.3.6.1.4.1.9.9.432.2.2.11current
ciscoEnhIPsecFlowPerformanceThroughputGroup
OBJECT-GROUP
This group consists of objects to show the the performance utilization.
1.3.6.1.4.1.9.9.432.2.2.12current