JNX-IPSEC-MONITOR-MIB
- Registered at
- 1.3.6.1.4.1.2636.3.22
- Last updated
- 2016-05-31 00:00
- Organization
- Juniper Networks, Inc.
- Revisions
- 2012-02-10 21:00, 2016-05-31 00:00
- Namespace
- juniper
- Source file
JNX-IPSEC-MONITOR-MIB- Digest
sha256:6b546c8a4d1cc5cc2868ba3d3eb3bd11ab97e5368e1783eab40ac4fdd31dd895
Contact
Juniper Technical Assistance Center Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, CA 94089 E-mail: support@juniper.net
Imports
| From | Symbols |
|---|---|
| INET-ADDRESS-MIB | InetAddress, InetAddressType |
| JUNIPER-IPSEC-FLOW-MON-MIB | JnxAuthAlgo, JnxDiffHellmanGrp, JnxEncapMode, JnxEncryptAlgo, JnxIkeAuthMethod, JnxIkeHashAlgo, JnxIkeNegoMode, JnxIkePeerRole, JnxIkePeerType, JnxKeyType, JnxRemotePeerType, JnxSAType |
| JUNIPER-SMI | jnxMibs |
| JUNIPER-SP-MIB | jnxSpSvcSetName |
| SNMPv2-CONF | MODULE-COMPLIANCE, NOTIFICATION-GROUP |
| SNMPv2-SMI | Counter32, Counter64, Integer32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso |
| SNMPv2-TC | DisplayString, TEXTUAL-CONVENTION, TimeInterval |
Imported by
Nothing in this corpus imports this module.
Load order
Every file a consumer needs in order to load this module, dependencies first.
HCNUM-TC IANAifType-MIB IF-MIB INET-ADDRESS-MIB JNX-IPSEC-MONITOR-MIB JUNIPER-IPSEC-FLOW-MON-MIB JUNIPER-SMI JUNIPER-SP-MIB SNMPv2-CONF SNMPv2-MIB SNMPv2-SMI SNMPv2-TC
Textual conventions
| Name | OID | Syntax | Access | Status |
|---|---|---|---|---|
| JnxIkeNegState TEXTUAL-CONVENTION State of the Phase-1 IKE negotiation. | current | |||
| JnxSpi TEXTUAL-CONVENTION The type of the SPI associated with IPsec Phase-2 security associations. | current |
Objects
| Name | OID | Syntax | Access | Status |
|---|---|---|---|---|
| jnxIpSecMIBObjects OBJECT-IDENTITY | 1.3.6.1.4.1.2636.3.22.1 | |||
| jnxIpSecLevels OBJECT-IDENTITY | 1.3.6.1.4.1.2636.3.22.1.1 | |||
| jnxIpSecMibLevel OBJECT-TYPE The version of the IPsec MIB. | 1.3.6.1.4.1.2636.3.22.1.1.1 | Integer32 (1..4096) | read-only | current |
| jnxIpSecPhaseOne OBJECT-IDENTITY | 1.3.6.1.4.1.2636.3.22.1.2 | |||
| jnxIkeTunnelTable OBJECT-TYPE The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1 | not-accessible | current | |
| jnxIkeTunnelEntry OBJECT-TYPE Each entry contains the attributes associated with an active IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1 | not-accessible | current | |
| jnxIkeTunIndex OBJECT-TYPE The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.1 | Integer32 (1..2147483647) | not-accessible | current |
| jnxIkeTunLocalRole OBJECT-TYPE The role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.2 | JnxIkePeerRole | read-only | current |
| jnxIkeTunNegState OBJECT-TYPE The state of the current negotiation , It can be 1. matured 2. not matured | 1.3.6.1.4.1.2636.3.22.1.2.1.1.3 | JnxIkeNegState | read-only | current |
| jnxIkeTunInitiatorCookie OBJECT-TYPE Cookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.4 | DisplayString | read-only | current |
| jnxIkeTunResponderCookie OBJECT-TYPE Cookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.5 | DisplayString | read-only | current |
| jnxIkeTunLocalIdType OBJECT-TYPE The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.6 | JnxIkePeerType | read-only | current |
| jnxIkeTunLocalIdValue OBJECT-TYPE The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.7 | DisplayString | read-only | current |
| jnxIkeTunLocalGwAddrType OBJECT-TYPE The IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.8 | InetAddressType | read-only | current |
| jnxIkeTunLocalGwAddr OBJECT-TYPE The IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.9 | InetAddress | read-only | current |
| jnxIkeTunLocalCertName OBJECT-TYPE Name of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.10 | DisplayString | read-only | current |
| jnxIkeTunRemoteIdType OBJECT-TYPE The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.11 | JnxIkePeerType | read-only | current |
| jnxIkeTunRemoteIdValue OBJECT-TYPE The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.12 | DisplayString | read-only | current |
| jnxIkeTunRemoteGwAddrType OBJECT-TYPE The IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.13 | InetAddressType | read-only | current |
| jnxIkeTunRemoteGwAddr OBJECT-TYPE The IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.14 | InetAddress | read-only | current |
| jnxIkeTunNegoMode OBJECT-TYPE The negotiation mode of the IPsec Phase-1 IKE Tunnel. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.15 | JnxIkeNegoMode | read-only | current |
| jnxIkeTunDiffHellmanGrp OBJECT-TYPE The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.16 | JnxDiffHellmanGrp | read-only | current |
| jnxIkeTunEncryptAlgo OBJECT-TYPE The encryption algorithm used in IPsec Phase-1 IKE negotiations. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.17 | JnxEncryptAlgo | read-only | current |
| jnxIkeTunHashAlgo OBJECT-TYPE The hash algorithm used in IPsec Phase-1 IKE negotiations. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.18 | JnxIkeHashAlgo | read-only | current |
| jnxIkeTunAuthMethod OBJECT-TYPE The authentication method used in IPsec Phase-1 IKE negotiations. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.19 | JnxIkeAuthMethod | read-only | current |
| jnxIkeTunLifeTime OBJECT-TYPE The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.20 | Integer32 (1..2147483647) | read-only | current |
| jnxIkeTunActiveTime OBJECT-TYPE The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.21 | TimeInterval | read-only | current |
| jnxIkeTunInOctets OBJECT-TYPE The total number of octets received by this IPsec Phase-1 IKE security association. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.22 | Counter64 | read-only | current |
| jnxIkeTunInPkts OBJECT-TYPE The total number of packets received by this IPsec Phase-1 IKE security association. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.23 | Counter32 | read-only | current |
| jnxIkeTunOutOctets OBJECT-TYPE The total number of octets sent by this IPsec Phase-1 IKE security association. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.24 | Counter64 | read-only | current |
| jnxIkeTunOutPkts OBJECT-TYPE The total number of packets sent by this IPsec Phase-1 IKE security association. | 1.3.6.1.4.1.2636.3.22.1.2.1.1.25 | Counter32 | read-only | current |
| jnxIpSecPhaseTwo OBJECT-IDENTITY | 1.3.6.1.4.1.2636.3.22.1.3 | |||
| jnxIpSecTunnelTable OBJECT-TYPE The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1 | not-accessible | current | |
| jnxIpSecTunnelEntry OBJECT-TYPE Each entry contains the attributes associated with an active IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1 | not-accessible | current | |
| jnxIpSecTunIndex OBJECT-TYPE The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.1 | Integer32 (1..2147483647) | not-accessible | current |
| jnxIpSecRuleName OBJECT-TYPE Name of the rule configured in IPSec configuration. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.2 | DisplayString | read-only | current |
| jnxIpSecTermName OBJECT-TYPE Name of the term configured under IPSec rule. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.3 | DisplayString | read-only | current |
| jnxIpSecTunLocalGwAddrType OBJECT-TYPE The IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.4 | InetAddressType | read-only | current |
| jnxIpSecTunLocalGwAddr OBJECT-TYPE The IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.5 | InetAddress | read-only | current |
| jnxIpSecTunRemoteGwAddrType OBJECT-TYPE The IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.6 | InetAddressType | read-only | current |
| jnxIpSecTunRemoteGwAddr OBJECT-TYPE The IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.7 | InetAddress | read-only | current |
| jnxIpSecTunLocalProxyId OBJECT-TYPE Identifier for the local end. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.8 | DisplayString | read-only | current |
| jnxIpSecTunRemoteProxyId OBJECT-TYPE Identifier for the remote end. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.9 | DisplayString | read-only | current |
| jnxIpSecTunKeyType OBJECT-TYPE The type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installed | 1.3.6.1.4.1.2636.3.22.1.3.1.1.10 | JnxKeyType | read-only | current |
| jnxIpSecRemotePeerType OBJECT-TYPE The type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand) | 1.3.6.1.4.1.2636.3.22.1.3.1.1.11 | JnxRemotePeerType | read-only | current |
| jnxIpSecTunMtu OBJECT-TYPE MTU value of this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.12 | Integer32 | read-only | current |
| jnxIpSecTunOutEncryptedBytes OBJECT-TYPE Number of bytes encrypted by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.13 | Counter64 | read-only | current |
| jnxIpSecTunOutEncryptedPkts OBJECT-TYPE Number of packets encrypted by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.14 | Counter64 | read-only | current |
| jnxIpSecTunInDecryptedBytes OBJECT-TYPE Number of bytes decrypted by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.15 | Counter64 | read-only | current |
| jnxIpSecTunInDecryptedPkts OBJECT-TYPE Number of packets decrypted by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.16 | Counter64 | read-only | current |
| jnxIpsSecTunAHInBytes OBJECT-TYPE Number of incoming bytes authenticated using AH by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.17 | Counter64 | read-only | current |
| jnxIpsSecTunAHInPkts OBJECT-TYPE Number of incoming packets authenticated using AH by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.18 | Counter64 | read-only | current |
| jnxIpsSecTunAHOutBytes OBJECT-TYPE Number of outgoing bytes applied AH by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.19 | Counter64 | read-only | current |
| jnxIpsSecTunAHOutPkts OBJECT-TYPE Number of outgoing packets applied AH by this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.20 | Counter64 | read-only | current |
| jnxIpSecTunReplayDropPkts OBJECT-TYPE Number of packets dropped by this Phase-2 tunnel due to anti replay check failure. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.21 | Counter64 | read-only | current |
| jnxIpSecTunAhAuthFails OBJECT-TYPE Number of packets received by this Phase-2 tunnel that failed AH authentication. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.22 | Counter64 | read-only | current |
| jnxIpSecTunEspAuthFails OBJECT-TYPE Number of packets received by this Phase-2 tunnel that failed ESP authentication. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.23 | Counter64 | read-only | current |
| jnxIpSecTunDecryptFails OBJECT-TYPE Number of packets received by this Phase-2 tunnel that failed decryption. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.24 | Counter64 | read-only | current |
| jnxIpSecTunBadHeaders OBJECT-TYPE Number of packets received by this Phase-2 tunnel that failed due to bad headers. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.25 | Counter64 | read-only | current |
| jnxIpSecTunBadTrailers OBJECT-TYPE Number of packets received by this Phase-2 tunnel that failed due to bad ESP trailers. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.26 | Counter64 | read-only | current |
| jnxIpSecTunDroppedPkts OBJECT-TYPE Total number of dropped packets for this Phase-2 tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.1.1.27 | Counter64 | read-only | current |
| jnxIpSecSaTable OBJECT-TYPE The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations. | 1.3.6.1.4.1.2636.3.22.1.3.2 | not-accessible | current | |
| jnxIpSecSaEntry OBJECT-TYPE Each entry contains the attributes associated with active and expiring IPsec Phase-2 security associations. | 1.3.6.1.4.1.2636.3.22.1.3.2.1 | not-accessible | current | |
| jnxIpSecSaProtocol OBJECT-TYPE The index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.1 | INTEGER {ah(1), esp(2)} | not-accessible | current |
| jnxIpSecSaIndex OBJECT-TYPE The index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.2 | Integer32 (1..2147483647) | not-accessible | current |
| jnxIpSecSaInSpi OBJECT-TYPE The value of the incoming SPI. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.3 | JnxSpi | read-only | current |
| jnxIpSecSaOutSpi OBJECT-TYPE The value of the outgoing SPI. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.4 | JnxSpi | read-only | current |
| jnxIpSecSaInAuxSpi OBJECT-TYPE The value of the incoming auxiliary SPI. This is valid for AH and ESP bundles. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.5 | JnxSpi | read-only | current |
| jnxIpSecSaOutAuxSpi OBJECT-TYPE The value of the outgoing auxiliary SPI. This is valid for AH and ESP bundles. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.6 | JnxSpi | read-only | current |
| jnxIpSecSaType OBJECT-TYPE This field represents the type of security associations which can be either manual or dynamic | 1.3.6.1.4.1.2636.3.22.1.3.2.1.7 | JnxSAType | read-only | current |
| jnxIpSecSaEncapMode OBJECT-TYPE The encapsulation mode used by an IPsec Phase-2 Tunnel. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.8 | JnxEncapMode | read-only | current |
| jnxIpSecSaLifeSize OBJECT-TYPE The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.9 | Integer32 | read-only | current |
| jnxIpSecSaLifeTime OBJECT-TYPE The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.10 | Integer32 | read-only | current |
| jnxIpSecSaActiveTime OBJECT-TYPE The length of time the IPsec Phase-2 Tunnel has been active in seconds. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.11 | TimeInterval | read-only | current |
| jnxIpSecSaLifeSizeThreshold OBJECT-TYPE The security association LifeSize refresh threshold in kilobytes. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.12 | Integer32 | read-only | current |
| jnxIpSecSaLifeTimeThreshold OBJECT-TYPE The security association LifeTime refresh threshold in seconds. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.13 | Integer32 | read-only | current |
| jnxIpSecSaEncryptAlgo OBJECT-TYPE The Encryption algorithm used to encrypt the packets which can be either es-cbc or 3des-cbc. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.14 | JnxEncryptAlgo | read-only | current |
| jnxIpSecSaAuthAlgo OBJECT-TYPE The algorithm used for authentication of packets which can be hmac-md5-96 or hmac-sha1-96 | 1.3.6.1.4.1.2636.3.22.1.3.2.1.15 | JnxAuthAlgo | read-only | current |
| jnxIpSecSaState OBJECT-TYPE This column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged. | 1.3.6.1.4.1.2636.3.22.1.3.2.1.16 | INTEGER {unknown(0), active(1), expiring(2)} | read-only | current |