MIBs Depot

JNX-IPSEC-MONITOR-MIB

Registered at
1.3.6.1.4.1.2636.3.22
Last updated
2016-05-31 00:00
Organization
Juniper Networks, Inc.
Revisions
2012-02-10 21:00, 2016-05-31 00:00
Namespace
juniper
Source file
JNX-IPSEC-MONITOR-MIB
Digest
sha256:6b546c8a4d1cc5cc2868ba3d3eb3bd11ab97e5368e1783eab40ac4fdd31dd895

Contact

Juniper Technical Assistance Center Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, CA 94089 E-mail: support@juniper.net

Imports

FromSymbols
INET-ADDRESS-MIBInetAddress, InetAddressType
JUNIPER-IPSEC-FLOW-MON-MIBJnxAuthAlgo, JnxDiffHellmanGrp, JnxEncapMode, JnxEncryptAlgo, JnxIkeAuthMethod, JnxIkeHashAlgo, JnxIkeNegoMode, JnxIkePeerRole, JnxIkePeerType, JnxKeyType, JnxRemotePeerType, JnxSAType
JUNIPER-SMIjnxMibs
JUNIPER-SP-MIBjnxSpSvcSetName
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP
SNMPv2-SMICounter32, Counter64, Integer32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, Unsigned32, iso
SNMPv2-TCDisplayString, TEXTUAL-CONVENTION, TimeInterval

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

HCNUM-TC
IANAifType-MIB
IF-MIB
INET-ADDRESS-MIB
JNX-IPSEC-MONITOR-MIB
JUNIPER-IPSEC-FLOW-MON-MIB
JUNIPER-SMI
JUNIPER-SP-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC

Textual conventions

NameOIDSyntaxAccessStatus
JnxIkeNegState
TEXTUAL-CONVENTION
State of the Phase-1 IKE negotiation.
current
JnxSpi
TEXTUAL-CONVENTION
The type of the SPI associated with IPsec Phase-2 security associations.
current

Objects

NameOIDSyntaxAccessStatus
jnxIpSecMIBObjects
OBJECT-IDENTITY
1.3.6.1.4.1.2636.3.22.1
jnxIpSecLevels
OBJECT-IDENTITY
1.3.6.1.4.1.2636.3.22.1.1
jnxIpSecMibLevel
OBJECT-TYPE
The version of the IPsec MIB.
1.3.6.1.4.1.2636.3.22.1.1.1Integer32 (1..4096)read-onlycurrent
jnxIpSecPhaseOne
OBJECT-IDENTITY
1.3.6.1.4.1.2636.3.22.1.2
jnxIkeTunnelTable
OBJECT-TYPE
The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1not-accessiblecurrent
jnxIkeTunnelEntry
OBJECT-TYPE
Each entry contains the attributes associated with an active IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1not-accessiblecurrent
jnxIkeTunIndex
OBJECT-TYPE
The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.2.1.1.1Integer32 (1..2147483647)not-accessiblecurrent
jnxIkeTunLocalRole
OBJECT-TYPE
The role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder.
1.3.6.1.4.1.2636.3.22.1.2.1.1.2JnxIkePeerRoleread-onlycurrent
jnxIkeTunNegState
OBJECT-TYPE
The state of the current negotiation , It can be 1. matured 2. not matured
1.3.6.1.4.1.2636.3.22.1.2.1.1.3JnxIkeNegStateread-onlycurrent
jnxIkeTunInitiatorCookie
OBJECT-TYPE
Cookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header.
1.3.6.1.4.1.2636.3.22.1.2.1.1.4DisplayStringread-onlycurrent
jnxIkeTunResponderCookie
OBJECT-TYPE
Cookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header.
1.3.6.1.4.1.2636.3.22.1.2.1.1.5DisplayStringread-onlycurrent
jnxIkeTunLocalIdType
OBJECT-TYPE
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.6JnxIkePeerTyperead-onlycurrent
jnxIkeTunLocalIdValue
OBJECT-TYPE
The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
1.3.6.1.4.1.2636.3.22.1.2.1.1.7DisplayStringread-onlycurrent
jnxIkeTunLocalGwAddrType
OBJECT-TYPE
The IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.8InetAddressTyperead-onlycurrent
jnxIkeTunLocalGwAddr
OBJECT-TYPE
The IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.9InetAddressread-onlycurrent
jnxIkeTunLocalCertName
OBJECT-TYPE
Name of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.10DisplayStringread-onlycurrent
jnxIkeTunRemoteIdType
OBJECT-TYPE
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.11JnxIkePeerTyperead-onlycurrent
jnxIkeTunRemoteIdValue
OBJECT-TYPE
The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
1.3.6.1.4.1.2636.3.22.1.2.1.1.12DisplayStringread-onlycurrent
jnxIkeTunRemoteGwAddrType
OBJECT-TYPE
The IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.13InetAddressTyperead-onlycurrent
jnxIkeTunRemoteGwAddr
OBJECT-TYPE
The IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.14InetAddressread-onlycurrent
jnxIkeTunNegoMode
OBJECT-TYPE
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.15JnxIkeNegoModeread-onlycurrent
jnxIkeTunDiffHellmanGrp
OBJECT-TYPE
The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.16JnxDiffHellmanGrpread-onlycurrent
jnxIkeTunEncryptAlgo
OBJECT-TYPE
The encryption algorithm used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.17JnxEncryptAlgoread-onlycurrent
jnxIkeTunHashAlgo
OBJECT-TYPE
The hash algorithm used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.18JnxIkeHashAlgoread-onlycurrent
jnxIkeTunAuthMethod
OBJECT-TYPE
The authentication method used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.19JnxIkeAuthMethodread-onlycurrent
jnxIkeTunLifeTime
OBJECT-TYPE
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.
1.3.6.1.4.1.2636.3.22.1.2.1.1.20Integer32 (1..2147483647)read-onlycurrent
jnxIkeTunActiveTime
OBJECT-TYPE
The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.
1.3.6.1.4.1.2636.3.22.1.2.1.1.21TimeIntervalread-onlycurrent
jnxIkeTunInOctets
OBJECT-TYPE
The total number of octets received by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.22Counter64read-onlycurrent
jnxIkeTunInPkts
OBJECT-TYPE
The total number of packets received by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.23Counter32read-onlycurrent
jnxIkeTunOutOctets
OBJECT-TYPE
The total number of octets sent by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.24Counter64read-onlycurrent
jnxIkeTunOutPkts
OBJECT-TYPE
The total number of packets sent by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.25Counter32read-onlycurrent
jnxIpSecPhaseTwo
OBJECT-IDENTITY
1.3.6.1.4.1.2636.3.22.1.3
jnxIpSecTunnelTable
OBJECT-TYPE
The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1not-accessiblecurrent
jnxIpSecTunnelEntry
OBJECT-TYPE
Each entry contains the attributes associated with an active IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1not-accessiblecurrent
jnxIpSecTunIndex
OBJECT-TYPE
The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.3.1.1.1Integer32 (1..2147483647)not-accessiblecurrent
jnxIpSecRuleName
OBJECT-TYPE
Name of the rule configured in IPSec configuration.
1.3.6.1.4.1.2636.3.22.1.3.1.1.2DisplayStringread-onlycurrent
jnxIpSecTermName
OBJECT-TYPE
Name of the term configured under IPSec rule.
1.3.6.1.4.1.2636.3.22.1.3.1.1.3DisplayStringread-onlycurrent
jnxIpSecTunLocalGwAddrType
OBJECT-TYPE
The IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.4InetAddressTyperead-onlycurrent
jnxIpSecTunLocalGwAddr
OBJECT-TYPE
The IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.5InetAddressread-onlycurrent
jnxIpSecTunRemoteGwAddrType
OBJECT-TYPE
The IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.6InetAddressTyperead-onlycurrent
jnxIpSecTunRemoteGwAddr
OBJECT-TYPE
The IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.7InetAddressread-onlycurrent
jnxIpSecTunLocalProxyId
OBJECT-TYPE
Identifier for the local end.
1.3.6.1.4.1.2636.3.22.1.3.1.1.8DisplayStringread-onlycurrent
jnxIpSecTunRemoteProxyId
OBJECT-TYPE
Identifier for the remote end.
1.3.6.1.4.1.2636.3.22.1.3.1.1.9DisplayStringread-onlycurrent
jnxIpSecTunKeyType
OBJECT-TYPE
The type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installed
1.3.6.1.4.1.2636.3.22.1.3.1.1.10JnxKeyTyperead-onlycurrent
jnxIpSecRemotePeerType
OBJECT-TYPE
The type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand)
1.3.6.1.4.1.2636.3.22.1.3.1.1.11JnxRemotePeerTyperead-onlycurrent
jnxIpSecTunMtu
OBJECT-TYPE
MTU value of this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.12Integer32read-onlycurrent
jnxIpSecTunOutEncryptedBytes
OBJECT-TYPE
Number of bytes encrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.13Counter64read-onlycurrent
jnxIpSecTunOutEncryptedPkts
OBJECT-TYPE
Number of packets encrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.14Counter64read-onlycurrent
jnxIpSecTunInDecryptedBytes
OBJECT-TYPE
Number of bytes decrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.15Counter64read-onlycurrent
jnxIpSecTunInDecryptedPkts
OBJECT-TYPE
Number of packets decrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.16Counter64read-onlycurrent
jnxIpsSecTunAHInBytes
OBJECT-TYPE
Number of incoming bytes authenticated using AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.17Counter64read-onlycurrent
jnxIpsSecTunAHInPkts
OBJECT-TYPE
Number of incoming packets authenticated using AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.18Counter64read-onlycurrent
jnxIpsSecTunAHOutBytes
OBJECT-TYPE
Number of outgoing bytes applied AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.19Counter64read-onlycurrent
jnxIpsSecTunAHOutPkts
OBJECT-TYPE
Number of outgoing packets applied AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.20Counter64read-onlycurrent
jnxIpSecTunReplayDropPkts
OBJECT-TYPE
Number of packets dropped by this Phase-2 tunnel due to anti replay check failure.
1.3.6.1.4.1.2636.3.22.1.3.1.1.21Counter64read-onlycurrent
jnxIpSecTunAhAuthFails
OBJECT-TYPE
Number of packets received by this Phase-2 tunnel that failed AH authentication.
1.3.6.1.4.1.2636.3.22.1.3.1.1.22Counter64read-onlycurrent
jnxIpSecTunEspAuthFails
OBJECT-TYPE
Number of packets received by this Phase-2 tunnel that failed ESP authentication.
1.3.6.1.4.1.2636.3.22.1.3.1.1.23Counter64read-onlycurrent
jnxIpSecTunDecryptFails
OBJECT-TYPE
Number of packets received by this Phase-2 tunnel that failed decryption.
1.3.6.1.4.1.2636.3.22.1.3.1.1.24Counter64read-onlycurrent
jnxIpSecTunBadHeaders
OBJECT-TYPE
Number of packets received by this Phase-2 tunnel that failed due to bad headers.
1.3.6.1.4.1.2636.3.22.1.3.1.1.25Counter64read-onlycurrent
jnxIpSecTunBadTrailers
OBJECT-TYPE
Number of packets received by this Phase-2 tunnel that failed due to bad ESP trailers.
1.3.6.1.4.1.2636.3.22.1.3.1.1.26Counter64read-onlycurrent
jnxIpSecTunDroppedPkts
OBJECT-TYPE
Total number of dropped packets for this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.27Counter64read-onlycurrent
jnxIpSecSaTable
OBJECT-TYPE
The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations.
1.3.6.1.4.1.2636.3.22.1.3.2not-accessiblecurrent
jnxIpSecSaEntry
OBJECT-TYPE
Each entry contains the attributes associated with active and expiring IPsec Phase-2 security associations.
1.3.6.1.4.1.2636.3.22.1.3.2.1not-accessiblecurrent
jnxIpSecSaProtocol
OBJECT-TYPE
The index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
1.3.6.1.4.1.2636.3.22.1.3.2.1.1INTEGER {ah(1), esp(2)}not-accessiblecurrent
jnxIpSecSaIndex
OBJECT-TYPE
The index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.3.2.1.2Integer32 (1..2147483647)not-accessiblecurrent
jnxIpSecSaInSpi
OBJECT-TYPE
The value of the incoming SPI.
1.3.6.1.4.1.2636.3.22.1.3.2.1.3JnxSpiread-onlycurrent
jnxIpSecSaOutSpi
OBJECT-TYPE
The value of the outgoing SPI.
1.3.6.1.4.1.2636.3.22.1.3.2.1.4JnxSpiread-onlycurrent
jnxIpSecSaInAuxSpi
OBJECT-TYPE
The value of the incoming auxiliary SPI. This is valid for AH and ESP bundles.
1.3.6.1.4.1.2636.3.22.1.3.2.1.5JnxSpiread-onlycurrent
jnxIpSecSaOutAuxSpi
OBJECT-TYPE
The value of the outgoing auxiliary SPI. This is valid for AH and ESP bundles.
1.3.6.1.4.1.2636.3.22.1.3.2.1.6JnxSpiread-onlycurrent
jnxIpSecSaType
OBJECT-TYPE
This field represents the type of security associations which can be either manual or dynamic
1.3.6.1.4.1.2636.3.22.1.3.2.1.7JnxSATyperead-onlycurrent
jnxIpSecSaEncapMode
OBJECT-TYPE
The encapsulation mode used by an IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.2.1.8JnxEncapModeread-onlycurrent
jnxIpSecSaLifeSize
OBJECT-TYPE
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
1.3.6.1.4.1.2636.3.22.1.3.2.1.9Integer32read-onlycurrent
jnxIpSecSaLifeTime
OBJECT-TYPE
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.10Integer32read-onlycurrent
jnxIpSecSaActiveTime
OBJECT-TYPE
The length of time the IPsec Phase-2 Tunnel has been active in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.11TimeIntervalread-onlycurrent
jnxIpSecSaLifeSizeThreshold
OBJECT-TYPE
The security association LifeSize refresh threshold in kilobytes.
1.3.6.1.4.1.2636.3.22.1.3.2.1.12Integer32read-onlycurrent
jnxIpSecSaLifeTimeThreshold
OBJECT-TYPE
The security association LifeTime refresh threshold in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.13Integer32read-onlycurrent
jnxIpSecSaEncryptAlgo
OBJECT-TYPE
The Encryption algorithm used to encrypt the packets which can be either es-cbc or 3des-cbc.
1.3.6.1.4.1.2636.3.22.1.3.2.1.14JnxEncryptAlgoread-onlycurrent
jnxIpSecSaAuthAlgo
OBJECT-TYPE
The algorithm used for authentication of packets which can be hmac-md5-96 or hmac-sha1-96
1.3.6.1.4.1.2636.3.22.1.3.2.1.15JnxAuthAlgoread-onlycurrent
jnxIpSecSaState
OBJECT-TYPE
This column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.
1.3.6.1.4.1.2636.3.22.1.3.2.1.16INTEGER {unknown(0), active(1), expiring(2)}read-onlycurrent