MIBs Depot

RAPID-IPSEC-SA-MON-MIB-EXT

Registered at
1.3.6.1.4.1.4355.3
Last updated
2000-03-21 12:00
Organization
WatchGuard Technologies, Inc.
Revisions
2000-03-21 12:00, 2002-11-01 12:00
Namespace
nortel
Source file
RAPID-IPSEC-SA-MON-MIB-EXT
Digest
sha256:e82d8e8294dd1b61c70800fe05bcdae477f0258269b6199a2b59f40e3dc45393

Description

The MIB module describes generic IPSec objects defined in IETF working draft 'draft-ieft-ipsec-monitor-mib-01' and RapidStream's extension.

Contact

Ella Yu WatchGuard Technologies, Inc. 1841 Zanker Road San Jose, CA 95112 USA 408-519-4888 ella.yu@watchguard.com

Imports

FromSymbols
IF-MIBifIndex
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform, IpsecDoiAuthAlgorithm, IpsecDoiEncapsulationMode, IpsecDoiEspTransform, IpsecDoiIdentType, IpsecDoiIpcompTransform, IpsecDoiSecProtocolId
RAPID-MIBrapidstream
SNMPv2-CONFMODULE-COMPLIANCE, NOTIFICATION-GROUP
SNMPv2-SMICounter32, Gauge32, Integer32, MODULE-IDENTITY, NOTIFICATION-TYPE, OBJECT-IDENTITY, OBJECT-TYPE, enterprises, iso
SNMPv2-TCDisplayString, TEXTUAL-CONVENTION, TruthValue

Imported by

Nothing in this corpus imports this module.

Load order

Every file a consumer needs in order to load this module, dependencies first.

IANAifType-MIB
IF-MIB
IPSEC-ISAKMP-IKE-DOI-TC
RAPID-IPSEC-SA-MON-MIB-EXT
RAPID-MIB
SNMPv2-CONF
SNMPv2-MIB
SNMPv2-SMI
SNMPv2-TC

Textual conventions

NameOIDSyntaxAccessStatus
IpsecIpv6Address
TEXTUAL-CONVENTION
This data type is used to model IPv6 address prefixes. This is a binary string of 16 octets in network byte-order.
current
IpsecSaCreatorIdent
TEXTUAL-CONVENTION
A value indicating how an SA was created.
current

Objects

NameOIDSyntaxAccessStatus
rsIpsecSaMonitorMIB
OBJECT-IDENTITY
This is the base object identifier for all IPSec branches.
1.3.6.1.4.1.4355.3.1current
rsSaTables
OBJECT-IDENTITY
This is the base object identifier for all SA tables.
1.3.6.1.4.1.4355.3.1.1current
rsIpsecSaEspInTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec inbound ESP SAs. There should be one row for every inbound ESP security association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.1not-accessiblecurrent
rsIpsecSaEspInEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec inbound ESP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.1.1not-accessiblecurrent
rsIpsecSaEspInAddress
OBJECT-TYPE
The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.1.1.1IpAddressread-onlycurrent
rsIpsecSaEspInSpi
OBJECT-TYPE
The security parameters index of the SA.
1.3.6.1.4.1.4355.3.1.1.1.1.2Integer32read-onlycurrent
rsIpsecSaEspInDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.1.1.3OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaEspInDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaEspInDestId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.1.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaEspInSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.1.1.5OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaEspInSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaEspInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.1.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaEspInProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.1.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaEspInDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.1.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaEspInSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.1.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaEspInCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.1.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaEspInEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.1.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaEspInEncAlg
OBJECT-TYPE
A unique value representing the encryption algorithm applied to traffic or 0 if there is no encryption used.
1.3.6.1.4.1.4355.3.1.1.1.1.12IpsecDoiEspTransformread-onlycurrent
rsIpsecSaEspInEncKeyLength
OBJECT-TYPE
The length of the encryption key in bits used for the algorithm specified in the 'rsIpsecSaEspInEncAlg' object, or 0 if the key length is implicit in the specified algorithm or there is no encryption specified.
1.3.6.1.4.1.4355.3.1.1.1.1.13Integer32 (0..65531)read-onlycurrent
rsIpsecSaEspInAuthAlg
OBJECT-TYPE
A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used.
1.3.6.1.4.1.4355.3.1.1.1.1.14IpsecDoiAuthAlgorithmread-onlycurrent
rsIpsecSaEspInLimitSeconds
OBJECT-TYPE
The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.1.1.15Integer32read-onlycurrent
rsIpsecSaEspInLimitKbytes
OBJECT-TYPE
The maximum traffic in kilobytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.1.1.16Integer32read-onlycurrent
rsIpsecSaEspInAccSeconds
OBJECT-TYPE
The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.1.1.17Counter32read-onlycurrent
rsIpsecSaEspInAccKbytes
OBJECT-TYPE
The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic.
1.3.6.1.4.1.4355.3.1.1.1.1.18Counter32read-onlycurrent
rsIpsecSaEspInUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit.
1.3.6.1.4.1.4355.3.1.1.1.1.19Counter32read-onlycurrent
rsIpsecSaEspInPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.1.1.20Counter32read-onlycurrent
rsIpsecSaEspInDecryptErrors
OBJECT-TYPE
The number of packets discarded by the SA due to decryption errors.
1.3.6.1.4.1.4355.3.1.1.1.1.21Counter32read-onlycurrent
rsIpsecSaEspInAuthErrors
OBJECT-TYPE
The number of packets discarded by the SA due to authentication errors.
1.3.6.1.4.1.4355.3.1.1.1.1.22Counter32read-onlycurrent
rsIpsecSaEspInReplayErrors
OBJECT-TYPE
The number of packets discarded by the SA due to replay errors.
1.3.6.1.4.1.4355.3.1.1.1.1.23Counter32read-onlycurrent
rsIpsecSaEspInPolicyErrors
OBJECT-TYPE
The number of packets discarded by the SA due to policy errors. This includes packets where the next protocol is invalid.
1.3.6.1.4.1.4355.3.1.1.1.1.24Counter32read-onlycurrent
rsIpsecSaEspInPadErrors
OBJECT-TYPE
The number of packets discarded by the SA due to pad value errors. Implementations that do not check this must not support this object.
1.3.6.1.4.1.4355.3.1.1.1.1.25Counter32read-onlycurrent
rsIpsecSaEspInOtherReceiveErrors
OBJECT-TYPE
The number of packets discarded by the SA due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the decryption element.
1.3.6.1.4.1.4355.3.1.1.1.1.26Counter32read-onlycurrent
rsIpsecSaAhInTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec inbound AH SAs. There should be one row for every inbound AH security association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.2not-accessiblecurrent
rsIpsecSaAhInEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec inbound AH SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.2.1not-accessiblecurrent
rsIpsecSaAhInAddress
OBJECT-TYPE
The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.2.1.1IpAddressread-onlycurrent
rsIpsecSaAhInSpi
OBJECT-TYPE
The security parameters index of the SA.
1.3.6.1.4.1.4355.3.1.1.2.1.2Integer32read-onlycurrent
rsIpsecSaAhInDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.2.1.3OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaAhInDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaAhInDestId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.2.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaAhInSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.2.1.5OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaAhInSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaAhInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.2.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaAhInProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.2.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaAhInDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.2.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaAhInSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.2.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaAhInCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.2.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaAhInEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.2.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaAhInAuthAlg
OBJECT-TYPE
A unique value representing the hash algorithm applied to traffic carried by this SA if it uses ESP or 0 if there is no authentication applied by ESP.
1.3.6.1.4.1.4355.3.1.1.2.1.12IpsecDoiAhTransformread-onlycurrent
rsIpsecSaAhInLimitSeconds
OBJECT-TYPE
The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.2.1.13Integer32read-onlycurrent
rsIpsecSaAhInLimitKbytes
OBJECT-TYPE
The maximum traffic in Kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.2.1.14Integer32read-onlycurrent
rsIpsecSaAhInAccSeconds
OBJECT-TYPE
The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.2.1.15Counter32read-onlycurrent
rsIpsecSaAhInAccKbytes
OBJECT-TYPE
The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic.
1.3.6.1.4.1.4355.3.1.1.2.1.16Counter32read-onlycurrent
rsIpsecSaAhInUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit.
1.3.6.1.4.1.4355.3.1.1.2.1.17Counter32read-onlycurrent
rsIpsecSaAhInPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.2.1.18Counter32read-onlycurrent
rsIpsecSaAhInAuthErrors
OBJECT-TYPE
The number of packets discarded by the SA due to authentication errors.
1.3.6.1.4.1.4355.3.1.1.2.1.19Counter32read-onlycurrent
rsIpsecSaAhInReplayErrors
OBJECT-TYPE
The number of packets discarded by the SA due to replay errors.
1.3.6.1.4.1.4355.3.1.1.2.1.20Counter32read-onlycurrent
rsIpsecSaAhInPolicyErrors
OBJECT-TYPE
The number of packets discarded by the SA due to policy errors. This includes packets where the next protocol is invalid.
1.3.6.1.4.1.4355.3.1.1.2.1.21Counter32read-onlycurrent
rsIpsecSaAhInOtherReceiveErrors
OBJECT-TYPE
The number of packets discarded by the SA due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the authentication element.
1.3.6.1.4.1.4355.3.1.1.2.1.22Counter32read-onlycurrent
rsIpsecSaIpcompInTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec inbound IPCOMP SAs. There should be one row for every inbound IPCOMP (security) association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.3not-accessiblecurrent
rsIpsecSaIpcompInEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec inbound IPCOMP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.3.1not-accessiblecurrent
rsIpsecSaIpcompInAddress
OBJECT-TYPE
The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.3.1.1IpAddressread-onlycurrent
rsIpsecSaIpcompInCpi
OBJECT-TYPE
The CPI of the SA. Since the lower values of CPIs are reserved to be the same as the algorithm, the syntax for this object is the same as the transform.
1.3.6.1.4.1.4355.3.1.1.3.1.2IpsecDoiIpcompTransformread-onlycurrent
rsIpsecSaIpcompInDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.3.1.3OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaIpcompInDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaIpcompInDestId', or 0 if unknown or if the SA uses transport mode, or 0 if this SA is used with multiple SAs in protection suites.
1.3.6.1.4.1.4355.3.1.1.3.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaIpcompInSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during SA creation negotiation.
1.3.6.1.4.1.4355.3.1.1.3.1.5OCTET STRING (SIZE(1..255))read-onlycurrent
rsIpsecSaIpcompInSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaIpcompInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites.
1.3.6.1.4.1.4355.3.1.1.3.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaIpcompInProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.3.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaIpcompInDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.3.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaIpcompInSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.3.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaIpcompInCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.3.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaIpcompInEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.3.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaIpcompInDecompAlg
OBJECT-TYPE
A unique value representing the decompression algorithm applied to traffic.
1.3.6.1.4.1.4355.3.1.1.3.1.12IpsecDoiIpcompTransformread-onlycurrent
rsIpsecSaIpcompInSeconds
OBJECT-TYPE
The number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.3.1.13Counter32read-onlycurrent
rsIpsecSaIpcompInUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA.
1.3.6.1.4.1.4355.3.1.1.3.1.14Counter32read-onlycurrent
rsIpsecSaIpcompInPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.3.1.15Counter32read-onlycurrent
rsIpsecSaIpcompInDecompErrors
OBJECT-TYPE
The number of packets discarded by the SA due to decompression errors.
1.3.6.1.4.1.4355.3.1.1.3.1.16Counter32read-onlycurrent
rsIpsecSaIpcompInOtherReceiveErrors
OBJECT-TYPE
The number of packets discarded by the SA due to errors other than decompression errors. This may include packets dropped due to a lack of receive buffers, and packets dropped due to congestion at the decompression element.
1.3.6.1.4.1.4355.3.1.1.3.1.17Counter32read-onlycurrent
rsIpsecSaEspOutTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec Outbound ESP SAs. There should be one row for every outbound ESP security association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.4not-accessiblecurrent
rsIpsecSaEspOutEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec Outbound ESP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.4.1not-accessiblecurrent
rsIpsecSaEspOutAddress
OBJECT-TYPE
The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.4.1.1IpAddressread-onlycurrent
rsIpsecSaEspOutSpi
OBJECT-TYPE
The security parameters index of the SA.
1.3.6.1.4.1.4355.3.1.1.4.1.2Integer32read-onlycurrent
rsIpsecSaEspOutSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.4.1.3OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaEspOutSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.4.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaEspOutDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.4.1.5OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaEspOutDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaEspOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.4.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaEspOutProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.4.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaEspOutSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.4.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaEspOutDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.4.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaEspOutCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.4.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaEspOutEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.4.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaEspOutEncAlg
OBJECT-TYPE
A unique value representing the encryption algorithm applied to traffic or 0 if there is no encryption used.
1.3.6.1.4.1.4355.3.1.1.4.1.12IpsecDoiEspTransformread-onlycurrent
rsIpsecSaEspOutEncKeyLength
OBJECT-TYPE
The length of the encryption key in bits used for the algorithm specified in the 'rsIpsecSaEspOutEncAlg' object, or 0 if the key length is implicit in the specified algorithm or there is no encryption specified.
1.3.6.1.4.1.4355.3.1.1.4.1.13Integer32 (0..65531)read-onlycurrent
rsIpsecSaEspOutAuthAlg
OBJECT-TYPE
A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used.
1.3.6.1.4.1.4355.3.1.1.4.1.14IpsecDoiAuthAlgorithmread-onlycurrent
rsIpsecSaEspOutLimitSeconds
OBJECT-TYPE
The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.4.1.15Integer32read-onlycurrent
rsIpsecSaEspOutLimitKbytes
OBJECT-TYPE
The maximum traffic in kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.4.1.16Integer32read-onlycurrent
rsIpsecSaEspOutAccSeconds
OBJECT-TYPE
The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.4.1.17Counter32read-onlycurrent
rsIpsecSaEspOutAccKbytes
OBJECT-TYPE
The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic.
1.3.6.1.4.1.4355.3.1.1.4.1.18Counter32read-onlycurrent
rsIpsecSaEspOutUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit.
1.3.6.1.4.1.4355.3.1.1.4.1.19Counter32read-onlycurrent
rsIpsecSaEspOutPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.4.1.20Counter32read-onlycurrent
rsIpsecSaEspOutSendErrors
OBJECT-TYPE
The number of packets discarded by the SA due to any error. This may include errors due to a lack of transmit buffers.
1.3.6.1.4.1.4355.3.1.1.4.1.21Counter32read-onlycurrent
rsIpsecSaAhOutTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec Outbound AH SAs. There should be one row for every outbound AH security association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.5not-accessiblecurrent
rsIpsecSaAhOutEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec Outbound AH SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.5.1not-accessiblecurrent
rsIpsecSaAhOutAddress
OBJECT-TYPE
The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.5.1.1IpAddressread-onlycurrent
rsIpsecSaAhOutSpi
OBJECT-TYPE
The security parameters index of the SA.
1.3.6.1.4.1.4355.3.1.1.5.1.2Integer32read-onlycurrent
rsIpsecSaAhOutSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.5.1.3OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaAhOutSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaAhOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.5.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaAhOutDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.5.1.5OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaAhOutDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaAhOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation.
1.3.6.1.4.1.4355.3.1.1.5.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaAhOutProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.5.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaAhOutSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.5.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaAhOutDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.5.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaAhOutCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.5.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaAhOutEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.5.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaAhOutAuthAlg
OBJECT-TYPE
A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used.
1.3.6.1.4.1.4355.3.1.1.5.1.12IpsecDoiAhTransformread-onlycurrent
rsIpsecSaAhOutLimitSeconds
OBJECT-TYPE
The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.5.1.13Integer32read-onlycurrent
rsIpsecSaAhOutLimitKbytes
OBJECT-TYPE
The maximum traffic in Kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated.
1.3.6.1.4.1.4355.3.1.1.5.1.14Integer32read-onlycurrent
rsIpsecSaAhOutAccSeconds
OBJECT-TYPE
The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.5.1.15Counter32read-onlycurrent
rsIpsecSaAhOutAccKbytes
OBJECT-TYPE
The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic.
1.3.6.1.4.1.4355.3.1.1.5.1.16Counter32read-onlycurrent
rsIpsecSaAhOutUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit.
1.3.6.1.4.1.4355.3.1.1.5.1.17Counter32read-onlycurrent
rsIpsecSaAhOutPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.5.1.18Counter32read-onlycurrent
rsIpsecSaAhOutSendErrors
OBJECT-TYPE
The number of packets discarded by the SA due to any error. This may include errors due to a lack of transmit buffers.
1.3.6.1.4.1.4355.3.1.1.5.1.19Counter32read-onlycurrent
rsIpsecSaIpcompOutTable
OBJECT-TYPE
The (conceptual) table containing information on IPSec Outbound IPCOMP SAs. There should be one row for every outbound IPCOMP (security) association that exists in the entity. The maximum number of rows is implementation dependent.
1.3.6.1.4.1.4355.3.1.1.6not-accessiblecurrent
rsIpsecSaIpcompOutEntry
OBJECT-TYPE
An entry (conceptual row) containing the information on a particular IPSec Outbound IPCOMP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table.
1.3.6.1.4.1.4355.3.1.1.6.1not-accessiblecurrent
rsIpsecSaIpcompOutAddress
OBJECT-TYPE
The destination address of the SA. If the IPCOMP SA is shared across multiple SAs in protection suites, this value may be 0. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes.
1.3.6.1.4.1.4355.3.1.1.6.1.1IpAddressread-onlycurrent
rsIpsecSaIpcompOutCpi
OBJECT-TYPE
The CPI of the SA. Since the lower values of CPIs are reserved to be the same as the algorithm, the syntax for this object is the same as the transform.
1.3.6.1.4.1.4355.3.1.1.6.1.2IpsecDoiIpcompTransformread-onlycurrent
rsIpsecSaIpcompOutSourceId
OBJECT-TYPE
The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.6.1.3OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaIpcompOutSourceIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaIpcompOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites.
1.3.6.1.4.1.4355.3.1.1.6.1.4IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaIpcompOutDestId
OBJECT-TYPE
The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during phase 2 negotiations.
1.3.6.1.4.1.4355.3.1.1.6.1.5OCTET STRING (SIZE(4..255))read-onlycurrent
rsIpsecSaIpcompOutDestIdType
OBJECT-TYPE
The type of identifier presented by 'rsIpsecSaIpcompOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites.
1.3.6.1.4.1.4355.3.1.1.6.1.6IpsecDoiIdentTyperead-onlycurrent
rsIpsecSaIpcompOutProtocol
OBJECT-TYPE
The transport-layer protocol number that this SA carries, or 0 if it carries any protocol.
1.3.6.1.4.1.4355.3.1.1.6.1.7Integer32 (0..255)read-onlycurrent
rsIpsecSaIpcompOutSourcePort
OBJECT-TYPE
The source port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.6.1.8Integer32 (0..65535)read-onlycurrent
rsIpsecSaIpcompOutDestPort
OBJECT-TYPE
The destination port number of the protocol that this SA carries, or 0 if it carries any port number.
1.3.6.1.4.1.4355.3.1.1.6.1.9Integer32 (0..65535)read-onlycurrent
rsIpsecSaIpcompOutCreator
OBJECT-TYPE
The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method.
1.3.6.1.4.1.4355.3.1.1.6.1.10IpsecSaCreatorIdentread-onlycurrent
rsIpsecSaIpcompOutEncapsulation
OBJECT-TYPE
The type of encapsulation used by this SA.
1.3.6.1.4.1.4355.3.1.1.6.1.11IpsecDoiEncapsulationModeread-onlycurrent
rsIpsecSaIpcompOutCompAlg
OBJECT-TYPE
A unique value representing the compression algorithm applied to traffic.
1.3.6.1.4.1.4355.3.1.1.6.1.12IpsecDoiIpcompTransformread-onlycurrent
rsIpsecSaIpcompOutSeconds
OBJECT-TYPE
The number of seconds that the SA has existed.
1.3.6.1.4.1.4355.3.1.1.6.1.13Counter32read-onlycurrent
rsIpsecSaIpcompOutUserOctets
OBJECT-TYPE
The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit.
1.3.6.1.4.1.4355.3.1.1.6.1.14Counter32read-onlycurrent
rsIpsecSaIpcompOutPackets
OBJECT-TYPE
The number of packets handled by the SA.
1.3.6.1.4.1.4355.3.1.1.6.1.15Counter32read-onlycurrent
rsSaStatistics
OBJECT-IDENTITY
This is the base object identifier for all objects which are global counters for IPSec security associations.
1.3.6.1.4.1.4355.3.1.2current
rsIpsecEspCurrentInboundSAs
OBJECT-TYPE
The current number of inbound ESP SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.1Gauge32read-onlycurrent
rsIpsecEspTotalInboundSAs
OBJECT-TYPE
The total number of inbound ESP SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.2Counter32read-onlycurrent
rsIpsecEspCurrentOutboundSAs
OBJECT-TYPE
The current number of outbound ESP SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.3Gauge32read-onlycurrent
rsIpsecEspTotalOutboundSAs
OBJECT-TYPE
The total number of outbound ESP SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.4Counter32read-onlycurrent
rsIpsecAhCurrentInboundSAs
OBJECT-TYPE
The current number of inbound AH SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.5Gauge32read-onlycurrent
rsIpsecAhTotalInboundSAs
OBJECT-TYPE
The total number of inbound AH SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.6Counter32read-onlycurrent
rsIpsecAhCurrentOutboundSAs
OBJECT-TYPE
The current number of outbound AH SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.7Gauge32read-onlycurrent
rsIpsecAhTotalOutboundSAs
OBJECT-TYPE
The total number of outbound AH SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.8Counter32read-onlycurrent
rsIpsecIpcompCurrentInboundSAs
OBJECT-TYPE
The current number of inbound IPCOMP SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.9Gauge32read-onlycurrent
rsIpsecIpcompTotalInboundSAs
OBJECT-TYPE
The total number of inbound IPCOMP SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.10Counter32read-onlycurrent
rsIpsecIpcompCurrentOutboundSAs
OBJECT-TYPE
The current number of outbound IPCOMP SAs in the entity.
1.3.6.1.4.1.4355.3.1.2.11Gauge32read-onlycurrent
rsIpsecIpcompTotalOutboundSAs
OBJECT-TYPE
The total number of outbound IPCOMP SAs created in the entity since boot time.
1.3.6.1.4.1.4355.3.1.2.12Counter32read-onlycurrent
rsSaErrors
OBJECT-IDENTITY
This is the base object identifier for all objects which are global error counters for IPSec security associations.
1.3.6.1.4.1.4355.3.1.3current
rsIpsecDecryptionErrors
OBJECT-TYPE
The total number of packets received by the entity in SAs since boot time with decryption errors.
1.3.6.1.4.1.4355.3.1.3.1Counter32read-onlycurrent
rsIpsecAuthenticationErrors
OBJECT-TYPE
The total number of packets received by the entity in SAs since boot time with authentication errors. This includes all packets in which the hash value is determined to be invalid, for both ESP and AH SAs.
1.3.6.1.4.1.4355.3.1.3.2Counter32read-onlycurrent
rsIpsecReplayErrors
OBJECT-TYPE
The total number of packets received by the entity in SAs since boot time with replay errors.
1.3.6.1.4.1.4355.3.1.3.3Counter32read-onlycurrent
rsIpsecPolicyErrors
OBJECT-TYPE
The total number of packets received by the entity in SAs since boot time and discarded due to policy errors. This includes packets that had selectors that were invalid for the SA that carried them.
1.3.6.1.4.1.4355.3.1.3.4Counter32read-onlycurrent
rsIpsecOtherReceiveErrors
OBJECT-TYPE
The total number of packets received by the entity in SAs since boot time and discarded due to errors not due to decryption, authentication, replay or policy.
1.3.6.1.4.1.4355.3.1.3.5Counter32read-onlycurrent
rsIpsecSendErrors
OBJECT-TYPE
The total number of packets to be sent by the entity in SAs since boot time and discarded due to errors.
1.3.6.1.4.1.4355.3.1.3.6Counter32read-onlycurrent
rsIpsecUnknownSpiErrors
OBJECT-TYPE
The total number of packets received by the entity since boot time with SPIs or CPIs that were not valid.
1.3.6.1.4.1.4355.3.1.3.7Counter32read-onlycurrent
rsSaTraps
OBJECT-IDENTITY
This is the base object identifier for all objects which are traps for IPSec security associations.
1.3.6.1.4.1.4355.3.1.4current
rsSaTrapObjects
OBJECT-IDENTITY
This is the base object identifier for objects which are used as part of traps.
1.3.6.1.4.1.4355.3.1.5current
rsIpsecSecurityProtocol
OBJECT-TYPE
A security protocol associated with the trap.
1.3.6.1.4.1.4355.3.1.5.1IpsecDoiSecProtocolIdread-onlycurrent
rsIpsecSPI
OBJECT-TYPE
An SPI associated with a trap. Where the security protocol associated with the trap is IPCOMP, this value has a maximum of 65535.
1.3.6.1.4.1.4355.3.1.5.2Integer32read-onlycurrent
rsIpsecLocalAddress
OBJECT-TYPE
A local IP address associated with the trap.
1.3.6.1.4.1.4355.3.1.5.3IpAddressread-onlycurrent
rsIpsecPeerAddress
OBJECT-TYPE
A peer IP address associated with the trap.
1.3.6.1.4.1.4355.3.1.5.4IpAddressread-onlycurrent
rsSaTrapControl
OBJECT-IDENTITY
This is the base object identifier for all objects which are trap controls for IPSec security associations.
1.3.6.1.4.1.4355.3.1.6current
rsEspAuthFailureTrapEnable
OBJECT-TYPE
Indicates whether espAuthFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.1TruthValueread-writecurrent
rsAhAuthFailureTrapEnable
OBJECT-TYPE
Indicates whether ahAuthFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.2TruthValueread-writecurrent
rsEspReplayFailureTrapEnable
OBJECT-TYPE
Indicates whether espReplayFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.3TruthValueread-writecurrent
rsAhReplayFailureTrapEnable
OBJECT-TYPE
Indicates whether ahReplayFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.4TruthValueread-writecurrent
rsEspPolicyFailureTrapEnable
OBJECT-TYPE
Indicates whether espPolicyFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.5TruthValueread-writecurrent
rsAhPolicyFailureTrapEnable
OBJECT-TYPE
Indicates whether ahPolicyFailureTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.6TruthValueread-writecurrent
rsInvalidSpiTrapEnable
OBJECT-TYPE
Indicates whether invalidSpiTrap traps should be generated.
1.3.6.1.4.1.4355.3.1.6.7TruthValueread-writecurrent
rsSaGroups
OBJECT-IDENTITY
This is the base object identifier for all objects which describe the groups in this MIB.
1.3.6.1.4.1.4355.3.1.7current
rsSaConformance
OBJECT-IDENTITY
This is the base object identifier for all objects which describe the conformance for this MIB.
1.3.6.1.4.1.4355.3.1.8current

Notifications

NameOIDStatus
rsEspAuthFailureTrap
NOTIFICATION-TYPE
IPSec packets with invalid hashes were found in an inbound ESP SA. The total number of authentication errors accumulated is sent for the specific row of the 'rsIpsecSaEspInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.1current
rsAhAuthFailureTrap
NOTIFICATION-TYPE
IPSec packets with invalid hashes were found in an inbound AH SA. The total number of authentication errors accumulated is sent for the specific row of the 'rsIpsecSaAhInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.2current
rsEspReplayFailureTrap
NOTIFICATION-TYPE
IPSec packets with invalid sequence numbers were found in an inbound ESP SA. The total number of replay errors accumulated is sent for the specific row of the 'rsIpsecSaEspInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.3current
rsAhReplayFailureTrap
NOTIFICATION-TYPE
IPSec packets with invalid sequence numbers were found in the specified AH SA. The total number of replay errors accumulated is sent for the specific row of the 'rsIpsecSaAhInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.4current
rsEspPolicyFailureTrap
NOTIFICATION-TYPE
IPSec packets carrying packets with invalid selectors for the specified ESP SA were found. The total number of policy errors accumulated is sent for the specific row of the 'rsIpsecSaEspInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.5current
rsAhPolicyFailureTrap
NOTIFICATION-TYPE
IPSec packets carrying packets with invalid selectors for the specified AH SA were found. The total number of policy errors accumulated is sent for the specific row of the 'rsIpsecSaAhInTable' table for the SA; this provides the identity of the SA in which the error occurred. Implementations SHOULD send one trap per SA (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.6current
rsInvalidSpiTrap
NOTIFICATION-TYPE
A packet with an unknown SPI was detected from the specified peer with the specified SPI using the specified protocol. The destination address of the received packet is specified by 'ipsecLocalAddress'. The value 'ifIndex' may be 0 if this optional linkage is unsupported. If the object 'ipsecSecurityProtocol' has the value for IPCOMP, then the 'ipsecSPI' object is the CPI of the packet. Implementations SHOULD send one trap per peer (within a reasonable time period), rather than sending one trap per packet.
1.3.6.1.4.1.4355.3.1.4.0.7current