ALCATEL-IND1-IPSEC-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
67
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.1 · 1 row entry · 3 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecSecurityKeyTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecSecurityKeyTable'
Table allowing the configuration of the switch's IPsec security key.
The security key is used to encrypt and IPsec related information
retained in permanent storage.
          
There is always a single row in this table with an index value of 1.
alaIPsecSecurityKeyEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.1.1
The security key entry.
Column Syntax OID
The row's identifier. Only one entry is ever present, with an
ID value of 1.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.1.1.1
The current value of the IPsec security key. If an attempt
is made to read the value of this object, a zero-length octet
string will be returned.
OctetStringr/w
Constraints:
range: 16-16
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.1.1.2
Used to set a new value for the IPsec security key.

Both alaIPsecSecurityKeyCurrent (with its correct value) and
alaIPsecSecurityKeyNew must be specified in the same SNMP SET
message. If alaIPsecSecurity…
OctetStringr/w
Constraints:
range: 16-16
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.1.1.3
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2 · 1 row entry · 20 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecStatisticsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecStatisticsTable'
Table allowing the IPv6 statistics to be retrieved.
alaIPsecStatisticsEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1
The statistics entry.
Column Syntax OID
IP protocol version covered by the IPsec statistics.
Enumeration
Enumerated Values:
6ipv6
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.1
Number of incoming packets requiring IPsec processing
that were successfully handled.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.2
Number of incoming packets that were dropped because
of policy violations.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.3
Number of incoming packets dropped because no
matching SA was found.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.4
Number of incoming packets dropped because the SPI was
unknown.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.5
Number of incoming packets that failed the AH replay
check.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.6
Number of incoming packets taht failed the ESP
replay check.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.7
Number of incoming packets that successfully passed
AH authentication.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.8
Number of incoming packets that failed AH
authentication.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.9
Number of incoming packets that successfully passed
ESP authentication.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.10
Number of incoming packets that failed ESP
authentication.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.11
Number of incoming packets requiring IPsec
processing that were not valid.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.12
Number of incoming IPsec packets dropped because
no memory was available.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.13
Number of outgoing packets requiring IPsec processing
that were successfully handled.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.14
Number of outgoing packets dropped because of a
policy violation.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.15
Number of outgoing packets dropped because no matching
SA was found.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.16
Number of outgoing packets requiring IPsec processing
that were not valid.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.17
Number of outgoing IPsec packets dropped because no
memory was available.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.18
Number of incoming packets dropped because they matched
a discard policy.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.19
Number of outgoing packets dropped because they matched
a discard policy.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.1.2.1.20
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2 · 1 row entry · 19 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecSecurityPolicyTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecSecurityPolicyTable'
Table allowing the configuration of IPsec security policies.
alaIPsecSecurityPolicyEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1
A security policy entry.
Column Syntax OID
A unique identifier for this security policy. When creating a
new policy, a zero value must be specified. An available
policy ID will then be automatically assigned to the policy.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.1
The type of source address specified.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.2
The source of packets covered by this policy.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.3
The number of bits of the source address used to determine
which packets are covered by this policy.

The default value varies depending upon the type of
source address specified:
IPv4 - 32
IPv6 - 12…
IPsecPrefixLengthr/w
Type Constraints:
range: 0..128
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.4
The source port of packets covered by this policy. To
match packets from any port, specify the 0 wildcard value. A
wildcard policy will only be used when there is no exact match
to a destination port in another entry.
IPsecPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.5
The type of destination address specified.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.6
The destination of packets covered by this policy.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.7
The number of bits of the destination prefix used to determine
which packets are covered by this policy.

The default value varies depending upon the type of
destination address specified:
IPv4 - 32
IPsecPrefixLengthr/w
Type Constraints:
range: 0..128
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.8
The destination port of packets covered by this policy. To
match packets from any port, specify the 0 wildcard value. A
wildcard policy will only be used when there is no exact match
to a destination port in another …
IPsecPortNumberr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.9
The upper-layer protocol of packets covered by this policy.
To match all protocols, specify the 255 wildcard value. A wildcard
policy will only be used when there is no exact match to the protocol
value specified in an…
IPsecULProtocolr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.10
If the upper-layer protocol is ICMPv6, an ICMPv6 type value may
be specified to restrict the policy to a specific packet type.

To match all ICMPv6 packets, the 0 wildcard value should be
specified.
Integer32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.11
The direction of traffic covered by this policy.
Enumerationr/w
Enumerated Values:
1in
2out
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.12
A name for this policy.
IPsecNamer/w
Type Constraints:
range: 1..20
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.13
A detailed description of this policy.
IPsecDescriptionr/w
Type Constraints:
range: 0..200
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.14
The action to take on traffic covered by this policy.

discard(0) means that all traffic covered by the policy
will be discarded.

ipsec(2) means that IPsec processing will take place on
the …
Enumerationr/w
Enumerated Values:
0discard
2ipsec
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.15
Allows a policy to be administratively enabled or
disabled.
IPsecAdminStater/w
Type Values:
1enabled
2disabled
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.16
The operational state of this policy.
IPsecOperationalState
Type Values:
1enabled
2disabled
3dnspending
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.17
The priority for this policy. When traffic would be covered by
multiple policies the policy with the highest priority value is
used. If two policies have the same priority, the one configured
first has precedence.
Integer32r/w
Constraints:
range: 1-1000
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.18
Used to control the addition and removal of security
policy entries.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.2.1.19
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3 · 1 row entry · 4 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecSecurityPolicyRuleTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecSecurityPolicyRuleTable'
Table allowing the configuration of the IPsec rules for
a security policy.
alaIPsecSecurityPolicyRuleEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3.1
A security policy entry.
Column Syntax OID
Index specifying the order in which multiple rules for
the same security policy will be applied. Rules are
indexed by the order in which they are applied to the
original payload.

For example, for a sec…
Unsigned32
Constraints:
range: 1-10
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3.1.1
Indicates the type of header required by the rule.
Enumerationr/w
Enumerated Values:
1ah
2esp
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3.1.2
The mode in which the rule's protocol is running. At present,
only transport(1) is allowed. Until tunnel mode is supported,
transport(1) will be treated as the default value.
Enumerationr/w
Enumerated Values:
1transport
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3.1.3
Used to control the addition and removal of security
policy IPsec rule entries.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.3.1.4
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4 · 1 row entry · 15 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecSAConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecSAConfigTable'
Table allowing the manual configuration of Security
Associations in the Security Association Database (SAD).
alaIPsecSAConfigEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1
Manually configured security association (SA) parameters.
Column Syntax OID
A unique identifier for this manually configured SA.
When creating a new SA, a zero value must be specified.
An available ID will then be automatically assigned to
the SA.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.1
The type of this SA: AH or ESP. Once set,
the type may not be changed.
IPsecSATyper/w
Type Values:
2ah
3esp
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.2
The type of source address specified.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.3
The source of packets covered by this SA.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.4
The type of destination address specified.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.5
The destination of packets covered by this SA.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.6
The Security Parameters Index (SPI) of this SA.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.7
The name of this manually configured SA.
IPsecNamer/w
Type Constraints:
range: 1..20
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.8
A detailed description for the manually created IPsec SA.
IPsecDescriptionr/w
Type Constraints:
range: 0..200
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.9
For an ESP SA, defines the encryption algorithm to be used.
none(0) should be specified if ESP is being used for integrity
only. If null(11) is specified,
alaIPsecSAConfigAuthenticationAlgorithm may not be none(0).
IPsecESPAlgorithmr/w
Type Values:
0none
2descbc
3des3cbc
11null
12aescbc
13aesctr
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.10
For those algorithms where multiple key lengths are supported,
specifies the key length to be used. Zero may be specified to
use the default key length.
bitsSNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.11
Defines the authentication algorithm to be used.

For ESP SAs, none(0) may be specified for encryption-only ESP.
For ESP integrity-only, ESP integrity and encryption, or for
AH SAs, hmacmd5(2), hmacsha1(3)…
IPsecAHAlgorithmr/w
Type Values:
0none
2hmacmd5
3hmacsha1
9aesxcbcmac
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.12
Allows a manually configured SA to be administratively enabled
or disabled.
IPsecAdminStater/w
Type Values:
1enabled
2disabled
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.13
The operational state of the manually configured SA.
IPsecOperationalState
Type Values:
1enabled
2disabled
3dnspending
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.14
Used to control the addition and removal of manually configured
IPsec SAs.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.4.1.15
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5 · 1 row entry · 6 columns
Uses the alcatel variant from /opt/observium/mibs/alcatel.
Command help
Walk alaIPsecKeyTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALCATEL-IND1-IPSEC-MIB' -M '/opt/observium/mibs/alcatel:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALCATEL-IND1-IPSEC-MIB::alaIPsecKeyTable'
Table used to configure the keys used by manually
configured Security Associations in the IPsec Security
Association Configuration table.
alaIPsecKeyEntry row .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1
An IPsec key. Keys in the table must be uniquely
identified by the combination of key type and key name.
However, since the key name can be up to 255 characters,
beyond the 128-element size limit for SNMP index objects…
Indexes
Column Syntax OID
A unique identifier for this key. When creating a
new key, a zero value must be specified. An available
ID will then be automatically assigned to the key.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.1
Indicates if the key is to be used for encryption or
authentication by a SA. Once a key is created, its type
may not be changed.
Enumerationr/w
Enumerated Values:
1saAuthentication
2saEncryption
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.2
The name of the key.

For manually-configured SA keys, the name is limited to
a maximum length of 20 characters and should correspond
to an entry in the alaIPsecSAConfigTable.

The key na…
OctetStringr/w
Constraints:
range: 1-255
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.3
The key value. The value specified must match the required
key length for the algorithm using the key. If
an attempt is made to read the value of this object a
zero-length octet string will be returned.
OctetStringr/w .1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.4
If true, the key value is specified in AOS encrypted form.
For example, keys being restored from the configuration file.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.5
Used to control the addition and removal of keys.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6486.800.1.2.1.43.1.1.5.1.6