ALU-SECURITY-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
34
Rows
34
Columns
425
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4 · 1 row entry · 19 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneConfigTable'
The aluZoneConfigTable has an entry for each 
zone configured on the system.
aluZoneConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1
Each row entry represents a zone entry.
Indexes
Column Syntax OID
The value of the object aluZoneConfigId specifies
the unique id of the Zone. The Id must be
unique within the system.
Unsigned32
Constraints:
range: 1-65534
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.1
The value of the object aluZoneConfigName
specifies the name of the Zone.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.2
The value of aluZoneConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluZoneConfigTable. aluZoneConfigRowStatus does not support
createAndWait. The status can only be acti…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.3
Description of this zone.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.4
This object controls the use of commit of the Zone Policy.

This object always reads none(1).

When set to initialize(2), the objects in standby zone
are set to the current active Operational…
Enumerationr/w
Enumerated Values:
1none
2initialize
3commit
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.5
Indicates the type of zone.
TZoneTyper/w
Type Values:
0unknown
1network
2service
3global
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.6
Specifies the service this zone belongs to when zone type is 'service'.
TIMETRA-TC-MIBTmnxServIdr/w
Type Constraints:
range: 0..2148278381
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.7
State of the Policy of this zone.
TPlcyState
Type Values:
0unknown
1empty
2draft
3commited
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.8
The value of aluZoneConfigBypass specifies whether this zone is being bypassed.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.9
The value of the object aluZoneConfigInTcpSessLimit
indicates the number of permitted active inbound sessions
with protocol TCP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.10
The value of the object aluZoneConfigInUdpSessLimit
indicates the number of permitted active inbound sessions
with protocol UDP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.11
The value of the object aluZoneConfigInIcmpSessLimit
indicates the number of permitted active in sessions with
protocol ICMP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.12
The value of the object aluZoneConfigOthSessLimit
indicates the number of permitted active in sessions of all
other protocols. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.13
The value of the object aluZoneConfigOutTcpSessLimit
indicates the number of permitted active outbound sessions
with protocol TCP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.14
The value of the object aluZoneConfigOutUdpSessLimit
indicates the number of permitted active outbound sessions
with protocol UDP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.15
The value of the object aluZoneConfigOutIcmpSessLimit
indicates the number of permitted active out sessions with
protocol ICMP. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.16
The value of the object aluZoneConfigOutOthSessLimit
indicates the number of permitted active out sessions of all
other protocols. A value of 0 indicates that there is no
limit.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.17
The value of the object aluZoneConfigLogId
indicates the log-id for security logging.
TSecurityLogIdr/w
Type Constraints:
range: 0..100
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.18
The value of aluZoneConfigAutoBind specifies whether this zone is being used to enforce policy
on traffic to/from MP-BGP auto-binding and spoke-sdps. This configuration is only permitted on
VPRN zones and can only be e…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.4.1.19
.1.3.6.1.4.1.6527.6.1.2.2.17.1.5 · 1 row entry · 3 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZonePlcyConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZonePlcyConfigTable'
The aluZonePlcyConfigTable has an entry for each
policy configured on a particular zone.
aluZonePlcyConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.5.1
Each row entry represents a particular policy entry.
Column Syntax OID
The value of the object aluZonePlcyConfigEntryId
specifies the unique id of the Zone entries within the zone.
This value must always be 1 in this release.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.5.1.1
The value of aluZonePlcyConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluZonePlcyConfigTable. aluZonePlcyConfigRowStatus
does not support createAndWait. The status can …
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.5.1.2
The value of aluZonePlcyConfigSecPlcyId specifies the
id of the security policy defined globally in the system.
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.5.1.3
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6 · 1 row entry · 6 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneNatPoolConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneNatPoolConfigTable'
The aluZoneNatPoolConfigTable has an entry for each
nat-pool of ip addresses and ports configured on a particular zone.
aluZoneNatPoolConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1
Each row entry represents a particular policy entry.
Column Syntax OID
The value of the object aluZoneNatPoolConfigId
specifies the unique id of the NAT-Pool entries within the zone.
Unsigned32
Constraints:
range: 1-100
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.1
The value of the object aluZoneNatPoolConfigName
specifies the name of the NAT Pool.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.2
The value of aluZoneNatPoolConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluZoneNatPoolConfigTable. aluZoneNatPoolConfigRowStatus
does not support createAndWait. The st…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.3
Description of this nat pool.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.4
Specifies if this pool is direct-mapped or pooled.
TPoolTyper/w
Type Values:
0unknown
1srcNatPool
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.5
Specifies the zone .
Enumerationr/w
Enumerated Values:
0unknown
1zoneInbound
2zoneOutbound
.1.3.6.1.4.1.6527.6.1.2.2.17.1.6.1.6
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7 · 1 row entry · 9 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneNatPoolParamsConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneNatPoolParamsConfigTable'
The aluZoneNatPoolParamsConfigTable has an entry NAT Pool 
params entry configured on this system.
aluZoneNatPoolParamsConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1
Each row entry represents a particular NAT Pool params entry.
Column Syntax OID
The value of aluZoneNatPoolParamsConfigEntryId specifies the
3rd index for the entry.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.1
The value of aluZoneNatPoolParamsConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluZoneNatPoolParamsConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.2
The value of the object
aluZoneNatPoolParamsConfigIPAddrValue1 specifies
the starting range of IP address of the NAT pool.
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.3
The value of the object
aluZoneNatPoolParamsConfigIPAddrValue2 specifies
the ending range of IP address of the NAT pool.
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.4
The operator specifies the manner in which
aluZoneNatPoolParamsConfigIPAddrValue1 and
aluZoneNatPoolParamsConfigIPAddrValue2
are to be used. The value of these below 2 objects and
aluZoneNatPoolParamsConfigIPOperator i…
TIPOperatorr/w
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.5
The aluZoneNatPoolParamsConfigIPInterfaceIndex specifies
the index of the interface that the primary-address of that
interface is to be used in the NAT pool.
The interface must exist in the same vRtr that the NAT pool
r…
IF-MIBInterfaceIndexOrZeror/w
Type Constraints:
range: 0..2147483647
Description:
This textual convention is an extension of the
InterfaceIndex convention. The latter defines a greater
than zero value used to identify an interface or interface
sub-layer in the managed system. This extension permits…
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.6
The operator specifies the manner in which
aluZoneNatPoolParamsConfigPortValue1 and
aluZoneNatPoolParamsConfigPortValue2
are to be used. The value of these below 2 objects and
aluZoneNatPoolParamsConfigPortOperator is …
TIMETRA-TC-MIBTTcpUdpPortOperatorr/w .1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.7
TCP/UDP port value1. The value of this object is used as per the
description for aluZoneNatPoolParamsConfigPortOperator.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.8
TCP/UDP port value2. The value of this object is used as per the
description for aluZoneNatPoolParamsConfigPortOperator.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.7.1.9
.1.3.6.1.4.1.6527.6.1.2.2.17.1.8 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPlcyConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPlcyConfigTable'
The aluSecPlcyConfigTable has an entry for each
security policy configured globally on this system.
aluSecPlcyConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.8.1
Each row entry represents a particular security policy.
Column Syntax OID
The value of the object aluSecPlcyConfigId
specifies the unique policy id.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.8.1.1
The value of aluSecPlcyConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecPlcyConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.8.1.2
Name of the security policy.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.8.1.3
Description of this security policy.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.8.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9 · 1 row entry · 32 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPlcyParamsConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPlcyParamsConfigTable'
The aluSecPlcyParamsConfigTable has an entry for each
rule configured as part of a security policy.
aluSecPlcyParamsConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1
Each row entry represents a particular rule entry.
Column Syntax OID
The value of aluSecPlcyParamsConfigRuleId specifies the
index of the rule within the security policy.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.1
The value of aluSecPlcyParamsConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecPlcyParamsConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.2
Description of this rule.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.3
The value of the object aluSecPlcyParamsConfigMatchSrcIPAddrValue1
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sour…
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.4
The value of the object aluSecPlcyParamsConfigMatchSrcIPAddrValue2
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sou…
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.5
The operator specifies the manner in which
aluSecPlcyParamsConfigMatchSrcIPAddrValue1 and
aluSecPlcyParamsConfigMatchSrcIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecPlcyParamsConfigMatchSrc…
TIPOperatorr/w
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.6
The value of the object aluSecPlcyParamsConfigMatchSrcIPHostGroup
specifies the host group name, where the group name is a collection
of IP addresses. When configured and activated, filter
policy will be applied to …
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.7
The value of the object aluSecPlcyParamsConfigMatchDstIPAddrValue1
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sour…
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.8
The value of the object aluSecPlcyParamsConfigMatchDstIPAddrValue2
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sou…
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.9
The operator specifies the manner in which
aluSecPlcyParamsConfigMatchDstIPAddrValue1 and
aluSecPlcyParamsConfigMatchDstIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecPlcyParamsConfigMatchDst…
TIPOperatorr/w
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.10
The value of the object aluSecPlcyParamsConfigMatchDstIPHostGroup
specifies the host group name, where the group name is a collection
of IP addresses. When configured and activated, filter
policy will be applied to …
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.11
IP protocol to match. set to -1 to disable matching IP protocol. If
the protocol is changed the protocol specific parameters are reset.
TIMETRA-TC-MIBTIpProtocolr/w
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.12
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.13
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.14
Source TCP/UDP port operator.
TIMETRA-TC-MIBTOperatorr/w
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.15
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.16
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.17
Destination TCP/UDP port operator.
TIMETRA-TC-MIBTOperatorr/w
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.18
The value of the object aluSecPlcyParamsConfigMatchAppGroup
specifies the application group name, where the group name is a
collection of protocol-id/src port/dest port. When configured
and activated, this filter wi…
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.19
Icmp code to be matched. aluSecPlcyParamsConfigMatchIcmpCode
complements the object aluSecPlcyParamsConfigMatchIcmpType.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code match…
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.20
Icmp type to be matched. aluSecPlcyParamsConfigMatchIcmpType
complements the object aluSecPlcyParamsConfigMatchIcmpCode.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code match…
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.21
Type of IGMP to be configured
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.22
This object specifies the direction of the packet flow
for which the security filter is to be applied.
in is equivalent to ingress flow,
out is equivalent to egress flow,
both is equivalent to both ingress and egress fl…
Enumerationr/w
Enumerated Values:
1zoneInbound
2zoneOutbound
3both
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.23
The value of the object specifies profile of this flow
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.24
The value of the object specifies the number of sessions (flows)
that can be active concurrently.
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.25
The value of aluSecPlcyParamsConfigCreateRevDirFlow specifies
whether return direction of the session is created or not
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.26
This object specifies whether the packet needs to be
passed or dropped if it satisfies the rule condition.
Enumerationr/w
Enumerated Values:
0forward
1drop
2nat
3reject
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.27
The value of aluSecPlcyParamsConfigMatchLocal specifies
whether to match traffic destined to node
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.28
The value of the object aluSecPlcyParamsConfigActionNatDstIPAddr
specifies the Dst IP address of the packet after NAT has been
performed
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.29
NAT Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.30
Log control for this rule. There are three options:
(1) suppress - (DEFAULT) Any events generated from this
rule will be suppressed.
(2) zone - Send any events generated from this rule
Enumerationr/w
Enumerated Values:
1suppress
2zone
3log
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.31
Log for policy to be logged. This can only be set
TSecurityLogIdr/w
Type Constraints:
range: 0..100
.1.3.6.1.4.1.6527.6.1.2.2.17.1.9.1.32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10 · 1 row entry · 29 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecProfileConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecProfileConfigTable'
The aluSecProfileConfigTable has an entry for each
security profile configured globally on this system.
aluSecProfileConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1
Each row entry represents a particular security profile.
Column Syntax OID
The value of the object aluSecProfileConfigId
specifies the unique profile id.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.1
The value of aluSecProfileConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecProfileConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.2
Name of the security profile.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.3
Description of this security profile.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.4
The value of the object specifies the number of seconds a
TCP session can wait for a SYN before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 6-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.5
The value of the object specifies the number of seconds a
TCP session can remain in time wait before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 0-240
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.6
The value of the object specifies the number of seconds a
TCP session can remain be transitory before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 60-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.7
The value of the object specifies the number of seconds a
TCP session has to reach established before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 60-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.8
The value of the object specifies the number of seconds a
UDP session can remain idle before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 60-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.9
The value of the object specifies the number of seconds a
UDP session can remain idle after recieving the first packet
before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 10-300
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.10
The value of the object specifies the number of seconds a
DNS request can take to recieve a response
before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 15-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.11
The value of the object specifies the number of seconds an
ICMP request can take to recieve a response
before being cleaned up.
secondsUnsigned32r/w
Constraints:
range: 60-240
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.12
The value of the object specifies the number of seconds other
protocol sessions can remain idle before being cleaned up.
This also includes all drop sessions regardless of protocol.
secondsUnsigned32r/w
Constraints:
range: 10-86400
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.13
The value of the object indicates whether application assurance inspection
should be performed on all active connections with this profile.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.14
The value of the object indicates whether stict TCP inspection
should be performed on all active TCP connections with this profile.
aluSecProfileConfigAppInspect must be enabled before TCP inspection
can be enabled.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.15
The value of the object indicates whether IP options inspection
is to be performed. When 'true' the object aluSecProfileConfigAllowedIpOpt
is used to specify permitted options.
aluSecProfileConfigAppInspect must be enab…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.16
The value of the object indicates the bitmask of allowed IP options when IP
option inspection is enabled.
aluSecProfileConfigAppInspect must be enabled before IP inspection
can be enabled.
SNMPv2-SMIUnsigned32r/w
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.17
The value of the object indicates whether fragmented IP packets are
permitted through connections with this profile.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.18
The value of the object indicates the application layer
gateway processing to be performed on this connection.
TAlgTyper/w
Type Values:
0none
1auto
2ftp
3tftp
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.19
The value of the object specifies the number of ICMP packets permitted
to travese the ICMP request session in each direction.
A value of 0 specifies that there is no packet limit.
aluSecProfileConfigAppInspect must be e…
packetsUnsigned32r/w
Constraints:
range: 0-254
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.20
The value of the object specifies the whether to limit the number of ICMP Type 3
packets that are permitted to travese the session in each direction.
aluSecProfileConfigAppInspect must be enabled before ICMP inspection…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.21
The value of the object specifies whether to limit the number of DNS
packets that are permitted to travese a DNS session in each direction.
aluSecProfileConfigAppInspect must be enabled before DNS inspection
can be en…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.22
The value of the object specifies if a TCP Session in the Established
state is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.23
The value of the object specifies if a UDP Session in the Established
state is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.24
The value of the object specifies if a ICMP Request Session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has bee…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.25
The value of the object specifies if a DNS Request Session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has been…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.26
The value of the object specifies if a Other protocol session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has b…
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.27
The value of the object specifies the policer group that the forward direction
of the session should be rate-limited with.
TSecurityPolicerIdr/w
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.28
The value of the object specifies the policer group that the reverse direction
of the session should be rate-limited with.
TSecurityPolicerIdr/w
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.1.10.1.29
.1.3.6.1.4.1.6527.6.1.2.2.17.1.21 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecHostGrpConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecHostGrpConfigTable'
The aluSecHostGrpConfigTable has an entry for each
security host group configured globally on this system.
aluSecHostGrpConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.21.1
Each row entry represents a particular security host group.
Column Syntax OID
The value of the object aluSecHosTGrpConfigId
specifies the unique host group id.
Unsigned32
Constraints:
range: 1-100
.1.3.6.1.4.1.6527.6.1.2.2.17.1.21.1.1
The value of aluSecHostGrpConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecHostGrpConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.21.1.2
Name of the security host group.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.21.1.3
Description of this security host group.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.21.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.22 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecHostConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecHostConfigTable'
The aluSecHostConfigTable has an entry for each
rule configured as part of a security host.
aluSecHostConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.22.1
Each row entry represents a particular host entry.
Column Syntax OID
The value of the object aluSecHostConfigIPAddrValue1
specifies the IP address of hosts in this group.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.22.1.1
The value of aluSecHostConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecHostConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.22.1.2
The value of the object aluSecHostConfigIPAddrValue2
specifies the 2nd IP address of a range of hosts.
SNMPv2-SMIIpAddressr/w
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.22.1.3
The operator specifies the manner in which
aluSecHostConfigIPAddrValue1 and
aluSecHostConfigIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecHostConfigIPOperator is used as described in
TIPOper…
TIPOperatorr/w
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.1.22.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.23 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecAppGrpConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecAppGrpConfigTable'
The aluSecAppGrpConfigTable has an entry for each
security application group configured globally on this system.
aluSecAppGrpConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.23.1
Each row entry represents a particular security app group.
Column Syntax OID
The value of the object aluSecAppGrpConfigId
specifies the unique application group id.
Unsigned32
Constraints:
range: 1-100
.1.3.6.1.4.1.6527.6.1.2.2.17.1.23.1.1
The value of aluSecAppGrpConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecAppGrpConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.23.1.2
Name of the security application group.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.23.1.3
Description of this security application group.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.23.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24 · 1 row entry · 11 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecAppConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecAppConfigTable'
The aluSecAppConfigTable has an entry for each
rule configured as part of a security application.
aluSecAppConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1
Each row entry represents a particular host entry.
Column Syntax OID
The value of aluSecAppConfigEntryId specifies the
index of the entry within the security app group.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.1
The value of aluSecAppConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecAppConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.2
IP protocol to match. set to -1 to disable matching IP protocol. If
the protocol is changed the protocol specific parameters are reset.
TIMETRA-TC-MIBTIpProtocolr/w
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.3
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.4
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.5
Source TCP/UDP port operator.
TIMETRA-TC-MIBTOperatorr/w
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.6
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.7
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPortr/w
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.8
Destination TCP/UDP port operator.
TIMETRA-TC-MIBTOperatorr/w
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.9
Icmp code to be matched. aluSecAppConfigMatchIcmpCode
complements the object aluSecAppConfigMatchIcmpType.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code matching is not
ena…
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.10
Icmp type to be matched. aluSecAppConfigMatchIcmpType
complements the object aluSecPlcyParamsConfigMatchIcmpCode.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code matching is …
Integer32r/w
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.1.24.1.11
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25 · 1 row entry · 6 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPolicerGrpConfigTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPolicerGrpConfigTable'
The aluSecPolcierGrpConfigTable has an entry for each
security policer group configured globally on this system.
aluSecPolicerGrpConfigEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1
Each row entry represents a particular security app group.
Column Syntax OID
The value of the object aluSecPolicerGrpConfigId
specifies the unique policer group id.
Unsigned32
Constraints:
range: 1-1024
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.1
The value of aluSecPolicerGrpConfigRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecPolicerGrpConfigTable.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.2
Name of the security policer group.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.3
Description of this security policer group.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.4
The aluSecPolicerGrpConfigRate object specifies the maximum ingress
bandwidth (in mega-bits per second) that the policer can receive.
A value of -1 means that no policing will be performed.
mega-bits per secondInteger32r/w
Constraints:
range: 1-10000
range: -1--1
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.14
aluSecPolicerGrpConfigRateCbs specifies the committed burst size that hard policer can accept while complying
to the ingress rate aluSecPolicerGrpConfigRate.

aluSecPolicerGrpConfigRateCbs is not applicab…
bytesUnsigned32r/w
Constraints:
range: 1-130816
.1.3.6.1.4.1.6527.6.1.2.2.17.1.25.1.17
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1 · 1 row entry · 44 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneOperTable'
The aluZoneOperTable has an entry for each zone 
configured on this system.
aluZoneOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1
Each row entry represents a particular zone.
Indexes
Column Syntax OID
The value of the object aluZoneOperId
specifies the unique id of the Zone in the system.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.1
The value of the object aluZoneOperName
specifies the name of the Zone in the system.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.2
The value of aluZoneOperBypass specifies whether this zone is being bypassed.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.3
Description about this zone.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.4
The value of aluZoneOperPlcyRuleCount indicates the number of rules that
this policy contains based on the security policies activated on this zone.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.5
Indicates the type of zone.
TZoneType
Type Values:
0unknown
1network
2service
3global
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.6
Specifies the service this zone belongs to when zone type is 'service'.
TIMETRA-TC-MIBTmnxServId
Type Constraints:
range: 0..2148278381
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.7
The value of the object aluZoneOperInSessionCount
indicates the total number of inbound sessions ever established for
this zone.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.8
The value of the object aluZoneOperInActiveSessions
indicates the number of currently active inbound sessions for
this zone.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.9
The value of the object aluZoneOperOutSessionCount
indicates the total number of outbound sessions ever established for
this zone.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.10
The value of the object aluZoneOperOutActiveSessions
indicates the number of currently active outbound sessions for
this zone.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.11
The number of inbound packets dropped due to policy.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.12
The number of inbound bytes dropped due to policy.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.13
The number of outbound packets dropped due to policy.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.14
The number of outbound bytes dropped due to policy.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.15
The number of inbound packets that the default
action was applied.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.16
The number of inbound bytes that the default
action was applied.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.17
The number of outbound packets that the default
action was applied.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.18
The number of outbound bytes that the default
action was applied.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.19
The last time a commit was performed on this zone.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.20
The value of the object aluZoneOperInTcpSessLimit
indicates the number of permitted active in sessions with
protocol TCP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.21
The value of the object aluZoneOperInUdpSessLimit
indicates the number of permitted active in sessions with
protocol UDP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.22
The value of the object aluZoneOpeInrIcmpSessLimit
indicates the number of permitted active in sessions with
protocol ICMP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.23
The value of the object aluZoneOperInOthSessLimit
indicates the number of permitted active in sessions of all
other protocols.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.24
The value of the object aluZoneOperInTcpSessLimit
indicates the number of permitted active outsessions with
protocol TCP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.25
The value of the object aluZoneOperInUdpSessLimit
indicates the number of permitted active out sessions with
protocol UDP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.26
The value of the object aluZoneOpeInrIcmpSessLimit
indicates the number of permitted active out sessions with
protocol ICMP.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.27
The value of the object aluZoneOperInOthSessLimit
indicates the number of permitted active out sessions of all
other protocols.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.28
The value of the object aluZoneInOperTcpActSessions
indicates the number of active sessions with
protocol TCP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.29
The value of the object aluZoneInOperUdpActSessions
indicates the number of active sessions with
protocol UDP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.30
The value of the object aluZoneOperInIcmpActSessions
indicates the number of active sessions with
protocol ICMP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.31
The value of the object aluZoneOperInOthActiveSessions
indicates the number of active sessions of all
other protocols.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.32
The value of the object aluZoneOperOutTcpActSessions
indicates the number of active sessions with
protocol TCP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.33
The value of the object aluZoneOperUdpActSessions
indicates the number of active sessions with
protocol UDP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.34
The value of the object aluZoneOperOutIcmpActSessions
indicates the number of active sessions with
protocol ICMP.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.35
The value of the object aluZoneOperOutOthActSessions
indicates the number of active sessions of all
other protocols.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.36
The value of the object aluZoneConfigLogId
indicates the log-id for security logging.
Unsigned32
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.38
The value of aluZoneConfigAutoBind specifies whether this zone is being used to enforce policy
on traffic to/from MP-BGP auto-binding and spoke-sdps. This configuration is only permitted on
VPRN zones and can only be e…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.39
The accumulated number of inbound sessions with forward action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.40
The accumulated number of outbound sessions with forward action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.41
The accumulated number of inbound sessions with NAT action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.42
The accumulated number of outbound sessions with NAT action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.43
The accumulated number of inbound sessions with drop action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.44
The accumulated number of outbound sessions with drop action.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.1.1.45
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2 · 1 row entry · 9 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZonePlcyOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZonePlcyOperTable'
The aluZonePlcyOperTable describes the active policy of this
zone.  This table is a flattened ordered list of rules for this zone based
on the security policies that have been activated.
aluZonePlcyOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1
Each row entry represents a particular zone entry.
Column Syntax OID
The value of the object aluZonePlcyOperRuleId
rule id of each operational rule in the Zone.
The rule id is assigned by the system based on the
security policies that have been activated on this zone.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.1
The value of the object aluZonePlcyOperEntryId
specifies the zone policy entry this rule is associated with.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.2
The value of the object aluZonePlcyOperActive
indicates whether this rule is active for rule parsing
in the zone policy.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.3
This object specifies all the conditions that
affect the active status of this Zone Policy.
Bits
Enumerated Values:
0noNatPool
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.4
The value of aluZonePlcyOperSecPlcyId specifies the security policy
that this rule was derived from.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.5
The value of aluZonePlcyOperSecPlcyRuleId specifies the rule from the
security policy specified by aluZonePlcyOperSecPlcyId that defines this
zone policy rule.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.6
The value of aluZonePlcyOperNatPoolId specifies the NAT Pool to be used
for this rule when the action is NAT.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.7
The value of aluZonePlcyOperRuleHitCount specifies the number of times this
rule has been matched.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.8
The value of aluZonePlcyOperRuleActiveSessions specifies the number of currently
active sessions this rule has outstanding.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.2.1.9
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3 · 1 row entry · 5 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneNatPoolOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneNatPoolOperTable'
The aluZoneNatPoolOperTable has an entry for each
nat-pool of ip addresses and ports configured on a particular zone.
aluZoneNatPoolOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1
Each row entry represents a particular policy entry.
Column Syntax OID
The value of the object aluZoneNatPoolOperId
specifies the unique id of the NAT-Pool entries within the zone.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1.1
The value of the object aluZoneNatPoolOperName
specifies the name of the NAT Pool.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1.2
Description of this nat pool.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1.3
Specifies type of pool
TPoolType
Type Values:
0unknown
1srcNatPool
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1.4
Specifies direction of the pool.
Enumeration
Enumerated Values:
0unknown
1zoneInbound
2zoneOutbound
.1.3.6.1.4.1.6527.6.1.2.2.17.2.3.1.5
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4 · 1 row entry · 8 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneNatPoolParamsOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneNatPoolParamsOperTable'
The aluZoneNatPoolParamsOperTable has an entry NAT Pool 
params entry configured on this system.
aluZoneNatPoolParamsOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1
Each row entry represents a particular NAT Pool params entry.
Column Syntax OID
The value of aluZoneNatPoolParamsOperEntryId specifies the
3rd index for the entry.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.1
The value of the object
aluZoneNatPoolParamsOperIPAddrValue1 specifies
the starting range of IP address of the NAT pool.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.2
The value of the object
aluZoneNatPoolParamsOperIPAddrValue2 specifies
the ending range of IP address of the NAT pool.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.3
The operator specifies the manner in which
aluZoneNatPoolParamsOperIPAddrValue1 and
aluZoneNatPoolParamsOperIPAddrValue2
are to be used. The value of these below 2 objects and
aluZoneNatPoolParamsOperIPOperator is used…
TIPOperator
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.4
The aluZoneNatPoolParamsOperIPInterfaceIndex specifies
the index of the interface that the primary-address of that
interface is to be used in the NAT pool.
The interface must exist in the same vRtr that the NAT pool
res…
IF-MIBInterfaceIndexOrZero
Type Constraints:
range: 0..2147483647
Description:
This textual convention is an extension of the
InterfaceIndex convention. The latter defines a greater
than zero value used to identify an interface or interface
sub-layer in the managed system. This extension permits…
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.5
The operator specifies the manner in which
aluZoneNatPoolParamsOperPortValue1 and
aluZoneNatPoolParamsOperPortValue2
are to be used. The value of these below 2 objects and
aluZoneNatPoolParamsOperPortOperator is used a…
TIMETRA-TC-MIBTTcpUdpPortOperator .1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.6
TCP/UDP port value1. The value of this object is used as per the
description for aluZoneNatPoolParamsOperPortOperator.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.7
TCP/UDP port value2. The value of this object is used as per the
description for aluZoneNatPoolParamsOperPortOperator.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.4.1.8
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5 · 1 row entry · 5 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPlcyOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPlcyOperTable'
The aluSecPlcyOperTable has an entry for each
policy configured globally on this system.
aluSecPlcyOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1
Each row entry represents a security policy.
Column Syntax OID
The value of the object aluSecPlcyOperId
specifies the unique id in the for the policy in
the system.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1.1
Name of the security policy.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1.2
Description of this security policy.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1.3
The value of aluSecPlcyOperRuleCount indicates the current number of
rules that are part of the security policy.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1.4
The value of aluSecPlcyOperZoneRefCount indicates the number of
zones that are using this security policy.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.5.1.5
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6 · 1 row entry · 31 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPlcyParamsOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPlcyParamsOperTable'
The aluSecPlcyParamsOperTable has an entry for each
rule configured in each security policy.
aluSecPlcyParamsOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1
Each row entry represents a particular rule parameters.
Column Syntax OID
The value of aluSecPlcyParamsOperRuleId specifies the
rule index within the Security Policy.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.1
Description of this rule.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.2
The value of the object aluSecPlcyParamsOperMatchSrcIPAddrValue1
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose source…
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.3
The value of the object aluSecPlcyParamsOperMatchSrcIPAddrValue2
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sourc…
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.4
The operator specifies the manner in which
aluSecPlcyParamsOperMatchSrcIPAddrValue1 and
aluSecPlcyParamsOperMatchSrcIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecPlcyParamsOperMatchSrcIPOper…
TIPOperator
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.5
The value of the object aluSecPlcyParamsOperMatchSrcIPHostGroup
specifies the host group name, where the group name is a collection
of IP addresses.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.6
The value of the object aluSecPlcyParamsOperMatchDstIPAddrValue1
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose source…
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.7
The value of the object aluSecPlcyParamsOperMatchDstIPAddrValue2
specifies the source IP address of the packets to be filltered.
When configured and activated, This filter will be
applied to all IP packets whose sourc…
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.8
The operator specifies the manner in which
aluSecPlcyParamsOperMatchDstIPAddrValue1 and
aluSecPlcyParamsOperMatchDstIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecPlcyParamsOperMatchDstIPOper…
TIPOperator
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.9
The value of the object
aluSecPlcyParamsOperMatchDstIPHostGroup specifies
the host group name, where the group name is a collection
of IP addresses.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.10
IP protocol to match. set to -1 to disable matching IP protocol. If
the protocol is changed the protocol specific parameters are reset.
TIMETRA-TC-MIBTIpProtocol
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.11
TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.12
TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.13
TCP/UDP port operator.
TIMETRA-TC-MIBTOperator
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.14
TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.15
TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.16
TCP/UDP port operator.
TIMETRA-TC-MIBTOperator
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.17
The value of the object aluSecPlcyParamsOperMatchAppGroup
specifies the application group, where the app-group is a
collection of protocol-id/src port/dest port.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.18
Icmp code to be matched.
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.19
Icmp type to be matched.
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.20
Type of IGMP to be configured
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.21
This object specifies the direction of the packet flow
for which the rule is matched.
in is equivalent to zone ingress flow,
out is equivalent to zone egress flow,
both is equivalent to both ingress and egress flow
Enumeration
Enumerated Values:
1zoneInbound
2zoneOutbound
3both
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.22
The value of the object specifies traffic profile.
Unsigned32
Constraints:
range: 0-120
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.23
The value of the object specifies max number of simultaneous
sessions allowed for this particular rule. Beyond this
limit, new sessions will not be created.
Sessions will be created internally for a packet with
uniqu…
Unsigned32
Constraints:
range: 0-10000
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.24
The value of aluSecPlcyParamsOperCreateRevDirFlow specifies
whether return direction of the session is created or not
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.25
This object specifies whether the packet needs to be
passed or dropped if it satisfies the rule condition.
Enumeration
Enumerated Values:
0forward
1drop
2nat
3reject
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.26
The value of aluSecPlcyParamsOperMatchLocal specifies
whether to match traffic destined to node
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.27
The value of the object aluSecPlcyParamsOperActionNatDstIPAddr
specifies the Dst IP address of the packet after NAT has been
performed
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.28
NAT Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.39
Log control for policy.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.40
Log Destination for policy.
TSecurityLogId
Type Constraints:
range: 0..100
.1.3.6.1.4.1.6527.6.1.2.2.17.2.6.1.41
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7 · 1 row entry · 29 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecProfileOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecProfileOperTable'
The aluSecProfileOperTable has an entry for each
security profile configured globally on this system.
aluSecProfileOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1
Each row entry represents a particular security profile.
Column Syntax OID
The value of the object aluSecProfileOperId
specifies the unique profile id.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.1
Name of the security profile.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.2
Description of this security profile.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.3
The value of the object specifies the number of times
this profile is referenced in security policies.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.4
The value of the object specifies the number of seconds a
TCP session can wait for a SYN before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.5
The value of the object specifies the number of seconds a
TCP session can remain in time wait before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.6
The value of the object specifies the number of seconds a
TCP session can remain be transitory before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.7
The value of the object specifies the number of seconds a
TCP session has to reach established before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.8
The value of the object specifies the number of seconds a
UDP session can remain idle before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.9
The value of the object specifies the number of seconds a
UDP session can remain idle after recieving the first packet
before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.10
The value of the object specifies the number of seconds a
DNS request can take to recieve a response
before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.11
The value of the object specifies the number of seconds an
ICMP request can take to recieve a response
before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.12
The value of the object specifies the number of seconds other
protocol sessions can remain idle before being cleaned up.
secondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.13
The value of the object indicates whether application inspection
should be performed on all active connections with this profile.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.14
The value of the object indicates whether stict TCP inspection
should be performed on all active TCP connections with this profile.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.15
The value of the object indicates whether IP options inspection
is to be performed. When 'true' the object aluSecProfileOperAllowedIpOpt
is used to specify permitted options.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.16
The value of the object indicates the bothmask of allowed IP options when IP
option inspection is enabled.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.17
The value of the object indicates whether fragmented IP packets are
permitted through connections with this profile.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.18
The value of the object indicates the application layer
gateway processing to be performed on this connection.
TAlgType
Type Values:
0none
1auto
2ftp
3tftp
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.19
The value of the object specifies the number of ICMP packets permitted
to travese the ICMP request session in each direction.
A value of 0 specifies that there is no packet limit.
aluSecProfileConfigAppInspect must be e…
packetsUnsigned32
Constraints:
range: 0-254
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.20
The value of the object specifies the whether to limit the number of ICMP Type 3
packets that are permitted to travese the session in each direction.
aluSecProfileConfigAppInspect must be enabled before ICMP inspection…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.21
The value of the object specifies the whether to limit the number of DNS
packets that are permitted to travese a DNS session in each direction.
aluSecProfileConfigAppInspect must be enabled before DNS inspection
can b…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.22
The value of the object specifies if a TCP Session in the Established
state is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.23
The value of the object specifies if a UDP Session in the Established
state is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.24
The value of the object specifies if a ICMP Request Session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has bee…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.25
The value of the object specifies if a DNS Request Session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has been…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.26
The value of the object specifies if a Other protocol session
is strictly enforced to timeout after the Timeout setting regardless of
session activity. When'false' the session will not timeout until the session
has b…
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.27
The value of the object specifies the policer group that the forward direction
of the session should be rate-limited with.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.28
The value of the object specifies the policer group that the reverse direction
of the session should be rate-limited with.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.7.1.29
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8 · 1 row entry · 19 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneInboundSessionTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneInboundSessionTable'
The aluZoneInboundSessionTable has an entry for each
session establish entering a zone.
aluZoneInboundSessionEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1
Each row entry represents a particular inbound active session.
Column Syntax OID
The value of aluZoneSessionId specifies the
session index for this active session.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.1
IP protocol of session.
TIMETRA-TC-MIBTIpProtocol
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.2
The value of aluZoneInboundSessionSrcZoneId secifies the
source zone that established this session.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.3
The value of aluZoneInboundSessionSrcIPAddrValue
specifies the source IP address of this flow.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.4
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.5
Destination IP address of this flow.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.6
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.7
The value of aluZoneInboundSessionRevDirCreated indicates
whether return direction of the session was created or not
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.8
This object specifies session action.
Enumeration
Enumerated Values:
0forward
1drop
2nat
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.9
The value of aluZoneInboundSessionNatSrcIPAddrValue
specifies the source IP address of this flow has after NAT.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.10
NAT Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.11
The value of aluZoneInboundSessionNatDstIPAddrValue
specifies the destination IP address of this flow has after NAT.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.12
NAT Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.13
Time that this session was established.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.14
This object specifies ALG being performed on session.
algRule - Dynamic Rule for ALG Data Sessions
ftp - FTP Control Session
Enumeration
Enumerated Values:
0none
1algRule
2ftp
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.15
This object specifies if session traffic is sent to central core.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.16
This object specifies policer-group that forward session traffic
is sent to.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.17
This object specifies policer-group that reverse session traffic
is sent to.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.18
This object specifies the session-id that created this session via ALG.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.8.1.19
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9 · 1 row entry · 18 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluZoneOutboundSessionTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluZoneOutboundSessionTable'
The aluZoneOutboundSessionTable has an entry for each
session establish leaving a zone.
aluZoneOutboundSessionEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1
Each row entry represents a particular inbound active session.
Column Syntax OID
IP protocol of session.
TIMETRA-TC-MIBTIpProtocol
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.1
The value of aluZoneOutboundSessionSrcIPAddrValue
specifies the source IP address of this flow.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.2
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.3
Destination IP address of this flow.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.4
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.5
The value of aluZoneOutboundSessionDstZoneId specifies the
destination zone for this session.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.6
The value of aluZoneOutboundSessionRevDirCreated indicates
whether return direction of the session was created or not
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.7
This object specifies session action.
Enumeration
Enumerated Values:
0forward
1drop
2nat
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.8
The value of aluZoneOutboundSessionNatSrcIPAddrValue
specifies the source IP address of this flow has after NAT.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.9
NAT Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.10
The value of aluZoneOutboundSessionNatDstIPAddrValue
specifies the destination IP address of this flow has after NAT.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.11
NAT Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.12
Time that this session was established.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.13
This object specifies ALG being performed on session.
algRule - Dynamic Rule for ALG Data Sessions
ftp - FTP Control Session
Enumeration
Enumerated Values:
0none
1algRule
2ftp
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.14
This object specifies if session traffic is sent to central core.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.15
This object specifies policer-group that forward session traffic
is sent to.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.16
This object specifies policer-group that reverse session traffic
is sent to.
TSecurityPolicerId
Type Constraints:
range: 0..1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.17
This object specifies the session-id that created this session via ALG.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.9.1.18
.1.3.6.1.4.1.6527.6.1.2.2.17.2.10 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecHostGrpOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecHostGrpOperTable'
The aluSecHostGrpOperTable has an entry for each
security host group configured globally on this system.
aluSecHostGrpOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.10.1
Each row entry represents a particular security host group.
Column Syntax OID
The value of the object aluSecHosTGrpOperId
specifies the unique host group id.
Unsigned32
Constraints:
range: 1-100
.1.3.6.1.4.1.6527.6.1.2.2.17.2.10.1.1
Name of the security host group.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.10.1.2
Description of this security host group.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.10.1.3
Number of policy references.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.10.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.11 · 1 row entry · 3 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecHostOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecHostOperTable'
The aluSecHostOperTable has an entry for each
rule configured as part of a security host.
aluSecHostOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.11.1
Each row entry represents a particular host entry.
Column Syntax OID
The value of the object aluSecHostOperIPAddrValue1
specifies the IP address of hosts in this group.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.11.1.1
The value of the object aluSecHostOperIPAddrValue2
specifies the 2nd IP address of a range of hosts.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.11.1.2
The operator specifies the manner in which
aluSecHostOperIPAddrValue1 and
aluSecHostOperIPAddrValue2
are to be used. The value of these below 2 objects and
aluSecHostOperIPOperator is used as described in
TIPOperator.
TIPOperator
Type Values:
0none
1eq
2range
.1.3.6.1.4.1.6527.6.1.2.2.17.2.11.1.3
.1.3.6.1.4.1.6527.6.1.2.2.17.2.12 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecAppGrpOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecAppGrpOperTable'
The aluSecAppGrpOperTable has an entry for each
security application group configured globally on this system.
aluSecAppGrpOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.12.1
Each row entry represents a particular security app group.
Column Syntax OID
The value of the object aluSecAppGrpOperId
specifies the unique application group id.
Unsigned32
Constraints:
range: 1-100
.1.3.6.1.4.1.6527.6.1.2.2.17.2.12.1.1
Name of the security application group.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.12.1.2
Description of this security application group.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.12.1.3
Number of policy references.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.12.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13 · 1 row entry · 10 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecAppOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecAppOperTable'
The aluSecAppOperTable has an entry for each
rule configured as part of a security application.
aluSecAppOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1
Each row entry represents a particular host entry.
Column Syntax OID
The value of aluSecAppOperEntryId specifies the
index of the entry within the security app group.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.1
IP protocol to match. set to -1 to disable matching IP protocol. If
the protocol is changed the protocol specific parameters are reset.
TIMETRA-TC-MIBTIpProtocol
Type Constraints:
range: -2..255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.2
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.3
Source TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.4
Source TCP/UDP port operator.
TIMETRA-TC-MIBTOperator
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.5
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.6
Destination TCP/UDP port value.
TIMETRA-TC-MIBTTcpUdpPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.7
Destination TCP/UDP port operator.
TIMETRA-TC-MIBTOperator
Type Values:
0none
1eq
2range
3lt
4gt
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.8
Icmp code to be matched. aluSecAppOperMatchIcmpCode
complements the object aluSecAppOperMatchIcmpType.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code matching is not
enabled.
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.9
Icmp type to be matched. aluSecAppOperMatchIcmpType
complements the object aluSecPlcyParamsOperMatchIcmpCode.
Both of them need to be set to actually
enable ICMP matching. The value -1 means Icmp code matching is not
Integer32
Constraints:
range: -1-255
.1.3.6.1.4.1.6527.6.1.2.2.17.2.13.1.10
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14 · 1 row entry · 12 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecPolicerGrpOperTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecPolicerGrpOperTable'
The aluSecPolcierGrpOperTable has an entry for each
security policer group configured globally on this system.
aluSecPolicerGrpOperEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1
Each row entry represents a particular security app group.
Column Syntax OID
The value of the object aluSecPolicerGrpOperId
specifies the unique policer group id.
Unsigned32
Constraints:
range: 1-1024
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.1
Name of the security policer group.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.2
Description of this security policer group.
TIMETRA-TC-MIBTItemDescription
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.3
The aluSecPolicerGrpOperRate object specifies the maximum ingress
bandwidth (in mega-bits per second) that the policer can receive.
A value of -1 means that no policing will be performed.
mega-bits per secondInteger32
Constraints:
range: 1-100000
range: -1--1
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.4
aluSecPolicerGrpOperRateCbs specifies the committed burst size that hard policer can accept while complying
to the ingress rate aluSecPolicerGrpOperRate.
bytesUnsigned32
Constraints:
range: 1-130816
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.5
Number of policy references.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.6
Pkts passed thru policer in session forward direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.7
Bytes passed thru policer in session forward direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.8
Pkts dropped by policer in session forward direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.9
Pkts passed thru policer in session reverse direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.10
Bytes passed thru policer in session reverse direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.11
Pkts dropped by policer in session reverse direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.2.14.1.12
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1 · 1 row entry · 19 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecSessionStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecSessionStatsTable'
The aluSecSessionStatsTable has an entry for each
active session.
aluSecSessionStatsEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1
Each row entry represents an active session.
Indexes
Column Syntax OID
The value of aluSecSessionId specifies the
session index for this active session.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.1
The value of aluSecSessionOutboundZoneId specifies the
zone this session is leaving.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.2
The value of aluSecSessionInboundZoneId specifies the
zone this session is entering.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.3
Pkts passed thru session in forward direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.4
Bytes passed thru session in forward direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.5
Pkts passed thru session in reverse direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.6
Bytes passed thru session in reverse direction.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.7
Packets/Fragments dropped due to session action being drop.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.8
Packets dropped due to containing prohibited IP Options
for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.9
Packets dropped due to containing prohibited IP Options
for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.10
Packets dropped due to exceeding the maximum number of packets
permitted for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.11
Packets dropped due to exceeding the maximum number of packets
permitted for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.12
ICMP Error Packets dropped due to exceeding the maximum number of errors
permitted for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.13
ICMP Error Packets dropped due to exceeding the maximum number of errors
permitted for this session.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.14
Packets dropped due to applications insepctions.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.15
Packets dropped due to applications insepctions.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.16
Packets dropped due to rate exceeded in policer.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.17
Packets dropped due to rate exceeded in policer.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.18
Packets/Fragments dropped due to session action being drop.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.1.1.19
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2 · 1 row entry · 6 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecZoneStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecZoneStatsTable'
The aluSecZoneStatsTable has an entry for each security zone
aluSecZoneStatsEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1
Each row entry represents stats for a security zone.
Indexes
Column Syntax OID
The value of aluSecZoneId specifies the
security zone index for this row entry.
Unsigned32
Constraints:
range: 1-65534
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.1
Pkts forwarded from the Receiving Security Control Queue to security engine for further inspection
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.2
Bytes forwarded from the Receiving Security Control Queue to security engine for further inspection
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.3
Pkts dropped from the Receiving Security Control Queue
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.4
Bytes dropped from the Receiving Security Control Queue
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.5
All Auto-Bind zones share a single Rx Control Queue. This object indicates
whether this zone row is displaying the aggregates stats for all Auto-Bind Zones
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.3.2.1.6
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3 · 1 row entry · 6 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecEngineStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecEngineStatsTable'
The aluSecEngineStatsTable has an entry for 
security engine in the system.
aluSecEngineStatsEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1
Each row entry represents a security engine.
Indexes
Column Syntax OID
The value of aluSecEngineId specifies the
identifier for security engine.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.1
The value of aluSecEngineUtilization specifies the
percentage of the processing capacity in use over
the last second.
percentSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.2
Control Pkts forwarded to Engine from Rx Queue.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.3
Session Data Pkts forwarded to Engine from Rx Queue.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.4
Pkts dropped by Engine Rx Queue.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.5
Pkts dropped by Engine due to security policy.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.6527.6.1.2.2.17.3.3.1.6
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1 · 1 row entry · 12 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecLogTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecLogTable'
The alSecLogTable has an entry for each 
security log configured on the system.
aluSecLogEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1
Each row entry represents a log entry.
Indexes
Column Syntax OID
The value of the object aluSecLogId specifies
the unique id of the Log. The Id must be
unique within the system.
TSecurityLogId
Type Constraints:
range: 0..100
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.1
The value of the object aluSecLogName
specifies the name of the Log.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.2
The value of aluSecLogRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecLogTable. aluSecLogRowStatus does not support
createAndWait. The status can only be active
or notIn…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.3
Description of this log.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.4
The value of the object aluSecLogEnabled
indicates whether this Log is currently enabled
to log events.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.5
The value of the object aluSecLogDestination
specifies the destination of log.
Enumerationr/w
Enumerated Values:
0none
1memory
2syslog
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.6
The value of the object aluSecLogMemSize
specifies the number of logs that are held in memory.
This value is only applicable when aluSecLogDestinations is
type 'memory'
Unsigned32r/w
Constraints:
range: 1-1024
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.7
The value of the object aluSecLogMemWrap
specifies if the log will overwrite the oldest logs once
the log has reached it's maximum size.
This value is only applicable when aluSecLogDestination is
type 'memory'
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.8
The value of the object aluSecLogSysLogId
specifies the unigue ID of the SysLog destination for logs
generated to this log id.
This value is only applicable when aluSecLogDestinations is
type 'syslog'
Unsigned32r/w
Constraints:
range: 0-65535
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.9
The value of the object aluSecLogLogProfileId
specifies the unigue ID of the Logging Profile of this
log.
TSecurityLogProfileIdr/w
Type Constraints:
range: 1..100
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.10
The value of the object aluSecLogApplied indicates
whether this log is in use.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.11
The value of the object aluSecLogNextEventNum indicates
the next event number to be used.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.5.1.1.12
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2 · 1 row entry · 5 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecLogProfileTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecLogProfileTable'
The alSecLogProfileTable has an entry for each 
each logging profile configured on the system.
aluSecLogProfileEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1
Each row entry represents a log profile.
Column Syntax OID
The value of the object aluSecLogProfileId
specifies the unigue ID of the Logging Profile of this
log.
TSecurityLogProfileId
Type Constraints:
range: 1..100
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1.1
The value of the object aluSecLogProfileName
specifies the name of the Log Profile.
TIMETRA-TC-MIBTNamedItemOrEmptyr/w
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1.2
The value of aluSecLogProfileRowStatus specifies the
row status. It allows entries to be created and deleted in the
aluSecLogProfileTable. aluSecLogProfileRowStatus does not support
createAndWait. The status can onl…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1.3
Description of this log profile.
TIMETRA-TC-MIBTItemDescriptionr/w
Type Constraints:
range: 0..80
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1.4
Indicates whether this profile is being used by any logs.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.6527.6.1.2.2.17.5.2.1.5
.1.3.6.1.4.1.6527.6.1.2.2.17.5.3 · 1 row entry · 4 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluSecLogEventTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluSecLogEventTable'
The alSecLogEventTable has an entry for each 
each log event configurable with a security log profile 
configured on the system.
aluSecLogEventEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.5.3.1
Each row entry represents a log event under a profile. All events
are auto-created when a Log Profile is created.
Column Syntax OID
The value of the object aluSecLogEventType specifies
the type/category of the event.
Enumeration
Enumerated Values:
1packet
2zone
3policy
4session
5application
6alg
.1.3.6.1.4.1.6527.6.1.2.2.17.5.3.1.1
The value of the object aluSecLogEventId specifies
the unique id of the event within the Event Type/Category.
An Event-Id of 0 is used to set settings at the Event Type level.
These setting will be applied to all events…
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.5.3.1.2
The value of the object aluSecLogEventName
specifies the name of the Log Event. This value is read-only.
TIMETRA-TC-MIBTNamedItemOrEmpty
Type Constraints:
range: 0..32
.1.3.6.1.4.1.6527.6.1.2.2.17.5.3.1.3
Suppress/Throttle the generation of an event or event type.
- Each event can individually be suppressed.
- Throttling or disabling event control must be done at the event-type
level by setting aluSecLogEventControl u…
Enumerationr/w
Enumerated Values:
1off
2throttled
3suppressed
.1.3.6.1.4.1.6527.6.1.2.2.17.5.3.1.4
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2 · 1 row entry · 24 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluMcPeerFwTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluMcPeerFwTable'
The aluMcPeerFwTable has an entry for each multi-chassis peer
end-point configured on this system.
aluMcPeerFwEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1
Each row entry represents a particular multi-chassis firewall peer.
Entries are create/deleted by the user.
Column Syntax OID
The value of aluMcPeerFwRowStatus is used for creation/deletion of
multi-chassis peer end-points.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.1
The value of aluMcPeerFwLastChanged indicates the sysUpTime
at the time of the last modification of this entry.

If no changes were made to the entry since the last re-initialization
of the local network m…
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.2
The value of aluMcPeerFwAdminState specifies the administrative state
of this multi-chassis peer end-point.
TIMETRA-TC-MIBTmnxAdminStater/w
Type Values:
1noop
2inService
3outOfService
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.3
The value of aluMcPeerFwSysPriority specifies the system priority
of this multi-chassis peer end-point.
Unsigned32r/w
Constraints:
range: 0-255
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.4
The value of aluMcPeerFwKeepAliveIntvl specifies the interval at which
keep-alive messages are exchanged between two peers participating
in a multi-chassis end-point tunnel (MC-FW).

These keep-alive messa…
deci-secondsUnsigned32r/w
Constraints:
range: 5-500
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.5
The value of aluMcPeerFwHoldOnNbrFail specifies the number of
keep-alive intervals that the local peer will wait for packets from the
multi-chassis end-point peer before assuming failure.
Unsigned32r/w
Constraints:
range: 2-25
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.6
The value of aluMcPeerFwBootTimer specifies the time the multi-chassis
end-point protocol keeps trying the establish a connection before
assuming a failure of the remote-peer.

This object is used at the b…
secondsUnsigned32r/w
Constraints:
range: 1-600
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.7
The value of aluMcPeerFwBfd specifies whether bi-directional
forwarding detection (BFD) is configured for this multi-chassis
end-point peering tunnel.
TIMETRA-TC-MIBTmnxEnabledDisabledr/w
Type Values:
1enabled
2disabled
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.8
The value of aluMcPeerFwOperState indicates the operational
status of this multi-chassis end-point peer.
Enumeration
Enumerated Values:
0inService
1outOfService
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.9
The value of aluMcPeerFwPeerLastStateChge indicates the sysUpTime
at the time of the last operational state change for this
multi-chassis end-point peer.

If no changes were made since the last re-initial…
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.10
The value of aluMcPeerFwRefCount indicates how many service end-points
are referencing this multi-chassis firewall peer.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.11
The value of aluMcPeerFwEncryption specifies whether encryption
is enabled for this multi-chassis firewall peer.
TIMETRA-TC-MIBTmnxEnabledDisabledr/w
Type Values:
1enabled
2disabled
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.12
The value of aluMcPeerFwEncryptionAuthAlg specifies the hashing
algorithm used for the AH (Authentication Header) protocol's
authentication function.
AluMcFwAuthAlgorithmr/w
Type Values:
1sha256
2sha512
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.13
The value of aluMcPeerFwEncryptionEncrAlg specifies the
encryptiontion algorithm to be used. Encryptiontion only applies
to ESP(Encapsulating Security Payload) configurations.
AluMcFwEncrAlgorithmr/w
Type Values:
1aes128
2aes256
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.14
The value of aluMcPeerFwEncryptionActOutSa specifies the SPI
to be used when performing encryption and authentication
on egressing packets using this MC firewall peer.
Unsigned32r/w
Constraints:
range: 0-1023
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.15
The value of aluMcPeerFwEncryptionSpi1 specifies the spi of the first security association.
spi 0 means that this security association is invalid
Unsigned32r/w
Constraints:
range: 0-1023
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.16
The value of aluMcPeerFwEncryptionSpiAuthKey1 specifies the key used
for the authentication algorithm defined by the
aluMcPeerFwEncryptionAuthAlg.

The length of the key must match the length required by t…
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.17
The value of aluMcPeerFwEncryptionSpiEncrKey1 specifies the key used
for the encryption algorithm defined by the
aluMcPeerFwEncryptionEncrAlg.

The length of the key must match the length required by the
e…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.18
The value of aluMcPeerFwEncryptionSpi2 specifies the spi of the second security association.
spi 0 means that this security association is invalid
Unsigned32r/w
Constraints:
range: 0-1023
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.19
The value of aluMcPeerFwEncryptionSpiAuthKey2 specifies the key used
for the authentication algorithm defined by the
aluMcPeerFwEncryptionAuthAlg.

The length of the key must match the length required by t…
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.20
The value of aluMcPeerFwEncryptionSpiEncrKey2 specifies the key used
for the encryption algorithm defined by the
aluMcPeerFwEncryptionEncrAlg.

The length of the key must match the length required by the
e…
OctetStringr/w
Constraints:
range: 0-32
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.21
The value of aluMcPeerFwElectionRole indicates the role
of this multi-chassis firewall peer.
Enumeration
Enumerated Values:
0not-applicable
1master
2slave
3standalone-master
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.22
The value of aluMcPeerFwPolicySync indicates the state of the
Policy Synchronization flag on this multi-chassis firewall peer.
Enumeration
Enumerated Values:
0not-applicable
1synced
2out-of-sync
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.23
The value of aluMcPeerFwSessionDBSync indicates the state of the
Session Database Synchronization flag on this multi-chassis firewall peer.
Enumeration
Enumerated Values:
0not-applicable
1synced
2out-of-sync
.1.3.6.1.4.1.6527.6.1.2.2.17.6.2.1.24
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1 · 1 row entry · 17 columns
Uses the nokia variant from /opt/observium/mibs/nokia.
Command help
Walk aluMcFwPeerStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'ALU-SECURITY-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'ALU-SECURITY-MIB::aluMcFwPeerStatsTable'
The aluMcFwPeerStatsTable has an entry for each multi-chassis peer
configured on this system.
aluMcFwPeerStatsEntry row .1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1
Each row entry represents a collection of statistics for a
multi-chassis peer.

Entries cannot be created and deleted via SNMP SET operations.
Column Syntax OID
The value of aluMcFwPeerStatsPktsRx indicates how many valid MC-Firewall
control packets were received on this system from the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.1
The value of aluMcFwPeerStatsPktsRxKpalive indicates how many valid
MC-Firewall control packets of type keepalive were received on this
system from the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.2
The value of aluMcFwPeerStatsPktsRxPeerCfg indicates how many valid
MC-Firewall control packets of type peer config were received on this
system from the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.3
The value of aluMcFwPeerStatsPktsRxPeerData indicates how many valid
MC-Firewall control packets of type peer data were received on this
system from the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.4
The value of aluMcFwPeerStatsDropRxPeerData indicates indicates how many MC-Firewall
control packets of type peer data were dropped on this system from the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.5
The value of aluMcFwPeerStatsDropStateDsbld indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the peer was administratively disabled.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.6
The value of aluMcFwPeerStatsDropPktTooShrt indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the packet was too short.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.7
The value of aluMcFwPeerStatsDropTlvInvldSz indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the packet size was invalid.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.8
The value of aluMcFwPeerStatsDropOutOfSeq indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the packet was out of sequence.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.9
The value of aluMcFwPeerStatsDropUnknownTlv indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the packet contained an unknown TLV.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.10
The value of aluMcFwPeerStatsDropMD5 indicates how many
MC-Firewall control packets were dropped on this system from the peer
because the packet failed MD5 authentication.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.11
The value of aluMcFwPeerStatsPktsTx indicates how many
MC-Firewall control packets were transmitted from this system to the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.12
The value of aluMcFwPeerStatsPktsTxKpalive indicates how many
MC-Firewall control packets of type keepalive were transmitted from
this system to the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.13
The value of aluMcFwPeerStatsPktsTxPeerCfg indicates how many
MC-Firewall control packets of type peer config were transmitted from
this system to the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.14
The value of aluMcFwPeerStatsPktsTxPeerData indicates how many
MC-Firewall control packets of type peer data were transmitted from
this system to the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.15
The value of aluMcFwPeerStatsPktsTxFailed indicates how many
MC-Firewall control packets failed to be transmitted from
this system to the peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.16
The value of aluMcFwPeerStatsDropFwNoPeer indicates how many
pkts were dropped because MC-Firewall does not have a MC-peer
assigned yet or MC-Firewall is attached to a different peer.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.6527.6.1.2.2.17.7.1.1.17