CISCO-ENHANCED-IPSEC-FLOW-MIB

        This is a MIB Module for monitoring the structures
and status of IPSec-based networks. The MIB has been 
designed to be adopted as an IETF standard. Hence 
vendor-specific features of IPSec protocol are excluded 
from this MIB.
        
Acronyms
The following acronyms are used in this document:
        
   IPsec:      Secure IP Protocol
        
   VPN:        Virtual Private Network
        
   ISAKMP:     Internet Security Association and Key Exchange
               Protocol
        
   IKE:        Internet Key Exchange Protocol
        
   SA:         Security Association
       (ref: rfc2408).
        
   SPI:        Security Parameter Index is the pointer or
       identifier used in accessing SA attributes
       (ref: rfc2408).
        
   MM:         Main Mode - the process of setting up
               a Phase 1 SA to secure the exchanges
               required to setup Phase 2 SAs
        
   QM:         Quick Mode - the process of setting up
               Phase 2 Security Associations using
               a Phase 1 SA.
        
   Phase 1 Tunnel:
               An ISAKMP SA can be regarded as representing
               a flow of ISAKMP/IKE traffic. Hence an ISAKMP
               is referred to as a 'Phase 1 Tunnel' in this
               document. 
        
   Control Tunnel:
               Another term for a Phase 1 Tunnel.
        
   Phase 2 Tunnel:
               An instance of a non-ISAKMP SA  bundle in which all
               the SA share the same proxy identifiers (IDii,IDir)
               protect the same stream of application traffic.
               Such an SA bundle is termed a 'Phase 2 Tunnel'.
               Note that a Phase 2 tunnel may comprise different
               SA bundles and different number of SA bundles at
               different times (due to key refresh).
        
   MTU:
               Maximum Transmission Unit (of an IPsec tunnel).
        
History of the MIB
 A precursor to this MIB was written by Tivoli and implemented 
 in IBM Nways routers in 1999. During late 1999, Cisco adopted
 the MIB and together with Tivoli publised the IPsec Flow
 Monitor MIB in IETF IPsec WG in 
 draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the
 MIB was Cisco-ized and implemented this draft as
 CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
        
 With the evolution of IKEv2, the MIB was modified and 
 presented to the IPsec WG again in May 2003 in
 draft-ietf-ipsec-flow-monitoring-mib-02.txt.
        
 With the emergence of multiple IPsec signaling protocols,
 it became apparent that the signaling aspects of IPsec
 need to be instrumented separately in their own right.
 Thus, the IPsec control attributes and metrics were 
 separated out into CISCO-IPSEC-SIGNALING-MIB and
 CISCO-IKE-FLOW-MIB.
        
 This version of the draft is the version of the draft
 that models that IPsec data protocol, structures and 
 activity alone.
        
Overview of MIB
        
 The MIB contains four major groups of objects which are
 used to manage the IPsec Protocol. These groups include
 a Levels Group, a Phase-1 Group, a Phase-2 Group,
 a History Group, a Failure Group and a TRAP Control Group.
 The following table illustrates the structure of the
 IPsec MIB.
        
 The Phase 2 group models objects pertaining to
 IPsec data tunnels.
        
 The History group is to aid applications that do
 trending analysis.
        
 The Failure group is to enable an operator to
 do troubleshooting and debugging of the VPN Router.
 Further, counters are supported to aid detection
 of potential security violations.
        
 In addition to the three major MIB Groups, there are
 a number of Notifications. The following table
 illustrates the name and description of the
 IPsec TRAPs.
    
Source file
CISCO-ENHANCED-IPSEC-FLOW-MIB
Last revised
Identity
ciscoEnhancedIpsecFlowMIB
Base OID
1.3.6.1.4.1.9.9.432
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhancedIpsecFlowMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhancedIpsecFlowMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (267)
.1.3.6.1.4.1.9.9.432
.1.3.6.1.4.1.9.9.432.0
.1.3.6.1.4.1.9.9.432.1
.1.3.6.1.4.1.9.9.432.1.1
.1.3.6.1.4.1.9.9.432.1.1.1
.1.3.6.1.4.1.9.9.432.1.1.1.1
.1.3.6.1.4.1.9.9.432.1.1.1.10
.1.3.6.1.4.1.9.9.432.1.1.1.11
.1.3.6.1.4.1.9.9.432.1.1.1.12
.1.3.6.1.4.1.9.9.432.1.1.1.13
.1.3.6.1.4.1.9.9.432.1.1.1.14
.1.3.6.1.4.1.9.9.432.1.1.1.15
.1.3.6.1.4.1.9.9.432.1.1.1.16
.1.3.6.1.4.1.9.9.432.1.1.1.17
.1.3.6.1.4.1.9.9.432.1.1.1.18
.1.3.6.1.4.1.9.9.432.1.1.1.19
.1.3.6.1.4.1.9.9.432.1.1.1.2
.1.3.6.1.4.1.9.9.432.1.1.1.20
.1.3.6.1.4.1.9.9.432.1.1.1.21
.1.3.6.1.4.1.9.9.432.1.1.1.22
.1.3.6.1.4.1.9.9.432.1.1.1.23
.1.3.6.1.4.1.9.9.432.1.1.1.24
.1.3.6.1.4.1.9.9.432.1.1.1.25
.1.3.6.1.4.1.9.9.432.1.1.1.26
.1.3.6.1.4.1.9.9.432.1.1.1.27
.1.3.6.1.4.1.9.9.432.1.1.1.28
.1.3.6.1.4.1.9.9.432.1.1.1.29
.1.3.6.1.4.1.9.9.432.1.1.1.3
.1.3.6.1.4.1.9.9.432.1.1.1.30
.1.3.6.1.4.1.9.9.432.1.1.1.31
.1.3.6.1.4.1.9.9.432.1.1.1.32
.1.3.6.1.4.1.9.9.432.1.1.1.33
.1.3.6.1.4.1.9.9.432.1.1.1.34
.1.3.6.1.4.1.9.9.432.1.1.1.35
.1.3.6.1.4.1.9.9.432.1.1.1.36
.1.3.6.1.4.1.9.9.432.1.1.1.4
.1.3.6.1.4.1.9.9.432.1.1.1.5
.1.3.6.1.4.1.9.9.432.1.1.1.6
.1.3.6.1.4.1.9.9.432.1.1.1.7
.1.3.6.1.4.1.9.9.432.1.1.1.8
.1.3.6.1.4.1.9.9.432.1.1.1.9
.1.3.6.1.4.1.9.9.432.1.1.2
.1.3.6.1.4.1.9.9.432.1.1.2.1
.1.3.6.1.4.1.9.9.432.1.1.2.1.1
.1.3.6.1.4.1.9.9.432.1.1.2.1.10
KBytesUnsigned32
.1.3.6.1.4.1.9.9.432.1.1.2.1.11
.1.3.6.1.4.1.9.9.432.1.1.2.1.12
.1.3.6.1.4.1.9.9.432.1.1.2.1.13
.1.3.6.1.4.1.9.9.432.1.1.2.1.14
.1.3.6.1.4.1.9.9.432.1.1.2.1.15
.1.3.6.1.4.1.9.9.432.1.1.2.1.16
.1.3.6.1.4.1.9.9.432.1.1.2.1.17
.1.3.6.1.4.1.9.9.432.1.1.2.1.18
.1.3.6.1.4.1.9.9.432.1.1.2.1.19
.1.3.6.1.4.1.9.9.432.1.1.2.1.2
.1.3.6.1.4.1.9.9.432.1.1.2.1.20
.1.3.6.1.4.1.9.9.432.1.1.2.1.21
.1.3.6.1.4.1.9.9.432.1.1.2.1.22
.1.3.6.1.4.1.9.9.432.1.1.2.1.23
.1.3.6.1.4.1.9.9.432.1.1.2.1.24
.1.3.6.1.4.1.9.9.432.1.1.2.1.25
.1.3.6.1.4.1.9.9.432.1.1.2.1.26
.1.3.6.1.4.1.9.9.432.1.1.2.1.27
.1.3.6.1.4.1.9.9.432.1.1.2.1.28
.1.3.6.1.4.1.9.9.432.1.1.2.1.29
.1.3.6.1.4.1.9.9.432.1.1.2.1.3
.1.3.6.1.4.1.9.9.432.1.1.2.1.30
.1.3.6.1.4.1.9.9.432.1.1.2.1.31
.1.3.6.1.4.1.9.9.432.1.1.2.1.32
.1.3.6.1.4.1.9.9.432.1.1.2.1.33
.1.3.6.1.4.1.9.9.432.1.1.2.1.34
.1.3.6.1.4.1.9.9.432.1.1.2.1.35
.1.3.6.1.4.1.9.9.432.1.1.2.1.36
.1.3.6.1.4.1.9.9.432.1.1.2.1.37
.1.3.6.1.4.1.9.9.432.1.1.2.1.38
.1.3.6.1.4.1.9.9.432.1.1.2.1.39
.1.3.6.1.4.1.9.9.432.1.1.2.1.4
.1.3.6.1.4.1.9.9.432.1.1.2.1.40
.1.3.6.1.4.1.9.9.432.1.1.2.1.41
.1.3.6.1.4.1.9.9.432.1.1.2.1.42
.1.3.6.1.4.1.9.9.432.1.1.2.1.43
.1.3.6.1.4.1.9.9.432.1.1.2.1.44
.1.3.6.1.4.1.9.9.432.1.1.2.1.45
.1.3.6.1.4.1.9.9.432.1.1.2.1.46
.1.3.6.1.4.1.9.9.432.1.1.2.1.47
.1.3.6.1.4.1.9.9.432.1.1.2.1.48
.1.3.6.1.4.1.9.9.432.1.1.2.1.49
.1.3.6.1.4.1.9.9.432.1.1.2.1.5
.1.3.6.1.4.1.9.9.432.1.1.2.1.50
.1.3.6.1.4.1.9.9.432.1.1.2.1.51
.1.3.6.1.4.1.9.9.432.1.1.2.1.52
.1.3.6.1.4.1.9.9.432.1.1.2.1.53
.1.3.6.1.4.1.9.9.432.1.1.2.1.54
.1.3.6.1.4.1.9.9.432.1.1.2.1.6
.1.3.6.1.4.1.9.9.432.1.1.2.1.7
.1.3.6.1.4.1.9.9.432.1.1.2.1.8
.1.3.6.1.4.1.9.9.432.1.1.2.1.9
.1.3.6.1.4.1.9.9.432.1.1.3
.1.3.6.1.4.1.9.9.432.1.1.3.1
Unsigned32
.1.3.6.1.4.1.9.9.432.1.1.3.1.1
.1.3.6.1.4.1.9.9.432.1.1.3.1.10
.1.3.6.1.4.1.9.9.432.1.1.3.1.11
.1.3.6.1.4.1.9.9.432.1.1.3.1.12
.1.3.6.1.4.1.9.9.432.1.1.3.1.13
.1.3.6.1.4.1.9.9.432.1.1.3.1.14
.1.3.6.1.4.1.9.9.432.1.1.3.1.15
.1.3.6.1.4.1.9.9.432.1.1.3.1.16
.1.3.6.1.4.1.9.9.432.1.1.3.1.17
.1.3.6.1.4.1.9.9.432.1.1.3.1.2
.1.3.6.1.4.1.9.9.432.1.1.3.1.3
.1.3.6.1.4.1.9.9.432.1.1.3.1.4
.1.3.6.1.4.1.9.9.432.1.1.3.1.5
.1.3.6.1.4.1.9.9.432.1.1.3.1.6
.1.3.6.1.4.1.9.9.432.1.1.3.1.7
.1.3.6.1.4.1.9.9.432.1.1.3.1.8
.1.3.6.1.4.1.9.9.432.1.1.3.1.9
.1.3.6.1.4.1.9.9.432.1.1.4
.1.3.6.1.4.1.9.9.432.1.1.4.1
.1.3.6.1.4.1.9.9.432.1.1.4.1.1
Unsigned32
.1.3.6.1.4.1.9.9.432.1.1.4.1.2
.1.3.6.1.4.1.9.9.432.1.1.4.1.3
.1.3.6.1.4.1.9.9.432.1.1.4.1.4
Enumeration
.1.3.6.1.4.1.9.9.432.1.1.4.1.5
.1.3.6.1.4.1.9.9.432.1.1.5
.1.3.6.1.4.1.9.9.432.1.1.5.1
.1.3.6.1.4.1.9.9.432.1.1.5.1.1
.1.3.6.1.4.1.9.9.432.1.1.5.1.10
.1.3.6.1.4.1.9.9.432.1.1.5.1.11
.1.3.6.1.4.1.9.9.432.1.1.5.1.12
.1.3.6.1.4.1.9.9.432.1.1.5.1.13
.1.3.6.1.4.1.9.9.432.1.1.5.1.14
.1.3.6.1.4.1.9.9.432.1.1.5.1.15
.1.3.6.1.4.1.9.9.432.1.1.5.1.16
.1.3.6.1.4.1.9.9.432.1.1.5.1.17
.1.3.6.1.4.1.9.9.432.1.1.5.1.18
.1.3.6.1.4.1.9.9.432.1.1.5.1.19
Unsigned32
.1.3.6.1.4.1.9.9.432.1.1.5.1.2
.1.3.6.1.4.1.9.9.432.1.1.5.1.20
.1.3.6.1.4.1.9.9.432.1.1.5.1.21
.1.3.6.1.4.1.9.9.432.1.1.5.1.22
.1.3.6.1.4.1.9.9.432.1.1.5.1.23
.1.3.6.1.4.1.9.9.432.1.1.5.1.24
.1.3.6.1.4.1.9.9.432.1.1.5.1.25
.1.3.6.1.4.1.9.9.432.1.1.5.1.26
Enumeration
.1.3.6.1.4.1.9.9.432.1.1.5.1.27
.1.3.6.1.4.1.9.9.432.1.1.5.1.3
.1.3.6.1.4.1.9.9.432.1.1.5.1.4
.1.3.6.1.4.1.9.9.432.1.1.5.1.5
.1.3.6.1.4.1.9.9.432.1.1.5.1.6
.1.3.6.1.4.1.9.9.432.1.1.5.1.7
.1.3.6.1.4.1.9.9.432.1.1.5.1.8
.1.3.6.1.4.1.9.9.432.1.1.5.1.9
.1.3.6.1.4.1.9.9.432.1.1.6
.1.3.6.1.4.1.9.9.432.1.1.6.1
.1.3.6.1.4.1.9.9.432.1.1.6.1.1
.1.3.6.1.4.1.9.9.432.1.2
.1.3.6.1.4.1.9.9.432.1.2.1
.1.3.6.1.4.1.9.9.432.1.2.1.1
.1.3.6.1.4.1.9.9.432.1.2.1.1.1
.1.3.6.1.4.1.9.9.432.1.2.2
.1.3.6.1.4.1.9.9.432.1.2.2.1
Unsigned32
.1.3.6.1.4.1.9.9.432.1.2.2.1.1
.1.3.6.1.4.1.9.9.432.1.2.2.1.10
.1.3.6.1.4.1.9.9.432.1.2.2.1.11
KBytesUnsigned32
.1.3.6.1.4.1.9.9.432.1.2.2.1.12
SecondsUnsigned32
.1.3.6.1.4.1.9.9.432.1.2.2.1.13
.1.3.6.1.4.1.9.9.432.1.2.2.1.14
.1.3.6.1.4.1.9.9.432.1.2.2.1.15
.1.3.6.1.4.1.9.9.432.1.2.2.1.16
.1.3.6.1.4.1.9.9.432.1.2.2.1.17
.1.3.6.1.4.1.9.9.432.1.2.2.1.18
.1.3.6.1.4.1.9.9.432.1.2.2.1.19
Enumeration
.1.3.6.1.4.1.9.9.432.1.2.2.1.2
.1.3.6.1.4.1.9.9.432.1.2.2.1.20
.1.3.6.1.4.1.9.9.432.1.2.2.1.21
.1.3.6.1.4.1.9.9.432.1.2.2.1.22
.1.3.6.1.4.1.9.9.432.1.2.2.1.23
.1.3.6.1.4.1.9.9.432.1.2.2.1.24
.1.3.6.1.4.1.9.9.432.1.2.2.1.25
.1.3.6.1.4.1.9.9.432.1.2.2.1.26
.1.3.6.1.4.1.9.9.432.1.2.2.1.27
.1.3.6.1.4.1.9.9.432.1.2.2.1.28
.1.3.6.1.4.1.9.9.432.1.2.2.1.29
.1.3.6.1.4.1.9.9.432.1.2.2.1.3
.1.3.6.1.4.1.9.9.432.1.2.2.1.30
.1.3.6.1.4.1.9.9.432.1.2.2.1.31
.1.3.6.1.4.1.9.9.432.1.2.2.1.32
.1.3.6.1.4.1.9.9.432.1.2.2.1.33
.1.3.6.1.4.1.9.9.432.1.2.2.1.34
.1.3.6.1.4.1.9.9.432.1.2.2.1.35
.1.3.6.1.4.1.9.9.432.1.2.2.1.36
.1.3.6.1.4.1.9.9.432.1.2.2.1.37
.1.3.6.1.4.1.9.9.432.1.2.2.1.38
.1.3.6.1.4.1.9.9.432.1.2.2.1.39
.1.3.6.1.4.1.9.9.432.1.2.2.1.4
.1.3.6.1.4.1.9.9.432.1.2.2.1.40
.1.3.6.1.4.1.9.9.432.1.2.2.1.41
.1.3.6.1.4.1.9.9.432.1.2.2.1.42
.1.3.6.1.4.1.9.9.432.1.2.2.1.43
.1.3.6.1.4.1.9.9.432.1.2.2.1.44
.1.3.6.1.4.1.9.9.432.1.2.2.1.45
.1.3.6.1.4.1.9.9.432.1.2.2.1.46
.1.3.6.1.4.1.9.9.432.1.2.2.1.47
.1.3.6.1.4.1.9.9.432.1.2.2.1.48
.1.3.6.1.4.1.9.9.432.1.2.2.1.49
.1.3.6.1.4.1.9.9.432.1.2.2.1.5
.1.3.6.1.4.1.9.9.432.1.2.2.1.50
.1.3.6.1.4.1.9.9.432.1.2.2.1.51
.1.3.6.1.4.1.9.9.432.1.2.2.1.6
.1.3.6.1.4.1.9.9.432.1.2.2.1.7
.1.3.6.1.4.1.9.9.432.1.2.2.1.8
.1.3.6.1.4.1.9.9.432.1.2.2.1.9
.1.3.6.1.4.1.9.9.432.1.2.3
.1.3.6.1.4.1.9.9.432.1.2.3.1
Unsigned32
.1.3.6.1.4.1.9.9.432.1.2.3.1.1
.1.3.6.1.4.1.9.9.432.1.2.3.1.10
.1.3.6.1.4.1.9.9.432.1.2.3.1.11
.1.3.6.1.4.1.9.9.432.1.2.3.1.12
.1.3.6.1.4.1.9.9.432.1.2.3.1.13
.1.3.6.1.4.1.9.9.432.1.2.3.1.14
.1.3.6.1.4.1.9.9.432.1.2.3.1.15
.1.3.6.1.4.1.9.9.432.1.2.3.1.16
.1.3.6.1.4.1.9.9.432.1.2.3.1.17
.1.3.6.1.4.1.9.9.432.1.2.3.1.18
.1.3.6.1.4.1.9.9.432.1.2.3.1.19
Unsigned32
.1.3.6.1.4.1.9.9.432.1.2.3.1.2
Unsigned32
.1.3.6.1.4.1.9.9.432.1.2.3.1.3
.1.3.6.1.4.1.9.9.432.1.2.3.1.4
.1.3.6.1.4.1.9.9.432.1.2.3.1.5
.1.3.6.1.4.1.9.9.432.1.2.3.1.6
.1.3.6.1.4.1.9.9.432.1.2.3.1.7
.1.3.6.1.4.1.9.9.432.1.2.3.1.8
.1.3.6.1.4.1.9.9.432.1.2.3.1.9
.1.3.6.1.4.1.9.9.432.1.3
.1.3.6.1.4.1.9.9.432.1.3.1
.1.3.6.1.4.1.9.9.432.1.3.1.1
.1.3.6.1.4.1.9.9.432.1.3.1.1.1
.1.3.6.1.4.1.9.9.432.1.3.2
.1.3.6.1.4.1.9.9.432.1.3.2.1
Unsigned32
.1.3.6.1.4.1.9.9.432.1.3.2.1.1
Enumeration
.1.3.6.1.4.1.9.9.432.1.3.2.1.2
.1.3.6.1.4.1.9.9.432.1.3.2.1.3
.1.3.6.1.4.1.9.9.432.1.3.2.1.4
.1.3.6.1.4.1.9.9.432.1.3.2.1.5
.1.3.6.1.4.1.9.9.432.1.3.2.1.6
.1.3.6.1.4.1.9.9.432.1.3.2.1.7
.1.3.6.1.4.1.9.9.432.1.3.2.1.8
.1.3.6.1.4.1.9.9.432.1.3.2.1.9
.1.3.6.1.4.1.9.9.432.1.5
.1.3.6.1.4.1.9.9.432.1.5.1
.1.3.6.1.4.1.9.9.432.1.5.2
.1.3.6.1.4.1.9.9.432.1.5.3
.1.3.6.1.4.1.9.9.432.1.5.4
.1.3.6.1.4.1.9.9.432.1.5.5
.1.3.6.1.4.1.9.9.432.1.5.6
.1.3.6.1.4.1.9.9.432.1.5.7
.1.3.6.1.4.1.9.9.432.1.5.8
.1.3.6.1.4.1.9.9.432.1.6
.1.3.6.1.4.1.9.9.432.1.6.1
.1.3.6.1.4.1.9.9.432.1.6.2
.1.3.6.1.4.1.9.9.432.1.6.3
.1.3.6.1.4.1.9.9.432.1.6.4
Enumeration
.1.3.6.1.4.1.9.9.432.1.6.5
Enumeration
.1.3.6.1.4.1.9.9.432.1.6.6
.1.3.6.1.4.1.9.9.432.2
.1.3.6.1.4.1.9.9.432.2.1
.1.3.6.1.4.1.9.9.432.2.2
Dependencies (11) 9 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Conformance Groups (12)
ceipSecGlobalActiveTunnels ceipSecGlobalPreviousTunnels ceipSecGlobalInOctets ceipSecGlobalInDecompOctets ceipSecGlobalInPkts ceipSecGlobalInDrops ceipSecGlobalInReplayDrops ceipSecGlobalInAuths ceipSecGlobalInAuthFails ceipSecGlobalInDecrypts ceipSecGlobalInDecryptFails ceipSecGlobalOutOctets ceipSecGlobalOutUncompOctets ceipSecGlobalOutPkts ceipSecGlobalOutDrops ceipSecGlobalOutAuths ceipSecGlobalOutAuthFails ceipSecGlobalOutEncrypts ceipSecGlobalOutEncryptFails ceipSecGlobalProtocolUseFails ceipSecGlobalNoSaFails ceipSecGlobalSysCapFails ceipSecGlobalOutCompressedPkts ceipSecGlobalOutCompSkippedPkts ceipSecGlobalOutCompFailPkts ceipSecGlobalOutCompTooSmallPkts ceipSecTunEncapMode ceipSecTunLifeSize ceipSecTunLifeTime ceipSecTunActiveTime ceipSecTunSaLifeSizeThreshold ceipSecTunSaLifeTimeThreshold ceipSecTunTotalRefreshes ceipSecTunExpiredSaInstances ceipSecTunCurrentSaInstances ceipSecTunInSaDHGrp ceipSecTunInSaEncryptAlgo ceipSecTunInSaAhAuthAlgo ceipSecTunInSaEspAuthAlgo ceipSecTunInSaDecompAlgo ceipSecTunOutSaDHGrp ceipSecTunOutSaEncryptAlgo ceipSecTunOutSaAhAuthAlgo ceipSecTunOutSaEspAuthAlgo ceipSecTunOutSaCompAlgo ceipSecTunPmtu ceipSecTunInOctets ceipSecTunInDecompOctets ceipSecTunInPkts ceipSecTunInDropPkts ceipSecTunInReplayDropPkts ceipSecTunInAuths ceipSecTunInAuthFails ceipSecTunInDecrypts ceipSecTunInDecryptFails ceipSecTunOutOctets ceipSecTunOutUncompOctets ceipSecTunOutPkts ceipSecTunOutDropPkts ceipSecTunOutAuths ceipSecTunOutAuthFails ceipSecTunOutEncrypts ceipSecTunOutEncryptFails ceipSecTunOutCompressedPkts ceipSecTunOutCompSkippedPkts ceipSecTunOutCompFailPkts ceipSecTunOutCompTooSmallPkts ceipSecIfIndex ceipSecTunStatus ceipSecTunControlTunnelIndex ceipSecTunControlProtocol ceipSecTunControlTunnelAlive ceipSecTunInSaEncryptKeySize ceipSecTunOutSaEncryptKeySize ceipSecTunLocalAddressType ceipSecTunLocalAddress ceipSecTunRemoteAddressType ceipSecTunRemoteAddress ceipSecTunNATTraversalMode ceipSecEndPtLocalName ceipSecEndPtLocalType ceipSecEndPtLocalAddrType1 ceipSecEndPtLocalAddr1 ceipSecEndPtLocalAddrType2 ceipSecEndPtLocalAddr2 ceipSecEndPtLocalProtocol ceipSecEndPtLocalPort ceipSecEndPtRemoteName ceipSecEndPtRemoteType ceipSecEndPtRemoteAddrType1 ceipSecEndPtRemoteAddr1 ceipSecEndPtRemoteAddrType2 ceipSecEndPtRemoteAddr2 ceipSecEndPtRemoteProtocol ceipSecEndPtRemotePort ceipSecSaDirection ceipSecSaValue ceipSecSaStatus
This group consists of:
1) IPsec Phase-2 Global Statistics
2) IPsec Phase-2 Tunnel Table
3) IPsec Phase-2 Endpoint Table
4) IPsec Phase-2 Security Association Table
.1.3.6.1.4.1.9.9.432.2.2.1
This group consists of the core (mandatory)
objects pertaining to maintaining history of
IPsec activity.
.1.3.6.1.4.1.9.9.432.2.2.2
ceipSecTunHistTermReason ceipSecTunHistActiveIndex ceipSecTunHistEncapMode ceipSecTunHistLifeSize ceipSecTunHistLifeTime ceipSecTunHistStartTime ceipSecTunHistActiveTime ceipSecTunHistTotalRefreshes ceipSecTunHistTotalSas ceipSecTunHistInSaDHGrp ceipSecTunHistInSaEncryptAlgo ceipSecTunHistInSaAhAuthAlgo ceipSecTunHistInSaEspAuthAlgo ceipSecTunHistInSaDecompAlgo ceipSecTunHistOutSaDHGrp ceipSecTunHistOutSaEncryptAlgo ceipSecTunHistOutSaAhAuthAlgo ceipSecTunHistOutSaEspAuthAlgo ceipSecTunHistOutSaCompAlgo ceipSecTunHistPmtu ceipSecTunHistInOctets ceipSecTunHistInDecompOctets ceipSecTunHistInPkts ceipSecTunHistInDropPkts ceipSecTunHistInReplayDropPkts ceipSecTunHistInAuths ceipSecTunHistInAuthFails ceipSecTunHistInDecrypts ceipSecTunHistInDecryptFails ceipSecTunHistOutOctets ceipSecTunHistOutUncompOctets ceipSecTunHistOutPkts ceipSecTunHistOutDropPkts ceipSecTunHistOutAuths ceipSecTunHistOutAuthFails ceipSecTunHistOutEncrypts ceipSecTunHistOutEncryptFails ceipSecTunHistOutCompressedPkts ceipSecTunHistOutCompSkippedPkts ceipSecTunHistOutCompFailPkts ceipSecTunHistOutCompSmallPkts ceipSecTunHistControlProtocol ceipSecTunHistControlTunnelIndex ceipSecTunHistInSaEncryptKeySize ceipSecTunHistOutSaEncryptKeySz ceipSecTunHistLocalAddressType ceipSecTunHistLocalAddress ceipSecTunHistRemoteAddressType ceipSecTunHistRemoteAddress ceipSecTunHistNATTraversalMode ceipSecEndPtHistTunIndex ceipSecEndPtHistActiveIndex ceipSecEndPtHistLocalName ceipSecEndPtHistLocalType ceipSecEndPtHistLocalAddrType1 ceipSecEndPtHistLocalAddr1 ceipSecEndPtHistLocalAddrType2 ceipSecEndPtHistLocalAddr2 ceipSecEndPtHistLocalProtocol ceipSecEndPtHistLocalPort ceipSecEndPtHistRemoteName ceipSecEndPtHistRemoteType ceipSecEndPtHistRemoteAddrType1 ceipSecEndPtHistRemoteAddr1 ceipSecEndPtHistRemoteAddrType2 ceipSecEndPtHistRemoteAddr2 ceipSecEndPtHistRemoteProtocol ceipSecEndPtHistRemotePort
This group consists of objects that pertain
to maintenance of history of IPsec Phase 2
activity.
.1.3.6.1.4.1.9.9.432.2.2.3
This group consists of the core (mandatory)
objects pertaining to maintaining history of
failure IPsec activity.
.1.3.6.1.4.1.9.9.432.2.2.4
This group consists of objects that pertain
to maintenance of history of failures
associated with Phase 2 IPsec activity.
.1.3.6.1.4.1.9.9.432.2.2.5
This group of objects controls the sending
of notifications pertaining to IPsec Phase-2
processing.
.1.3.6.1.4.1.9.9.432.2.2.6
This group contains the notifications pertaining
to Phase-2 operations and data transfer.
.1.3.6.1.4.1.9.9.432.2.2.7
This group consists of the Phase-2 IPsec tunnel
Security Association and traffic information.
.1.3.6.1.4.1.9.9.432.2.2.8
This supplement group of objects controls the sending of X.509
certificate IPSec notifications.
.1.3.6.1.4.1.9.9.432.2.2.9
This supplement group contains the X.509 certificate
notifications for the IPSec MIB.
.1.3.6.1.4.1.9.9.432.2.2.10
This group consists of objects to support X.509 certificates.
.1.3.6.1.4.1.9.9.432.2.2.11
This group consists of objects to show the the performance
utilization.
.1.3.6.1.4.1.9.9.432.2.2.12
Compliance Statements (3)

OID .1.3.6.1.4.1.9.9.432.2.1.1
The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
Required groups
mandatory ciscoEnhIPsecFlowActivityGroup
mandatory ciscoEnhIPsecFlowCoreHistGroup
mandatory ciscoEnhIPsecFlowCoreFailGroup
mandatory ciscoEnhIPsecFlowTunnelSaGroup
optional ciscoEnhIPsecFlowHistoryGroup This group is optional and must be implemented
by the agent of the managed entity if the managed
entity implements historical archiving of IPsec
flows.
optional ciscoEnhIPsecFlowFailureGroup This group is optional and must be implemented
by the agent of the managed entity if the
managed entity implements historical archiving
of failure of IPsec Phase-2 operations and tunnels.
optional ciscoEnhIPsecFlowNotifGroup The group is optional.
optional ciscoEnhIPsecFlowNotifCntlGroup The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroup'.
Object refinements
ObjectAccessSyntaxDescription
ceipSecTunStatus readonly
Write access is not required.
ceipSecHistTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of tunnels may set the value of this object to
zero.
ceipSecFailTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of failures may set the value of this object to
zero.
ceipSecNotiCntlIpSecAllNotifs readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStart readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStop readonly
Write access is not required.
ceipSecNotifCntlIpSecSysFailure readonly
Write access is not required.
ceipSecNotifCntlIpSecSetUpFail readonly
Write access is not required.
ceipSecNotifCntlIpSecBadSa readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.432.2.1.2
The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
Required groups
mandatory ciscoEnhIPsecFlowActivityGroup
mandatory ciscoEnhIPsecFlowCoreHistGroup
mandatory ciscoEnhIPsecFlowCoreFailGroup
mandatory ciscoEnhIPsecFlowTunnelSaGroup
optional ciscoEnhIPsecFlowHistoryGroup This group is optional and must be implemented
by the agent of the managed entity if the managed
entity implements historical archiving of IPsec
flows.
optional ciscoEnhIPsecFlowFailureGroup This group is optional and must be implemented
by the agent of the managed entity if the
managed entity implements historical archiving
of failure of IPsec Phase-2 operations and tunnels.
optional ciscoEnhIPsecFlowNotifGroup The group is optional.
optional ciscoEnhIPsecFlowNotifCntlGroup The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroup'.
optional ciscoEnhIPsecFlowNotifGroupSup01 This group is optional.
optional ciscoEnhIPsecFlowNotifCntlGroupSup01 The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroupSup01'.
optional ciscoEnhIPsecFlowCertObjectGroup The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroupSup01'.
Object refinements
ObjectAccessSyntaxDescription
ceipSecTunStatus readonly
Write access is not required.
ceipSecHistTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of tunnels may set the value of this object to
zero.
ceipSecFailTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of failures may set the value of this object to
zero.
ceipSecNotiCntlIpSecAllNotifs readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStart readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStop readonly
Write access is not required.
ceipSecNotifCntlIpSecSysFailure readonly
Write access is not required.
ceipSecNotifCntlIpSecSetUpFail readonly
Write access is not required.
ceipSecNotifCntlIpSecBadSa readonly
Write access is not required.

OID .1.3.6.1.4.1.9.9.432.2.1.3
The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
Required groups
mandatory ciscoEnhIPsecFlowActivityGroup
mandatory ciscoEnhIPsecFlowCoreHistGroup
mandatory ciscoEnhIPsecFlowCoreFailGroup
mandatory ciscoEnhIPsecFlowTunnelSaGroup
optional ciscoEnhIPsecFlowHistoryGroup This group is optional and must be implemented
by the agent of the managed entity if the managed
entity implements historical archiving of IPsec
flows.
optional ciscoEnhIPsecFlowFailureGroup This group is optional and must be implemented
by the agent of the managed entity if the
managed entity implements historical archiving
of failure of IPsec Phase-2 operations and tunnels.
optional ciscoEnhIPsecFlowNotifGroup The group is optional.
optional ciscoEnhIPsecFlowNotifCntlGroup The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroup'.
optional ciscoEnhIPsecFlowNotifGroupSup01 This group is optional.
optional ciscoEnhIPsecFlowNotifCntlGroupSup01 The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroupSup01'.
optional ciscoEnhIPsecFlowCertObjectGroup The agent must implement this group if it implements
the group 'ciscoEnhIPsecFlowNotifGroupSup01'.
optional ciscoEnhIPsecFlowPerformanceThroughputGroup This group is optional.
Object refinements
ObjectAccessSyntaxDescription
ceipSecTunStatus readonly
Write access is not required.
ceipSecHistTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of tunnels may set the value of this object to
zero.
ceipSecFailTableSize readonly
Write access is not required. In addition,
implementations which want to disable archiving
of failures may set the value of this object to
zero.
ceipSecNotiCntlIpSecAllNotifs readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStart readonly
Write access is not required.
ceipSecNotifCntlIpSecTunnelStop readonly
Write access is not required.
ceipSecNotifCntlIpSecSysFailure readonly
Write access is not required.
ceipSecNotifCntlIpSecSetUpFail readonly
Write access is not required.
ceipSecNotifCntlIpSecBadSa readonly
Write access is not required.
Notifications / Traps (7)
NameOIDDescription
.1.3.6.1.4.1.9.9.432.0.1
This notification is generated when an IPsec Phase-2
Tunnel becomes active.
.1.3.6.1.4.1.9.9.432.0.2
This notification is generated when an IPsec Phase-2
Tunnel becomes inactive.
.1.3.6.1.4.1.9.9.432.0.3
This notification is generated when the processing
for an IPsec Phase-2 Tunnel experiences an internal
or system capacity error.
.1.3.6.1.4.1.9.9.432.0.4
This notification is generated when the setup for
an IPsec Phase-2 Tunnel fails.
.1.3.6.1.4.1.9.9.432.0.5
This notification is generated when the managed
entity receives an IPsec packet with a non-existent
(non-existant in the local Security Association
Database) SPI.
.1.3.6.1.4.1.9.9.432.0.6
This notification is generated to notify that an X.509
certificate is going to expire. The notification is triggered
the time threshold configured on the application for
notification before the certificate is going to expire, which
is when the value of ceipSecCertExpiryStatus is changed from
certOK(1) to certGoingExpired(2). The user should take action
to renew the certificate identified in the notification prior
to the certificate expiration, which is at the validity
notAfter time provided in the notification.
.1.3.6.1.4.1.9.9.432.0.7
This notification is generated to report a status transition
for an X.509 certificate renewal performed by the application.
The notification is generated when the value of
ceipSecCertRenewalStatus is changed from
1. renewalNotNeeded(1) to renewalRequestNeeded(2) or
renewalRequested(3)
2. renewalRequestNeeded(2) to renewalRequested(3)
3. renewalRequested(3) to renewalSuccess(4) or
renewalFailedUpdate(5) or renewalFailedExpired(6)
4. renewalFailedUpdate(5) to renewalFailedExpired(6)