CISCO-ENHANCED-IPSEC-FLOW-MIB
This is a MIB Module for monitoring the structures
and status of IPSec-based networks. The MIB has been
designed to be adopted as an IETF standard. Hence
vendor-specific features of IPSec protocol are excluded
from this MIB.
Acronyms
The following acronyms are used in this document:
IPsec: Secure IP Protocol
VPN: Virtual Private Network
ISAKMP: Internet Security Association and Key Exchange
Protocol
IKE: Internet Key Exchange Protocol
SA: Security Association
(ref: rfc2408).
SPI: Security Parameter Index is the pointer or
identifier used in accessing SA attributes
(ref: rfc2408).
MM: Main Mode - the process of setting up
a Phase 1 SA to secure the exchanges
required to setup Phase 2 SAs
QM: Quick Mode - the process of setting up
Phase 2 Security Associations using
a Phase 1 SA.
Phase 1 Tunnel:
An ISAKMP SA can be regarded as representing
a flow of ISAKMP/IKE traffic. Hence an ISAKMP
is referred to as a 'Phase 1 Tunnel' in this
document.
Control Tunnel:
Another term for a Phase 1 Tunnel.
Phase 2 Tunnel:
An instance of a non-ISAKMP SA bundle in which all
the SA share the same proxy identifiers (IDii,IDir)
protect the same stream of application traffic.
Such an SA bundle is termed a 'Phase 2 Tunnel'.
Note that a Phase 2 tunnel may comprise different
SA bundles and different number of SA bundles at
different times (due to key refresh).
MTU:
Maximum Transmission Unit (of an IPsec tunnel).
History of the MIB
A precursor to this MIB was written by Tivoli and implemented
in IBM Nways routers in 1999. During late 1999, Cisco adopted
the MIB and together with Tivoli publised the IPsec Flow
Monitor MIB in IETF IPsec WG in
draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the
MIB was Cisco-ized and implemented this draft as
CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified and
presented to the IPsec WG again in May 2003 in
draft-ietf-ipsec-flow-monitoring-mib-02.txt.
With the emergence of multiple IPsec signaling protocols,
it became apparent that the signaling aspects of IPsec
need to be instrumented separately in their own right.
Thus, the IPsec control attributes and metrics were
separated out into CISCO-IPSEC-SIGNALING-MIB and
CISCO-IKE-FLOW-MIB.
This version of the draft is the version of the draft
that models that IPsec data protocol, structures and
activity alone.
Overview of MIB
The MIB contains four major groups of objects which are
used to manage the IPsec Protocol. These groups include
a Levels Group, a Phase-1 Group, a Phase-2 Group,
a History Group, a Failure Group and a TRAP Control Group.
The following table illustrates the structure of the
IPsec MIB.
The Phase 2 group models objects pertaining to
IPsec data tunnels.
The History group is to aid applications that do
trending analysis.
The Failure group is to enable an operator to
do troubleshooting and debugging of the VPN Router.
Further, counters are supported to aid detection
of potential security violations.
In addition to the three major MIB Groups, there are
a number of Notifications. The following table
illustrates the name and description of the
IPsec TRAPs.
- Source file
CISCO-ENHANCED-IPSEC-FLOW-MIB- Last revised
- Identity
ciscoEnhancedIpsecFlowMIB- Base OID
1.3.6.1.4.1.9.9.432
Imported Objects
| CISCO-IPSEC-TC | CIPsecAuthAlgorithm CIPsecCompAlgorithm CIPsecControlProtocol CIPsecDiffHellmanGrp CIPsecEncapMode CIPsecEncryptAlgorithm CIPsecEncryptionKeySize CIPsecEndPtType CIPsecNATTraversalMode CIPsecPhase1TunnelIndexOrZero CIPsecPhase2SaDirection CIPsecPhase2TunnelIndex CIPsecPmtu CIPsecProtocol CIPsecSpi CIPsecTunnelStatus |
| CISCO-SMI | ciscoMgmt |
| CISCO-TC | CiscoIpProtocol CiscoPort |
| IF-MIB | ifIndex InterfaceIndex |
| INET-ADDRESS-MIB | InetAddress InetAddressType |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Counter64 Gauge32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | DateAndTime TimeInterval TimeStamp TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhancedIpsecFlowMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhancedIpsecFlowMIB'
Objects (267)
Showing 267 of 267 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.432 |
||
.1.3.6.1.4.1.9.9.432.0 |
||
.1.3.6.1.4.1.9.9.432.1 |
||
.1.3.6.1.4.1.9.9.432.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.1 |
||
|
TunnelsSNMPv2-SMIGauge32
|
.1.3.6.1.4.1.9.9.432.1.1.1.1 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.10 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.11 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.12 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.13 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.14 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.15 |
|
|
EventsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.16 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.17 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.18 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.19 |
|
|
TunnelsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.2 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.20 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.21 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.22 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.23 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.24 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.25 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.26 |
|
|
SecondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.1.27 |
|
.1.3.6.1.4.1.9.9.432.1.1.1.28 |
||
|
bytesSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.1.29 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.3 |
|
.1.3.6.1.4.1.9.9.432.1.1.1.30 |
||
.1.3.6.1.4.1.9.9.432.1.1.1.31 |
||
|
PercentSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.1.32 |
|
|
PercentSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.1.33 |
|
.1.3.6.1.4.1.9.9.432.1.1.1.34 |
||
.1.3.6.1.4.1.9.9.432.1.1.1.35 |
||
|
bytesSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.1.36 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.4 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.5 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.6 |
|
|
PacketsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.7 |
|
|
EventsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.8 |
|
|
FailuresSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.1.9 |
|
.1.3.6.1.4.1.9.9.432.1.1.2 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.10 |
||
|
KBytesUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.11 |
|
|
SecondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.12 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.13 |
||
|
KBytesSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.14 |
|
|
SecondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.15 |
|
|
QM ExchangesSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.16 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.17 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.18 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.19 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.2 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.20 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.21 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.22 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.23 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.24 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.25 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.26 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.27 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.28 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.29 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.30 |
||
|
OctetsCISCO-IPSEC-TCCIPsecPmtu
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.31 |
|
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.32 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.33 |
||
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.34 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.35 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.36 |
|
|
EventsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.37 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.38 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.39 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.4 |
||
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.40 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.41 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.42 |
||
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.43 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.44 |
|
|
EventsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.45 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.46 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.47 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.48 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.49 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.5 |
||
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.50 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.51 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.52 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.53 |
||
|
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.54 |
|
.1.3.6.1.4.1.9.9.432.1.1.2.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.1.2.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.3.1.1 |
|
.1.3.6.1.4.1.9.9.432.1.1.3.1.10 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.11 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.12 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.13 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.14 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.15 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.16 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.17 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.2 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.1.3.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.1.4.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.4.1.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.4.1.2 |
|
.1.3.6.1.4.1.9.9.432.1.1.4.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.1.4.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.1.4.1.5 |
|
.1.3.6.1.4.1.9.9.432.1.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.10 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.11 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.12 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.13 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.14 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.15 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.16 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.17 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.18 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.19 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.1.5.1.2 |
|
.1.3.6.1.4.1.9.9.432.1.1.5.1.20 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.21 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.22 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.23 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.24 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.25 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.26 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.1.5.1.27 |
|
.1.3.6.1.4.1.9.9.432.1.1.5.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.1.5.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.1.6.1 |
||
.1.3.6.1.4.1.9.9.432.1.1.6.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.2 |
||
.1.3.6.1.4.1.9.9.432.1.2.1 |
||
.1.3.6.1.4.1.9.9.432.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.2.1.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.2.2 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.1 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.10 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.11 |
||
|
KBytesUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.12 |
|
|
SecondsUnsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.13 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.14 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.15 |
||
|
QM ExchangesSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.16 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.17 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.18 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.19 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.2 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.20 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.21 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.22 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.23 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.24 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.25 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.26 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.27 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.28 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.29 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.3 |
||
|
OctetsCISCO-IPSEC-TCCIPsecPmtu
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.30 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.31 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.32 |
||
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.33 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.34 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.35 |
|
|
EventsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.36 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.37 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.38 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.39 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.40 |
||
|
OctetsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.41 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.42 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.43 |
|
|
EventsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.44 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.45 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.46 |
|
|
FailuresSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.47 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.48 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.49 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.5 |
||
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.50 |
|
|
PacketsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.51 |
|
.1.3.6.1.4.1.9.9.432.1.2.2.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.2.2.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.2.3 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.3.1.1 |
|
.1.3.6.1.4.1.9.9.432.1.2.3.1.10 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.11 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.12 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.13 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.14 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.15 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.16 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.17 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.18 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.19 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.3.1.2 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.2.3.1.3 |
|
.1.3.6.1.4.1.9.9.432.1.2.3.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.2.3.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.3.1 |
||
.1.3.6.1.4.1.9.9.432.1.3.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.3.1.1.1 |
||
.1.3.6.1.4.1.9.9.432.1.3.2 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.432.1.3.2.1.1 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.3.2.1.2 |
|
.1.3.6.1.4.1.9.9.432.1.3.2.1.3 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.4 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.7 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.8 |
||
.1.3.6.1.4.1.9.9.432.1.3.2.1.9 |
||
.1.3.6.1.4.1.9.9.432.1.5 |
||
.1.3.6.1.4.1.9.9.432.1.5.1 |
||
.1.3.6.1.4.1.9.9.432.1.5.2 |
||
.1.3.6.1.4.1.9.9.432.1.5.3 |
||
.1.3.6.1.4.1.9.9.432.1.5.4 |
||
.1.3.6.1.4.1.9.9.432.1.5.5 |
||
.1.3.6.1.4.1.9.9.432.1.5.6 |
||
.1.3.6.1.4.1.9.9.432.1.5.7 |
||
.1.3.6.1.4.1.9.9.432.1.5.8 |
||
.1.3.6.1.4.1.9.9.432.1.6 |
||
.1.3.6.1.4.1.9.9.432.1.6.1 |
||
.1.3.6.1.4.1.9.9.432.1.6.2 |
||
.1.3.6.1.4.1.9.9.432.1.6.3 |
||
.1.3.6.1.4.1.9.9.432.1.6.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.6.5 |
|
|
Enumeration
|
.1.3.6.1.4.1.9.9.432.1.6.6 |
|
.1.3.6.1.4.1.9.9.432.2 |
||
.1.3.6.1.4.1.9.9.432.2.1 |
||
.1.3.6.1.4.1.9.9.432.2.2 |
Dependencies (11) 9 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-IPSEC-TCcisco
- CISCO-TCcisco
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- INET-ADDRESS-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-ENHANCED-IPSEC-FLOW-MIBciscoselected
Conformance Groups (12)
Compliance Statements (3)
OID
.1.3.6.1.4.1.9.9.432.2.1.1The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
pertaining to Phase-2 of IP Security Protocol.
Required groups
| mandatory | ciscoEnhIPsecFlowActivityGroup | |
| mandatory | ciscoEnhIPsecFlowCoreHistGroup | |
| mandatory | ciscoEnhIPsecFlowCoreFailGroup | |
| mandatory | ciscoEnhIPsecFlowTunnelSaGroup | |
| optional | ciscoEnhIPsecFlowHistoryGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of IPsec flows. |
| optional | ciscoEnhIPsecFlowFailureGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of failure of IPsec Phase-2 operations and tunnels. |
| optional | ciscoEnhIPsecFlowNotifGroup | The group is optional. |
| optional | ciscoEnhIPsecFlowNotifCntlGroup |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroup'. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| ceipSecTunStatus | readonly | Write access is not required. | |
| ceipSecHistTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of tunnels may set the value of this object to zero. |
|
| ceipSecFailTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of failures may set the value of this object to zero. |
|
| ceipSecNotiCntlIpSecAllNotifs | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStart | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStop | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSysFailure | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSetUpFail | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecBadSa | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.432.2.1.2The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
pertaining to Phase-2 of IP Security Protocol.
Required groups
| mandatory | ciscoEnhIPsecFlowActivityGroup | |
| mandatory | ciscoEnhIPsecFlowCoreHistGroup | |
| mandatory | ciscoEnhIPsecFlowCoreFailGroup | |
| mandatory | ciscoEnhIPsecFlowTunnelSaGroup | |
| optional | ciscoEnhIPsecFlowHistoryGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of IPsec flows. |
| optional | ciscoEnhIPsecFlowFailureGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of failure of IPsec Phase-2 operations and tunnels. |
| optional | ciscoEnhIPsecFlowNotifGroup | The group is optional. |
| optional | ciscoEnhIPsecFlowNotifCntlGroup |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroup'. |
| optional | ciscoEnhIPsecFlowNotifGroupSup01 | This group is optional. |
| optional | ciscoEnhIPsecFlowNotifCntlGroupSup01 |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroupSup01'. |
| optional | ciscoEnhIPsecFlowCertObjectGroup |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroupSup01'. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| ceipSecTunStatus | readonly | Write access is not required. | |
| ceipSecHistTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of tunnels may set the value of this object to zero. |
|
| ceipSecFailTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of failures may set the value of this object to zero. |
|
| ceipSecNotiCntlIpSecAllNotifs | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStart | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStop | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSysFailure | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSetUpFail | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecBadSa | readonly | Write access is not required. |
OID
.1.3.6.1.4.1.9.9.432.2.1.3The compliance statement for SNMP entities
pertaining to Phase-2 of IP Security Protocol.
pertaining to Phase-2 of IP Security Protocol.
Required groups
| mandatory | ciscoEnhIPsecFlowActivityGroup | |
| mandatory | ciscoEnhIPsecFlowCoreHistGroup | |
| mandatory | ciscoEnhIPsecFlowCoreFailGroup | |
| mandatory | ciscoEnhIPsecFlowTunnelSaGroup | |
| optional | ciscoEnhIPsecFlowHistoryGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of IPsec flows. |
| optional | ciscoEnhIPsecFlowFailureGroup |
This group is optional and must be implemented by the agent of the managed entity if the managed entity implements historical archiving of failure of IPsec Phase-2 operations and tunnels. |
| optional | ciscoEnhIPsecFlowNotifGroup | The group is optional. |
| optional | ciscoEnhIPsecFlowNotifCntlGroup |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroup'. |
| optional | ciscoEnhIPsecFlowNotifGroupSup01 | This group is optional. |
| optional | ciscoEnhIPsecFlowNotifCntlGroupSup01 |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroupSup01'. |
| optional | ciscoEnhIPsecFlowCertObjectGroup |
The agent must implement this group if it implements the group 'ciscoEnhIPsecFlowNotifGroupSup01'. |
| optional | ciscoEnhIPsecFlowPerformanceThroughputGroup | This group is optional. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| ceipSecTunStatus | readonly | Write access is not required. | |
| ceipSecHistTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of tunnels may set the value of this object to zero. |
|
| ceipSecFailTableSize | readonly | Write access is not required. In addition, implementations which want to disable archiving of failures may set the value of this object to zero. |
|
| ceipSecNotiCntlIpSecAllNotifs | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStart | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecTunnelStop | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSysFailure | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecSetUpFail | readonly | Write access is not required. | |
| ceipSecNotifCntlIpSecBadSa | readonly | Write access is not required. |
Notifications / Traps (7)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.432.0.1 |
This notification is generated when an IPsec Phase-2
Tunnel becomes active. |
|
.1.3.6.1.4.1.9.9.432.0.2 |
This notification is generated when an IPsec Phase-2
Tunnel becomes inactive. |
|
.1.3.6.1.4.1.9.9.432.0.3 |
This notification is generated when the processing
for an IPsec Phase-2 Tunnel experiences an internal or system capacity error. |
|
.1.3.6.1.4.1.9.9.432.0.4 |
This notification is generated when the setup for
an IPsec Phase-2 Tunnel fails. |
|
.1.3.6.1.4.1.9.9.432.0.5 |
This notification is generated when the managed
entity receives an IPsec packet with a non-existent (non-existant in the local Security Association Database) SPI. |
|
.1.3.6.1.4.1.9.9.432.0.6 |
This notification is generated to notify that an X.509
certificate is going to expire. The notification is triggered the time threshold configured on the application for notification before the certificate is going to expire, which is when the value of ceipSecCertExpiryStatus is changed from certOK(1) to certGoingExpired(2). The user should take action to renew the certificate identified in the notification prior to the certificate expiration, which is at the validity notAfter time provided in the notification. |
|
.1.3.6.1.4.1.9.9.432.0.7 |
This notification is generated to report a status transition
for an X.509 certificate renewal performed by the application. The notification is generated when the value of ceipSecCertRenewalStatus is changed from 1. renewalNotNeeded(1) to renewalRequestNeeded(2) or renewalRequested(3) 2. renewalRequestNeeded(2) to renewalRequested(3) 3. renewalRequested(3) to renewalSuccess(4) or renewalFailedUpdate(5) or renewalFailedExpired(6) 4. renewalFailedUpdate(5) to renewalFailedExpired(6) |