CISCO-ENHANCED-IPSEC-FLOW-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
183
.1.3.6.1.4.1.9.9.432.1.1.2 · 1 row entry · 54 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecTunnelTable'
The IPsec Phase-2 Tunnel Table.
There is one entry in this table for
each active IPsec Phase-2 Tunnel.
ceipSecTunnelEntry row .1.3.6.1.4.1.9.9.432.1.1.2.1
Each entry contains the attributes
associated with an active IPsec Phase-2 Tunnel.
Indexes
Column Syntax OID
The index of the IPsec Phase-2 Tunnel Table.
The value of the index is a number which begins
at 1 and is incremented with each tunnel that is
created. The value of this object will wrap at
2,147,483,647.

CISCO-IPSEC-TCCIPsecPhase2TunnelIndex
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.9.9.432.1.1.2.1.1
The type of the IP address of the local endpoint
for the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.2.1.2
The IP address of the local endpoint
for the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.2.1.3
The type of the IP address of the remote
endpoint for the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.2.1.4
The IP address of the remote endpoint for
the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.2.1.5
Identifies the protocol used to setup and
administer this Phase-2 IPsec tunnel.

In case this tunnel was spawned by an IPsec
signaling protocol, this MIB object contains the
value of the object 'cisgIps…
CISCO-IPSEC-TCCIPsecControlProtocol
Type Values:
1cpUnknown
2cpAll
3cpOther
4cpManual
5cpIkev1
6cpIkev2
7cpKink
8cpPhoturis
.1.3.6.1.4.1.9.9.432.1.1.2.1.6
The index of the associated IPsec Phase-1
Tunnel. In case this tunnel was spawned by an
IPsec signaling protocol, this MIB object
contains the value of the object 'cisgIpsSgTunIndex'
defined in CISCO-IPSEC-SIGNALING-MIB…
CISCO-IPSEC-TCCIPsecPhase1TunnelIndexOrZero
Type Constraints:
range: 0..2147483647
.1.3.6.1.4.1.9.9.432.1.1.2.1.7
An indicator which specifies whether or not the
IPsec Phase-1 Tunnel that spawned this Phase-2
tunnel currently exists.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.432.1.1.2.1.8
The encapsulation mode used by the
IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncapMode
Type Values:
1encapTunnel
2encapTransport
.1.3.6.1.4.1.9.9.432.1.1.2.1.9
The encapsulation used by the IPsec Phase-2
tunnel for NAT traversal.

The value of this object is constrained based on
the value of the column 'ceipSecTunEncapMode'. If
the value of 'ceipSecTunEncapMode' …
CISCO-IPSEC-TCCIPsecNATTraversalMode
Type Values:
1natEncapNone
2natEncapOther
3natEncapIPsecOverUdp
4natEncapIPsecOverTcp
5natEncapNATT
.1.3.6.1.4.1.9.9.432.1.1.2.1.10
The negotiated LifeSize of the
IPsec Phase-2 Tunnel in kilobytes.
KBytesUnsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.11
The negotiated LifeTime of the IPsec Phase-2
Tunnel in seconds.

If the tunnel was setup manually, the value of this
MIB element should be 0.
SecondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.12
The length of time the IPsec Phase-2
Tunnel has been active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.432.1.1.2.1.13
The security association LifeSize refresh
threshold in kilobytes.

If the tunnel was setup manually, the value of this
MIB element should be 0.
KBytesSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.14
The security association LifeTime refresh
threshold in seconds.

If the tunnel was setup manually, the value of this
MIB element should be 0.
SecondsSNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.15
The total number of security
association refreshes performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.16
The total number of security associations
which have expired.

If the tunnel was setup manually, the value of this
MIB element should be 0.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.17
The number of security associations
which are currently active or expiring.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.18
The Diffie Hellman Group used
by the inbound security association of the
IPsec Phase-2 Tunnel.

If the tunnel was setup manually, the value of this
MIB element would be `none'.
CISCO-IPSEC-TCCIPsecDiffHellmanGrp
Type Values:
1other
2notDH
3modp768
4modp1024
5ec2nGP155
6ec2nGP185
7modp1536
8ec2nGF163
9ec2nGF283
10ec2nGF409
11ec2nGF571
12modp2048
.1.3.6.1.4.1.9.9.432.1.1.2.1.19
The encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncryptAlgorithm
Type Values:
1none
2other
3espDes
4esp3des
5espRc5
6espIdea
7espCast
8espTwofish
9espBlowfish
10esp3idea
11espRc4
12espNull
13espAes128
14espAes192
15espAes256
16espAesCtr128
17espAesCtr192
18espAesCtr256
.1.3.6.1.4.1.9.9.432.1.1.2.1.20
The key size in bits of the negotiated key to be
used with the algorithm denoted by
'ceipSecTunInSaEncryptAlgo'.

For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the ne…
BitsCISCO-IPSEC-TCCIPsecEncryptionKeySize
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.1.2.1.21
The authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.1.2.1.22
The authentication algorithm used by the inbound
ecapsulation security protocol (ESP) security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.1.2.1.23
The decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecCompAlgorithm
Type Values:
1none
2other
3compOui
4compDeflate
5compLzs
6compLzjh
.1.3.6.1.4.1.9.9.432.1.1.2.1.24
The Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.

If the tunnel was setup manually, the value of this
MIB element would be 'none'.
CISCO-IPSEC-TCCIPsecDiffHellmanGrp
Type Values:
1other
2notDH
3modp768
4modp1024
5ec2nGP155
6ec2nGP185
7modp1536
8ec2nGF163
9ec2nGF283
10ec2nGF409
11ec2nGF571
12modp2048
.1.3.6.1.4.1.9.9.432.1.1.2.1.25
The encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncryptAlgorithm
Type Values:
1none
2other
3espDes
4esp3des
5espRc5
6espIdea
7espCast
8espTwofish
9espBlowfish
10esp3idea
11espRc4
12espNull
13espAes128
14espAes192
15espAes256
16espAesCtr128
17espAesCtr192
18espAesCtr256
.1.3.6.1.4.1.9.9.432.1.1.2.1.26
The key size in bits of the negotiated key to be
used with the algorithm denoted by
'ceipSecTunOutSaEncryptAlgo'.

For DES and 3DES the key size is respectively 56 and
168. For AES, this will denote the n…
BitsCISCO-IPSEC-TCCIPsecEncryptionKeySize
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.1.2.1.27
The authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.1.2.1.28
The authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.1.2.1.29
The compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecCompAlgorithm
Type Values:
1none
2other
3compOui
4compDeflate
5compLzs
6compLzjh
.1.3.6.1.4.1.9.9.432.1.1.2.1.30
The Path MTU for this IPsec Phase-2 tunnel, which has
been either learnt from the network or which has been
specified by the administrator. The lower end of the
range is 68 which is the minimum MTU for IPv4.
OctetsCISCO-IPSEC-TCCIPsecPmtu
Type Constraints:
range: 68..1500
.1.3.6.1.4.1.9.9.432.1.1.2.1.31
A high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value is
accumulated BEFORE determining whether or not the packet
should be decompressed.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.2.1.32
A high capacity count of the total number of decompressed
octets received by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will matc…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.2.1.33
The total number of packets received by this IPsec
Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.34
The total number of packets dropped
during receive processing by this IPsec Phase-2
Tunnel. This count does NOT include
packets dropped due to Anti-Replay processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.35
The total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.36
The total number of inbound
authentication's performed by this
IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.37
The total number of inbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel .
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.38
The total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.39
The total number of inbound decryption's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.40
A high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value is
accumulated AFTER determining whether or not the
packet should be compressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.2.1.41
A high capacity count of the total number
of uncompressed octets sent by this IPsec
Phase-2 Tunnel. This value is accumulated BEFORE
the packet is compressed. If compression
is not being used, this value will match the…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.2.1.42
The total number of packets sent by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.43
The total number of packets dropped during
send processing by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.44
The total number of outbound authentication's performed
by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.45
The total number of outbound
authentication's which ended in failure
by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.46
The total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.47
The total number of outbound encryption's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.48
The total number of outbound packets
which were successfully compressed.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.49
The total number of outbound packets that were to be
compressed but which were skipped due to the compression
hysteresis.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.50
The total number of outbound packets that failed
compression because they grew in size after compression.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.51
The total number of outbound packets that were to be
compressed but were smaller than the compression threshold
size.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.1.2.1.52
This object represents the ifIndex of an interface
where this tunnel is created.
Multiple IPsec tunnels can be created using the same
interface.
IF-MIBInterfaceIndex
Type Constraints:
range: 1..2147483647
Description:
A unique value, greater than zero, for each interface or
interface sub-layer in the managed system. It is
recommended that values are assigned contiguously starting
from 1. The value for each interface sub-layer must …
.1.3.6.1.4.1.9.9.432.1.1.2.1.53
The status of the MIB table row.

This object can be used to bring the tunnel down
or force a rekeying.
When the value is set to destroy(5), the SA
bundle is destroyed and this row is deleted
from this tab…
CISCO-IPSEC-TCCIPsecTunnelStatusr/w
Type Values:
1initializePhase1
2awaitXauth
3awaitCommit
4active
5destroy
6rekey
.1.3.6.1.4.1.9.9.432.1.1.2.1.54
.1.3.6.1.4.1.9.9.432.1.1.3 · 1 row entry · 17 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecEndPtTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecEndPtTable'
The IPsec Phase-2 Tunnel Endpoint Table.
This table contains an entry for each
active endpoint associated with an IPsec
Phase-2 Tunnel.
ceipSecEndPtEntry row .1.3.6.1.4.1.9.9.432.1.1.3.1
An IPsec Phase-2 Tunnel Endpoint entry.
Column Syntax OID
The number of the Endpoint associated with the
IPsec Phase-2 Tunnel Table. The value of this
index is a number which begins at one and
is incremented with each Endpoint associated
with an IPsec Phase-2 Tunnel.
The valu…
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.1.3.1.1
The DNS name of the local Endpoint.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.2
The type of identity for the local Endpoint.
CISCO-IPSEC-TCCIPsecEndPtType
Type Values:
1other
2idIpv4Addr
3idIpv4AddrRange
4idIpv4AddrSubnet
5idFqdn
6idUserFqdn
7idIpv6Addr
8idIpv6AddrRange
9idIpv6AddrSubnet
10idDerAsn1Dn
11idDerAsn1Gn
12idKeyId
.1.3.6.1.4.1.9.9.432.1.1.3.1.3
The type of the IP address for this local Endpoint's
first IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.3.1.4
The local Endpoint's first IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, then…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.5
The type of the IP address for this local Endpoint's
second IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.3.1.6
The local Endpoint's second IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, the…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.7
The protocol number of the local Endpoint's traffic.
CISCO-TCCiscoIpProtocol
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.8
The port number of the local Endpoint's traffic.
CISCO-TCCiscoPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.1.3.1.9
The DNS name of the remote Endpoint.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.10
The type of identity for the remote Endpoint.
CISCO-IPSEC-TCCIPsecEndPtType
Type Values:
1other
2idIpv4Addr
3idIpv4AddrRange
4idIpv4AddrSubnet
5idFqdn
6idUserFqdn
7idIpv6Addr
8idIpv6AddrRange
9idIpv6AddrSubnet
10idDerAsn1Dn
11idDerAsn1Gn
12idKeyId
.1.3.6.1.4.1.9.9.432.1.1.3.1.11
The type of the IP address for this remote Endpoint's
first IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.3.1.12
The remote Endpoint's first IP address specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet, t…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.13
The type of the IP address for this remote Endpoint's
second IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.1.3.1.14
The remote Endpoint's second IP address specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet, …
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.15
The protocol number of the remote Endpoint's traffic.
CISCO-TCCiscoIpProtocol
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.1.3.1.16
The port number of the remote Endpoint's traffic.
CISCO-TCCiscoPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.1.3.1.17
.1.3.6.1.4.1.9.9.432.1.1.4 · 1 row entry · 5 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecSaTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecSaTable'
The IPsec Phase-2 Security Association Table.
This table identifies the structure (in terms of
component SAs) of each active Phase-2 IPsec tunnel.
This table contains an entry for each active and
expiring security association and maps each entry
in the active Phase-2 tunnel table (ceipSecTunTable)
into a number of entries in this table. The index 
of this table reflects the
          
     <destination-address, protocol, spi>
          
rule for identifying Security Associations.
ceipSecSaEntry row .1.3.6.1.4.1.9.9.432.1.1.4.1
Each entry contains the attributes associated with
active and expiring IPsec Phase-2
security associations.
Column Syntax OID
This column represents the security protocol (AH,
ESP or IPComp) for which this security association
was setup.
CISCO-IPSEC-TCCIPsecProtocol
Type Values:
1ipsecProtUnknown
2ipsecProtAh
3ipsecProtEsp
4ipsecProtIPcomp
.1.3.6.1.4.1.9.9.432.1.1.4.1.1
The object, in the context of the IPsec tunnel
'ceipSecTunIndex', is an index of security
associations comprising the Phase-2 IPsec tunnel
represented by the tunnel index 'ceipSecTunIndex'.

The value of…
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.1.4.1.2
Phase-2 IPsec security associations are simplex.
Hence a particular security association is used either
for securing outgoing traffic or decoding incoming
traffic. This column identifies the direction of the
security …
CISCO-IPSEC-TCCIPsecPhase2SaDirection
Type Values:
1saDirectionUnknown
2saDirectionIn
3saDirectionOut
.1.3.6.1.4.1.9.9.432.1.1.4.1.3
This is the value of the Security Protection Index
(SPI) assigned by the system to the security
association represented by this entry.
CISCO-IPSEC-TCCIPsecSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.9.9.432.1.1.4.1.4
This column represents the status of the security
association represented by this conceptual row. If
the status of the SA is 'active', the SA is ready
for active use. The status 'expiring' represents any
of the vario…
Enumeration
Enumerated Values:
1unknown
2active
3expiring
.1.3.6.1.4.1.9.9.432.1.1.4.1.5
.1.3.6.1.4.1.9.9.432.1.1.5 · 1 row entry · 27 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecTunnelSaTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecTunnelSaTable'
The IPsec Phase-2 Tunnel Security Association Table.
This table identifies the SAs that are currently
associated with an active Phase-2 tunnel.
This table contains an entry for each active or
expiring security association (SA) which is
associated with an ceipSecTunnelEntry in 'active' state
and provides statistic information of this SA.
There might be multiple SAs associated with one
ceipSecTunnelEntry.
ceipSecTunnelSaEntry row .1.3.6.1.4.1.9.9.432.1.1.5.1
Each entry contains the attributes and statistics
associated with an active or expiring IPsec Phase-2
security associations.
Column Syntax OID
This column represents the security protocol (AH,
ESP or IPComp) for which this security association
was setup.
CISCO-IPSEC-TCCIPsecProtocol
Type Values:
1ipsecProtUnknown
2ipsecProtAh
3ipsecProtEsp
4ipsecProtIPcomp
.1.3.6.1.4.1.9.9.432.1.1.5.1.1
The object, in the context of the IPsec tunnel
'ceipSecTunIndex', is an index of security
associations comprising the Phase-2 IPsec tunnel
represented by the tunnel index 'ceipSecTunIndex'.

The value of…
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.1.5.1.2
Phase-2 IPsec security associations are simplex.
Hence a particular security association is used either
for securing outgoing traffic or decoding incoming
traffic. This column identifies the direction of the
security …
CISCO-IPSEC-TCCIPsecPhase2SaDirection
Type Values:
1saDirectionUnknown
2saDirectionIn
3saDirectionOut
.1.3.6.1.4.1.9.9.432.1.1.5.1.3
This is the value of the Security Protection Index
(SPI) assigned by the system to the security
association represented by this entry.
CISCO-IPSEC-TCCIPsecSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.9.9.432.1.1.5.1.4
This object represents the ifIndex of an interface
where a tunnel with ceipSecTunIndex is created.
Multiple IPsec tunnels can be created using the same
interface.
IF-MIBInterfaceIndex
Type Constraints:
range: 1..2147483647
Description:
A unique value, greater than zero, for each interface or
interface sub-layer in the managed system. It is
recommended that values are assigned contiguously starting
from 1. The value for each interface sub-layer must …
.1.3.6.1.4.1.9.9.432.1.1.5.1.5
A high capacity count of the total number of octets
received by using this SA. This value is
accumulated BEFORE determining whether or not the packet
should be decompressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.6
A high capacity count of the total number of decompressed
octets received by using this SA. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will match the
value …
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.7
The total number of packets received by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.8
The total number of packets dropped
during receive process by using this SA.
This count does NOT include packets dropped due
to Anti-Replay processing.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.9
The total number of packets dropped during
receive processing due to Anti-Replay processing
by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.10
The total number of inbound authentication's
performed by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.11
The total number of inbound authentication's
which ended in failure by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.12
The total number of inbound decryption's performed
by this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.13
The total number of inbound decryption's
which ended in failure by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.14
A high capacity count of the total number of octets
sent by using this SA. This value is
accumulated AFTER determining whether or not the packet
should be compressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.15
A high capacity count of the total number
of uncompressed octets sent by using this SA.
This value is accumulated BEFORE
the packet is compressed. If compression
is not being used, this value will match the value
of cei…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.16
The total number of packets sent by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.17
The total number of packets dropped during
send processing by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.18
The total number of outbound authentication's performed
by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.19
The total number of outbound
authentication's which ended in failure
by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.20
The total number of outbound encryption's performed
by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.21
The total number of outbound encryption's
which ended in failure by using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.22
The total number of outbound packets
which were successfully compressed by using this
SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.23
The total number of outbound packets that were to be
compressed but which were skipped due to the compression
hysteresis when using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.24
The total number of outbound packets that failed
compression because they grew in size after compression
when using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.25
The total number of outbound packets that were to be
compressed but were smaller than the compression threshold
size when using this SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.1.5.1.26
This column represents the status of the security
association represented by this conceptual row. If
the status of the SA is 'active', the SA is ready
for active use. The status 'expiring' represents any
of the various …
Enumeration
Enumerated Values:
1unknown
2active
3expiring
.1.3.6.1.4.1.9.9.432.1.1.5.1.27
.1.3.6.1.4.1.9.9.432.1.1.6 · 1 row entry · 1 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecIfTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecIfTunnelTable'
The IPsec Phase-2 Tunnels to Interface association
table.  This table contains an entry for each
active IPsec Phase-2 Tunnel created under an interface.
Multiple IPsec Phase-2 Tunnels can be created using the
same interface.
ceipSecIfTunnelEntry row .1.3.6.1.4.1.9.9.432.1.1.6.1
Each entry contains the IPsec Phase-2 Tunnel
associated with an interface.
Column Syntax OID
This object corresponds to the status of
a IPsec Phase-2 Tunnel in ceipSecTunnelTable
indexed by ceipSecTunIndex. The valid status
this object can have are 'active' and
'awaitCommit'.
CISCO-IPSEC-TCCIPsecTunnelStatus
Type Values:
1initializePhase1
2awaitXauth
3awaitCommit
4active
5destroy
6rekey
.1.3.6.1.4.1.9.9.432.1.1.6.1.1
.1.3.6.1.4.1.9.9.432.1.2.2 · 1 row entry · 51 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecTunnelHistTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecTunnelHistTable'
The IPsec Phase-2 Tunnel History Table.
This table is conceptually a sliding window in 
which only the last 'N' entries are maintained,
where 'N' is the value of the object 
'ceipSecHistTableSize'.
          
If the value of 'ceipSecHistTableSize' is 0,
archiving of entries in this table is disabled.
ceipSecTunnelHistEntry row .1.3.6.1.4.1.9.9.432.1.2.2.1
Each entry contains the attributes associated
with a previously active IPsec Phase-2 Tunnel.
Column Syntax OID
The index of the IPsec Phase-2 Tunnel History Table.
The value of the index is a number which
begins at one and is incremented with each tunnel
that ends. The value
of this object will wrap at 4,294,967,295.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.1
The reason the IPsec Phase-2 Tunnel was terminated.
Possible reasons include:
1 = other
2 = normal termination
3 = operator request
4 = peer delete request was received
5 = contact with peer was lost
6 = applicationInit…
Enumeration
Enumerated Values:
1other
2normal
3operRequest
4peerDelRequest
5peerLost
6applicationInitiated
7xauthFailure
8seqNumRollOver
9checkPointReq
.1.3.6.1.4.1.9.9.432.1.2.2.1.2
The index of the previously active IPsec Phase-2
Tunnel.

This object must correspond to an expired IPsec
tunnel; hence this object may not assume the value
of 0.
CISCO-IPSEC-TCCIPsecPhase2TunnelIndex
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.9.9.432.1.2.2.1.3
The type of the IP address of the local endpoint for
the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.2.1.4
The IP address of the local endpoint for
the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.2.1.5
The type of the IP address of the remote endpoint
for the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.2.1.6
The IP address of the remote endpoint for
the IPsec Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.2.1.7
Identifies the protocol that was used to setup
and administer Phase-2 IPsec tunnel.
CISCO-IPSEC-TCCIPsecControlProtocol
Type Values:
1cpUnknown
2cpAll
3cpOther
4cpManual
5cpIkev1
6cpIkev2
7cpKink
8cpPhoturis
.1.3.6.1.4.1.9.9.432.1.2.2.1.8
The index of the IPsec Phase-1 Tunnel that spawned
this Phase-2 tunnel (in case of IKE, this value
would refer to 'csikeTunIndex' in the 'csikeTunnelTable').

If the IPsec tunnel corresponding to this ent…
CISCO-IPSEC-TCCIPsecPhase1TunnelIndexOrZero
Type Constraints:
range: 0..2147483647
.1.3.6.1.4.1.9.9.432.1.2.2.1.9
The encapsulation mode used by the
IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncapMode
Type Values:
1encapTunnel
2encapTransport
.1.3.6.1.4.1.9.9.432.1.2.2.1.10
The encapsulation used by the IPsec Phase-2
tunnel corresponding to this conceptual row
for NAT traversal.
CISCO-IPSEC-TCCIPsecNATTraversalMode
Type Values:
1natEncapNone
2natEncapOther
3natEncapIPsecOverUdp
4natEncapIPsecOverTcp
5natEncapNATT
.1.3.6.1.4.1.9.9.432.1.2.2.1.11
The negotiated LifeSize of the IPsec Phase-2 Tunnel in
kilobytes.
KBytesUnsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.12
The negotiated LifeTime of the IPsec Phase-2 Tunnel in
seconds.
SecondsUnsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.13
The value of sysUpTime in hundredths of seconds
when the IPsec Phase-2 Tunnel was started.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.432.1.2.2.1.14
The length of time the IPsec Phase-2 Tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.432.1.2.2.1.15
The total number of security association refreshes
performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.16
The total number of security associations used
during the life of the IPsec Phase-2 Tunnel.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.17
The Diffie Hellman Group used by the inbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecDiffHellmanGrp
Type Values:
1other
2notDH
3modp768
4modp1024
5ec2nGP155
6ec2nGP185
7modp1536
8ec2nGF163
9ec2nGF283
10ec2nGF409
11ec2nGF571
12modp2048
.1.3.6.1.4.1.9.9.432.1.2.2.1.18
The encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncryptAlgorithm
Type Values:
1none
2other
3espDes
4esp3des
5espRc5
6espIdea
7espCast
8espTwofish
9espBlowfish
10esp3idea
11espRc4
12espNull
13espAes128
14espAes192
15espAes256
16espAesCtr128
17espAesCtr192
18espAesCtr256
.1.3.6.1.4.1.9.9.432.1.2.2.1.19
The size in bits of the key which was negotiated to
be used with the encryption transform used with this
tunnel denoted by ceipSecTunHistInSaEncryptAlgo.

For DES and 3DES the key size is respectively 56 …
BitsCISCO-IPSEC-TCCIPsecEncryptionKeySize
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.2.2.1.20
The authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.2.2.1.21
The authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.2.2.1.22
The decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecCompAlgorithm
Type Values:
1none
2other
3compOui
4compDeflate
5compLzs
6compLzjh
.1.3.6.1.4.1.9.9.432.1.2.2.1.23
The Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecDiffHellmanGrp
Type Values:
1other
2notDH
3modp768
4modp1024
5ec2nGP155
6ec2nGP185
7modp1536
8ec2nGF163
9ec2nGF283
10ec2nGF409
11ec2nGF571
12modp2048
.1.3.6.1.4.1.9.9.432.1.2.2.1.24
The encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecEncryptAlgorithm
Type Values:
1none
2other
3espDes
4esp3des
5espRc5
6espIdea
7espCast
8espTwofish
9espBlowfish
10esp3idea
11espRc4
12espNull
13espAes128
14espAes192
15espAes256
16espAesCtr128
17espAesCtr192
18espAesCtr256
.1.3.6.1.4.1.9.9.432.1.2.2.1.25
The size in bits of the key which was negotiated to
be used with the encryption transform used with this
tunnel denoted by ceipSecTunHistOutSaEncryptAlgo.

For DES and 3DES the key size is respectively 56…
BitsCISCO-IPSEC-TCCIPsecEncryptionKeySize
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.2.2.1.26
The authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.2.2.1.27
The authentication algorithm used by the inbound
ecapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecAuthAlgorithm
Type Values:
1none
2other
3hmacMd5
4hmacSha
5desMac
6hmacSha256
7hmacSha384
8hmacSha512
9ripemd
.1.3.6.1.4.1.9.9.432.1.2.2.1.28
The compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CISCO-IPSEC-TCCIPsecCompAlgorithm
Type Values:
1none
2other
3compOui
4compDeflate
5compLzs
6compLzjh
.1.3.6.1.4.1.9.9.432.1.2.2.1.29
The Path MTU that was determined for this IPsec
Phase-2 tunnel.
OctetsCISCO-IPSEC-TCCIPsecPmtu
Type Constraints:
range: 68..1500
.1.3.6.1.4.1.9.9.432.1.2.2.1.30
A high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value
is accumulated BEFORE determining whether or not
the packet should be decompressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.2.2.1.31
A high capacity count of the total number of
decompressed octets received by this IPsec Phase-2 Tunnel.
This value is accumulated AFTER the packet is
decompressed.
If compression is not being used, this value will m…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.2.2.1.32
The total number of packets received by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.33
The total number of packets dropped during
receive processing by this IPsec Phase-2 Tunnel.
This count does NOT include packets
dropped due to Anti-Replay processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.34
The total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.35
The total number of inbound authentication's
performed by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.36
The total number of inbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel .
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.37
The total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.38
The total number of inbound decryption's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.39
A high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER determining whether or not
the packet should be compressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.2.2.1.40
A high capacity count of the total
number of uncompressed octets sent by this
IPsec Phase-2 Tunnel. This value is accumulated
BEFORE the packet is compressed. If compression
is not being used, this value will match the…
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.432.1.2.2.1.41
The total number of packets sent by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.42
The total number of packets dropped during
send processing by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.43
The total number of outbound authentication's
performed by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.44
The total number of outbound authentication's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.45
The total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.46
The total number of outbound encryption's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.47
The total number of outbound packets
which were successfully compressed.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.48
The total number of outbound packets that were to be
compressed but which were skipped due to the
compression hysteresis.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.49
The total number of outbound packets that failed
compression because they grew in size after compression.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.50
The total number of outbound packets that were
to be compressed but were smaller than the
compression threshold size.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.432.1.2.2.1.51
.1.3.6.1.4.1.9.9.432.1.2.3 · 1 row entry · 19 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecEndPtHistTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecEndPtHistTable'
The IPsec Phase-2 Tunnel Endpoint History Table.
This table is conceptually a sliding window in 
which only the last 'N' entries are maintained,
where 'N' is the value of the object 
'ceipSecHistTableSize'.
          
If the value of 'ceipSecHistTableSize' is 0,
archiving of entries in this table is disabled.
ceipSecEndPtHistEntry row .1.3.6.1.4.1.9.9.432.1.2.3.1
Each entry contains the attributes associated with
a previously active IPsec Phase-2 Tunnel Endpoint.
Column Syntax OID
The number of the previously active Endpoint
associated with a IPsec Phase-2 Tunnel Table.
The value of this index is a number which begins
at one and is incremented with each Endpoint
associated with an IPsec Phase-…
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.3.1.1
The index of the previously active IPsec
Phase-2 Tunnel Table.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.3.1.2
The index of the previously active Endpoint.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.2.3.1.3
The DNS name of the local Endpoint.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.4
The type of identity for the local Endpoint.
CISCO-IPSEC-TCCIPsecEndPtType
Type Values:
1other
2idIpv4Addr
3idIpv4AddrRange
4idIpv4AddrSubnet
5idFqdn
6idUserFqdn
7idIpv6Addr
8idIpv6AddrRange
9idIpv6AddrSubnet
10idDerAsn1Dn
11idDerAsn1Gn
12idKeyId
.1.3.6.1.4.1.9.9.432.1.2.3.1.5
The type of the IP address for this local Endpoint's
first IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.3.1.6
The local Endpoint's first IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, then…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.7
The type of the IP address for this local Endpoint's
second IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.3.1.8
The local Endpoint's second IP address
specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, the…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.9
The protocol number of the local Endpoint's
traffic.
CISCO-TCCiscoIpProtocol
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.10
The port number of the local Endpoint's traffic.
CISCO-TCCiscoPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.2.3.1.11
The DNS name of the remote Endpoint.
SNMP-FRAMEWORK-MIBSnmpAdminString
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.12
The type of identity for the remote Endpoint.
CISCO-IPSEC-TCCIPsecEndPtType
Type Values:
1other
2idIpv4Addr
3idIpv4AddrRange
4idIpv4AddrSubnet
5idFqdn
6idUserFqdn
7idIpv6Addr
8idIpv6AddrRange
9idIpv6AddrSubnet
10idDerAsn1Dn
11idDerAsn1Gn
12idKeyId
.1.3.6.1.4.1.9.9.432.1.2.3.1.13
The type of the IP address for this remote Endpoint's
first IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.3.1.14
The remote Endpoint's first IP address
specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet, t…
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.15
The type of the IP address for this remote Endpoint's
second IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.2.3.1.16
The remote Endpoint's second IP address
specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet, …
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.17
The protocol number of the remote Endpoint's traffic.
CISCO-TCCiscoIpProtocol
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.2.3.1.18
The port number of the remote Endpoint's traffic.
CISCO-TCCiscoPort
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.9.9.432.1.2.3.1.19
.1.3.6.1.4.1.9.9.432.1.3.2 · 1 row entry · 9 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk ceipSecFailTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-ENHANCED-IPSEC-FLOW-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-ENHANCED-IPSEC-FLOW-MIB::ceipSecFailTable'
The IPsec Phase-2 Failure Table.
This table is implemented as a sliding window
in which only the last n entries are maintained.
The maximum number of entries
is specified by the ceipSecFailTableSize object.
ceipSecFailEntry row .1.3.6.1.4.1.9.9.432.1.3.2.1
Each entry contains the attributes associated with
an IPsec Phase-1 failure.
Column Syntax OID
The IPsec Phase-2 Failure Table index.
The value of the index is a number which
begins at one and is incremented with each
IPsec Phase-1 failure. The value of this
object will wrap at 4,294,967,295.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.432.1.3.2.1.1
The reason for the failure. Possible reasons
include:
1 = other
2 = internal error occurred
3 = peer encoding error
4 = proposal failure
5 = protocol use failure
6 = non-existent security …
Enumeration
Enumerated Values:
1other
2internalError
3peerEncodingError
4proposalFailure
5protocolUseFail
6nonExistentSa
7decryptFailure
8encryptFailure
9inAuthFailure
10outAuthFailure
11compression
12sysCapExceeded
13peerDelRequest
14peerLost
15seqNumRollOver
16operRequest
17performanceUtilization
.1.3.6.1.4.1.9.9.432.1.3.2.1.2
The value of sysUpTime in hundredths of seconds
at the time of the failure.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.432.1.3.2.1.3
The Phase-2 Tunnel index (ceipSecTunIndex).

If this conceptual row corresponds to an operation
failure (that is, the failure of an established
Phase-2 IPsec tunnel), then the value of this object
may not …
CISCO-IPSEC-TCCIPsecPhase2TunnelIndex
Type Constraints:
range: 1..2147483647
.1.3.6.1.4.1.9.9.432.1.3.2.1.4
The security association SPI value.

If this conceptual row corresponds to a setup
failure (failure to establish the tunnel), the
value of this MIB object is undefined.
CISCO-IPSEC-TCCIPsecSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.9.9.432.1.3.2.1.5
The type of the packet's source IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.3.2.1.6
The packet's source IP address.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.3.2.1.7
The type of the packet's destination IP address.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.432.1.3.2.1.8
The packet's destination IP address.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.432.1.3.2.1.9