CISCO-IKE-CONFIGURATION-MIB

        This is a MIB Module for configuring and viewing IKE 
parameters and policies. 
        
Acronyms
The following acronyms are used in this document:
        
IPsec:      Secure IP Protocol
        
VPN:        Virtual Private Network
        
ISAKMP:     Internet Security Association and Key Exchange
            Protocol
        
IKE:        Internet Key Exchange Protocol
        
DOI:        Domain of Interpretation (of the attributes
            of IKE protocol in the context of a specific 
            Phase-2 protocol).
        
SA:         Security Association
            (ref: rfc2408).
        
SPI:        Security Parameter Index is the pointer or
            identifier used in accessing SA attributes
            (ref: rfc2408).
        
MM:         Main Mode - the process of setting up
            a Phase 1 SA to secure the exchanges
            required to setup Phase 2 SAs
        
Phase 1 Tunnel:
            An ISAKMP SA can be regarded as representing
            a flow of ISAKMP/IKE traffic. Hence an ISAKMP
            is referred to as a 'Phase 1 Tunnel' in this
            document. 
        
Phase 2 Tunnel:
            A Phase 2 Tunnel is an instance of a
            non-ISAKMP SA bundle in which all the SA
            share the same proxy identifiers (IDii,IDir)
            and protect the same stream of application
            traffic.
            Note that a Phase 2 tunnel may comprise one
            SA bundle at any given point of time, but 
            the SA bundle changes with time due to 
            key refresh.
        
        
History of the MIB
This MIB was originally written as CISCO-IPSEC-MIB
which combined the configuration of IKE and IPsec
protocols into a single MIB.
    
Source file
CISCO-IKE-CONFIGURATION-MIB
Last revised
Identity
ciscoIkeConfigMIB
Base OID
1.3.6.1.4.1.9.9.423
Imported Objects
CISCO-IPSEC-TC CIKEIsakmpDoi CIKELifesize CIKELifetime CIPsecControlProtocol CIPsecDiffHellmanGrp CIPsecEncryptAlgorithm CIPsecIkeAuthMethod CIPsecIkeHashAlgorithm CIPsecIkePRFAlgorithm CIPsecPhase1PeerIdentityType
CISCO-SMI ciscoMgmt
INET-ADDRESS-MIB InetAddress InetAddressPrefixLength InetAddressType
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowStatus TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IKE-CONFIGURATION-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IKE-CONFIGURATION-MIB::ciscoIkeConfigMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IKE-CONFIGURATION-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IKE-CONFIGURATION-MIB::ciscoIkeConfigMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (72)
.1.3.6.1.4.1.9.9.423
.1.3.6.1.4.1.9.9.423.0
.1.3.6.1.4.1.9.9.423.1
.1.3.6.1.4.1.9.9.423.1.1
.1.3.6.1.4.1.9.9.423.1.1.1
.1.3.6.1.4.1.9.9.423.1.1.2
.1.3.6.1.4.1.9.9.423.1.2
.1.3.6.1.4.1.9.9.423.1.2.1
.1.3.6.1.4.1.9.9.423.1.2.1.1
.1.3.6.1.4.1.9.9.423.1.2.1.1.1
.1.3.6.1.4.1.9.9.423.1.2.1.1.2
.1.3.6.1.4.1.9.9.423.1.2.2
.1.3.6.1.4.1.9.9.423.1.2.2.1
.1.3.6.1.4.1.9.9.423.1.2.2.1.1
.1.3.6.1.4.1.9.9.423.1.2.3
.1.3.6.1.4.1.9.9.423.1.2.3.1
.1.3.6.1.4.1.9.9.423.1.2.3.1.1
.1.3.6.1.4.1.9.9.423.1.2.3.1.2
OctetString
.1.3.6.1.4.1.9.9.423.1.2.3.1.3
.1.3.6.1.4.1.9.9.423.1.2.3.1.4
.1.3.6.1.4.1.9.9.423.1.2.3.1.5
.1.3.6.1.4.1.9.9.423.1.3
.1.3.6.1.4.1.9.9.423.1.3.1
.1.3.6.1.4.1.9.9.423.1.3.1.1
.1.3.6.1.4.1.9.9.423.1.3.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.423.1.3.1.1.2
secondsUnsigned32
.1.3.6.1.4.1.9.9.423.1.3.1.1.3
secondsUnsigned32
.1.3.6.1.4.1.9.9.423.1.3.1.1.4
.1.3.6.1.4.1.9.9.423.1.3.1.1.5
.1.3.6.1.4.1.9.9.423.1.4
.1.3.6.1.4.1.9.9.423.1.4.1
.1.3.6.1.4.1.9.9.423.1.4.1.1
.1.3.6.1.4.1.9.9.423.1.4.1.1.1
.1.3.6.1.4.1.9.9.423.1.4.1.1.1.1
.1.3.6.1.4.1.9.9.423.1.4.1.2
.1.3.6.1.4.1.9.9.423.1.4.1.2.1
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.1
OctetString
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.2
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.3
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.4
OctetString
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.5
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.6
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.7
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.8
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.9
.1.3.6.1.4.1.9.9.423.1.4.2
.1.3.6.1.4.1.9.9.423.1.4.3
.1.3.6.1.4.1.9.9.423.1.5
.1.3.6.1.4.1.9.9.423.1.5.1
.1.3.6.1.4.1.9.9.423.1.5.1.1
Unsigned32
.1.3.6.1.4.1.9.9.423.1.5.1.1.1
.1.3.6.1.4.1.9.9.423.1.5.1.1.2
.1.3.6.1.4.1.9.9.423.1.5.1.1.3
.1.3.6.1.4.1.9.9.423.1.5.1.1.4
.1.3.6.1.4.1.9.9.423.1.5.1.1.5
.1.3.6.1.4.1.9.9.423.1.5.1.1.6
.1.3.6.1.4.1.9.9.423.1.5.1.1.7
.1.3.6.1.4.1.9.9.423.1.5.1.1.8
.1.3.6.1.4.1.9.9.423.1.5.1.1.9
.1.3.6.1.4.1.9.9.423.1.6
.1.3.6.1.4.1.9.9.423.1.6.1
.1.3.6.1.4.1.9.9.423.1.6.2
.1.3.6.1.4.1.9.9.423.1.7
.1.3.6.1.4.1.9.9.423.1.7.1
.1.3.6.1.4.1.9.9.423.1.7.2
.1.3.6.1.4.1.9.9.423.1.7.3
.1.3.6.1.4.1.9.9.423.1.7.4
.1.3.6.1.4.1.9.9.423.1.7.5
.1.3.6.1.4.1.9.9.423.1.7.6
.1.3.6.1.4.1.9.9.423.2
.1.3.6.1.4.1.9.9.423.2.1
.1.3.6.1.4.1.9.9.423.2.2
Dependencies (6) 6 direct Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. CISCO-IPSEC-TCcisco
  5. INET-ADDRESS-MIBrfc
  6. SNMPv2-CONFrfc
  7. CISCO-IKE-CONFIGURATION-MIBciscoselected
Type Definitions (2)
Unsigned32 range: 1..65535
Unsigned32 range: 1..65535
Conformance Groups (8)
This group consists of objects that reflect the
operational state of the IKE entity on the
managed device.
.1.3.6.1.4.1.9.9.423.2.1.1
This group consists of objects that reflect the
Phase 1 ID used by the IKE entity on the
managed device.
.1.3.6.1.4.1.9.9.423.2.1.2
This group consists of objects that define how the
local IKE entity is configured to respond to
common failures.
.1.3.6.1.4.1.9.9.423.2.1.3
This group consists of objects that are used to
view and configure the preshared keys configured on
the managed entity.
.1.3.6.1.4.1.9.9.423.2.1.4
This group consists of objects that are used to
view and configure the ISAKMP policies configured on
the managed device.
.1.3.6.1.4.1.9.9.423.2.1.5
This group consists of objects pertaining to ISAKMP
policy management which are optional and may not be
supported by every implementation of IKE.
.1.3.6.1.4.1.9.9.423.2.1.6
This group of objects controls the sending
of notifications to signal the state of Phase-1 IKE
configuration on the managed device.
.1.3.6.1.4.1.9.9.423.2.1.7
This group contains the notifications to signal the
changes to IKE on the managed device.
.1.3.6.1.4.1.9.9.423.2.1.8
Compliance Statements (1)

OID .1.3.6.1.4.1.9.9.423.2.2.1
The compliance statement for SNMP entities
the Internet Key Exchange Protocol
configuration MIB.
Required groups
mandatory cicIkeCfgOperGroup
mandatory cicIkeCfgIdentitiesGroup
mandatory cicIkeCfgPskAuthGroup
mandatory cicIkeCfgPolicyGroup
optional cicIkeCfgOptionalPolicyGroup This group is optional.
optional cicIkeCfgFailureRecoveryGroup This group is conditionally mandatory and must be
implemented by the agent of the managed entity
if and only if
a) the managed entity implements Internet Key
Exchange keepalive operations or
b) the managed entity implements IKE
failure signaling (such as the Invalid SPI
notification).
optional cicIkeCfgNotificationGroup This group is optional.
optional cicIkeCfgNotifCntlGroup The agent must implement this group if it
implements the group 'cicIkeCfgNotificationGroup'.
Object refinements
ObjectAccessSyntaxDescription
cicIkeEnabled readonly
Write access is not required.
cicIkeAggressModeEnabled readonly
Write access is not required.
cicIkeKeepAliveEnabled readonly
Write access is not required.
cicIkeKeepAliveType readonly
Write access is not required.
cicIkeKeepAliveInterval readonly
Write access is not required. It is compliant
to support only a subset of the values in the
range defined.
cicIkeKeepAliveRetryInterval readonly
Write access is not required. It is compliant
to support only a subset of the values in the
range defined.
cicIkeInvalidSpiNotify readonly
Write access is not required.
cicIkeCfgPskKey readonly
Write access is not required.
cicIkeCfgPskRemIdentType readonly
Write access is not required.
Note that an implementation need not support all
identity types listed in the definition of the
textual convention CIPsecPhase1PeerIdentityType.
cicIkeCfgPskRemIdentity readonly
Write access is not required.
cicIkeCfgPskRemIdAddrOrRg1OrSn readonly
Write access is not required.
cicIkeCfgPskRemIdAddrRange2 readonly
Write access is not required.
cicIkeCfgPskRemIdSubnetMask readonly
Write access is not required.
cicIkeCfgPskStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported if write is supported.
cicIkeCfgPolicyStatus
active(1), createAndGo(4), destroy(6)
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported if write is supported.
cicNotifCntlIkeAllNotifs readonly
Write access is not required.
cicNotifCntlIkeOperStateChanged readonly
Write access is not required.
cicNotifCntlIkePskAdded readonly
Write access is not required.
cicNotifCntlIkePskDeleted readonly
Write access is not required.
cicNotifCntlIkePolicyAdded readonly
Write access is not required.
cicNotifCntlIkePolicyDeleted readonly
Write access is not required.
cicIkeCfgInitiatorPAddrType readonly
Write access is not required.
cicIkeCfgInitiatorPAddr readonly
Write access is not required.
cicIkeCfgInitiatorVer readonly
Write access is not required.
cicIkeCfgInitiatorStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported if write is supported.
Notifications / Traps (5)
NameOIDDescription
.1.3.6.1.4.1.9.9.423.0.1
The notification is generated when the operational
state of IKE entity on the managed device has
been changed.
.1.3.6.1.4.1.9.9.423.0.2
This notification is generated when a new preshared
key is configured on the managed device.
.1.3.6.1.4.1.9.9.423.0.3
This notification is generated when an existing
preshared key is configured on the managed device is
about to be deleted.
.1.3.6.1.4.1.9.9.423.0.4
This notification is generated when a new ISAKMP
policy is configured on the managed device.
.1.3.6.1.4.1.9.9.423.0.5
This notification is issued when an existing ISAKMP
policy configured on the managed device is about
to be deleted.