CISCO-IKE-CONFIGURATION-MIB
This is a MIB Module for configuring and viewing IKE
parameters and policies.
Acronyms
The following acronyms are used in this document:
IPsec: Secure IP Protocol
VPN: Virtual Private Network
ISAKMP: Internet Security Association and Key Exchange
Protocol
IKE: Internet Key Exchange Protocol
DOI: Domain of Interpretation (of the attributes
of IKE protocol in the context of a specific
Phase-2 protocol).
SA: Security Association
(ref: rfc2408).
SPI: Security Parameter Index is the pointer or
identifier used in accessing SA attributes
(ref: rfc2408).
MM: Main Mode - the process of setting up
a Phase 1 SA to secure the exchanges
required to setup Phase 2 SAs
Phase 1 Tunnel:
An ISAKMP SA can be regarded as representing
a flow of ISAKMP/IKE traffic. Hence an ISAKMP
is referred to as a 'Phase 1 Tunnel' in this
document.
Phase 2 Tunnel:
A Phase 2 Tunnel is an instance of a
non-ISAKMP SA bundle in which all the SA
share the same proxy identifiers (IDii,IDir)
and protect the same stream of application
traffic.
Note that a Phase 2 tunnel may comprise one
SA bundle at any given point of time, but
the SA bundle changes with time due to
key refresh.
History of the MIB
This MIB was originally written as CISCO-IPSEC-MIB
which combined the configuration of IKE and IPsec
protocols into a single MIB.
- Source file
CISCO-IKE-CONFIGURATION-MIB- Last revised
- Identity
ciscoIkeConfigMIB- Base OID
1.3.6.1.4.1.9.9.423
Imported Objects
| CISCO-IPSEC-TC | CIKEIsakmpDoi CIKELifesize CIKELifetime CIPsecControlProtocol CIPsecDiffHellmanGrp CIPsecEncryptAlgorithm CIPsecIkeAuthMethod CIPsecIkeHashAlgorithm CIPsecIkePRFAlgorithm CIPsecPhase1PeerIdentityType |
| CISCO-SMI | ciscoMgmt |
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | RowStatus TEXTUAL-CONVENTION (no object page) TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IKE-CONFIGURATION-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IKE-CONFIGURATION-MIB::ciscoIkeConfigMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IKE-CONFIGURATION-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IKE-CONFIGURATION-MIB::ciscoIkeConfigMIB'
Objects (72)
Showing 72 of 72 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.423 |
||
.1.3.6.1.4.1.9.9.423.0 |
||
.1.3.6.1.4.1.9.9.423.1 |
||
.1.3.6.1.4.1.9.9.423.1.1 |
||
|
|
.1.3.6.1.4.1.9.9.423.1.1.1 |
|
.1.3.6.1.4.1.9.9.423.1.1.2 |
||
.1.3.6.1.4.1.9.9.423.1.2 |
||
.1.3.6.1.4.1.9.9.423.1.2.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.1.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.1.1.2 |
||
.1.3.6.1.4.1.9.9.423.1.2.2 |
||
.1.3.6.1.4.1.9.9.423.1.2.2.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.2.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.3 |
||
.1.3.6.1.4.1.9.9.423.1.2.3.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.3.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.2.3.1.2 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.423.1.2.3.1.3 |
|
.1.3.6.1.4.1.9.9.423.1.2.3.1.4 |
||
.1.3.6.1.4.1.9.9.423.1.2.3.1.5 |
||
.1.3.6.1.4.1.9.9.423.1.3 |
||
.1.3.6.1.4.1.9.9.423.1.3.1 |
||
.1.3.6.1.4.1.9.9.423.1.3.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.3.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.423.1.3.1.1.2 |
|
|
secondsUnsigned32
|
.1.3.6.1.4.1.9.9.423.1.3.1.1.3 |
|
|
secondsUnsigned32
|
.1.3.6.1.4.1.9.9.423.1.3.1.1.4 |
|
.1.3.6.1.4.1.9.9.423.1.3.1.1.5 |
||
.1.3.6.1.4.1.9.9.423.1.4 |
||
.1.3.6.1.4.1.9.9.423.1.4.1 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.1.1.1 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.1 |
||
|
|
OctetString
|
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.2 |
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.3 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.4 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.5 |
|
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.6 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.7 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.8 |
||
.1.3.6.1.4.1.9.9.423.1.4.1.2.1.9 |
||
.1.3.6.1.4.1.9.9.423.1.4.2 |
||
.1.3.6.1.4.1.9.9.423.1.4.3 |
||
.1.3.6.1.4.1.9.9.423.1.5 |
||
.1.3.6.1.4.1.9.9.423.1.5.1 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.423.1.5.1.1.1 |
|
.1.3.6.1.4.1.9.9.423.1.5.1.1.2 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1.3 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1.4 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1.5 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1.6 |
||
|
secondsCISCO-IPSEC-TCCIKELifetime
|
.1.3.6.1.4.1.9.9.423.1.5.1.1.7 |
|
.1.3.6.1.4.1.9.9.423.1.5.1.1.8 |
||
.1.3.6.1.4.1.9.9.423.1.5.1.1.9 |
||
.1.3.6.1.4.1.9.9.423.1.6 |
||
.1.3.6.1.4.1.9.9.423.1.6.1 |
||
.1.3.6.1.4.1.9.9.423.1.6.2 |
||
.1.3.6.1.4.1.9.9.423.1.7 |
||
.1.3.6.1.4.1.9.9.423.1.7.1 |
||
.1.3.6.1.4.1.9.9.423.1.7.2 |
||
.1.3.6.1.4.1.9.9.423.1.7.3 |
||
.1.3.6.1.4.1.9.9.423.1.7.4 |
||
.1.3.6.1.4.1.9.9.423.1.7.5 |
||
.1.3.6.1.4.1.9.9.423.1.7.6 |
||
.1.3.6.1.4.1.9.9.423.2 |
||
.1.3.6.1.4.1.9.9.423.2.1 |
||
.1.3.6.1.4.1.9.9.423.2.2 |
Dependencies (6) 6 direct Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-IPSEC-TCcisco
- INET-ADDRESS-MIBrfc
- SNMPv2-CONFrfc
- CISCO-IKE-CONFIGURATION-MIBciscoselected
Type Definitions (2)
| Unsigned32 |
range: 1..65535 |
|
| Unsigned32 |
range: 1..65535 |
Conformance Groups (8)
|
This group consists of objects that reflect the
operational state of the IKE entity on the managed device. |
.1.3.6.1.4.1.9.9.423.2.1.1
|
|
|
cicIkeCfgIdentityType cicIkeCfgInitiatorNextAvailIndex cicIkeCfgInitiatorPAddrType cicIkeCfgInitiatorPAddr cicIkeCfgInitiatorVer cicIkeCfgInitiatorStatus
This group consists of objects that reflect the
Phase 1 ID used by the IKE entity on the managed device. |
.1.3.6.1.4.1.9.9.423.2.1.2
|
|
|
cicIkeKeepAliveEnabled cicIkeKeepAliveType cicIkeKeepAliveInterval cicIkeKeepAliveRetryInterval cicIkeInvalidSpiNotify
This group consists of objects that define how the
local IKE entity is configured to respond to common failures. |
.1.3.6.1.4.1.9.9.423.2.1.3
|
|
|
cicIkeCfgPskNextAvailIndex cicIkeCfgPskKey cicIkeCfgPskRemIdentType cicIkeCfgPskRemIdentTypeStand cicIkeCfgPskRemIdentity cicIkeCfgPskRemIdAddrOrRg1OrSn cicIkeCfgPskRemIdAddrRange2 cicIkeCfgPskRemIdSubnetMask cicIkeCfgPskStatus
This group consists of objects that are used to
view and configure the preshared keys configured on the managed entity. |
.1.3.6.1.4.1.9.9.423.2.1.4
|
|
|
cicIkeCfgPolicyEncr cicIkeCfgPolicyHash cicIkeCfgPolicyPRF cicIkeCfgPolicyAuth cicIkeCfgPolicyDHGroup cicIkeCfgPolicyLifetime cicIkeCfgPolicyStatus
This group consists of objects that are used to
view and configure the ISAKMP policies configured on the managed device. |
.1.3.6.1.4.1.9.9.423.2.1.5
|
|
|
This group consists of objects pertaining to ISAKMP
policy management which are optional and may not be supported by every implementation of IKE. |
.1.3.6.1.4.1.9.9.423.2.1.6
|
|
|
cicNotifCntlIkeAllNotifs cicNotifCntlIkeOperStateChanged cicNotifCntlIkePskAdded cicNotifCntlIkePskDeleted cicNotifCntlIkePolicyAdded cicNotifCntlIkePolicyDeleted
This group of objects controls the sending
of notifications to signal the state of Phase-1 IKE configuration on the managed device. |
.1.3.6.1.4.1.9.9.423.2.1.7
|
|
|
ciscoIkeConfigOperStateChanged ciscoIkeConfigPskAdded ciscoIkeConfigPskDeleted ciscoIkeConfigPolicyAdded ciscoIkeConfigPolicyDeleted
This group contains the notifications to signal the
changes to IKE on the managed device. |
.1.3.6.1.4.1.9.9.423.2.1.8
|
Compliance Statements (1)
OID
.1.3.6.1.4.1.9.9.423.2.2.1The compliance statement for SNMP entities
the Internet Key Exchange Protocol
configuration MIB.
the Internet Key Exchange Protocol
configuration MIB.
Required groups
| mandatory | cicIkeCfgOperGroup | |
| mandatory | cicIkeCfgIdentitiesGroup | |
| mandatory | cicIkeCfgPskAuthGroup | |
| mandatory | cicIkeCfgPolicyGroup | |
| optional | cicIkeCfgOptionalPolicyGroup | This group is optional. |
| optional | cicIkeCfgFailureRecoveryGroup |
This group is conditionally mandatory and must be implemented by the agent of the managed entity if and only if a) the managed entity implements Internet Key Exchange keepalive operations or b) the managed entity implements IKE failure signaling (such as the Invalid SPI notification). |
| optional | cicIkeCfgNotificationGroup | This group is optional. |
| optional | cicIkeCfgNotifCntlGroup |
The agent must implement this group if it implements the group 'cicIkeCfgNotificationGroup'. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cicIkeEnabled | readonly | Write access is not required. | |
| cicIkeAggressModeEnabled | readonly | Write access is not required. | |
| cicIkeKeepAliveEnabled | readonly | Write access is not required. | |
| cicIkeKeepAliveType | readonly | Write access is not required. | |
| cicIkeKeepAliveInterval | readonly | Write access is not required. It is compliant to support only a subset of the values in the range defined. |
|
| cicIkeKeepAliveRetryInterval | readonly | Write access is not required. It is compliant to support only a subset of the values in the range defined. |
|
| cicIkeInvalidSpiNotify | readonly | Write access is not required. | |
| cicIkeCfgPskKey | readonly | Write access is not required. | |
| cicIkeCfgPskRemIdentType | readonly | Write access is not required. Note that an implementation need not support all identity types listed in the definition of the textual convention CIPsecPhase1PeerIdentityType. |
|
| cicIkeCfgPskRemIdentity | readonly | Write access is not required. | |
| cicIkeCfgPskRemIdAddrOrRg1OrSn | readonly | Write access is not required. | |
| cicIkeCfgPskRemIdAddrRange2 | readonly | Write access is not required. | |
| cicIkeCfgPskRemIdSubnetMask | readonly | Write access is not required. | |
| cicIkeCfgPskStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported if write is supported. |
| cicIkeCfgPolicyStatus |
active(1), createAndGo(4), destroy(6)
|
Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported if write is supported. |
|
| cicNotifCntlIkeAllNotifs | readonly | Write access is not required. | |
| cicNotifCntlIkeOperStateChanged | readonly | Write access is not required. | |
| cicNotifCntlIkePskAdded | readonly | Write access is not required. | |
| cicNotifCntlIkePskDeleted | readonly | Write access is not required. | |
| cicNotifCntlIkePolicyAdded | readonly | Write access is not required. | |
| cicNotifCntlIkePolicyDeleted | readonly | Write access is not required. | |
| cicIkeCfgInitiatorPAddrType | readonly | Write access is not required. | |
| cicIkeCfgInitiatorPAddr | readonly | Write access is not required. | |
| cicIkeCfgInitiatorVer | readonly | Write access is not required. | |
| cicIkeCfgInitiatorStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported if write is supported. |
Notifications / Traps (5)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.423.0.1 |
The notification is generated when the operational
state of IKE entity on the managed device has been changed. |
|
.1.3.6.1.4.1.9.9.423.0.2 |
This notification is generated when a new preshared
key is configured on the managed device. |
|
.1.3.6.1.4.1.9.9.423.0.3 |
This notification is generated when an existing
preshared key is configured on the managed device is about to be deleted. |
|
.1.3.6.1.4.1.9.9.423.0.4 |
This notification is generated when a new ISAKMP
policy is configured on the managed device. |
|
.1.3.6.1.4.1.9.9.423.0.5 |
This notification is issued when an existing ISAKMP
policy configured on the managed device is about to be deleted. |