CISCO-IPSEC-FLOW-MONITOR-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
13
Rows
13
Columns
290
.1.3.6.1.4.1.9.9.171.1.2.2 · 1 row entry · 9 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikePeerTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikePeerTable'
The IPsec Phase-1 Internet Key Exchange Peer Table.
There is one entry in this table for each IPsec
Phase-1 IKE peer association which is currently
associated with an active IPsec Phase-1 Tunnel.
The IPsec Phase-1 IKE Tunnel associated with this
IPsec Phase-1 IKE peer association may or may not
be currently active.
cikePeerEntry row .1.3.6.1.4.1.9.9.171.1.2.2.1
Each entry contains the attributes associated
with an IPsec Phase-1 IKE peer association.
Column Syntax OID
The type of local peer identity. The local peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.2.1.1
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is a host name, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.2.1.2
The type of remote peer identity. The remote peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.2.1.3
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is a host name, then t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.2.1.4
The internal index of the local-remote
peer association. This internal index is used
to uniquely identify multiple associations between
the local and remote peer.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.2.1.5
The IP address of the local peer.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.2.2.1.6
The IP address of the remote peer.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.2.2.1.7
The length of time that the peer association has
existed in hundredths of a second.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.171.1.2.2.1.8
The index of the active IPsec Phase-1 IKE Tunnel
(cikeTunIndex in the cikeTunnelTable) for this peer
association. If an IPsec Phase-1 IKE Tunnel is
not currently active, then the value of this
object will be zero.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.2.1.9
.1.3.6.1.4.1.9.9.171.1.2.3 · 1 row entry · 35 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikeTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikeTunnelTable'
The IPsec Phase-1 Internet Key Exchange Tunnel Table.
There is one entry in this table for each active IPsec
Phase-1 IKE Tunnel.
cikeTunnelEntry row .1.3.6.1.4.1.9.9.171.1.2.3.1
Each entry contains the attributes associated with
an active IPsec Phase-1 IKE Tunnel.
Indexes
Column Syntax OID
The index of the IPsec Phase-1 IKE Tunnel Table.
The value of the index is a number which begins
at one and is incremented with each tunnel that
is created. The value of this object will
wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.3.1.1
The type of local peer identity. The local
peer may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.3.1.2
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is a host name, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.3.1.3
The IP address of the local endpoint for the IPsec
Phase-1 IKE Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.2.3.1.4
The DNS name of the local IP address for
the IPsec Phase-1 IKE Tunnel. If the DNS
name associated with the local tunnel endpoint
is not known, then the value of this
object will be a NULL string.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.3.1.5
The type of remote peer identity.
The remote peer may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.3.1.6
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is a host name, then
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.3.1.7
The IP address of the remote endpoint for the IPsec
Phase-1 IKE Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.2.3.1.8
The DNS name of the remote IP address of IPsec Phase-1
IKE Tunnel. If the DNS name associated with the remote
tunnel endpoint is not known, then the value of this
object will be a NULL string.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.3.1.9
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
IkeNegoMode
Type Values:
1main
2aggressive
.1.3.6.1.4.1.9.9.171.1.2.3.1.10
The Diffie Hellman Group used in IPsec Phase-1 IKE
negotiations.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.2.3.1.11
The encryption algorithm used in IPsec Phase-1 IKE
negotiations.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.2.3.1.12
The hash algorithm used in IPsec Phase-1 IKE
negotiations.
IkeHashAlgo
Type Values:
1none
2md5
3sha
.1.3.6.1.4.1.9.9.171.1.2.3.1.13
The authentication method used in IPsec Phase-1 IKE
negotiations.
IkeAuthMethod
Type Values:
1none
2preSharedKey
3rsaSig
4rsaEncrypt
5revPublicKey
.1.3.6.1.4.1.9.9.171.1.2.3.1.14
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel
in seconds.
secondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.3.1.15
The length of time the IPsec Phase-1 IKE tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.171.1.2.3.1.16
The security association refresh threshold in seconds.
secondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.3.1.17
The total number of security associations
refreshes performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.18
The total number of octets received by
this IPsec Phase-1 IKE Tunnel.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.19
The total number of packets received by
this IPsec Phase-1 IKE Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.20
The total number of packets dropped
by this IPsec Phase-1 IKE Tunnel during
receive processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.21
The total number of notifys received by
this IPsec Phase-1 IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.22
The total number of IPsec Phase-2
exchanges received by
this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.23
The total number of IPsec Phase-2
exchanges received and found to be invalid
by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.24
The total number of IPsec Phase-2 exchanges
received and rejected by this IPsec Phase-1
Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.25
The total number of IPsec Phase-2
security association delete requests received
by this IPsec Phase-1 IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.26
The total number of octets sent by this IPsec Phase-1
IKE Tunnel.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.27
The total number of packets sent by this IPsec Phase-1
IKE Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.28
The total number of packets dropped by this
IPsec Phase-1 IKE Tunnel during send processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.29
The total number of notifys sent by this
IPsec Phase-1 Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.30
The total number of IPsec Phase-2 exchanges sent by
this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.31
The total number of IPsec Phase-2 exchanges sent and
found to be invalid by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.32
The total number of IPsec Phase-2 exchanges sent and
rejected by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.33
The total number of IPsec Phase-2 security association
delete requests sent by this IPsec Phase-1 IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.3.1.34
The status of the MIB table row.

This object can be used to bring the tunnel down
by setting value of this object to destroy(2).

This object cannot be used to create
a MIB table row.
TunnelStatusr/w
Type Values:
1active
2destroy
.1.3.6.1.4.1.9.9.171.1.2.3.1.35
.1.3.6.1.4.1.9.9.171.1.2.4 · 1 row entry · 7 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikePeerCorrTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikePeerCorrTable'
The IPsec Phase-1 Internet Key Exchange Peer
Association to IPsec Phase-2 Tunnel
Correlation Table. There is one entry in
this table for each active IPsec Phase-2
Tunnel.
cikePeerCorrEntry row .1.3.6.1.4.1.9.9.171.1.2.4.1
Each entry contains the attributes of an
IPsec Phase-1 IKE Peer Association to IPsec
Phase-2 Tunnel Correlation.
Column Syntax OID
The type of local peer identity. The local peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.4.1.1
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is a host name, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.4.1.2
The type of remote peer identity. The remote peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.2.4.1.3
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is a host name, then t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.2.4.1.4
The internal index of the local-remote
peer association. This internal index is
used to uniquely identify multiple associations
between the local and remote peer.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.4.1.5
The sequence number of the local-remote
peer association. This sequence number is
used to uniquely identify multiple instances
of an unique association between
the local and remote peer.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.4.1.6
The index of the active IPsec Phase-2 Tunnel
(cipSecTunIndex in the cipSecTunnelTable) for this
IPsec Phase-1 IKE Peer Association.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.2.4.1.7
.1.3.6.1.4.1.9.9.171.1.2.5 · 1 row entry · 26 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikePhase1GWStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikePhase1GWStatsTable'
Phase-1 IKE stats information is included in this table.
Each entry is related to a specific gateway which is 
identified by 'cmgwIndex'.
cikePhase1GWStatsEntry row .1.3.6.1.4.1.9.9.171.1.2.5.1
Each entry contains the attributes of an Phase-1 IKE stats
information for the related gateway.

There is only one entry for each gateway. The entry
is created when a gateway up and cannot be deleted.
Column Syntax OID
The number of currently active IPsec
Phase-1 IKE Tunnels.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.1
The total number of previously active
IPsec Phase-1 IKE Tunnels.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.2
The total number of octets received by all currently
and previously active IPsec Phase-1 IKE Tunnels.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.3
The total number of packets received by all
currently and previously active IPsec
Phase-1 IKE Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.4
The total number of packets which were
dropped during receive processing by all
currently and previously
active IPsec Phase-1 IKE Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.5
The total number of notifys received by
all currently and previously active IPsec
Phase-1 IKE Tunnels.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.6
The total number of IPsec Phase-2 exchanges
received by all currently and previously
active IPsec Phase-1 IKE Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.7
The total number of IPsec Phase-2 exchanges
which were received and found to be invalid
by all currently and previously active IPsec
Phase-1 IKE Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.8
The total number of IPsec Phase-2 exchanges
which were received and rejected by all
currently and previously active IPsec Phase-1
IKE Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.9
The total number of IPsec Phase-2 'Security
Association' delete requests received by all
currently and previously active and IPsec
Phase-1 IKE Tunnels.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.10
The total number of octets sent by all currently
and previously active and IPsec Phase-1
IKE Tunnels.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.11
The total number of packets sent by all currently
and previously active and IPsec Phase-1
Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.12
The total number of packets which were dropped
during send processing by all currently
and previously
active IPsec Phase-1 IKE Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.13
The total number of notifys sent by all currently
and previously active IPsec Phase-1 IKE Tunnels.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.14
The total number of IPsec Phase-2 exchanges
which were sent by all currently and previously
active IPsec Phase-1 IKE Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.15
The total number of IPsec Phase-2 exchanges
which were sent and found to be invalid by
all currently and previously active IPsec Phase-1
Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.16
The total number of IPsec Phase-2 exchanges
which were sent and rejected by all currently and
previously active IPsec Phase-1 IKE Tunnels.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.17
The total number of IPsec Phase-2 SA
delete requests sent by all currently and
previously active IPsec Phase-1 IKE Tunnels.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.18
The total number of IPsec Phase-1 IKE
Tunnels which were locally initiated.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.19
The total number of IPsec Phase-1 IKE Tunnels
which were locally initiated and failed to activate.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.20
The total number of IPsec Phase-1 IKE Tunnels
which were remotely initiated and failed to activate.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.21
The total number of system capacity failures
which occurred during processing of all current
and previously active IPsec Phase-1 IKE Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.22
The total number of authentications which ended
in failure by all current and previous IPsec Phase-1
IKE Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.23
The total number of decryptions which ended
in failure by all current and previous IPsec Phase-1
IKE Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.24
The total number of hash validations which ended
in failure by all current and previous IPsec Phase-1
IKE Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.25
The total number of non-existent 'Security Association'
failures occurred during processing of current and
previous IPsec Phase-1 IKE Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.2.5.1.26
.1.3.6.1.4.1.9.9.171.1.3.2 · 1 row entry · 51 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecTunnelTable'
The IPsec Phase-2 Tunnel Table.
There is one entry in this table for 
each active IPsec Phase-2 Tunnel.
cipSecTunnelEntry row .1.3.6.1.4.1.9.9.171.1.3.2.1
Each entry contains the attributes
associated with an active IPsec Phase-2 Tunnel.
Indexes
Column Syntax OID
The index of the IPsec Phase-2 Tunnel Table.
The value of the index is a number which begins
at one and is incremented with each tunnel that
is created. The value of this object will wrap
at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.1
The index of the associated IPsec Phase-1
IKE Tunnel.
(cikeTunIndex in the cikeTunnelTable)
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.2
An indicator which specifies whether or not the
IPsec Phase-1 IKE Tunnel currently exists.
SNMPv2-TCTruthValue
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.171.1.3.2.1.3
The IP address of the local endpoint for the IPsec
Phase-2 Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.2.1.4
The IP address of the remote endpoint for the IPsec
Phase-2 Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.2.1.5
The type of key used by the IPsec Phase-2 Tunnel.
KeyType
Type Values:
1ike
2manual
.1.3.6.1.4.1.9.9.171.1.3.2.1.6
The encapsulation mode used by the
IPsec Phase-2 Tunnel.
EncapMode
Type Values:
1tunnel
2transport
.1.3.6.1.4.1.9.9.171.1.3.2.1.7
The negotiated LifeSize of the
IPsec Phase-2 Tunnel in kilobytes.
KBytesInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.8
The negotiated LifeTime of the
IPsec Phase-2 Tunnel in seconds.
SecondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.9
The length of time the IPsec Phase-2
Tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.171.1.3.2.1.10
The security association LifeSize refresh
threshold in kilobytes.
KBytesInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.11
The security association LifeTime refresh
threshold in seconds.
SecondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.2.1.12
The total number of security
association refreshes performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.13
The total number of security associations
which have expired.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.14
The number of security associations
which are currently active or expiring.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.15
The Diffie Hellman Group used
by the inbound security association of the
IPsec Phase-2 Tunnel.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.3.2.1.16
The encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.3.2.1.17
The authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.3.2.1.18
The authentication algorithm used by the inbound
encapsulation security protocol (ESP) security
association of the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.3.2.1.19
The decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CompAlgo
Type Values:
1none
2ldf
.1.3.6.1.4.1.9.9.171.1.3.2.1.20
The Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.3.2.1.21
The encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.3.2.1.22
The authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.3.2.1.23
The authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.3.2.1.24
The compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CompAlgo
Type Values:
1none
2ldf
.1.3.6.1.4.1.9.9.171.1.3.2.1.25
The total number of octets received by this IPsec
Phase-2 Tunnel. This value is accumulated
BEFORE determining whether or not the packet should be
decompressed. See also cipSecTunInOctWraps for the
number of times thi…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.26
A high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value is
accumulated BEFORE determining whether or not the packet
should be decompressed.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.3.2.1.27
The number of times the octets received counter
(cipSecTunInOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.28
The total number of decompressed octets received
by this IPsec Phase-2 Tunnel. This value is
accumulated AFTER the packet is decompressed.
If compression is not being
used, this value will match the value of
cipSec…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.29
A high capacity count of the total number of decompressed
octets received by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will matc…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.3.2.1.30
The number of times the decompressed
octets received counter
(cipSecTunInDecompOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.31
The total number of packets received
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.32
The total number of packets dropped
during receive processing by this IPsec Phase-2
Tunnel. This count does NOT include
packets dropped due to Anti-Replay processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.33
The total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.34
The total number of inbound
authentication's performed by this
IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.35
The total number of inbound authentication's
which ended in
failure by this IPsec Phase-2 Tunnel .
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.36
The total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.37
The total number of inbound decryption's
which ended in failure
by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.38
The total number of octets sent by this IPsec
Phase-2 Tunnel. This value is accumulated
AFTER determining whether or not the packet should
be compressed. See also cipSecTunOutOctWraps for
the number of times this cou…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.39
A high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value is
accumulated AFTER determining whether or not the
packet
should be compressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.3.2.1.40
The number of times the out octets counter
(cipSecTunOutOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.41
The total number of uncompressed octets sent
by this IPsec Phase-2 Tunnel. This value
is accumulated BEFORE the packet is compressed.
If compression is not being used, this value
will match the value of cipSecTunOut…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.42
A high capacity count of the total number
of uncompressed octets sent by this IPsec
Phase-2 Tunnel. This value is accumulated BEFORE
the packet is compressed. If compression
is not being used, this value will match …
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.3.2.1.43
The number of times the uncompressed octets sent
counter (cipSecTunOutUncompOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.44
The total number of packets sent by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.45
The total number of packets dropped during
send processing by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.46
The total number of outbound authentication's performed
by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.47
The total number of outbound
authentication's which ended in failure
by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.48
The total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.49
The total number of outbound encryption's
which ended in failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.2.1.50
The status of the MIB table row.

This object can be used to bring the tunnel down
by setting value of this object to destroy(2).
When the value is set to destroy(2), the SA
bundle is destroyed and this ro…
TunnelStatusr/w
Type Values:
1active
2destroy
.1.3.6.1.4.1.9.9.171.1.3.2.1.51
.1.3.6.1.4.1.9.9.171.1.3.3 · 1 row entry · 13 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecEndPtTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecEndPtTable'
The IPsec Phase-2 Tunnel Endpoint Table.
This table contains an entry for each 
active endpoint associated with an IPsec
 Phase-2 Tunnel.
cipSecEndPtEntry row .1.3.6.1.4.1.9.9.171.1.3.3.1
An IPsec Phase-2 Tunnel Endpoint entry.
Column Syntax OID
The number of the Endpoint associated with the
IPsec Phase-2 Tunnel Table. The value of this
index is a number which begins at one and
is incremented with each Endpoint associated
with an IPsec Phase-2 Tunnel.
The va…
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.3.1.1
The DNS name of the local Endpoint.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.3.3.1.2
The type of identity for the local Endpoint.
Possible values are:
1) a single IP address, or
2) an IP address range, or
3) an IP subnet.
EndPtType
Type Values:
1singleIpAddr
2ipAddrRange
3ipSubnet
.1.3.6.1.4.1.9.9.171.1.3.3.1.3
The local Endpoint's first IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, the…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.3.1.4
The local Endpoint's second IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, th…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.3.1.5
The protocol number of the local Endpoint's traffic.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.171.1.3.3.1.6
The port number of the local Endpoint's traffic.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.171.1.3.3.1.7
The DNS name of the remote Endpoint.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.3.3.1.8
The type of identity for the remote Endpoint.
Possible values are:
1) a single IP address, or
2) an IP address range, or
3) an IP subnet.
EndPtType
Type Values:
1singleIpAddr
2ipAddrRange
3ipSubnet
.1.3.6.1.4.1.9.9.171.1.3.3.1.9
The remote Endpoint's first IP address specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet, …
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.3.1.10
The remote Endpoint's second IP address specification.

If the remote Endpoint type is single IP address,
then this is the value of the IP address.

If the remote Endpoint type is IP subnet,…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.3.3.1.11
The protocol number of the remote Endpoint's traffic.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.171.1.3.3.1.12
The port number of the remote Endpoint's traffic.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.171.1.3.3.1.13
.1.3.6.1.4.1.9.9.171.1.3.4 · 1 row entry · 5 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecSpiTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecSpiTable'
The IPsec Phase-2 Security Protection Index Table.
This table contains an entry for each active 
and expiring security
 association.
cipSecSpiEntry row .1.3.6.1.4.1.9.9.171.1.3.4.1
Each entry contains the attributes associated with
active and expiring IPsec Phase-2
security associations.
Column Syntax OID
The number of the SPI associated with the
Phase-2 Tunnel Table. The value of this
index is a number which begins at one and is
incremented with each SPI associated with an
IPsec Phase-2 Tunnel. The value of this
o…
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.3.4.1.1
The direction of the SPI.
Enumeration
Enumerated Values:
1in
2out
.1.3.6.1.4.1.9.9.171.1.3.4.1.2
The value of the SPI.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.9.9.171.1.3.4.1.3
The protocol of the SPI.
Enumeration
Enumerated Values:
1ah
2esp
3ipcomp
.1.3.6.1.4.1.9.9.171.1.3.4.1.4
The status of the SPI.
Enumeration
Enumerated Values:
1active
2expiring
.1.3.6.1.4.1.9.9.171.1.3.4.1.5
.1.3.6.1.4.1.9.9.171.1.3.5 · 1 row entry · 26 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecPhase2GWStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecPhase2GWStatsTable'
Phase-2 IPsec stats information is included in this table.
Each entry is related to a specific gateway which is 
identified by 'cmgwIndex'
cipSecPhase2GWStatsEntry row .1.3.6.1.4.1.9.9.171.1.3.5.1
Each entry contains the attributes of an Phase-2 IPsec stats
information for the related gateway.

There is only one entry for each gateway. The entry
is created when a gateway up and cannot be deleted.
Column Syntax OID
The total number of currently active
IPsec Phase-2 Tunnels.
SNMPv2-SMIGauge32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.1
The total number of previously active
IPsec Phase-2 Tunnels.
Phase-2 TunnelsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.2
The total number of octets received by all
current and previous IPsec Phase-2 Tunnels.
This value is accumulated BEFORE determining
whether or not the packet should be decompressed.
See also cipSecGlobalInOctWraps fo…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.3
The number of times the global octets received
counter (cipSecGlobalInOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.4
The total number of decompressed octets received
by all current and previous IPsec Phase-2 Tunnels.
This value is accumulated AFTER the packet is
decompressed. If compression is not being used,
this value will match…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.5
The number of times the global decompressed
octets received counter (cipSecGlobalInDecompOctets)
has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.6
The total number of packets received
by all current and previous IPsec Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.7
The total number of packets dropped
during receive processing by all current and previous
IPsec Phase-2 Tunnels. This count does NOT include
packets dropped due to Anti-Replay processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.8
The total number of packets dropped during
receive processing due to Anti-Replay
processing by all current and previous IPsec
Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.9
The total number of inbound authentication's
performed by all current and previous IPsec
Phase-2 Tunnels.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.10
The total number of inbound authentication's
which ended in failure by all current and previous
IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.11
The total number of inbound decryption's
performed by all current and previous IPsec
Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.12
The total number of inbound decryption's
which ended in failure by all current and
previous IPsec Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.13
The total number of octets sent by all
current and previous IPsec Phase-2 Tunnels.
This value is accumulated AFTER determining
whether or not the packet should be compressed.
See also cipSecGlobalOutOctWraps for th…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.14
The number of times the global octets sent counter
(cipSecGlobalOutOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.15
The total number of uncompressed octets sent
by all current and previous IPsec Phase-2 Tunnels.
This value is accumulated BEFORE the packet is
compressed. If compression is not being used, this
value will match the …
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.16
The number of times the global uncompressed
octets sent counter (cipSecGlobalOutUncompOctets)
has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.17
The total number of packets sent by all
current and previous IPsec Phase-2
Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.18
The total number of packets dropped during send
processing by all current and previous IPsec
Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.19
The total number of outbound authentication's
performed by all current and previous IPsec
Phase-2 Tunnels.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.20
The total number of outbound authentication's
which ended in failure
by all current and previous IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.21
The total number of outbound encryption's performed
by all current and previous IPsec Phase-2 Tunnels.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.22
The total number of outbound encryption's
which ended in failure by all current and
previous IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.23
The total number of protocol use failures
which occurred during processing of all current
and previously active IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.24
The total number of non-existent
Security Association in failures which occurred
during processing of all current
and previous IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.25
The total number of system capacity failures
which occurred during processing of all current
and previously active IPsec Phase-2 Tunnels.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.3.5.1.26
.1.3.6.1.4.1.9.9.171.1.4.2.1 · 1 row entry · 38 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikeTunnelHistTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikeTunnelHistTable'
The IPsec Phase-1 Internet Key Exchange Tunnel
History Table.  This table is implemented as a 
sliding window in which only the last n entries 
are maintained.  The maximum number of entries
 is specified by the cipSecHistTableSize object.
cikeTunnelHistEntry row .1.3.6.1.4.1.9.9.171.1.4.2.1.1
Each entry contains the attributes
associated with a previously active IPsec
Phase-1 IKE Tunnel.
Column Syntax OID
The index of the IPsec Phase-1 IKE Tunnel History
Table. The value of the index is a number which
begins at one and is incremented with each
tunnel that ends. The value of this object
will wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.1
The reason the IPsec Phase-1 IKE Tunnel was terminated.
Possible reasons include:
1 = other
2 = normal termination
3 = operator request
4 = peer delete request was received
5 = contact with peer was lost
6 = local failu…
Enumeration
Enumerated Values:
1other
2normal
3operRequest
4peerDelRequest
5peerLost
6localFailure
7checkPointReg
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.2
The index of the previously active IPsec
Phase-1 IKE Tunnel.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.3
The type of local peer identity. The local peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.4
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is a host name, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.5
The internal index of the local-remote peer
association. This internal index is used to
uniquely identify multiple associations between
the local and remote peer.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.6
The type of remote peer identity. The remote
peer may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.7
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is a host name, then t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.8
The IP address of the local endpoint for the IPsec
Phase-1 IKE Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.9
The DNS name of the local IP address for
the IPsec Phase-1 IKE Tunnel. If the DNS
name associated with the local tunnel endpoint
is not known, then the value of this
object will be a NULL string.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.10
The IP address of the remote endpoint for the IPsec
Phase-1 IKE Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.11
The DNS name of the remote IP address of IPsec Phase-1
IKE Tunnel. If the DNS name associated with the remote
tunnel endpoint is not known, then the value of this
object will be a NULL string.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.12
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
IkeNegoMode
Type Values:
1main
2aggressive
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.13
The Diffie Hellman Group used in IPsec Phase-1 IKE
negotiations.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.14
The encryption algorithm used in IPsec Phase-1 IKE
negotiations.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.15
The hash algorithm used in IPsec Phase-1 IKE
negotiations.
IkeHashAlgo
Type Values:
1none
2md5
3sha
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.16
The authentication method used in IPsec Phase-1 IKE
negotiations.
IkeAuthMethod
Type Values:
1none
2preSharedKey
3rsaSig
4rsaEncrypt
5revPublicKey
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.17
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel
in seconds.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.18
The value of sysUpTime in hundredths of seconds
when the IPsec Phase-1 IKE tunnel was started.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.19
The length of time the IPsec Phase-1 IKE tunnel was been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.20
The total number of security associations
refreshes performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.21
The total number of security associations
used during the
life of the IPsec Phase-1 IKE Tunnel.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.22
The total number of octets
received by this IPsec Phase-1
IKE Tunnel.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.23
The total number of packets received
by this IPsec Phase-1
IKE Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.24
The total number of packets dropped
by this IPsec Phase-1
IKE Tunnel during receive processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.25
The total number of notifys received
by this IPsec Phase-1
IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.26
The total number of IPsec Phase-2
exchanges received by
this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.27
The total number of IPsec Phase-2
exchanges received and
found to be invalid by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.28
The total number of IPsec Phase-2
exchanges received and
rejected by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.29
The total number of IPsec Phase-2 security association
delete requests received by this IPsec
Phase-1 IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.30
The total number of octets sent by this IPsec Phase-1
IKE Tunnel.
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.31
The total number of packets sent by this IPsec Phase-1
IKE Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.32
The total number of packets dropped
by this IPsec Phase-1
IKE Tunnel during send processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.33
The total number of notifys sent by this IPsec Phase-1
IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.34
The total number of IPsec Phase-2 exchanges sent by
this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.35
The total number of IPsec Phase-2 exchanges sent and
found to be invalid by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.36
The total number of IPsec Phase-2 exchanges sent and
rejected by this IPsec Phase-1 IKE Tunnel.
SA PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.37
The total number of IPsec Phase-2 security association
delete requests sent by this IPsec Phase-1 IKE Tunnel.
Notification PayloadsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.2.1.1.38
.1.3.6.1.4.1.9.9.171.1.4.3.1 · 1 row entry · 49 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecTunnelHistTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecTunnelHistTable'
The IPsec Phase-2 Tunnel History Table.
This table is implemented as a sliding 
window in which only the
last n entries are maintained.  The maximum number 
of entries
is specified by the cipSecHistTableSize object.
cipSecTunnelHistEntry row .1.3.6.1.4.1.9.9.171.1.4.3.1.1
Each entry contains the attributes associated with
a previously active IPsec Phase-2 Tunnel.
Column Syntax OID
The index of the IPsec Phase-2 Tunnel History Table.
The value of the index is a number which
begins at one and is incremented with each tunnel
that ends. The value
of this object will wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.1
The reason the IPsec Phase-2 Tunnel was terminated.
Possible reasons include:
1 = other
2 = normal termination
3 = operator request
4 = peer delete request was received
5 = contact with peer was lost
6 = local failure o…
Enumeration
Enumerated Values:
1other
2normal
3operRequest
4peerDelRequest
5peerLost
6seqNumRollOver
7checkPointReq
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.2
The index of the previously active
IPsec Phase-2 Tunnel.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.3
The index of the associated IPsec Phase-1 Tunnel
(cikeTunIndex in the cikeTunnelTable).
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.4
The IP address of the local endpoint for the IPsec
Phase-2 Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.5
The IP address of the remote endpoint for the IPsec
Phase-2 Tunnel.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.6
The type of key used by the IPsec Phase-2 Tunnel.
KeyType
Type Values:
1ike
2manual
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.7
The encapsulation mode used by the
IPsec Phase-2 Tunnel.
EncapMode
Type Values:
1tunnel
2transport
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.8
The negotiated LifeSize of the IPsec Phase-2 Tunnel in
kilobytes.
KBytesInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.9
The negotiated LifeTime of the IPsec Phase-2 Tunnel in
seconds.
SecondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.10
The value of sysUpTime in hundredths of seconds
when the IPsec Phase-2 Tunnel was started.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.11
The length of time the IPsec Phase-2 Tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.12
The total number of security association refreshes
performed.
QM ExchangesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.13
The total number of security associations used
during the
life of the IPsec Phase-2 Tunnel.
SAsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.14
The Diffie Hellman Group used by the inbound security
association of the IPsec Phase-2 Tunnel.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.15
The encryption algorithm used by the inbound security
association of the IPsec Phase-2 Tunnel.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.16
The authentication algorithm used by the inbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.17
The authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of
the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.18
The decompression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CompAlgo
Type Values:
1none
2ldf
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.19
The Diffie Hellman Group used by the outbound security
association of the IPsec Phase-2 Tunnel.
DiffHellmanGrp
Type Values:
1none
2dhGroup1
3dhGroup2
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.20
The encryption algorithm used by the outbound security
association of the IPsec Phase-2 Tunnel.
EncryptAlgo
Type Values:
1none
2des
3des3
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.21
The authentication algorithm used by the outbound
authentication header (AH) security association of
the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.22
The authentication algorithm used by the inbound
encapsulation security protocol (ESP)
security association of the IPsec Phase-2 Tunnel.
AuthAlgo
Type Values:
1none
2hmacMd5
3hmacSha
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.23
The compression algorithm used by the inbound
security association of the IPsec Phase-2 Tunnel.
CompAlgo
Type Values:
1none
2ldf
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.24
The total number of octets received by this IPsec
Phase-2 Tunnel. This value is accumulated
BEFORE determining whether or not the packet should
be decompressed. See also cipSecTunInOctWraps for
the number of times t…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.25
A high capacity count of the total number of octets
received by this IPsec Phase-2 Tunnel. This value is
accumulated BEFORE determining whether or not
the packet should be decompressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.26
The number of times the octets received counter
(cipSecTunInOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.27
The total number of decompressed octets received by this
IPsec Phase-2 Tunnel. This value is accumulated AFTER
the packet is decompressed. If compression is not being
used, this value will match the value of cipSecTunH…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.28
A high capacity count of the total number of decompressed
octets received by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER the packet is decompressed. If
compression is not being used, this value will matc…
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.29
The number of times the decompressed octets
received counter (cipSecTunInDecompOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.30
The total number of packets received by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.31
The total number of packets dropped during
receive processing by this IPsec Phase-2 Tunnel.
This count does NOT include packets
dropped due to Anti-Replay processing.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.32
The total number of packets dropped during
receive processing due to Anti-Replay processing
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.33
The total number of inbound authentication's
performed
by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.34
The total number of inbound authentication's
which ended in
failure by this IPsec Phase-2 Tunnel .
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.35
The total number of inbound decryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.36
The total number of inbound decryption's
which ended in failure
by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.37
The total number of octets sent by this IPsec
Phase-2 Tunnel. This value is accumulated
AFTER determining whether or not the
packet should be
compressed. See also cipSecTunOutOctWraps for the
number of times this cou…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.38
A high capacity count of the total number of octets
sent by this IPsec Phase-2 Tunnel. This value
is accumulated AFTER determining whether or not
the packet should be
compressed.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.39
The number of times the octets sent counter
(cipSecTunOutOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.40
The total number of uncompressed octets sent by this
IPsec Phase-2 Tunnel. This value is accumulated BEFORE
the packet is compressed. If compression is not being
used, this value will match the value of
cipSecTunHistO…
OctetsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.41
A high capacity count of the total
number of uncompressed octets sent by this
IPsec Phase-2 Tunnel. This value is accumulated
BEFORE the packet is compressed. If compression
is not being used, this value will match t…
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.42
The number of times the uncompressed octets sent counter
(cipSecTunOutUncompOctets) has wrapped.
Integral unitsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.43
The total number of packets sent by this
IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.44
The total number of packets dropped
during send processing
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.45
The total number of outbound authentication's performed
by this IPsec Phase-2 Tunnel.
EventsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.46
The total number of outbound authentication's
which ended in
failure by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.47
The total number of outbound encryption's performed
by this IPsec Phase-2 Tunnel.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.48
The total number of outbound encryption's
which ended in failure
by this IPsec Phase-2 Tunnel.
FailuresSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.171.1.4.3.1.1.49
.1.3.6.1.4.1.9.9.171.1.4.3.2 · 1 row entry · 15 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecEndPtHistTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecEndPtHistTable'
The IPsec Phase-2 Tunnel Endpoint History Table.
This table is implemented as a 
sliding window in which only the
last n entries are maintained.  
The maximum number of entries
is specified by the cipSecHistTableSize object.
cipSecEndPtHistEntry row .1.3.6.1.4.1.9.9.171.1.4.3.2.1
Each entry contains the attributes associated with
a previously active IPsec Phase-2 Tunnel Endpoint.
Column Syntax OID
The number of the previously active
Endpoint associated
with a IPsec Phase-2 Tunnel Table. The value
of this index is a number which begins at
one and is incremented with each Endpoint
associated with an IPsec P…
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.1
The index of the previously active IPsec
Phase-2 Tunnel Table.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.2
The index of the previously active Endpoint.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.3
The DNS name of the local Endpoint.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.4
The type of identity for the local Endpoint.
Possible values are:
1) a single IP address, or
2) an IP address range, or
3) an IP subnet.
EndPtType
Type Values:
1singleIpAddr
2ipAddrRange
3ipSubnet
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.5
The local Endpoint's first IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, the…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.6
The local Endpoint's second IP address specification.

If the local Endpoint type is single IP address,
then this is the value of the IP address.

If the local Endpoint type is IP subnet, th…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.7
The protocol number of the local Endpoint's traffic.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.8
The port number of the local Endpoint's traffic.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.9
The DNS name of the remote Endpoint.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.10
The type of identity for the remote Endpoint.
Possible values are:
1) a single IP address, or
2) an IP address range, or
3) an IP subnet.
EndPtType
Type Values:
1singleIpAddr
2ipAddrRange
3ipSubnet
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.11
The remote Endpoint's first IP address specification.

If the remote Endpoint type is single IP address,
then this
is the value of the IP address.

If the remote Endpoint type is IP subnet, …
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.12
The remote Endpoint's second IP address specification.

If the remote Endpoint type is single IP address,
then this
is the value of the IP address.

If the remote Endpoint type is IP subnet,…
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.13
The protocol number of the remote Endpoint's traffic.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.14
The port number of the remote Endpoint's traffic.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.9.9.171.1.4.3.2.1.15
.1.3.6.1.4.1.9.9.171.1.5.2.1 · 1 row entry · 9 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cikeFailTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cikeFailTable'
The IPsec Phase-1 Failure Table.
This table is implemented as a sliding 
window in which only the last n entries are 
maintained.  The maximum number of entries
is specified by the cipSecFailTableSize object.
cikeFailEntry row .1.3.6.1.4.1.9.9.171.1.5.2.1.1
Each entry contains the attributes associated
with
an IPsec Phase-1 failure.
Indexes
Column Syntax OID
The IPsec Phase-1 Failure Table index.
The value of the index is a number which
begins at one and is incremented with each
IPsec Phase-1 failure. The value
of this object will wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.1
The reason for the failure. Possible reasons include:
1 = other
2 = peer delete request was received
3 = contact with peer was lost
4 = local failure occurred
5 = authentication failure
6 = hash validation failure
7 = …
Enumeration
Enumerated Values:
1other
2peerDelRequest
3peerLost
4localFailure
5authFailure
6hashValidation
7encryptFailure
8internalError
9sysCapExceeded
10proposalFailure
11peerCertUnavailable
12peerCertNotValid
13localCertExpired
14crlFailure
15peerEncodingError
16nonExistentSa
17operRequest
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.2
The value of sysUpTime in hundredths of seconds
at the time of the failure.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.3
The type of local peer identity. The local peer
may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.4
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is a host name, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.5
The type of remote peer identity. The remote
peer may be identified by:
1. an IP address, or
2. a host name.
IkePeerType
Type Values:
1ipAddrPeer
2namePeer
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.6
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is a host name, then t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.7
The IP address of the local peer.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.8
The IP address of the remote peer.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.5.2.1.1.9
.1.3.6.1.4.1.9.9.171.1.5.3.1 · 1 row entry · 7 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipSecFailTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-FLOW-MONITOR-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-FLOW-MONITOR-MIB::cipSecFailTable'
The IPsec Phase-2 Failure Table.
This table is implemented as a sliding window 
in which only the last n entries are maintained.  
The maximum number of entries
is specified by the cipSecFailTableSize object.
cipSecFailEntry row .1.3.6.1.4.1.9.9.171.1.5.3.1.1
Each entry contains the attributes associated with
an IPsec Phase-1 failure.
Indexes
Column Syntax OID
The IPsec Phase-2 Failure Table index.
The value of the index is a number which
begins at one and is incremented with each
IPsec Phase-1 failure. The value
of this object will wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.1
The reason for the failure. Possible reasons
include:
1 = other
2 = internal error occurred
3 = peer encoding error
4 = proposal failure
5 = protocol use failure
6 = non-existent security association
7 = …
Enumeration
Enumerated Values:
1other
2internalError
3peerEncodingError
4proposalFailure
5protocolUseFail
6nonExistentSa
7decryptFailure
8encryptFailure
9inAuthFailure
10outAuthFailure
11compression
12sysCapExceeded
13peerDelRequest
14peerLost
15seqNumRollOver
16operRequest
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.2
The value of sysUpTime in hundredths of seconds
at the time of the failure.
SNMPv2-TCTimeStamp
Based On: SNMPv2-SMITimeTicks
Description:
The value of the sysUpTime object at which a specific
occurrence happened. The specific occurrence must be

defined in the description of any object defined using this
type.

If sysUpTime is reset t…
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.3
The Phase-2 Tunnel index (cipSecTunIndex).
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.4
The security association SPI value.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.5
The packet's source IP address.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.6
The packet's destination IP address.
IPSIpAddress
Type Constraints:
range: 4
range: 16
.1.3.6.1.4.1.9.9.171.1.5.3.1.1.7