CISCO-IPSEC-MIB
The MIB module for modeling Cisco-specific
IPsec attributes
Overview of Cisco IPsec MIB
MIB description
This MIB models the Cisco implementation-specific
attributes of a Cisco entity that implements IPsec.
This MIB is complementary to the standard IPsec MIB
proposed jointly by Tivoli and Cisco.
The ciscoIPsec MIB provides the operational information
on Cisco's IPsec tunnelling implementation.
The following entities are managed:
1) ISAKMP Group:
a) ISAKMP global parameters
b) ISAKMP Policy Table
2) IPSec Group:
a) IPSec Global Parameters
b) IPSec Global Traffic Parameters
c) Cryptomap Group
- Cryptomap Set Table
- Cryptomap Table
- CryptomapSet Binding Table
3) System Capacity & Capability Group:
a) Capacity Parameters
b) Capability Parameters
4) Trap Control Group
5) Notifications Group
- Source file
CISCO-IPSEC-MIB- Last revised
- Identity
ciscoIPsecMIB- Base OID
1.3.6.1.4.1.9.10.62
Imported Objects
| CISCO-SMI | ciscoExperiment |
| IF-MIB | ifIndex |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) |
| SNMPv2-TC | DisplayString TEXTUAL-CONVENTION (no object page) TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IPSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IPSEC-MIB::ciscoIPsecMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-MIB::ciscoIPsecMIB'
Objects (74)
Showing 74 of 74 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.10.62 |
||
.1.3.6.1.4.1.9.10.62.1 |
||
.1.3.6.1.4.1.9.10.62.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.1.2 |
||
|
secondsInteger32
|
.1.3.6.1.4.1.9.10.62.1.1.3 |
|
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.1.4 |
|
.1.3.6.1.4.1.9.10.62.1.1.5 |
||
.1.3.6.1.4.1.9.10.62.1.1.5.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.1.5.1.1 |
|
.1.3.6.1.4.1.9.10.62.1.1.5.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.1.5.1.3 |
||
.1.3.6.1.4.1.9.10.62.1.1.5.1.4 |
||
.1.3.6.1.4.1.9.10.62.1.1.5.1.5 |
||
|
secondsInteger32
|
.1.3.6.1.4.1.9.10.62.1.1.5.1.6 |
|
.1.3.6.1.4.1.9.10.62.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.2.1 |
||
|
SecondsCIPsecLifetime
|
.1.3.6.1.4.1.9.10.62.1.2.1.1 |
|
|
KBytesCIPsecLifesize
|
.1.3.6.1.4.1.9.10.62.1.2.1.2 |
|
|
Integral UnitsCIPsecNumCryptoMaps
|
.1.3.6.1.4.1.9.10.62.1.2.1.3 |
|
|
Integral UnitsCIPsecNumCryptoMaps
|
.1.3.6.1.4.1.9.10.62.1.2.1.4 |
|
|
Integral UnitsCIPsecNumCryptoMaps
|
.1.3.6.1.4.1.9.10.62.1.2.1.5 |
|
|
Integral UnitsCIPsecNumCryptoMaps
|
.1.3.6.1.4.1.9.10.62.1.2.1.6 |
|
.1.3.6.1.4.1.9.10.62.1.2.2 |
||
|
Integral UnitsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.10.62.1.2.2.1 |
|
|
Integral UnitsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.10.62.1.2.2.2 |
|
|
Integral UnitsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.10.62.1.2.2.3 |
|
.1.3.6.1.4.1.9.10.62.1.2.3 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.3 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.4 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.5 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.6 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.7 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.8 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.2 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.2.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.3 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.3 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.3.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.1 |
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.3 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.4 |
||
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.5 |
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.6 |
||
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.7 |
|
|
Integer32
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.8 |
|
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.9 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.4 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.4.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.4.1.1 |
||
.1.3.6.1.4.1.9.10.62.1.2.3.4.1.2 |
||
.1.3.6.1.4.1.9.10.62.1.3 |
||
|
Integral UnitsInteger32
|
.1.3.6.1.4.1.9.10.62.1.3.1 |
|
.1.3.6.1.4.1.9.10.62.1.3.2 |
||
.1.3.6.1.4.1.9.10.62.1.4 |
||
.1.3.6.1.4.1.9.10.62.1.4.1 |
||
.1.3.6.1.4.1.9.10.62.1.4.2 |
||
.1.3.6.1.4.1.9.10.62.1.4.3 |
||
.1.3.6.1.4.1.9.10.62.1.4.4 |
||
.1.3.6.1.4.1.9.10.62.1.4.5 |
||
.1.3.6.1.4.1.9.10.62.1.4.6 |
||
.1.3.6.1.4.1.9.10.62.1.4.7 |
||
.1.3.6.1.4.1.9.10.62.2 |
||
.1.3.6.1.4.1.9.10.62.2.0 |
||
.1.3.6.1.4.1.9.10.62.3 |
||
.1.3.6.1.4.1.9.10.62.3.1 |
||
.1.3.6.1.4.1.9.10.62.3.2 |
Dependencies (7) 5 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- CISCO-IPSEC-MIBciscoselected
Type Definitions (12)
| Unsigned32 |
range: 2560..536870912 |
|
| Unsigned32 |
range: 120..86400 |
|
| Unsigned32 |
range: 0..2147483647 |
|
| Enumeration |
unknown(0)attached(1)detached(2) |
|
| Enumeration |
cryptomapTypeNONE(0)cryptomapTypeMANUAL(1)cryptomapTypeISAKMP(2)cryptomapTypeCET(3)cryptomapTypeDYNAMIC(4)cryptomapTypeDYNAMICDISCOVERY(5) |
|
| Enumeration |
none(1)dhGroup1(2)dhGroup2(3) |
|
| Enumeration |
none(1)des(2)des3(3) |
|
| OctetString |
range: 4range: 16 |
|
| Enumeration |
none(1)preSharedKey(2)rsaSig(3)rsaEncrypt(4)revPublicKey(5) |
|
| Enumeration |
none(1)md5(2)sha(3) |
|
| Enumeration |
isakmpIdTypeUNKNOWN(0)isakmpIdTypeADDRESS(1)isakmpIdTypeHOSTNAME(2) |
|
| Enumeration |
enabled(1)disabled(2) |
Conformance Groups (7)
|
A collection of objects providing Global
ISAKMP policy monitoring capability to a Cisco IPsec capable VPN router. |
.1.3.6.1.4.1.9.10.62.3.2.1
|
|
|
A collection of objects providing Global
IPSec policy monitoring capability to a Cisco IPsec capable VPN router. |
.1.3.6.1.4.1.9.10.62.3.2.2
|
|
|
A collection of objects providing IPsec
System Capacity monitoring capability to a Cisco IPsec capable VPN router. |
.1.3.6.1.4.1.9.10.62.3.2.3
|
|
|
cipsStaticCryptomapSetSize cipsStaticCryptomapSetNumIsakmp cipsStaticCryptomapSetNumCET cipsStaticCryptomapSetNumSAs
A collection of objects instrumenting
the properties of the Static (fully specified) Cryptomap Sets on an IPsec-capable IOS router. |
.1.3.6.1.4.1.9.10.62.3.2.4
|
|
|
A collection of objects instrumenting
the properties of the Manual Cryptomap entries on a Cisco IPsec capable IOS router. |
.1.3.6.1.4.1.9.10.62.3.2.5
|
|
|
cipsNumTEDProbesReceived cipsNumTEDProbesSent cipsNumTEDFailures cipsStaticCryptomapSetNumDynamic cipsStaticCryptomapSetNumDisc cipsNumTEDCryptomapSets cipsDynamicCryptomapSetSize cipsDynamicCryptomapSetNumAssoc
A collection of objects instrumenting
the properties of the Dynamic Cryptomap group on a Cisco IPsec capable IOS router. |
.1.3.6.1.4.1.9.10.62.3.2.6
|
|
|
cipsCntlIsakmpPolicyAdded cipsCntlIsakmpPolicyDeleted cipsCntlCryptomapAdded cipsCntlCryptomapDeleted cipsCntlCryptomapSetAttached cipsCntlCryptomapSetDetached cipsCntlTooManySAs
A collection of objects providing IPsec
Notification capability to a IPsec-capable IOS router. It is mandatory to implement this set of objects pertaining to IOS notifications about IPSec activity. |
.1.3.6.1.4.1.9.10.62.3.2.7
|
Compliance Statements (1)
OID
.1.3.6.1.4.1.9.10.62.3.1.1The compliance statement for entities which
implement the Cisco IPsec MIB
implement the Cisco IPsec MIB
Required groups
| mandatory | cipsMIBConfIsakmpGroup | |
| mandatory | cipsMIBConfIPSecGlobalsGroup | |
| mandatory | cipsMIBConfCapacityGroup | |
| mandatory | cipsMIBStaticCryptomapGroup | |
| mandatory | cipsMIBMandatoryNotifCntlGroup |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cipsCntlIsakmpPolicyAdded | readonly | Write access is not required. | |
| cipsCntlIsakmpPolicyDeleted | readonly | Write access is not required. | |
| cipsCntlCryptomapAdded | readonly | Write access is not required. | |
| cipsCntlCryptomapDeleted | readonly | Write access is not required. | |
| cipsCntlCryptomapSetAttached | readonly | Write access is not required. | |
| cipsCntlCryptomapSetDetached | readonly | Write access is not required. | |
| cipsCntlTooManySAs | readonly | Write access is not required. |
Notifications / Traps (7)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.10.62.2.0.1 |
This trap is generated when a new ISAKMP
policy element is defined on the managed entity. The context of the event includes the updated number of ISAKMP policy elements currently available. |
|
.1.3.6.1.4.1.9.10.62.2.0.2 |
This trap is generated when an existing ISAKMP
policy element is deleted on the managed entity. The context of the event includes the updated number of ISAKMP policy elements currently available. |
|
.1.3.6.1.4.1.9.10.62.2.0.3 |
This trap is generated when a new cryptomap is
added to the specified cryptomap set. |
|
.1.3.6.1.4.1.9.10.62.2.0.4 |
This trap is generated when a cryptomap is
removed from the specified cryptomap set. |
|
.1.3.6.1.4.1.9.10.62.2.0.5 |
A cryptomap set must be attached to an interface
of the device in order for it to be operational. This trap is generated when the cryptomap set attached to an active interface of the managed entity. The context of the notification includes: Size of the attached cryptomap set, Number of ISAKMP cryptomaps in the set and Number of Dynamic cryptomaps in the set. |
|
.1.3.6.1.4.1.9.10.62.2.0.6 |
This trap is generated when a cryptomap set is
detached from an interafce to which it was bound earlier. The context of the event identifies the size of the cryptomap set. |
|
.1.3.6.1.4.1.9.10.62.2.0.7 |
This trap is generated when a new SA is attempted
to be setup while the number of currently active SAs equals the maximum configurable. The variables are: cipsMaxSAs |