CISCO-IPSEC-MIB

        The MIB module for modeling Cisco-specific 
IPsec attributes
        
Overview of Cisco IPsec MIB
        
MIB description
        
This MIB models the Cisco implementation-specific 
attributes of a Cisco entity that implements IPsec. 
This MIB is complementary to the standard IPsec MIB 
proposed jointly by Tivoli and Cisco.
        
The ciscoIPsec MIB provides the operational information 
on Cisco's IPsec tunnelling implementation.  
The following entities are managed:
1) ISAKMP Group:
a) ISAKMP global parameters
b) ISAKMP Policy Table
        
2) IPSec Group:
a) IPSec Global Parameters
b) IPSec Global Traffic Parameters
c) Cryptomap Group
- Cryptomap Set Table
- Cryptomap Table
- CryptomapSet Binding Table
        
3) System Capacity & Capability Group:
a) Capacity Parameters
b) Capability Parameters
        
4) Trap Control Group
5) Notifications Group
    
Source file
CISCO-IPSEC-MIB
Last revised
Identity
ciscoIPsecMIB
Base OID
1.3.6.1.4.1.9.10.62
Imported Objects
CISCO-SMI ciscoExperiment
IF-MIB ifIndex
SNMPv2-CONF MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page)
SNMPv2-TC DisplayString TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IPSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IPSEC-MIB::ciscoIPsecMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-MIB::ciscoIPsecMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (74)
.1.3.6.1.4.1.9.10.62
.1.3.6.1.4.1.9.10.62.1
.1.3.6.1.4.1.9.10.62.1.1
.1.3.6.1.4.1.9.10.62.1.1.1
.1.3.6.1.4.1.9.10.62.1.1.2
secondsInteger32
.1.3.6.1.4.1.9.10.62.1.1.3
Integer32
.1.3.6.1.4.1.9.10.62.1.1.4
.1.3.6.1.4.1.9.10.62.1.1.5
.1.3.6.1.4.1.9.10.62.1.1.5.1
Integer32
.1.3.6.1.4.1.9.10.62.1.1.5.1.1
.1.3.6.1.4.1.9.10.62.1.1.5.1.2
.1.3.6.1.4.1.9.10.62.1.1.5.1.3
.1.3.6.1.4.1.9.10.62.1.1.5.1.4
.1.3.6.1.4.1.9.10.62.1.1.5.1.5
secondsInteger32
.1.3.6.1.4.1.9.10.62.1.1.5.1.6
.1.3.6.1.4.1.9.10.62.1.2
.1.3.6.1.4.1.9.10.62.1.2.1
.1.3.6.1.4.1.9.10.62.1.2.1.1
.1.3.6.1.4.1.9.10.62.1.2.1.2
Integral UnitsCIPsecNumCryptoMaps
.1.3.6.1.4.1.9.10.62.1.2.1.3
Integral UnitsCIPsecNumCryptoMaps
.1.3.6.1.4.1.9.10.62.1.2.1.4
Integral UnitsCIPsecNumCryptoMaps
.1.3.6.1.4.1.9.10.62.1.2.1.5
Integral UnitsCIPsecNumCryptoMaps
.1.3.6.1.4.1.9.10.62.1.2.1.6
.1.3.6.1.4.1.9.10.62.1.2.2
Integral UnitsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.10.62.1.2.2.1
Integral UnitsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.10.62.1.2.2.2
Integral UnitsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.10.62.1.2.2.3
.1.3.6.1.4.1.9.10.62.1.2.3
.1.3.6.1.4.1.9.10.62.1.2.3.1
.1.3.6.1.4.1.9.10.62.1.2.3.1.1
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.1
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.2
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.3
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.4
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.5
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.6
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.7
.1.3.6.1.4.1.9.10.62.1.2.3.1.1.8
.1.3.6.1.4.1.9.10.62.1.2.3.2
.1.3.6.1.4.1.9.10.62.1.2.3.2.1
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.1
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.2
.1.3.6.1.4.1.9.10.62.1.2.3.2.1.3
.1.3.6.1.4.1.9.10.62.1.2.3.3
.1.3.6.1.4.1.9.10.62.1.2.3.3.1
Integer32
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.1
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.2
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.3
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.4
Integer32
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.5
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.6
Integer32
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.7
Integer32
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.8
.1.3.6.1.4.1.9.10.62.1.2.3.3.1.9
.1.3.6.1.4.1.9.10.62.1.2.3.4
.1.3.6.1.4.1.9.10.62.1.2.3.4.1
.1.3.6.1.4.1.9.10.62.1.2.3.4.1.1
.1.3.6.1.4.1.9.10.62.1.2.3.4.1.2
.1.3.6.1.4.1.9.10.62.1.3
Integral UnitsInteger32
.1.3.6.1.4.1.9.10.62.1.3.1
.1.3.6.1.4.1.9.10.62.1.3.2
.1.3.6.1.4.1.9.10.62.1.4
.1.3.6.1.4.1.9.10.62.1.4.1
.1.3.6.1.4.1.9.10.62.1.4.2
.1.3.6.1.4.1.9.10.62.1.4.3
.1.3.6.1.4.1.9.10.62.1.4.4
.1.3.6.1.4.1.9.10.62.1.4.5
.1.3.6.1.4.1.9.10.62.1.4.6
.1.3.6.1.4.1.9.10.62.1.4.7
.1.3.6.1.4.1.9.10.62.2
.1.3.6.1.4.1.9.10.62.2.0
.1.3.6.1.4.1.9.10.62.3
.1.3.6.1.4.1.9.10.62.3.1
.1.3.6.1.4.1.9.10.62.3.2
Dependencies (7) 5 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. IANAifType-MIBrfc
  5. SNMPv2-CONFrfc
  6. SNMPv2-MIBrfc
  7. IF-MIBrfc
  8. CISCO-IPSEC-MIBciscoselected
Type Definitions (12)
Unsigned32 range: 2560..536870912
Unsigned32 range: 120..86400
Unsigned32 range: 0..2147483647
Enumeration
unknown(0)
attached(1)
detached(2)
Enumeration
cryptomapTypeNONE(0)
cryptomapTypeMANUAL(1)
cryptomapTypeISAKMP(2)
cryptomapTypeCET(3)
cryptomapTypeDYNAMIC(4)
cryptomapTypeDYNAMICDISCOVERY(5)
Enumeration
none(1)
dhGroup1(2)
dhGroup2(3)
Enumeration
none(1)
des(2)
des3(3)
OctetString range: 4range: 16
Enumeration
none(1)
preSharedKey(2)
rsaSig(3)
rsaEncrypt(4)
revPublicKey(5)
Enumeration
none(1)
md5(2)
sha(3)
Enumeration
isakmpIdTypeUNKNOWN(0)
isakmpIdTypeADDRESS(1)
isakmpIdTypeHOSTNAME(2)
Enumeration
enabled(1)
disabled(2)
Conformance Groups (7)
A collection of objects providing Global
ISAKMP policy monitoring capability to a
Cisco IPsec capable VPN router.
.1.3.6.1.4.1.9.10.62.3.2.1
A collection of objects providing Global
IPSec policy monitoring capability to a
Cisco IPsec capable VPN router.
.1.3.6.1.4.1.9.10.62.3.2.2
A collection of objects providing IPsec
System Capacity monitoring capability to
a Cisco IPsec capable VPN router.
.1.3.6.1.4.1.9.10.62.3.2.3
A collection of objects instrumenting
the properties of the Static (fully specified)
Cryptomap Sets on an IPsec-capable
IOS router.
.1.3.6.1.4.1.9.10.62.3.2.4
A collection of objects instrumenting
the properties of the Manual Cryptomap entries
on a Cisco IPsec capable IOS router.
.1.3.6.1.4.1.9.10.62.3.2.5
A collection of objects instrumenting
the properties of the Dynamic Cryptomap group
on a Cisco IPsec capable IOS router.
.1.3.6.1.4.1.9.10.62.3.2.6
A collection of objects providing IPsec
Notification capability to a IPsec-capable
IOS router. It is mandatory to implement
this set of objects pertaining to
IOS notifications about IPSec activity.
.1.3.6.1.4.1.9.10.62.3.2.7
Compliance Statements (1)

OID .1.3.6.1.4.1.9.10.62.3.1.1
The compliance statement for entities which
implement the Cisco IPsec MIB
Required groups
Object refinements
ObjectAccessSyntaxDescription
cipsCntlIsakmpPolicyAdded readonly
Write access is not required.
cipsCntlIsakmpPolicyDeleted readonly
Write access is not required.
cipsCntlCryptomapAdded readonly
Write access is not required.
cipsCntlCryptomapDeleted readonly
Write access is not required.
cipsCntlCryptomapSetAttached readonly
Write access is not required.
cipsCntlCryptomapSetDetached readonly
Write access is not required.
cipsCntlTooManySAs readonly
Write access is not required.
Notifications / Traps (7)
NameOIDDescription
.1.3.6.1.4.1.9.10.62.2.0.1
This trap is generated when a new ISAKMP
policy element is defined on the managed entity.
The context of the event includes the updated
number of ISAKMP policy elements currently available.
.1.3.6.1.4.1.9.10.62.2.0.2
This trap is generated when an existing ISAKMP
policy element is deleted on the managed entity.
The context of the event includes the updated
number of ISAKMP policy elements currently available.
.1.3.6.1.4.1.9.10.62.2.0.3
This trap is generated when a new cryptomap is
added to the specified cryptomap set.
.1.3.6.1.4.1.9.10.62.2.0.4
This trap is generated when a cryptomap is
removed from the specified cryptomap set.
.1.3.6.1.4.1.9.10.62.2.0.5
A cryptomap set must be attached to an interface
of the device in order for it to be operational.
This trap is generated when the cryptomap set
attached to an active interface of the managed entity.

The context of the notification includes:
Size of the attached cryptomap set,
Number of ISAKMP cryptomaps in the set and
Number of Dynamic cryptomaps in the set.
.1.3.6.1.4.1.9.10.62.2.0.6
This trap is generated when a cryptomap set is
detached from an interafce to which it was
bound earlier. The context of the event identifies the
size of the cryptomap set.
.1.3.6.1.4.1.9.10.62.2.0.7
This trap is generated when a new SA is attempted
to be setup while the number of currently active SAs
equals the maximum configurable. The variables are:
cipsMaxSAs