CISCO-IPSEC-PROVISIONING-MIB

        IPSec is the next-generation network layer crypto
framework described in RFC2401-2411. 
This MIB defines the IPsec configurations.
It may be used to view and provision IPsec-based
VPNs.
        
To create an IPsec tunnel, you need first configure
Internet Key Exchange (IKE). IKE negotiates Security
Associations with the peer for IPsec. To find out
how to configure IKE, please see
CISCO-IKE-CONFIGURATION-MIB for detail.
        
Once you setup IKE, you will have to configure IPsec.
To configure IPsec, you need perform following steps.
1. Create an IPsec transform set.
   A transform set describes a security protocol
   (AH or ESP) with its corresponding algorithms.
   For example, ESP with the DES cipher algorithm
   and HMAC-SHA for authentication.
        
	2. Create a cryptomap and its peers.
   This will a) select data flows that need security
   processing and b) defines the policy for these flows
   and the crypto peer that traffic needs to go to.
        
3. Apply cryptomap to an interface
   A crypto map is applied to an egress interface.
   Outgoing data flows are protected by this cryptomap.
        
Acronyms
The following acronyms are used in this document:
        
  Static Cryptomap Template:
   A static cryptomap template (or static cryptomap)
   is a security template created for IPsec.
   A static cryptomap pulls together various parts
   to set up an IPsec security association
   which includes:
   - which traffic should be protected by IPsec
   - where IPsec protected traffic should be sent
   - the local address used for the the IPsec traffic
   - which transform sets should be applied to this
     traffic
        
  Dynamic Cryptomap Template:
   A dynamic cryptomap template (or a dynamic cryptomap)
   is essentially a crypto map entry without all the
   parameters configured.  It acts as a policy template
   where the missing parameters are later dynamically
   configured (as the result of an IPsec negotiation)
   to match a peer's requirements.
        
  Cryptomap Set:
   A cryptomap set may contain multiple cryptomap
   templates which specify an IPsec policy.
        
  TED:
   Tunnel Endpoint Discovery protocol
        
MIB Structure
-------------
  This MIB provides the operational information on 
  Cisco's IPsec implementation of IPsec. This MIB 
  delineates ISAKMP and IPsec configuration. This MIB
  deals only with IPsec (Phase-2) configuration.  The
  following entities are managed:
    a) IPsec Global Parameters
    b) IPsec transform set definitions
    c) Cryptomap Group
       - Cryptomap Set Table
       - Cryptomap Table
       - CryptomapSet Transform Binding Table
       - CryptomapSet Peer Binding Table
       - CryptomapSet Interface Binding Table
        
    d) Notification Control Group
    e) Notifications Group
    
Source file
CISCO-IPSEC-PROVISIONING-MIB
Last revised
Identity
ciscoIPsecProvisioningMIB
Base OID
1.3.6.1.4.1.9.9.431
Imported Objects
CISCO-IPSEC-TC CIPsecCryptomapType CIPsecDiffHellmanGrp CIPsecEncapMode CIPsecLifesize CIPsecLifetime CIPsecNumCryptoMaps CIPsecSecuritySuite CIPsecTransform CIPsecTunnelIdleTime
CISCO-SMI ciscoMgmt
IF-MIB ifIndex
INET-ADDRESS-MIB InetAddress InetAddressType
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowStatus TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IPSEC-PROVISIONING-MIB::ciscoIPsecProvisioningMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::ciscoIPsecProvisioningMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (73)
.1.3.6.1.4.1.9.9.431
.1.3.6.1.4.1.9.9.431.0
.1.3.6.1.4.1.9.9.431.1
.1.3.6.1.4.1.9.9.431.1.1
.1.3.6.1.4.1.9.9.431.1.1.1
.1.3.6.1.4.1.9.9.431.1.1.2
.1.3.6.1.4.1.9.9.431.1.1.3
.1.3.6.1.4.1.9.9.431.1.2
.1.3.6.1.4.1.9.9.431.1.2.1
.1.3.6.1.4.1.9.9.431.1.2.1.1
OctetString
.1.3.6.1.4.1.9.9.431.1.2.1.1.1
Unsigned32
.1.3.6.1.4.1.9.9.431.1.2.1.1.2
.1.3.6.1.4.1.9.9.431.1.2.1.1.3
.1.3.6.1.4.1.9.9.431.1.2.1.1.4
.1.3.6.1.4.1.9.9.431.1.2.1.1.5
.1.3.6.1.4.1.9.9.431.1.2.1.1.6
.1.3.6.1.4.1.9.9.431.1.2.1.1.7
.1.3.6.1.4.1.9.9.431.1.2.1.1.8
.1.3.6.1.4.1.9.9.431.1.2.1.1.9
.1.3.6.1.4.1.9.9.431.1.3
.1.3.6.1.4.1.9.9.431.1.3.1
.1.3.6.1.4.1.9.9.431.1.3.2
.1.3.6.1.4.1.9.9.431.1.3.3
.1.3.6.1.4.1.9.9.431.1.4
.1.3.6.1.4.1.9.9.431.1.4.1
.1.3.6.1.4.1.9.9.431.1.4.1.1
.1.3.6.1.4.1.9.9.431.1.4.1.1.1
.1.3.6.1.4.1.9.9.431.1.4.1.1.2
.1.3.6.1.4.1.9.9.431.1.4.1.1.3
.1.3.6.1.4.1.9.9.431.1.4.1.1.4
.1.3.6.1.4.1.9.9.431.1.4.1.1.5
.1.3.6.1.4.1.9.9.431.1.4.1.1.6
.1.3.6.1.4.1.9.9.431.1.4.3
.1.3.6.1.4.1.9.9.431.1.4.3.1
OctetString
.1.3.6.1.4.1.9.9.431.1.4.3.1.1
.1.3.6.1.4.1.9.9.431.1.4.3.1.10
.1.3.6.1.4.1.9.9.431.1.4.3.1.11
.1.3.6.1.4.1.9.9.431.1.4.3.1.12
.1.3.6.1.4.1.9.9.431.1.4.3.1.13
.1.3.6.1.4.1.9.9.431.1.4.3.1.14
.1.3.6.1.4.1.9.9.431.1.4.3.1.15
.1.3.6.1.4.1.9.9.431.1.4.3.1.16
.1.3.6.1.4.1.9.9.431.1.4.3.1.17
Unsigned32
.1.3.6.1.4.1.9.9.431.1.4.3.1.2
.1.3.6.1.4.1.9.9.431.1.4.3.1.3
OctetString
.1.3.6.1.4.1.9.9.431.1.4.3.1.4
OctetString
.1.3.6.1.4.1.9.9.431.1.4.3.1.5
OctetString
.1.3.6.1.4.1.9.9.431.1.4.3.1.6
Unsigned32
.1.3.6.1.4.1.9.9.431.1.4.3.1.7
Unsigned32
.1.3.6.1.4.1.9.9.431.1.4.3.1.8
.1.3.6.1.4.1.9.9.431.1.4.3.1.9
.1.3.6.1.4.1.9.9.431.1.4.4
.1.3.6.1.4.1.9.9.431.1.4.4.1
.1.3.6.1.4.1.9.9.431.1.4.4.1.1
.1.3.6.1.4.1.9.9.431.1.4.4.1.2
.1.3.6.1.4.1.9.9.431.1.4.4.1.3
Unsigned32
.1.3.6.1.4.1.9.9.431.1.4.4.1.4
.1.3.6.1.4.1.9.9.431.1.4.4.1.5
.1.3.6.1.4.1.9.9.431.1.4.5
.1.3.6.1.4.1.9.9.431.1.4.5.1
.1.3.6.1.4.1.9.9.431.1.4.5.1.1
.1.3.6.1.4.1.9.9.431.1.4.6
.1.3.6.1.4.1.9.9.431.1.4.6.1
OctetString
.1.3.6.1.4.1.9.9.431.1.4.6.1.1
.1.3.6.1.4.1.9.9.431.1.5
.1.3.6.1.4.1.9.9.431.1.5.1
.1.3.6.1.4.1.9.9.431.1.5.2
.1.3.6.1.4.1.9.9.431.1.5.3
.1.3.6.1.4.1.9.9.431.1.5.4
.1.3.6.1.4.1.9.9.431.1.5.5
.1.3.6.1.4.1.9.9.431.2
.1.3.6.1.4.1.9.9.431.2.1
.1.3.6.1.4.1.9.9.431.2.2
Dependencies (10) 8 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Conformance Groups (9)
A collection of objects providing Global
IPSec policy monitoring capability to a
IPsec capable VPN router.
.1.3.6.1.4.1.9.9.431.2.2.1
A collection of objects modeling IPsec
transform sets and transform set mappings.
.1.3.6.1.4.1.9.9.431.2.2.2
A collection of objects modeling static
crypto configuration of the Static (fully specified)
Cryptomap Sets on the managed entity.
.1.3.6.1.4.1.9.9.431.2.2.3
A collection of objects modeling the configuration
of IPsec dynamic cryptomap elements.
.1.3.6.1.4.1.9.9.431.2.2.4
A collection of objects instrumenting the
properties of the Cryptomaps using tunnel
endpoint discovery protocol.
.1.3.6.1.4.1.9.9.431.2.2.5
A collection of objects displaying the
binding of an IPsec peer address to the specified
cryptomap.
.1.3.6.1.4.1.9.9.431.2.2.6
A collection of objects providing IPsec
Notification capability to a IPsec-capable
router. It is mandatory to implement
this set of objects pertaining to
IOS notifications about IPSec activity.
.1.3.6.1.4.1.9.9.431.2.2.7
A collection of notification objects signaling
changes to the IPsec configuration on the managed
entity.
.1.3.6.1.4.1.9.9.431.2.2.8
A collection of objects providing current IPsec
configuration information on the managedentity.
.1.3.6.1.4.1.9.9.431.2.2.9
Compliance Statements (2)

OID .1.3.6.1.4.1.9.9.431.2.1.1
The compliance statement for entities which
implement the Cisco IPsec Provisioning MIB.
Required groups
mandatory ciscoIPsecProvGlobalsGroup
mandatory ciscoIPsecProvXformsGroup
mandatory ciscoIPsecProvStCryptomapGroup
mandatory ciscoIPsecCryptomapPeerGroup
mandatory ciscoIPsecProvNotifCntlGroup
optional ciscoIPsecProvDynCryptomapGroup This group must be implemented if the
IKE implementation on the managed entity
implements dynamic cryptomaps.
optional ciscoIPsecProvTedCryptomapGroup This group must be implemented if the
IKE implementation on the managed entity
implements tunnel endpoint discovery.
optional ciscoIPsecProvNotifGroup This group is optional.
Object refinements
ObjectAccessSyntaxDescription
cipsTunnelLifetime readonly
Write access is not required.
cipsTunnelLifesize readonly
Write access is not required.
cipsTunnelIdleTimeout readonly
Write access is not required.
cipsCntlAllNotifs readonly
Write access is not required.
cipsCntlCryptomapAdded readonly
Write access is not required.
cipsCntlCryptomapDeleted readonly
Write access is not required.
cipsCntlCryptomapSetAttached readonly
Write access is not required.
cipsCntlCryptomapSetDetached readonly
Write access is not required.
cipsXformSetMode readonly
Write access is not required.
cipsStaticCryptomapIpFilter readonly
Write access is not required.
cipsStaticCryptomapXformSetList readonly
Write access is not required.
cipsStaticCryptomapPfs readonly
Write access is not required.
cipsStaticCryptomapLifetime readonly
Write access is not required.
cipsStaticCryptomapLifesize readonly
Write access is not required.
cipsStaticCryptomapLevelHost readonly
Write access is not required.
cipsStaticCryptomapIdleTimeout readonly
Write access is not required.
cipsStaticCryptomapAutoPeer readonly
Write access is not required.
cipsXformSetStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.

If write access is implemented, only three values
'createAndGo', 'destroy' and 'active' out of the
six enumerated values need to be supported.
cipsStaticCryptomapStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.

If write access is implemented, only three values
'createAndGo', 'destroy' and 'active' out of the
six enumerated values need to be supported.
cipsCryMapPeerStatus readonly
active(1), createAndGo(4), destroy(6)
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported.

Write access is not required.
cipsCryptomapSetIfStatus readonly
active(1), createAndGo(4), destroy(6)
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported.

Write access is not required.

OID .1.3.6.1.4.1.9.9.431.2.1.2
The compliance statement for entities which
implement the Cisco IPsec Provisioning MIB.
Required groups
mandatory ciscoIPsecProvGlobalsGroup
mandatory ciscoIPsecProvXformsGroup
mandatory ciscoIPsecProvStCryptomapGroup
mandatory ciscoIPsecCryptomapPeerGroup
mandatory ciscoIPsecProvNotifCntlGroup
mandatory ciscoIPsecProvInfoGroup
optional ciscoIPsecProvDynCryptomapGroup This group must be implemented if the
IKE implementation on the managed entity
implements dynamic cryptomaps.
optional ciscoIPsecProvTedCryptomapGroup This group must be implemented if the
IKE implementation on the managed entity
implements tunnel endpoint discovery.
optional ciscoIPsecProvNotifGroup This group is optional.
Object refinements
ObjectAccessSyntaxDescription
cipsTunnelLifetime readonly
Write access is not required.
cipsTunnelLifesize readonly
Write access is not required.
cipsTunnelIdleTimeout readonly
Write access is not required.
cipsCntlAllNotifs readonly
Write access is not required.
cipsCntlCryptomapAdded readonly
Write access is not required.
cipsCntlCryptomapDeleted readonly
Write access is not required.
cipsCntlCryptomapSetAttached readonly
Write access is not required.
cipsCntlCryptomapSetDetached readonly
Write access is not required.
cipsXformSetMode readonly
Write access is not required.
cipsStaticCryptomapIpFilter readonly
Write access is not required.
cipsStaticCryptomapXformSetList readonly
Write access is not required.
cipsStaticCryptomapPfs readonly
Write access is not required.
cipsStaticCryptomapLifetime readonly
Write access is not required.
cipsStaticCryptomapLifesize readonly
Write access is not required.
cipsStaticCryptomapLevelHost readonly
Write access is not required.
cipsStaticCryptomapIdleTimeout readonly
Write access is not required.
cipsStaticCryptomapAutoPeer readonly
Write access is not required.
cipsXformSetStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.

If write access is implemented, only three values
'createAndGo', 'destroy' and 'active' out of the
six enumerated values need to be supported.
cipsStaticCryptomapStatus readonly
active(1), createAndGo(4), destroy(6)
Write access is not required.

If write access is implemented, only three values
'createAndGo', 'destroy' and 'active' out of the
six enumerated values need to be supported.
cipsCryMapPeerStatus readonly
active(1), createAndGo(4), destroy(6)
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported.

Write access is not required.
cipsCryptomapSetIfStatus readonly
active(1), createAndGo(4), destroy(6)
Only three values 'createAndGo', 'destroy' and
'active' out of the six enumerated values need to
be supported.

Write access is not required.
Notifications / Traps (4)
NameOIDDescription
.1.3.6.1.4.1.9.9.431.0.1
This notification is generated when a new cryptomap
is added to the specified cryptomap set. Object
'cipsStaticCryptomapSetSize' contains the number of
cryptomap entries after the addition.
.1.3.6.1.4.1.9.9.431.0.2
This notification is generated when a cryptomap is
removed from the specified cryptomap set. Object
'cipsStaticCryptomapSetSize' contains the number of
cryptomap entries after the deletion.
.1.3.6.1.4.1.9.9.431.0.3
A cryptomap set must be attached to an interface
of the device in order for it to be operational.
This trap is generated when the cryptomap set
attached to an active interface of
the managed entity.

The contents of the notification includes:
Size of the attached cryptomap set,
Number of ISAKMP cryptomaps in the set and
Number of Dynamic cryptomaps in the set.
.1.3.6.1.4.1.9.9.431.0.4
This trap is generated when a cryptomap set is
detached from an interafce to which it was bound
earlier. The context of the event identifies the
size of the cryptomap set.