CISCO-IPSEC-PROVISIONING-MIB
IPSec is the next-generation network layer crypto
framework described in RFC2401-2411.
This MIB defines the IPsec configurations.
It may be used to view and provision IPsec-based
VPNs.
To create an IPsec tunnel, you need first configure
Internet Key Exchange (IKE). IKE negotiates Security
Associations with the peer for IPsec. To find out
how to configure IKE, please see
CISCO-IKE-CONFIGURATION-MIB for detail.
Once you setup IKE, you will have to configure IPsec.
To configure IPsec, you need perform following steps.
1. Create an IPsec transform set.
A transform set describes a security protocol
(AH or ESP) with its corresponding algorithms.
For example, ESP with the DES cipher algorithm
and HMAC-SHA for authentication.
2. Create a cryptomap and its peers.
This will a) select data flows that need security
processing and b) defines the policy for these flows
and the crypto peer that traffic needs to go to.
3. Apply cryptomap to an interface
A crypto map is applied to an egress interface.
Outgoing data flows are protected by this cryptomap.
Acronyms
The following acronyms are used in this document:
Static Cryptomap Template:
A static cryptomap template (or static cryptomap)
is a security template created for IPsec.
A static cryptomap pulls together various parts
to set up an IPsec security association
which includes:
- which traffic should be protected by IPsec
- where IPsec protected traffic should be sent
- the local address used for the the IPsec traffic
- which transform sets should be applied to this
traffic
Dynamic Cryptomap Template:
A dynamic cryptomap template (or a dynamic cryptomap)
is essentially a crypto map entry without all the
parameters configured. It acts as a policy template
where the missing parameters are later dynamically
configured (as the result of an IPsec negotiation)
to match a peer's requirements.
Cryptomap Set:
A cryptomap set may contain multiple cryptomap
templates which specify an IPsec policy.
TED:
Tunnel Endpoint Discovery protocol
MIB Structure
-------------
This MIB provides the operational information on
Cisco's IPsec implementation of IPsec. This MIB
delineates ISAKMP and IPsec configuration. This MIB
deals only with IPsec (Phase-2) configuration. The
following entities are managed:
a) IPsec Global Parameters
b) IPsec transform set definitions
c) Cryptomap Group
- Cryptomap Set Table
- Cryptomap Table
- CryptomapSet Transform Binding Table
- CryptomapSet Peer Binding Table
- CryptomapSet Interface Binding Table
d) Notification Control Group
e) Notifications Group
- Source file
CISCO-IPSEC-PROVISIONING-MIB- Last revised
- Identity
ciscoIPsecProvisioningMIB- Base OID
1.3.6.1.4.1.9.9.431
Imported Objects
| CISCO-IPSEC-TC | CIPsecCryptomapType CIPsecDiffHellmanGrp CIPsecEncapMode CIPsecLifesize CIPsecLifetime CIPsecNumCryptoMaps CIPsecSecuritySuite CIPsecTransform CIPsecTunnelIdleTime |
| CISCO-SMI | ciscoMgmt |
| IF-MIB | ifIndex |
| INET-ADDRESS-MIB | InetAddress InetAddressType |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | RowStatus TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IPSEC-PROVISIONING-MIB::ciscoIPsecProvisioningMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::ciscoIPsecProvisioningMIB'
Objects (73)
Showing 73 of 73 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.431 |
||
.1.3.6.1.4.1.9.9.431.0 |
||
.1.3.6.1.4.1.9.9.431.1 |
||
.1.3.6.1.4.1.9.9.431.1.1 |
||
|
secondsCISCO-IPSEC-TCCIPsecLifetime
|
.1.3.6.1.4.1.9.9.431.1.1.1 |
|
.1.3.6.1.4.1.9.9.431.1.1.2 |
||
.1.3.6.1.4.1.9.9.431.1.1.3 |
||
.1.3.6.1.4.1.9.9.431.1.2 |
||
.1.3.6.1.4.1.9.9.431.1.2.1 |
||
.1.3.6.1.4.1.9.9.431.1.2.1.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.2.1.1.1 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.431.1.2.1.1.2 |
|
.1.3.6.1.4.1.9.9.431.1.2.1.1.3 |
||
.1.3.6.1.4.1.9.9.431.1.2.1.1.4 |
||
.1.3.6.1.4.1.9.9.431.1.2.1.1.5 |
||
.1.3.6.1.4.1.9.9.431.1.2.1.1.6 |
||
.1.3.6.1.4.1.9.9.431.1.2.1.1.7 |
||
|
|
.1.3.6.1.4.1.9.9.431.1.2.1.1.8 |
|
.1.3.6.1.4.1.9.9.431.1.2.1.1.9 |
||
.1.3.6.1.4.1.9.9.431.1.3 |
||
.1.3.6.1.4.1.9.9.431.1.3.1 |
||
.1.3.6.1.4.1.9.9.431.1.3.2 |
||
.1.3.6.1.4.1.9.9.431.1.3.3 |
||
.1.3.6.1.4.1.9.9.431.1.4 |
||
.1.3.6.1.4.1.9.9.431.1.4.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.2 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.3 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.4 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.5 |
||
.1.3.6.1.4.1.9.9.431.1.4.1.1.6 |
||
.1.3.6.1.4.1.9.9.431.1.4.3 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.1 |
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.10 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1.11 |
||
|
secondsCISCO-IPSEC-TCCIPsecLifetime
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.12 |
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.13 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1.14 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1.15 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1.16 |
||
.1.3.6.1.4.1.9.9.431.1.4.3.1.17 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.2 |
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.3 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.4 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.5 |
|
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.6 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.7 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.8 |
|
.1.3.6.1.4.1.9.9.431.1.4.3.1.9 |
||
.1.3.6.1.4.1.9.9.431.1.4.4 |
||
.1.3.6.1.4.1.9.9.431.1.4.4.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.4.1.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.4.1.2 |
||
.1.3.6.1.4.1.9.9.431.1.4.4.1.3 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.431.1.4.4.1.4 |
|
.1.3.6.1.4.1.9.9.431.1.4.4.1.5 |
||
.1.3.6.1.4.1.9.9.431.1.4.5 |
||
.1.3.6.1.4.1.9.9.431.1.4.5.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.5.1.1 |
||
.1.3.6.1.4.1.9.9.431.1.4.6 |
||
.1.3.6.1.4.1.9.9.431.1.4.6.1 |
||
|
OctetString
|
.1.3.6.1.4.1.9.9.431.1.4.6.1.1 |
|
.1.3.6.1.4.1.9.9.431.1.5 |
||
.1.3.6.1.4.1.9.9.431.1.5.1 |
||
.1.3.6.1.4.1.9.9.431.1.5.2 |
||
.1.3.6.1.4.1.9.9.431.1.5.3 |
||
.1.3.6.1.4.1.9.9.431.1.5.4 |
||
.1.3.6.1.4.1.9.9.431.1.5.5 |
||
.1.3.6.1.4.1.9.9.431.2 |
||
.1.3.6.1.4.1.9.9.431.2.1 |
||
.1.3.6.1.4.1.9.9.431.2.2 |
Dependencies (10) 8 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-IPSEC-TCcisco
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- INET-ADDRESS-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-IPSEC-PROVISIONING-MIBciscoselected
Conformance Groups (9)
|
A collection of objects providing Global
IPSec policy monitoring capability to a IPsec capable VPN router. |
.1.3.6.1.4.1.9.9.431.2.2.1
|
|
|
cipsXformSetId cipsXformSetMode cipsXformSetSuite cipsXformSetEncryptionXform cipsXformSetIntegrityXformEsp cipsXformSetIntegrityXformAh cipsXformSetCompressionXform cipsXformSetStatus
A collection of objects modeling IPsec
transform sets and transform set mappings. |
.1.3.6.1.4.1.9.9.431.2.2.2
|
|
|
cipsNumStaticCryptomapSets cipsStaticCryptomapSetSize cipsStaticCryptomapSetNumIsakmp cipsStaticCryptomapSetNumManual cipsStaticCryptomapSetNumDynamic cipsStaticCryptomapSetNumTED cipsStaticCryptomapSetNumSAs cipsStaticCryptomapType cipsStaticCryptomapDescr cipsStaticCryptomapIpFilter cipsStaticCryptomapXformSetList cipsStaticCryptomapNumPeers cipsStaticCryotomapNextPIndex cipsStaticCryptomapCurPAddrType cipsStaticCryptomapCurPAddr cipsStaticCryptomapPfs cipsStaticCryptomapLifetime cipsStaticCryptomapLifesize cipsStaticCryptomapLevelHost cipsStaticCryptomapIdleTimeout cipsStaticCryptomapStatus cipsStaticCryptomapAutoPeer cipsCryMapPeerStatus cipsCryptomapSetIfStatus
A collection of objects modeling static
crypto configuration of the Static (fully specified) Cryptomap Sets on the managed entity. |
.1.3.6.1.4.1.9.9.431.2.2.3
|
|
|
A collection of objects modeling the configuration
of IPsec dynamic cryptomap elements. |
.1.3.6.1.4.1.9.9.431.2.2.4
|
|
|
A collection of objects instrumenting the
properties of the Cryptomaps using tunnel endpoint discovery protocol. |
.1.3.6.1.4.1.9.9.431.2.2.5
|
|
|
A collection of objects displaying the
binding of an IPsec peer address to the specified cryptomap. |
.1.3.6.1.4.1.9.9.431.2.2.6
|
|
|
cipsCntlAllNotifs cipsCntlCryptomapAdded cipsCntlCryptomapDeleted cipsCntlCryptomapSetAttached cipsCntlCryptomapSetDetached
A collection of objects providing IPsec
Notification capability to a IPsec-capable router. It is mandatory to implement this set of objects pertaining to IOS notifications about IPSec activity. |
.1.3.6.1.4.1.9.9.431.2.2.7
|
|
|
ciscoIPsecProvCryptomapDetached ciscoIPsecProvCryptomapAttached ciscoIPsecProvCryptomapDeleted ciscoIPsecProvCryptomapAdded
A collection of notification objects signaling
changes to the IPsec configuration on the managed entity. |
.1.3.6.1.4.1.9.9.431.2.2.8
|
|
|
A collection of objects providing current IPsec
configuration information on the managedentity. |
.1.3.6.1.4.1.9.9.431.2.2.9
|
Compliance Statements (2)
OID
.1.3.6.1.4.1.9.9.431.2.1.1The compliance statement for entities which
implement the Cisco IPsec Provisioning MIB.
implement the Cisco IPsec Provisioning MIB.
Required groups
| mandatory | ciscoIPsecProvGlobalsGroup | |
| mandatory | ciscoIPsecProvXformsGroup | |
| mandatory | ciscoIPsecProvStCryptomapGroup | |
| mandatory | ciscoIPsecCryptomapPeerGroup | |
| mandatory | ciscoIPsecProvNotifCntlGroup | |
| optional | ciscoIPsecProvDynCryptomapGroup |
This group must be implemented if the IKE implementation on the managed entity implements dynamic cryptomaps. |
| optional | ciscoIPsecProvTedCryptomapGroup |
This group must be implemented if the IKE implementation on the managed entity implements tunnel endpoint discovery. |
| optional | ciscoIPsecProvNotifGroup | This group is optional. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cipsTunnelLifetime | readonly | Write access is not required. | |
| cipsTunnelLifesize | readonly | Write access is not required. | |
| cipsTunnelIdleTimeout | readonly | Write access is not required. | |
| cipsCntlAllNotifs | readonly | Write access is not required. | |
| cipsCntlCryptomapAdded | readonly | Write access is not required. | |
| cipsCntlCryptomapDeleted | readonly | Write access is not required. | |
| cipsCntlCryptomapSetAttached | readonly | Write access is not required. | |
| cipsCntlCryptomapSetDetached | readonly | Write access is not required. | |
| cipsXformSetMode | readonly | Write access is not required. | |
| cipsStaticCryptomapIpFilter | readonly | Write access is not required. | |
| cipsStaticCryptomapXformSetList | readonly | Write access is not required. | |
| cipsStaticCryptomapPfs | readonly | Write access is not required. | |
| cipsStaticCryptomapLifetime | readonly | Write access is not required. | |
| cipsStaticCryptomapLifesize | readonly | Write access is not required. | |
| cipsStaticCryptomapLevelHost | readonly | Write access is not required. | |
| cipsStaticCryptomapIdleTimeout | readonly | Write access is not required. | |
| cipsStaticCryptomapAutoPeer | readonly | Write access is not required. | |
| cipsXformSetStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. If write access is implemented, only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. |
| cipsStaticCryptomapStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. If write access is implemented, only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. |
| cipsCryMapPeerStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. Write access is not required. |
| cipsCryptomapSetIfStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. Write access is not required. |
OID
.1.3.6.1.4.1.9.9.431.2.1.2The compliance statement for entities which
implement the Cisco IPsec Provisioning MIB.
implement the Cisco IPsec Provisioning MIB.
Required groups
| mandatory | ciscoIPsecProvGlobalsGroup | |
| mandatory | ciscoIPsecProvXformsGroup | |
| mandatory | ciscoIPsecProvStCryptomapGroup | |
| mandatory | ciscoIPsecCryptomapPeerGroup | |
| mandatory | ciscoIPsecProvNotifCntlGroup | |
| mandatory | ciscoIPsecProvInfoGroup | |
| optional | ciscoIPsecProvDynCryptomapGroup |
This group must be implemented if the IKE implementation on the managed entity implements dynamic cryptomaps. |
| optional | ciscoIPsecProvTedCryptomapGroup |
This group must be implemented if the IKE implementation on the managed entity implements tunnel endpoint discovery. |
| optional | ciscoIPsecProvNotifGroup | This group is optional. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cipsTunnelLifetime | readonly | Write access is not required. | |
| cipsTunnelLifesize | readonly | Write access is not required. | |
| cipsTunnelIdleTimeout | readonly | Write access is not required. | |
| cipsCntlAllNotifs | readonly | Write access is not required. | |
| cipsCntlCryptomapAdded | readonly | Write access is not required. | |
| cipsCntlCryptomapDeleted | readonly | Write access is not required. | |
| cipsCntlCryptomapSetAttached | readonly | Write access is not required. | |
| cipsCntlCryptomapSetDetached | readonly | Write access is not required. | |
| cipsXformSetMode | readonly | Write access is not required. | |
| cipsStaticCryptomapIpFilter | readonly | Write access is not required. | |
| cipsStaticCryptomapXformSetList | readonly | Write access is not required. | |
| cipsStaticCryptomapPfs | readonly | Write access is not required. | |
| cipsStaticCryptomapLifetime | readonly | Write access is not required. | |
| cipsStaticCryptomapLifesize | readonly | Write access is not required. | |
| cipsStaticCryptomapLevelHost | readonly | Write access is not required. | |
| cipsStaticCryptomapIdleTimeout | readonly | Write access is not required. | |
| cipsStaticCryptomapAutoPeer | readonly | Write access is not required. | |
| cipsXformSetStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. If write access is implemented, only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. |
| cipsStaticCryptomapStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Write access is not required. If write access is implemented, only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. |
| cipsCryMapPeerStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. Write access is not required. |
| cipsCryptomapSetIfStatus | readonly |
active(1), createAndGo(4), destroy(6)
|
Only three values 'createAndGo', 'destroy' and 'active' out of the six enumerated values need to be supported. Write access is not required. |
Notifications / Traps (4)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.431.0.1 |
This notification is generated when a new cryptomap
is added to the specified cryptomap set. Object 'cipsStaticCryptomapSetSize' contains the number of cryptomap entries after the addition. |
|
.1.3.6.1.4.1.9.9.431.0.2 |
This notification is generated when a cryptomap is
removed from the specified cryptomap set. Object 'cipsStaticCryptomapSetSize' contains the number of cryptomap entries after the deletion. |
|
.1.3.6.1.4.1.9.9.431.0.3 |
A cryptomap set must be attached to an interface
of the device in order for it to be operational. This trap is generated when the cryptomap set attached to an active interface of the managed entity. The contents of the notification includes: Size of the attached cryptomap set, Number of ISAKMP cryptomaps in the set and Number of Dynamic cryptomaps in the set. |
|
.1.3.6.1.4.1.9.9.431.0.4 |
This trap is generated when a cryptomap set is
detached from an interafce to which it was bound earlier. The context of the event identifies the size of the cryptomap set. |