CISCO-IPSEC-PROVISIONING-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
39
.1.3.6.1.4.1.9.9.431.1.2.1 · 1 row entry · 9 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsIPsecXformSetTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsIPsecXformSetTable'
This table contains the list of all the transform sets
configured on the managed entity. A transform set is usually
configured by a management console before a cryptomap is
created.  Multiple transform sets could be assigned to a
cryptomap configuration.
cipsIPsecXformSetEntry row .1.3.6.1.4.1.9.9.431.1.2.1.1
Each entry represents a single configured
IPsec transform set.
Column Syntax OID
This object contains the name of the transform set
corresponding to this conceptual row.
OctetString
Constraints:
range: 1-80
.1.3.6.1.4.1.9.9.431.1.2.1.1.1
This is the sequence number of the transform set that
uniquely identifies the transform set.
Distinct transform sets must have distinct sequence
numbers.
Unsigned32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.9.9.431.1.2.1.1.2
This object represents the suite of Phase-2 security
protocols of this transform set.
CISCO-IPSEC-TCCIPsecSecuritySuiter/w
Type Values:
1suiteOther
2suiteConfEsp
3suiteIntegEsp
4suiteIntegAh
5suiteConfComp
6suiteIntegEspComp
7suiteIntegAhComp
8suiteConfAh
9suiteConfAhComp
10suiteIntegEspAh
11suiteIntegEspAhComp
12suiteConfIntegEsp
13suiteConfIntegEspComp
14suiteConfIntegEspAh
15suiteConfIntegEspAhComp
.1.3.6.1.4.1.9.9.431.1.2.1.1.3
This object represents the transform used for
ESP encryption.

The only values this object may assume are 'xformNONE',
'xformEspNULL', 'xformEspDES', 'xformEsp3DES',
'xformEspAES128', 'xformEspAES192', '…
CISCO-IPSEC-TCCIPsecTransformr/w
Type Values:
1xformNONE
2xformOTHER
3xformAhRFC1829
4xformAhMD5
5xformAhSHA1
6xformEspNULL
7xformEspDES
8xformEsp3DES
9xformEspAES128
10xformEspAES192
11xformEspAES256
12xformEspMD5
13xformEspSHA1
14xformCompLZS
15xformEspAESCtr128
16xformEspAESCtr192
17xformEspAESCtr256
18xformEspRc5
19xformEspIdea
20xformEspCast
21xformEspTwofish
22xformEspBlowfish
23xformEsp3idea
24xformEspRc4
25xformEspDesMac
26xformEspHmacSha256
27xformEspHmacSha384
28xformEspHmacSha512
29xformEspRipemd
30xformAHDesMac
31xformAHHmacSha256
32xformAHHmacSha384
33xformAHHmacSha512
34xformAHRipemd
35xformEspAESXCbcMac
36xformAHAESXCbcMac
.1.3.6.1.4.1.9.9.431.1.2.1.1.4
This object represents the transform used to
implement integrity check with ESP protocol.

If the value of the corresponding instance of
cipsXformSetSuite is 'suiteIntegAh', 'suiteIntegAhComp'
or 'suiteOt…
CISCO-IPSEC-TCCIPsecTransformr/w
Type Values:
1xformNONE
2xformOTHER
3xformAhRFC1829
4xformAhMD5
5xformAhSHA1
6xformEspNULL
7xformEspDES
8xformEsp3DES
9xformEspAES128
10xformEspAES192
11xformEspAES256
12xformEspMD5
13xformEspSHA1
14xformCompLZS
15xformEspAESCtr128
16xformEspAESCtr192
17xformEspAESCtr256
18xformEspRc5
19xformEspIdea
20xformEspCast
21xformEspTwofish
22xformEspBlowfish
23xformEsp3idea
24xformEspRc4
25xformEspDesMac
26xformEspHmacSha256
27xformEspHmacSha384
28xformEspHmacSha512
29xformEspRipemd
30xformAHDesMac
31xformAHHmacSha256
32xformAHHmacSha384
33xformAHHmacSha512
34xformAHRipemd
35xformEspAESXCbcMac
36xformAHAESXCbcMac
.1.3.6.1.4.1.9.9.431.1.2.1.1.5
This object represents the transform used to
implement integrity check with AH protocol.

If the value of the corresponding instance of
cipsXformSetSuite is neither 'suiteIntegAh' nor
'suiteIntegAhComp', …
CISCO-IPSEC-TCCIPsecTransformr/w
Type Values:
1xformNONE
2xformOTHER
3xformAhRFC1829
4xformAhMD5
5xformAhSHA1
6xformEspNULL
7xformEspDES
8xformEsp3DES
9xformEspAES128
10xformEspAES192
11xformEspAES256
12xformEspMD5
13xformEspSHA1
14xformCompLZS
15xformEspAESCtr128
16xformEspAESCtr192
17xformEspAESCtr256
18xformEspRc5
19xformEspIdea
20xformEspCast
21xformEspTwofish
22xformEspBlowfish
23xformEsp3idea
24xformEspRc4
25xformEspDesMac
26xformEspHmacSha256
27xformEspHmacSha384
28xformEspHmacSha512
29xformEspRipemd
30xformAHDesMac
31xformAHHmacSha256
32xformAHHmacSha384
33xformAHHmacSha512
34xformAHRipemd
35xformEspAESXCbcMac
36xformAHAESXCbcMac
.1.3.6.1.4.1.9.9.431.1.2.1.1.6
This object represents the transform used to
implement packet compression.

If the value of the corresponding instance of
cipsXformSetSuite is 'suiteConf', 'suiteIntegEsp',
'suiteIntegAh', 'suiteConfAh', '…
CISCO-IPSEC-TCCIPsecTransformr/w
Type Values:
1xformNONE
2xformOTHER
3xformAhRFC1829
4xformAhMD5
5xformAhSHA1
6xformEspNULL
7xformEspDES
8xformEsp3DES
9xformEspAES128
10xformEspAES192
11xformEspAES256
12xformEspMD5
13xformEspSHA1
14xformCompLZS
15xformEspAESCtr128
16xformEspAESCtr192
17xformEspAESCtr256
18xformEspRc5
19xformEspIdea
20xformEspCast
21xformEspTwofish
22xformEspBlowfish
23xformEsp3idea
24xformEspRc4
25xformEspDesMac
26xformEspHmacSha256
27xformEspHmacSha384
28xformEspHmacSha512
29xformEspRipemd
30xformAHDesMac
31xformAHHmacSha256
32xformAHHmacSha384
33xformAHHmacSha512
34xformAHRipemd
35xformEspAESXCbcMac
36xformAHAESXCbcMac
.1.3.6.1.4.1.9.9.431.1.2.1.1.7
This object represents the encapsulation mode of the
transform set.
CISCO-IPSEC-TCCIPsecEncapModer/w
Type Values:
1encapTunnel
2encapTransport
.1.3.6.1.4.1.9.9.431.1.2.1.1.8
This object represents the status of the
transform set entry.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.431.1.2.1.1.9
.1.3.6.1.4.1.9.9.431.1.4.1 · 1 row entry · 6 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsStaticCryptomapSetTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsStaticCryptomapSetTable'
This read-only table contains the list of all
cryptomap sets that are fully configured.
          
The operator may include different types of
cryptomaps in such a set - manual, ISAKMP or 
dynamic.
          
An entry is added to (removed from) this table
automatically by the agent when the first (last)
'active' entry with the corresponding
cipsStaticCryptomapSetName is added to
(removed from) cipsStaticCryptomapTable.
cipsStaticCryptomapSetEntry row .1.3.6.1.4.1.9.9.431.1.4.1.1
Each entry contains the attributes
associated with a single static cryptomap set.
Column Syntax OID
This object reflects the total number of cryptomap
templates contained in this cryptomap set.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.1
This object reflects the number of cryptomaps
associated with this cryptomap set that use ISAKMP
protocol to do key exchange.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.2
This object reflects the number of cryptomaps
associated with this cryptomap set that require the
operator to manually setup the keys and SPIs.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.3
This object reflects the number of dynamic
cryptomap templates linked to this cryptomap set.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.4
This object reflects the number of dynamic
cryptomap templates linked to this cryptomap set
that have Tunnel Endpoint Discovery (TED) enabled.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.5
This object reflects the number of IPsec Security
Associations that are active and were setup using this
cryptomap set.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.1.1.6
.1.3.6.1.4.1.9.9.431.1.4.3 · 1 row entry · 17 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsStaticCryptomapTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsStaticCryptomapTable'
The table listing the member cryptomaps
of the cryptomap sets that are configured
on the managed entity.
          
This table does not include the members 
of dynamic cryptomap sets that may be
linked with the parent static cryptomap set.
          
Deletion of a cipsStaticCryptomapEntry will
fail if the cipsStaticCryptomapSetName this
cipsStaticCryptomapEntry belongs to is referred
by a cipsCryptomapSetIfEntry.
cipsStaticCryptomapEntry row .1.3.6.1.4.1.9.9.431.1.4.3.1
Each entry contains the attributes associated with a
single static (fully specified) cryptomap entry,
identified by its priority.
Column Syntax OID
The index of the static cryptomap table. The value
of the string is the name string assigned by the
NMS when defining a cryptomap set.
OctetString
Constraints:
range: 1-80
.1.3.6.1.4.1.9.9.431.1.4.3.1.1
The priority of the cryptomap entry in the
cryptomap set. A cryptomap entry with smaller
cipsStaticCryptomapPriority value takes
precedence over the ones with larger values.
Unsigned32
Constraints:
range: 1-65535
.1.3.6.1.4.1.9.9.431.1.4.3.1.2
The type of the cryptomap entry. This can be an ISAKMP
cryptomap or manual. Dynamic cryptomaps are not
counted in this table.
CISCO-IPSEC-TCCIPsecCryptomapTyper/w
Type Values:
1cryptomapTypeNONE
2cryptomapTypeMANUAL
3cryptomapTypeISAKMP
4cryptomapTypeCET
5cryptomapTypeDYNAMIC
6cryptomapTypeDYNAMICDISCOVERY
.1.3.6.1.4.1.9.9.431.1.4.3.1.3
The description string created by the SNMP agent
while creating this cryptomap. The string generally
identifies a description and the purpose of this
policy.
OctetString
Constraints:
range: 1-127
.1.3.6.1.4.1.9.9.431.1.4.3.1.4
This object specifies an IP protocol filter,
cippfIpProfileName
(defined in CISCO-IP-PROTOCOL-FILTER-MIB),
to be secured using this cryptomap entry.

When this object has a value of zero-length
string, thi…
OctetStringr/w
Constraints:
range: 0-64
.1.3.6.1.4.1.9.9.431.1.4.3.1.5
The list of cipsXformSetId that are members
of this CipsStaticCryptomapEntry.

The value of this object is a concatenation of zero or
more 4-octet strings, where each 4-octet string contains
a 32-bit cipsX…
OctetStringr/w
Constraints:
range: 0-255
.1.3.6.1.4.1.9.9.431.1.4.3.1.6
This object reflects the number of peers associated
with this cryptomap entry. The other peers listed in
table cipsIPsecCryMapPeerTable are backup peers.
Unsigned32
Constraints:
range: 0-50
.1.3.6.1.4.1.9.9.431.1.4.3.1.7
This object specifies the next available index for object
cipsCryMapPeerIndex which can be used for
creating an entry in cipsIPsecCryMapPeerTable.
Unsigned32
Constraints:
range: 1-50
.1.3.6.1.4.1.9.9.431.1.4.3.1.8
This object represents the address type of
cipsStaticCryptomapCurPAddr to which this cryptomap
entry is currently connected.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.431.1.4.3.1.9
The IP address of the peer to which this cryptomap
entry is currently connected.

The value of cipsStaticCryptomapCurPAddrType is
'unknown' and this MIB object is a zero-length
string when no tunnels are …
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.431.1.4.3.1.10
This object identifies if the tunnels instantiated
due to this policy item should use Perfect Forward
Secrecy (PFS) and if so, what group of Oakley
they should use.
CISCO-IPSEC-TCCIPsecDiffHellmanGrpr/w
Type Values:
1other
2notDH
3modp768
4modp1024
5ec2nGP155
6ec2nGP185
7modp1536
8ec2nGF163
9ec2nGF283
10ec2nGF409
11ec2nGF571
12modp2048
.1.3.6.1.4.1.9.9.431.1.4.3.1.11
This object specifies the lifetime of the IPsec
Security Associations (SA) created using this IPsec
policy entry.

The default value of this object is the current value
of the object cipsTunnelLifetime. …
secondsCISCO-IPSEC-TCCIPsecLifetimer/w
Type Constraints:
range: 0
range: 120..86400
.1.3.6.1.4.1.9.9.431.1.4.3.1.12
This object identifies the lifesize (maximum traffic
in bytes that may be carried) of the IPSec SAs
created using this IPSec policy entry.
When a Security Association (SA) is created using
this IPsec policy entry, its l…
KBytesCISCO-IPSEC-TCCIPsecLifesizer/w
Type Constraints:
range: 0
range: 2560..4294967295
.1.3.6.1.4.1.9.9.431.1.4.3.1.13
This object specifies the granularity of the
IPSec SAs created using this IPSec policy entry.
If this value is 'true', distinct SA bundles are
created for distinct hosts at the end of
the application traffic.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.431.1.4.3.1.14
This object specifies the idle time (lack of traffic)
in seconds of a tunnel spawned by this cryptomap after
which the tunnel will be torn down.

The default value of this object is the current value
of c…
CISCO-IPSEC-TCCIPsecTunnelIdleTimer/w
Type Constraints:
range: 0
range: 60..86400
.1.3.6.1.4.1.9.9.431.1.4.3.1.15
If 'true' the destination address is taken as the
peer address, while creating the tunnel.
If 'false' the value shown by the object
cipsStaticCryptomapCurPAddr is being used as
the peer address.
SNMPv2-TCTruthValuer/w
Type Values:
1true
2false
Description:
Represents a boolean value.
.1.3.6.1.4.1.9.9.431.1.4.3.1.16
This object identifies the status of the cryptomap
entry represented by this conceptual row.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.431.1.4.3.1.17
.1.3.6.1.4.1.9.9.431.1.4.4 · 1 row entry · 5 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsIPsecCryMapPeerTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsIPsecCryMapPeerTable'
The table containing the binding of peers to
cryptomap entries.
          
An entry is removed from this table
automatically by the agent when the last
'active' entry with the corresponding
cipsStaticCryptomapSetName is removed from
cipsStaticCryptomapTable.
cipsIPsecCryMapPeerEntry row .1.3.6.1.4.1.9.9.431.1.4.4.1
Each entry represents the binding of
an IPsec peer address to the specified
cryptomap.
Column Syntax OID
This arbitrary number represents the index number
in the cryptomap entry of the peer corresponding
to this conceptual row.

This object could have the same value as
cipsStaticCryotomapNextPIndex.
SNMPv2-SMIUnsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.9.9.431.1.4.4.1.1
This object represents the address type of
cipsCryMapPeerAddr.

This object cannot be modified while the corresponding
value of cipsCryMapPeerStatus is equal to
'active'.
INET-ADDRESS-MIBInetAddressTyper/w
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.9.9.431.1.4.4.1.2
This object represents the address of the peer
corresponding to this conceptual row.

This object cannot be modified while the corresponding
value of cipsCryMapPeerStatus is equal to
'active'.
INET-ADDRESS-MIBInetAddressr/w
Type Constraints:
range: 0..255
.1.3.6.1.4.1.9.9.431.1.4.4.1.3
This object represents the order in the cryptomap
entry of the peer corresponding to this
conceptual row.

The peer with the lowest order number is applied
first, that is cipsCryMapPeerOrder '1'.
Unsigned32
Constraints:
range: 1-50
.1.3.6.1.4.1.9.9.431.1.4.4.1.4
This object specifies the status column used for
creating and deleting instances of the columnar
objects in the table.
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.431.1.4.4.1.5
.1.3.6.1.4.1.9.9.431.1.4.5 · 1 row entry · 1 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsCryptomapSetIfTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsCryptomapSetIfTable'
The table lists the binding of cryptomap sets
to the interfaces of the managed entity.
One interface can be bound to only one cryptomap set
while one cryptomap set can be bound to multiple
interfaces.
          
Any interface (with any ifType) which supports
IPsec can be used in this table.
cipsCryptomapSetIfEntry row .1.3.6.1.4.1.9.9.431.1.4.5.1
Each entry lists the association between an interface
and a cryptomap set (static) that is defined
on the managed entity.
Column Syntax OID
This object identifies the status of the binding
of the specified cryptomap set with the specified
interface.

Detaching a cryptomap from an interface:
----------------------------------------
When se…
SNMPv2-TCRowStatusr/w
Type Values:
1active
2notInService
3notReady
4createAndGo
5createAndWait
6destroy
Description:
The RowStatus textual convention is used to manage the
creation and deletion of conceptual rows, and is used as the
value of the SYNTAX clause for the status column of a
conceptual row (as described in Section 7.7.1 of …
.1.3.6.1.4.1.9.9.431.1.4.5.1.1
.1.3.6.1.4.1.9.9.431.1.4.6 · 1 row entry · 1 columns
Uses the cisco variant from /opt/observium/mibs/cisco.
Command help
Walk cipsIfCryptomapSetInfoTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-PROVISIONING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-PROVISIONING-MIB::cipsIfCryptomapSetInfoTable'
The table lists the binding information of a
interface to a cryptomap sets on the managed entity.
One interface can be bound to only one cryptomap set
while one cryptomap set can be bound to multiple
interfaces.
          
An entry is added to cipsIfCryptomapSetInfoTable when
a static cryptomap set is successfully assigned to an
interface (of any ifType) in cipsCryptomapSetIfTable.
An entry is deleted from cipsIfCryptomapSetInfoTable
when its assignment is removed
from cipsIfCryptomapSetInfoTable.
cipsIfCryptomapSetInfoEntry row .1.3.6.1.4.1.9.9.431.1.4.6.1
Each entry lists the binding between an interface
and a cryptomap set (static) that is defined
on the managed entity.
Indexes
Column Syntax OID
The name of a static cryptomap set which is bound
to this interface. The value of the string is one of
the entries in cipsStaticCryptomapSetTable indexed by
cipsStaticCryptomapSetName.
OctetString
Constraints:
range: 1-80
.1.3.6.1.4.1.9.9.431.1.4.6.1.1