CISCO-IPSEC-SIGNALING-MIB

        
This MIB Module models status, performance and failures
of a protocol with the generic characteristics of signalling 
protocols used with IPsec and FC-SP protocols. Examples
of such protocols include IKE, KINK, etc. This MIB views the
common attributes of such protocols. Signaling protocols are
also referred in this document as 'Control Protocols', since 
they perform session control.
        
This MIB is an attempt to capture the generic aspects 
of the signaling activity. The protocol-specific aspects
of a signaling protocol still need to be captured 
in a protocol-specific MIB (e.g., CISCO-IKE-FLOW-MIB, etc.).
        
Acronyms
The following acronyms are used in this document:
        
   IPsec:      Secure IP Protocol
        
   VPN:        Virtual Private Network
        
   ISAKMP:     Internet Security Association and Key Exchange
               Protocol
        
   IKE:        Internet Key Exchange Protocol
        
   SA:         Security Association 
           (ref: rfc2408).
        
   Phase 1 Tunnel:
               An ISAKMP SA can be regarded as representing
               a flow of ISAKMP/IKE traffic. Hence an ISAKMP
               is referred to as a 'Phase 1 Tunnel' in this
               document. 
        
   Control Tunnel:
               Another term for a Phase 1 Tunnel.
        
   Phase 2 Tunnel:
               An instance of a non-ISAKMP SA  bundle in which all
               the SA share the same proxy identifiers (IDii,IDir)
               protect the same stream of application traffic.
               Such an SA bundle is termed a 'Phase 2 Tunnel'.
               Note that a Phase 2 tunnel may comprise different
               SA bundles and different number of SA bundles at
               different times (due to key refresh).
        
        
History of the MIB
 A precursor to this MIB was the IPsec Flow Monitor MIB, which
 combined the objects pertaining to IKE and IPsec (Phase-2)
 into a single MIB module. Furthermore, the MIB supported only
 one signaling protocol, IKEv1, in addition to manual keying.
        
 The MIB was written by Tivoli and implemented in IBM Nways 
 routers in 1999. During late 1999, Cisco adopted the MIB and 
 together with Tivoli publised the IPsec Flow Monitor MIB in 
 IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. 
 In 2000, the MIB was Cisco-ized and implemented as
 CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
        
 With the evolution of IKEv2, the MIB was modified and 
 presented to the IPsec WG again in May 2003 in
 draft-ietf-ipsec-flow-monitoring-mib-02.txt.
        
 With the emergence to multiple signaling protocols, it has
 further evolved to define separate set of MIB modules to 
 instrument IPsec signaling alone. Thus, this MIB module
 is now the generic IPsec signaling MIB.
          
Overview of MIB
 The MIB contains major groups of objects which are
 used to manage the generic aspects of IPsec signaling. 
 These groups include a global statistics, control tunnel table,
 Peer association group, control tunnel history group,
 signaling failure group and notification group.
        
 The global statistics, tunnel table and peer association
 groups aid in the real-time monitoring of IPsec signaling
 activity.
        
 The History group is to aid applications that do
 trending analysis.
        
 The Failure group is to enable an operator to
 do troubleshooting and debugging.
 Further, counters are supported to aid detection
 of potential security violations.
        
 The notifications are modeled as generic IPsec control 
 notifications and are parameterized by the identity of the
 specific signaling protocol which caused the notification
 to be issued.
    
Source file
CISCO-IPSEC-SIGNALING-MIB
Last revised
Identity
ciscoIPsecSignalingMIB
Base OID
1.3.6.1.4.1.9.9.438
Imported Objects
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IPSEC-SIGNALING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IPSEC-SIGNALING-MIB::ciscoIPsecSignalingMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IPSEC-SIGNALING-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IPSEC-SIGNALING-MIB::ciscoIPsecSignalingMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (122)
.1.3.6.1.4.1.9.9.438
.1.3.6.1.4.1.9.9.438.0
.1.3.6.1.4.1.9.9.438.1
.1.3.6.1.4.1.9.9.438.1.1
.1.3.6.1.4.1.9.9.438.1.1.1
.1.3.6.1.4.1.9.9.438.1.1.1.1
.1.3.6.1.4.1.9.9.438.1.1.1.1.1
.1.3.6.1.4.1.9.9.438.1.1.1.1.10
.1.3.6.1.4.1.9.9.438.1.1.1.1.11
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.12
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.13
.1.3.6.1.4.1.9.9.438.1.1.1.1.14
.1.3.6.1.4.1.9.9.438.1.1.1.1.15
.1.3.6.1.4.1.9.9.438.1.1.1.1.16
.1.3.6.1.4.1.9.9.438.1.1.1.1.17
.1.3.6.1.4.1.9.9.438.1.1.1.1.18
.1.3.6.1.4.1.9.9.438.1.1.1.1.19
.1.3.6.1.4.1.9.9.438.1.1.1.1.2
.1.3.6.1.4.1.9.9.438.1.1.1.1.20
.1.3.6.1.4.1.9.9.438.1.1.1.1.21
.1.3.6.1.4.1.9.9.438.1.1.1.1.22
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.23
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.24
.1.3.6.1.4.1.9.9.438.1.1.1.1.3
.1.3.6.1.4.1.9.9.438.1.1.1.1.4
.1.3.6.1.4.1.9.9.438.1.1.1.1.5
.1.3.6.1.4.1.9.9.438.1.1.1.1.6
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.7
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.1.1.1.8
.1.3.6.1.4.1.9.9.438.1.1.1.1.9
.1.3.6.1.4.1.9.9.438.1.1.2
.1.3.6.1.4.1.9.9.438.1.1.2.1
.1.3.6.1.4.1.9.9.438.1.1.2.1.1
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.10
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.11
.1.3.6.1.4.1.9.9.438.1.1.2.1.12
.1.3.6.1.4.1.9.9.438.1.1.2.1.13
.1.3.6.1.4.1.9.9.438.1.1.2.1.14
.1.3.6.1.4.1.9.9.438.1.1.2.1.15
secondsUnsigned32
.1.3.6.1.4.1.9.9.438.1.1.2.1.16
.1.3.6.1.4.1.9.9.438.1.1.2.1.17
.1.3.6.1.4.1.9.9.438.1.1.2.1.18
.1.3.6.1.4.1.9.9.438.1.1.2.1.19
.1.3.6.1.4.1.9.9.438.1.1.2.1.2
.1.3.6.1.4.1.9.9.438.1.1.2.1.20
Notification PayloadsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.9.438.1.1.2.1.21
.1.3.6.1.4.1.9.9.438.1.1.2.1.22
.1.3.6.1.4.1.9.9.438.1.1.2.1.23
.1.3.6.1.4.1.9.9.438.1.1.2.1.24
Notification PayloadsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.9.438.1.1.2.1.25
Notification PayloadsSNMPv2-SMICounter32
.1.3.6.1.4.1.9.9.438.1.1.2.1.26
.1.3.6.1.4.1.9.9.438.1.1.2.1.27
Enumeration
.1.3.6.1.4.1.9.9.438.1.1.2.1.28
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.3
.1.3.6.1.4.1.9.9.438.1.1.2.1.4
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.5
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.6
.1.3.6.1.4.1.9.9.438.1.1.2.1.7
OctetString
.1.3.6.1.4.1.9.9.438.1.1.2.1.8
.1.3.6.1.4.1.9.9.438.1.1.2.1.9
.1.3.6.1.4.1.9.9.438.1.2
.1.3.6.1.4.1.9.9.438.1.3
.1.3.6.1.4.1.9.9.438.1.3.1
.1.3.6.1.4.1.9.9.438.1.3.1.1
Unsigned32
.1.3.6.1.4.1.9.9.438.1.3.1.1.1
.1.3.6.1.4.1.9.9.438.1.3.2
.1.3.6.1.4.1.9.9.438.1.3.2.1
.1.3.6.1.4.1.9.9.438.1.3.2.1.1
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.10
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.11
.1.3.6.1.4.1.9.9.438.1.3.2.1.12
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.13
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.14
.1.3.6.1.4.1.9.9.438.1.3.2.1.15
.1.3.6.1.4.1.9.9.438.1.3.2.1.16
.1.3.6.1.4.1.9.9.438.1.3.2.1.17
.1.3.6.1.4.1.9.9.438.1.3.2.1.18
Unsigned32
.1.3.6.1.4.1.9.9.438.1.3.2.1.19
Enumeration
.1.3.6.1.4.1.9.9.438.1.3.2.1.2
.1.3.6.1.4.1.9.9.438.1.3.2.1.20
.1.3.6.1.4.1.9.9.438.1.3.2.1.21
.1.3.6.1.4.1.9.9.438.1.3.2.1.22
.1.3.6.1.4.1.9.9.438.1.3.2.1.23
.1.3.6.1.4.1.9.9.438.1.3.2.1.24
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.3.2.1.25
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.3.2.1.26
.1.3.6.1.4.1.9.9.438.1.3.2.1.27
.1.3.6.1.4.1.9.9.438.1.3.2.1.28
.1.3.6.1.4.1.9.9.438.1.3.2.1.29
.1.3.6.1.4.1.9.9.438.1.3.2.1.3
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.3.2.1.30
Notification PayloadsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.438.1.3.2.1.31
.1.3.6.1.4.1.9.9.438.1.3.2.1.4
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.5
Unsigned32
.1.3.6.1.4.1.9.9.438.1.3.2.1.6
.1.3.6.1.4.1.9.9.438.1.3.2.1.7
OctetString
.1.3.6.1.4.1.9.9.438.1.3.2.1.8
.1.3.6.1.4.1.9.9.438.1.3.2.1.9
.1.3.6.1.4.1.9.9.438.1.4
.1.3.6.1.4.1.9.9.438.1.4.1
.1.3.6.1.4.1.9.9.438.1.4.1.1
Unsigned32
.1.3.6.1.4.1.9.9.438.1.4.1.1.1
.1.3.6.1.4.1.9.9.438.1.4.2
.1.3.6.1.4.1.9.9.438.1.4.2.1
.1.3.6.1.4.1.9.9.438.1.4.2.1.1
Enumeration
.1.3.6.1.4.1.9.9.438.1.4.2.1.2
.1.3.6.1.4.1.9.9.438.1.4.2.1.3
.1.3.6.1.4.1.9.9.438.1.4.2.1.4
OctetString
.1.3.6.1.4.1.9.9.438.1.4.2.1.5
.1.3.6.1.4.1.9.9.438.1.4.2.1.6
OctetString
.1.3.6.1.4.1.9.9.438.1.4.2.1.7
OctetString
.1.3.6.1.4.1.9.9.438.1.4.2.1.8
OctetString
.1.3.6.1.4.1.9.9.438.1.4.2.1.9
.1.3.6.1.4.1.9.9.438.1.5
.1.3.6.1.4.1.9.9.438.1.5.1
.1.3.6.1.4.1.9.9.438.1.5.2
.1.3.6.1.4.1.9.9.438.1.5.3
.1.3.6.1.4.1.9.9.438.1.5.4
.1.3.6.1.4.1.9.9.438.1.5.5
.1.3.6.1.4.1.9.9.438.2
.1.3.6.1.4.1.9.9.438.2.1
.1.3.6.1.4.1.9.9.438.2.2
Dependencies (6) 6 direct Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. CISCO-IPSEC-TCcisco
  5. SNMPv2-CONFrfc
  6. SNMP-FRAMEWORK-MIBrfc
  7. CISCO-IPSEC-SIGNALING-MIBciscoselected
Conformance Groups (7)
This group consists of:
1) Signaling Global Objects
2) control Tunnel table.
.1.3.6.1.4.1.9.9.438.2.2.1
This group consists of the core (mandatory)
objects pertaining to maintaining history of
signaling activity.
.1.3.6.1.4.1.9.9.438.2.2.2
This group consists of objects that pertain
to maintenance of history of
signaling activity.
.1.3.6.1.4.1.9.9.438.2.2.3
This group consists of the core (mandatory)
objects pertaining to maintaining history of
failure signaling activity.
.1.3.6.1.4.1.9.9.438.2.2.4
This group consists of objects that pertain
to maintenance of history of failures
associated with Ipsec signaling activity.
.1.3.6.1.4.1.9.9.438.2.2.5
This group of objects controls the sending
of notifications pertaining to signaling
operations.
.1.3.6.1.4.1.9.9.438.2.2.6
This group contains the notifications pertaining
to Ipsec signaling operations.
.1.3.6.1.4.1.9.9.438.2.2.7
Compliance Statements (1)

OID .1.3.6.1.4.1.9.9.438.2.1.1
The compliance statement for SNMP entities
the IPsec Signaling MIB.
Required groups
mandatory ciscoIpsSgActivityGroup
mandatory ciscoIpsSgCoreHistoryGroup
mandatory ciscoIpsSgCoreFailureGroup
optional ciscoIpsSgHistoryGroup This group is optional and must be implemented
by the agent of the managed entity if and only
if
a) the managed entity implements signaling for
IPsec and FC-SP
b) and the managed entity implements historical
archiving of control tunnels.
optional ciscoIpsSgFailureGroup This group is optional and must be implemented
by the agent of the managed entity if and only
if
a) the managed entity implements signaling for
IPsec and FC-SP and
b) the managed entity implements historical
archiving of setup and operational failures
of IPsec control tunnels.
optional ciscoIpsSgNotifcationGroup This group is optional.
optional ciscoIpsSgNotifCntlGroup The agent must implement this group if it
implements the group 'ciscoIpsSgNotifcationGroup'.
Object refinements
ObjectAccessSyntaxDescription
cisgIpsSgTunAction readonly
It is compliant to support only a subset of the values
defined.
Notifications / Traps (4)
NameOIDDescription
.1.3.6.1.4.1.9.9.438.0.1
This notification is generated when an control tunnel
becomes active.
.1.3.6.1.4.1.9.9.438.0.2
This notification is generated when an
control tunnel becomes inactive.
.1.3.6.1.4.1.9.9.438.0.3
This notification is generated when the processing
for an control Tunnel experiences an
system capacity error.
.1.3.6.1.4.1.9.9.438.0.4
This notification is generated when the
processing for an control Tunnel
experiences a Certificate or a Certificate
validation (CRL or OCSP) related error.