IPSEC-SA-MON-MIB

        The MIB module to describe generic IPsec objects, and
entity level objects and events for those types.
    
Source file
IPSEC-SA-MON-MIB
Last revised
Identity
ipsecSaMonModule
Base OID
1.3.6.1.2.1.500
Imported Objects
IF-MIB ifIndex
IPSEC-ISAKMP-IKE-DOI-TC IpsecDoiAhTransform IpsecDoiAuthAlgorithm IpsecDoiEncapsulationMode IpsecDoiEspTransform IpsecDoiIdentType IpsecDoiIpcompTransform IpsecDoiSecProtocolId
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Counter64 Gauge32 Integer32 mib-2 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the rfc MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'IPSEC-SA-MON-MIB::ipsecSaMonModule'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaMonModule'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (180)
.1.3.6.1.2.1.500
.1.3.6.1.2.1.500.1
.1.3.6.1.2.1.500.1.1
.1.3.6.1.2.1.500.1.1.1
.1.3.6.1.2.1.500.1.1.1.1
.1.3.6.1.2.1.500.1.1.1.1.1
.1.3.6.1.2.1.500.1.1.1.1.10
.1.3.6.1.2.1.500.1.1.1.1.11
.1.3.6.1.2.1.500.1.1.1.1.12
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.1.1.13
.1.3.6.1.2.1.500.1.1.1.1.14
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.1.1.15
.1.3.6.1.2.1.500.1.1.1.1.16
.1.3.6.1.2.1.500.1.1.1.1.17
.1.3.6.1.2.1.500.1.1.1.1.18
.1.3.6.1.2.1.500.1.1.1.1.19
.1.3.6.1.2.1.500.1.1.1.1.2
.1.3.6.1.2.1.500.1.1.1.1.20
.1.3.6.1.2.1.500.1.1.1.1.21
.1.3.6.1.2.1.500.1.1.1.1.22
.1.3.6.1.2.1.500.1.1.1.1.23
.1.3.6.1.2.1.500.1.1.1.1.24
.1.3.6.1.2.1.500.1.1.1.1.25
.1.3.6.1.2.1.500.1.1.1.1.26
.1.3.6.1.2.1.500.1.1.1.1.27
.1.3.6.1.2.1.500.1.1.1.1.28
.1.3.6.1.2.1.500.1.1.1.1.3
.1.3.6.1.2.1.500.1.1.1.1.4
.1.3.6.1.2.1.500.1.1.1.1.5
.1.3.6.1.2.1.500.1.1.1.1.6
Integer32
.1.3.6.1.2.1.500.1.1.1.1.7
Integer32
.1.3.6.1.2.1.500.1.1.1.1.8
Integer32
.1.3.6.1.2.1.500.1.1.1.1.9
.1.3.6.1.2.1.500.1.1.2
.1.3.6.1.2.1.500.1.1.2.1
.1.3.6.1.2.1.500.1.1.2.1.1
.1.3.6.1.2.1.500.1.1.2.1.10
.1.3.6.1.2.1.500.1.1.2.1.11
.1.3.6.1.2.1.500.1.1.2.1.12
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.2.1.13
.1.3.6.1.2.1.500.1.1.2.1.14
.1.3.6.1.2.1.500.1.1.2.1.15
.1.3.6.1.2.1.500.1.1.2.1.16
.1.3.6.1.2.1.500.1.1.2.1.17
.1.3.6.1.2.1.500.1.1.2.1.18
.1.3.6.1.2.1.500.1.1.2.1.19
.1.3.6.1.2.1.500.1.1.2.1.2
.1.3.6.1.2.1.500.1.1.2.1.20
.1.3.6.1.2.1.500.1.1.2.1.21
.1.3.6.1.2.1.500.1.1.2.1.22
.1.3.6.1.2.1.500.1.1.2.1.23
.1.3.6.1.2.1.500.1.1.2.1.24
.1.3.6.1.2.1.500.1.1.2.1.3
.1.3.6.1.2.1.500.1.1.2.1.4
.1.3.6.1.2.1.500.1.1.2.1.5
.1.3.6.1.2.1.500.1.1.2.1.6
Integer32
.1.3.6.1.2.1.500.1.1.2.1.7
Integer32
.1.3.6.1.2.1.500.1.1.2.1.8
Integer32
.1.3.6.1.2.1.500.1.1.2.1.9
.1.3.6.1.2.1.500.1.1.3
.1.3.6.1.2.1.500.1.1.3.1
.1.3.6.1.2.1.500.1.1.3.1.1
.1.3.6.1.2.1.500.1.1.3.1.10
.1.3.6.1.2.1.500.1.1.3.1.11
.1.3.6.1.2.1.500.1.1.3.1.12
.1.3.6.1.2.1.500.1.1.3.1.13
.1.3.6.1.2.1.500.1.1.3.1.14
.1.3.6.1.2.1.500.1.1.3.1.15
.1.3.6.1.2.1.500.1.1.3.1.16
.1.3.6.1.2.1.500.1.1.3.1.17
.1.3.6.1.2.1.500.1.1.3.1.2
.1.3.6.1.2.1.500.1.1.3.1.3
.1.3.6.1.2.1.500.1.1.3.1.4
.1.3.6.1.2.1.500.1.1.3.1.5
.1.3.6.1.2.1.500.1.1.3.1.6
Integer32
.1.3.6.1.2.1.500.1.1.3.1.7
Integer32
.1.3.6.1.2.1.500.1.1.3.1.8
Integer32
.1.3.6.1.2.1.500.1.1.3.1.9
.1.3.6.1.2.1.500.1.1.4
.1.3.6.1.2.1.500.1.1.4.1
.1.3.6.1.2.1.500.1.1.4.1.1
.1.3.6.1.2.1.500.1.1.4.1.10
.1.3.6.1.2.1.500.1.1.4.1.11
.1.3.6.1.2.1.500.1.1.4.1.12
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.4.1.13
.1.3.6.1.2.1.500.1.1.4.1.14
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.4.1.15
.1.3.6.1.2.1.500.1.1.4.1.16
.1.3.6.1.2.1.500.1.1.4.1.17
.1.3.6.1.2.1.500.1.1.4.1.18
.1.3.6.1.2.1.500.1.1.4.1.19
.1.3.6.1.2.1.500.1.1.4.1.2
.1.3.6.1.2.1.500.1.1.4.1.20
.1.3.6.1.2.1.500.1.1.4.1.21
.1.3.6.1.2.1.500.1.1.4.1.22
.1.3.6.1.2.1.500.1.1.4.1.3
.1.3.6.1.2.1.500.1.1.4.1.4
.1.3.6.1.2.1.500.1.1.4.1.5
.1.3.6.1.2.1.500.1.1.4.1.6
Integer32
.1.3.6.1.2.1.500.1.1.4.1.7
Integer32
.1.3.6.1.2.1.500.1.1.4.1.8
Integer32
.1.3.6.1.2.1.500.1.1.4.1.9
.1.3.6.1.2.1.500.1.1.5
.1.3.6.1.2.1.500.1.1.5.1
.1.3.6.1.2.1.500.1.1.5.1.1
.1.3.6.1.2.1.500.1.1.5.1.10
.1.3.6.1.2.1.500.1.1.5.1.11
.1.3.6.1.2.1.500.1.1.5.1.12
bitsUnsigned32
.1.3.6.1.2.1.500.1.1.5.1.13
.1.3.6.1.2.1.500.1.1.5.1.14
.1.3.6.1.2.1.500.1.1.5.1.15
.1.3.6.1.2.1.500.1.1.5.1.16
.1.3.6.1.2.1.500.1.1.5.1.17
.1.3.6.1.2.1.500.1.1.5.1.18
.1.3.6.1.2.1.500.1.1.5.1.19
.1.3.6.1.2.1.500.1.1.5.1.2
.1.3.6.1.2.1.500.1.1.5.1.20
.1.3.6.1.2.1.500.1.1.5.1.3
.1.3.6.1.2.1.500.1.1.5.1.4
.1.3.6.1.2.1.500.1.1.5.1.5
.1.3.6.1.2.1.500.1.1.5.1.6
Integer32
.1.3.6.1.2.1.500.1.1.5.1.7
Integer32
.1.3.6.1.2.1.500.1.1.5.1.8
Integer32
.1.3.6.1.2.1.500.1.1.5.1.9
.1.3.6.1.2.1.500.1.1.6
.1.3.6.1.2.1.500.1.1.6.1
.1.3.6.1.2.1.500.1.1.6.1.1
.1.3.6.1.2.1.500.1.1.6.1.10
.1.3.6.1.2.1.500.1.1.6.1.11
.1.3.6.1.2.1.500.1.1.6.1.12
.1.3.6.1.2.1.500.1.1.6.1.13
.1.3.6.1.2.1.500.1.1.6.1.14
.1.3.6.1.2.1.500.1.1.6.1.15
.1.3.6.1.2.1.500.1.1.6.1.16
.1.3.6.1.2.1.500.1.1.6.1.2
.1.3.6.1.2.1.500.1.1.6.1.3
.1.3.6.1.2.1.500.1.1.6.1.4
.1.3.6.1.2.1.500.1.1.6.1.5
.1.3.6.1.2.1.500.1.1.6.1.6
Integer32
.1.3.6.1.2.1.500.1.1.6.1.7
Integer32
.1.3.6.1.2.1.500.1.1.6.1.8
Integer32
.1.3.6.1.2.1.500.1.1.6.1.9
.1.3.6.1.2.1.500.1.2
.1.3.6.1.2.1.500.1.2.1
.1.3.6.1.2.1.500.1.2.10
.1.3.6.1.2.1.500.1.2.11
.1.3.6.1.2.1.500.1.2.12
.1.3.6.1.2.1.500.1.2.2
.1.3.6.1.2.1.500.1.2.3
.1.3.6.1.2.1.500.1.2.4
.1.3.6.1.2.1.500.1.2.5
.1.3.6.1.2.1.500.1.2.6
.1.3.6.1.2.1.500.1.2.7
.1.3.6.1.2.1.500.1.2.8
.1.3.6.1.2.1.500.1.2.9
.1.3.6.1.2.1.500.1.3
.1.3.6.1.2.1.500.1.3.1
.1.3.6.1.2.1.500.1.3.2
.1.3.6.1.2.1.500.1.3.3
.1.3.6.1.2.1.500.1.3.4
.1.3.6.1.2.1.500.1.3.5
.1.3.6.1.2.1.500.1.3.6
.1.3.6.1.2.1.500.1.3.7
.1.3.6.1.2.1.500.1.4
.1.3.6.1.2.1.500.1.5
.1.3.6.1.2.1.500.1.5.1
.1.3.6.1.2.1.500.1.5.2
.1.3.6.1.2.1.500.1.5.3
.1.3.6.1.2.1.500.1.5.4
.1.3.6.1.2.1.500.1.6
.1.3.6.1.2.1.500.1.6.1
.1.3.6.1.2.1.500.1.6.2
.1.3.6.1.2.1.500.1.6.3
.1.3.6.1.2.1.500.1.6.4
.1.3.6.1.2.1.500.1.6.5
.1.3.6.1.2.1.500.1.6.6
.1.3.6.1.2.1.500.1.6.7
.1.3.6.1.2.1.500.1.6.8
.1.3.6.1.2.1.500.1.7
.1.3.6.1.2.1.500.1.8
Dependencies (7) 5 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (3)
OctetString range: 16
OctetString range: 0..255
Enumeration
unknown(0)
static(1)
ike(2)
other(3)
Conformance Groups (7)
A collection of objects that describe the state of the
security associations of the ESP protocol.
.1.3.6.1.2.1.500.1.7.1
A collection of objects that describe the state of the
security associations of the AH protocol.
.1.3.6.1.2.1.500.1.7.2
A collection of objects that describe the state of the
security associations of the IPComp protocol.
.1.3.6.1.2.1.500.1.7.3
A collection of objects providing global IPsec error
counters.
.1.3.6.1.2.1.500.1.7.4
A collection of objects providing control over trap
generation.
.1.3.6.1.2.1.500.1.7.5
A collection of objects used only as arguments in traps.
.1.3.6.1.2.1.500.1.7.6
A collection of traps.
.1.3.6.1.2.1.500.1.7.7
Compliance Statements (1)

OID .1.3.6.1.2.1.500.1.8.1
The compliance statement for SNMPv2 entities which
implement the IPsec Monitoring MIB.
Required groups
mandatory ipsecSaEspGroup
mandatory ipsecSaAhGroup
mandatory ipsecSaErrorsGroup
mandatory ipsecSaFailureTrapEnableGroup
mandatory ipsecSaFailureTrapGroup
optional ipsecSaIpcompGroup This group is mandatory only for those systems that
implement the IPComp protocol as a part of the IPsec
suite.
Object refinements
ObjectAccessSyntaxDescription
espAuthFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
ahAuthFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
espReplayFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
ahReplayFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
espPolicyFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
ahPolicyFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
invalidSpiTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
otherPolicyFailureTrapEnable readonly
If an implementation cannot properly secure this
variable against unauthorized write access, it
SHOULD implement it as read-only, to prevent the
security risk of enabling the traps. Of course,
there must be other means of controlling the
generation of the associated trap.
Notifications / Traps (8)
NameOIDDescription
.1.3.6.1.2.1.500.1.4.0.1
IPsec packets with invalid hashes were found in an inbound
ESP SA. The total number of authentication errors
accumulated is sent for the specific row of the
'ipsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.2
IPsec packets with invalid hashes were found in an inbound
AH SA. The total number of authentication errors accumulated
is sent for the specific row of the 'ipsecSaAhInTable' table
for the SA; this provides the identity of the SA in which
the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.3
IPsec packets with invalid sequence numbers were found in
an inbound ESP SA. The total number of replay errors
accumulated is sent for the specific row of the
'ipsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.4
IPsec packets with invalid sequence numbers were found in
the specified AH SA. The total number of replay errors
accumulated is sent for the specific row of the
'ipsecSaAhInTable' table for the SA; this provides the
identity of the SA in which the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.5
IPsec packets carrying packets with invalid selectors for
the specified ESP SA were found. The total number of policy
errors accumulated is sent for the specific row of the
'ipsecSaEspInTable' table for the SA; this provides the
identity of the SA in which the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.6
IPsec packets carrying packets with invalid selectors for
the specified AH SA were found. The total number of policy
errors accumulated is sent for the specific row of the
'ipsecSaAhInTable' table for the SA; this provides the
identity of the SA in which the error occurred.

Implementations SHOULD send one trap per SA (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.7
A packet with an unknown SPI was detected from the
specified peer with the specified SPI using the specified
protocol. The destination address of the received packet is
specified by 'ipsecLocalAddress'.

The value 'ifIndex' may be 0 if this optional linkage is
unsupported.

If the object 'ipsecSecurityProtocol' has the value for
IPcomp, then the 'ipsecSPI' object is the CPI of the packet.

Implementations SHOULD send one trap per peer (within a
reasonable time period), rather than sending one trap per
packet.
.1.3.6.1.2.1.500.1.4.0.8
Clear packets were found that should not have been sent to
the entity in the clear. The total number of policy errors
accumulated by the entity is sent, along with the source and
destination addresses of the packet that triggered the trap.

Implementations SHOULD send one trap per source address pair
(within a reasonable time period), rather than sending one
trap per packet.