IPSEC-SA-MON-MIB Table View
Table-centric layout grouping table, row, and column objects.
Tables
6
Rows
6
Columns
127
ipsecSaEspInTable
table.1.3.6.1.2.1.500.1.1.1
·
1 row entry
·
28 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaEspInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaEspInTable'
The (conceptual) table containing information on IPsec
inbound ESP SAs.
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec inbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec inbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
IPv4 entities will prefix the IP address with '0000:0000:0000:0000:0000:FFFF::'. |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.1.1.1 |
||||||||||||||||||||||||
|
The security parameters index of the SA.
|
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.2 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creatio… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.1.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaEspInDestId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.4 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creation neg… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.1.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaEspInSourceId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.1.1.7 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.1.1.8 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.1.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.11 |
||||||||||||||||||||||||
|
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.12 |
||||||||||||||||||||||||
|
The length of the encryption key in bits used for the
algorithm specified in the 'ipsecSaEspInEncAlg' object. It may be 0 if the key length is implicit in the specified algorithm or there is no encryption specified. |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.1.1.13 |
||||||||||||||||||||||||
|
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Type Values:
|
.1.3.6.1.2.1.500.1.1.1.1.14 |
||||||||||||||||||||||||
|
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaEspInAuthAlg'. It may be 0 if the key length is implicit in the specified algorithm or there is no authentication specified. |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.1.1.15 |
||||||||||||||||||||||||
|
The size of the anti-replay window used by this SA, or 0 if
anti-replay checking is not being done. |
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.16 |
||||||||||||||||||||||||
|
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value w… |
secondsSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.17 |
||||||||||||||||||||||||
|
The maximum traffic in kilobytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that… |
kilobytesSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.18 |
||||||||||||||||||||||||
|
The number of seconds accumulated against the SA's
expiration by time. This is also the number of seconds that the SA has existed. |
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.19 |
||||||||||||||||||||||||
|
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in kilobytes. This value may be 0 if the SA does not expire based on traffic. |
kilobytesSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.20 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the decrypted IP packet, including the original IP header of that decrypted packet. This is not necessa… |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.1.1.21 |
||||||||||||||||||||||||
|
The number of packets handled by the SA.
|
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.1.1.22 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to detectable
decryption errors. Not all decryption errors are detectable within SA processing, so this count should not be considered definitive. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.23 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to
authentication errors. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.24 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to replay
errors. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.25 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is invalid. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.26 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to pad value
errors. Implementations that do not check this must not support this object. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.27 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to errors
other than decryption, authentication, replay errors or, when supported, invalid padding errors. This may include packets dropped due to a lack of receive buffers,… |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.1.1.28 |
ipsecSaAhInTable
table.1.3.6.1.2.1.500.1.1.2
·
1 row entry
·
24 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaAhInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaAhInTable'
The (conceptual) table containing information on IPsec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec inbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec inbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
IPv4 entities will prefix the IP address with '0000:0000:0000:0000:0000:FFFF::'. |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.2.1.1 |
||||||||||||||||||||||||
|
The security parameters index of the SA.
|
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.2 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creatio… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.2.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaAhInDestId'. It
may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.2.1.4 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creation neg… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.2.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaAhInSourceId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.2.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.2.1.7 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.2.1.8 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.2.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.2.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.2.1.11 |
||||||||||||||||||||||||
|
A unique value representing the hash algorithm applied to
traffic carried by this SA. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.2.1.12 |
||||||||||||||||||||||||
|
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaAhInAuthAlg' object. It may be 0 if the key length is implicit in the specified algorithm. |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.2.1.13 |
||||||||||||||||||||||||
|
The size of the anti-replay window used by this SA, or 0 if
anti-replay checking is not being done. |
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.14 |
||||||||||||||||||||||||
|
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value w… |
secondsSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.15 |
||||||||||||||||||||||||
|
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that val… |
kilobytesSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.16 |
||||||||||||||||||||||||
|
The number of seconds accumulated against the SA's
expiration by time. This is also the number of seconds that the SA has existed. |
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.17 |
||||||||||||||||||||||||
|
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in kilobytes. This value may be 0 if the SA does not expire based on traffic. |
kilobytesSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.18 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the de-processed IP packet, including the original IP header of that de- processed packet. This is not … |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.2.1.19 |
||||||||||||||||||||||||
|
The number of packets handled by the SA.
|
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.2.1.20 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to
authentication errors. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.21 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to replay
errors. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.22 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is invalid. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.23 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to c… |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.2.1.24 |
ipsecSaIpcompInTable
table.1.3.6.1.2.1.500.1.1.3
·
1 row entry
·
17 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaIpcompInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaIpcompInTable'
The (conceptual) table containing information on IPsec
inbound IPcomp SAs.
There should be one row for every inbound IPcomp (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec inbound IPcomp SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec inbound IPcomp SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
IPv4 entities will prefix the IP address with '0000:0000:0000:0000:0000:FFFF::'. |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.3.1.1 |
||||||||||||||||||||||||
|
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for this object is the same as the transform. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.2 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode, or 0 if this SA is used with multiple SAs in security association suites. This value, if non-zero, is taken directly from th… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.3.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by
'ipsecSaIpcompInDestId'. It may be 0 if unknown or if the SA uses transport mode, or if this SA is used with multiple SAs in security association suites. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.4 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in security association suites. This value, if non-zero, i… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.3.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by
'ipsecSaIpcompInSourceId'. It may be 0 if unknown or if the SA uses transport mode encapsulation, or if this SA is used with multiple SAs in security association suites. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.3.1.7 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.3.1.8 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.3.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.11 |
||||||||||||||||||||||||
|
A unique value representing the decompression algorithm
applied to traffic. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.3.1.12 |
||||||||||||||||||||||||
|
The number of seconds that the SA has existed.
|
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.3.1.13 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the uncompressed IP packet, including the original IP header of that uncompressed packet. Packets which… |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.3.1.14 |
||||||||||||||||||||||||
|
The number of packets handled by the SA.
|
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.3.1.15 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to
decompression errors. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.3.1.16 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to errors
other than decompression errors. This may include packets dropped due to a lack of receive buffers, and packets dropped due to congestion at the decompression elem… |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.3.1.17 |
ipsecSaEspOutTable
table.1.3.6.1.2.1.500.1.1.4
·
1 row entry
·
22 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaEspOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaEspOutTable'
The (conceptual) table containing information on IPsec
Outbound ESP SAs.
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec Outbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec Outbound ESP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
IPv4 entities will prefix the IP address with '0000:0000:0000:0000:0000:FFFF::'. |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.4.1.1 |
||||||||||||||||||||||||
|
The security parameters index of the SA.
|
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.2 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during phase 2 negotia… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.4.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by
'ipsecSaEspOutSourceId'. It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.4 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during phase 2 ne… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.4.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaEspOutDestId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.4.1.7 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.4.1.8 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.4.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.11 |
||||||||||||||||||||||||
|
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.12 |
||||||||||||||||||||||||
|
The length of the encryption key in bits used for the
algorithm specified in the 'ipsecSaEspOutEncAlg' object. It may be 0 if the key length is implicit in the specified algorithm or there is no encryption specified. |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.4.1.13 |
||||||||||||||||||||||||
|
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Type Values:
|
.1.3.6.1.2.1.500.1.1.4.1.14 |
||||||||||||||||||||||||
|
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaEspOutAuthAlg' object. It may be 0 if the key length is implicit in the specified algorithm or there is no authentication spec… |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.4.1.15 |
||||||||||||||||||||||||
|
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value w… |
secondsSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.16 |
||||||||||||||||||||||||
|
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that val… |
kilobytesSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.17 |
||||||||||||||||||||||||
|
The number of seconds accumulated against the SA's
expiration by time. This is also the number of seconds that the SA has existed. |
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.18 |
||||||||||||||||||||||||
|
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in kilobytes. This value may be 0 if the SA does not expire based on traffic. |
kilobytesSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.19 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the unencrypted IP packet, including the original IP header of that unencrypted packet. This is not nec… |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.4.1.20 |
||||||||||||||||||||||||
|
The number of packets handled by the SA.
|
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.4.1.21 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.4.1.22 |
ipsecSaAhOutTable
table.1.3.6.1.2.1.500.1.1.5
·
1 row entry
·
20 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaAhOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaAhOutTable'
The (conceptual) table containing information on IPsec
Outbound AH SAs.
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec Outbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec Outbound AH SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
IPv4 entities will prefix the IP address with '0000:0000:0000:0000:0000:FFFF::'. |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.5.1.1 |
||||||||||||||||||||||||
|
The security parameters index of the SA.
|
SNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.2 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during phase 2 negotia… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.5.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaAhOutSourceId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.5.1.4 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during phase 2 ne… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.5.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by 'ipsecSaAhOutDestId'.
It may be 0 if unknown or if the SA uses transport mode encapsulation. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.5.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.5.1.7 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.5.1.8 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.5.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.5.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.5.1.11 |
||||||||||||||||||||||||
|
A unique value representing the hash algorithm applied to
traffic carried by this SA. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.5.1.12 |
||||||||||||||||||||||||
|
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaAhOutAuthAlg' object. It may be 0 if the key length is implicit in the specified algorithm. |
bitsUnsigned32 Constraints: range: 0-65531 |
.1.3.6.1.2.1.500.1.1.5.1.13 |
||||||||||||||||||||||||
|
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value w… |
secondsSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.14 |
||||||||||||||||||||||||
|
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that val… |
kilobytesSNMPv2-SMIUnsigned32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.15 |
||||||||||||||||||||||||
|
The number of seconds accumulated against the SA's
expiration by time. This is also the number of seconds that the SA has existed. |
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.16 |
||||||||||||||||||||||||
|
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in kilobytes. This value may be 0 if the SA does not expire based on traffic. |
kilobytesSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.17 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the unprocessed IP packet, including the original IP header of that unprocessed packet. This is not nec… |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.5.1.18 |
||||||||||||||||||||||||
|
The number of packets handled by the SA.
|
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.5.1.19 |
||||||||||||||||||||||||
|
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers. |
SNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.5.1.20 |
ipsecSaIpcompOutTable
table.1.3.6.1.2.1.500.1.1.6
·
1 row entry
·
16 columns
Uses the rfc variant from
Command help
/opt/observium/mibs/rfc.
Walk ipsecSaIpcompOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SA-MON-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SA-MON-MIB::ipsecSaIpcompOutTable'
The (conceptual) table containing information on IPsec
Outbound IPcomp SAs.
There should be one row for every outbound IPcomp (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
An entry (conceptual row) containing the information on a
particular IPsec Outbound IPcomp SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
particular IPsec Outbound IPcomp SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
| Column | Syntax | OID | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
The destination address of the SA.
If the IPcomp SA is shared across multiple SAs in security association suites, this value may be 0. IPv4 entities will prefix the IP address with '0000:00… |
IpsecIpv6Address Type Constraints: range: 16 |
.1.3.6.1.2.1.500.1.1.6.1.1 |
||||||||||||||||||||||||
|
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for this object is the same as the transform. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.2 |
||||||||||||||||||||||||
|
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation, or if this SA is used with multiple SAs in security association suites. This value, if non-zero, is … |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.6.1.3 |
||||||||||||||||||||||||
|
The type of identifier presented by
'ipsecSaIpcompOutSourceId'. It may be 0 if unknown or if the SA uses transport mode encapsulation, or if this SA is used with multiple SAs in security association suites. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.4 |
||||||||||||||||||||||||
|
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation, or if this SA is used with multiple SAs in security association suites. This value, if non-zero… |
IpsecRawId Type Constraints: range: 0..255 |
.1.3.6.1.2.1.500.1.1.6.1.5 |
||||||||||||||||||||||||
|
The type of identifier presented by
'ipsecSaIpcompOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in security association suites. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.6 |
||||||||||||||||||||||||
|
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol. |
Integer32 Constraints: range: 0-255 |
.1.3.6.1.2.1.500.1.1.6.1.7 |
||||||||||||||||||||||||
|
The source port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.6.1.8 |
||||||||||||||||||||||||
|
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number. |
Integer32 Constraints: range: 0-65535 |
.1.3.6.1.2.1.500.1.1.6.1.9 |
||||||||||||||||||||||||
|
The creator of this SA.
This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
IpsecSaCreatorIdent Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.10 |
||||||||||||||||||||||||
|
The type of encapsulation used by this SA.
|
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.11 |
||||||||||||||||||||||||
|
A unique value representing the compression algorithm
applied to traffic. |
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Type Values:
|
.1.3.6.1.2.1.500.1.1.6.1.12 |
||||||||||||||||||||||||
|
The number of seconds that the SA has existed.
|
secondsSNMPv2-SMICounter32 Type Constraints: range: 0..4294967295 |
.1.3.6.1.2.1.500.1.1.6.1.13 |
||||||||||||||||||||||||
|
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the decompressed IP packet, including the original IP header of that decompressed packet. |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.6.1.14 |
||||||||||||||||||||||||
|
The amount of traffic measured in bytes output by the SA.
This includes byte counts from packets compressed by the SA and also packets not modified by the SA. This object can be divided into the 'ipsecSaI… |
bytesSNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.6.1.15 |
||||||||||||||||||||||||
|
The number of packets handled by the SA. This includes
packets that were both compressed and not compressed. |
SNMPv2-SMICounter64 Type Constraints: range: 0..18446744073709551615 |
.1.3.6.1.2.1.500.1.1.6.1.16 |