IPSEC-SPD-MIB

        This MIB module defines configuration objects for managing
IPsec Security Policies.  In general, this MIB can be
implemented anywhere IPsec security services exist (e.g.,
bump-in-the-wire, host, gateway, firewall, router, etc.).
        
Copyright (C) The IETF Trust (2007).  This version of
this MIB module is part of RFC 4807; see the RFC itself for
full legal notices.
    
Source file
IPSEC-SPD-MIB
Last revised
Identity
spdMIB
Base OID
1.3.6.1.2.1.153
Imported Objects
DIFFSERV-MIB diffServMIBMultiFieldClfrGroup (no object page) diffServMultiFieldClfrNextFree IfDirection
IF-MIB InterfaceIndex
INET-ADDRESS-MIB InetAddress InetAddressType
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Integer32 mib-2 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowStatus StorageType TEXTUAL-CONVENTION (no object page) TimeStamp TruthValue VariablePointer
Net-SNMP examples using the rfc MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'IPSEC-SPD-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'IPSEC-SPD-MIB::spdMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'IPSEC-SPD-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'IPSEC-SPD-MIB::spdMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (117)
.1.3.6.1.2.1.153
.1.3.6.1.2.1.153.1
.1.3.6.1.2.1.153.1.1
OctetString
.1.3.6.1.2.1.153.1.1.1
OctetString
.1.3.6.1.2.1.153.1.1.2
.1.3.6.1.2.1.153.1.10
.1.3.6.1.2.1.153.1.10.1
OctetString
.1.3.6.1.2.1.153.1.10.1.1
Bits
.1.3.6.1.2.1.153.1.10.1.2
Enumeration
.1.3.6.1.2.1.153.1.10.1.3
Enumeration
.1.3.6.1.2.1.153.1.10.1.4
.1.3.6.1.2.1.153.1.10.1.5
.1.3.6.1.2.1.153.1.10.1.6
.1.3.6.1.2.1.153.1.10.1.7
.1.3.6.1.2.1.153.1.11
.1.3.6.1.2.1.153.1.11.1
OctetString
.1.3.6.1.2.1.153.1.11.1.1
Enumeration
.1.3.6.1.2.1.153.1.11.1.2
.1.3.6.1.2.1.153.1.11.1.3
.1.3.6.1.2.1.153.1.11.1.4
.1.3.6.1.2.1.153.1.11.1.5
.1.3.6.1.2.1.153.1.12
.1.3.6.1.2.1.153.1.12.1
Integer32
.1.3.6.1.2.1.153.1.12.1.1
.1.3.6.1.2.1.153.1.12.1.2
.1.3.6.1.2.1.153.1.12.1.3
.1.3.6.1.2.1.153.1.12.1.4
.1.3.6.1.2.1.153.1.12.1.5
.1.3.6.1.2.1.153.1.13
Integer32
.1.3.6.1.2.1.153.1.13.1
Integer32
.1.3.6.1.2.1.153.1.13.2
Integer32
.1.3.6.1.2.1.153.1.13.3
Integer32
.1.3.6.1.2.1.153.1.13.4
.1.3.6.1.2.1.153.1.2
.1.3.6.1.2.1.153.1.2.1
.1.3.6.1.2.1.153.1.2.1.1
.1.3.6.1.2.1.153.1.2.1.2
OctetString
.1.3.6.1.2.1.153.1.2.1.3
.1.3.6.1.2.1.153.1.2.1.4
.1.3.6.1.2.1.153.1.2.1.5
.1.3.6.1.2.1.153.1.2.1.6
.1.3.6.1.2.1.153.1.3
.1.3.6.1.2.1.153.1.3.1
OctetString
.1.3.6.1.2.1.153.1.3.1.1
Integer32
.1.3.6.1.2.1.153.1.3.1.2
.1.3.6.1.2.1.153.1.3.1.3
Enumeration
.1.3.6.1.2.1.153.1.3.1.4
OctetString
.1.3.6.1.2.1.153.1.3.1.5
.1.3.6.1.2.1.153.1.3.1.6
.1.3.6.1.2.1.153.1.3.1.7
.1.3.6.1.2.1.153.1.3.1.8
.1.3.6.1.2.1.153.1.4
.1.3.6.1.2.1.153.1.4.1
OctetString
.1.3.6.1.2.1.153.1.4.1.1
.1.3.6.1.2.1.153.1.4.1.2
.1.3.6.1.2.1.153.1.4.1.3
.1.3.6.1.2.1.153.1.4.1.4
.1.3.6.1.2.1.153.1.4.1.5
.1.3.6.1.2.1.153.1.4.1.6
.1.3.6.1.2.1.153.1.4.1.7
.1.3.6.1.2.1.153.1.4.1.8
.1.3.6.1.2.1.153.1.4.1.9
.1.3.6.1.2.1.153.1.5
.1.3.6.1.2.1.153.1.5.1
OctetString
.1.3.6.1.2.1.153.1.5.1.1
.1.3.6.1.2.1.153.1.5.1.2
.1.3.6.1.2.1.153.1.5.1.3
.1.3.6.1.2.1.153.1.5.1.4
.1.3.6.1.2.1.153.1.5.1.5
.1.3.6.1.2.1.153.1.5.1.6
.1.3.6.1.2.1.153.1.6
.1.3.6.1.2.1.153.1.6.1
Integer32
.1.3.6.1.2.1.153.1.6.1.1
.1.3.6.1.2.1.153.1.6.1.2
.1.3.6.1.2.1.153.1.6.1.3
.1.3.6.1.2.1.153.1.6.1.4
.1.3.6.1.2.1.153.1.6.1.5
.1.3.6.1.2.1.153.1.6.1.6
.1.3.6.1.2.1.153.1.7
Integer32
.1.3.6.1.2.1.153.1.7.1
.1.3.6.1.2.1.153.1.7.1.0
.1.3.6.1.2.1.153.1.8
.1.3.6.1.2.1.153.1.8.1
OctetString
.1.3.6.1.2.1.153.1.8.1.1
Unsigned32
.1.3.6.1.2.1.153.1.8.1.2
Enumeration
.1.3.6.1.2.1.153.1.8.1.3
OctetString
.1.3.6.1.2.1.153.1.8.1.4
.1.3.6.1.2.1.153.1.8.1.5
.1.3.6.1.2.1.153.1.8.1.6
.1.3.6.1.2.1.153.1.8.1.7
.1.3.6.1.2.1.153.1.9
.1.3.6.1.2.1.153.1.9.1
OctetString
.1.3.6.1.2.1.153.1.9.1.1
.1.3.6.1.2.1.153.1.9.1.2
Bits
.1.3.6.1.2.1.153.1.9.1.3
OctetString
.1.3.6.1.2.1.153.1.9.1.4
Bits
.1.3.6.1.2.1.153.1.9.1.5
.1.3.6.1.2.1.153.1.9.1.6
.1.3.6.1.2.1.153.1.9.1.7
.1.3.6.1.2.1.153.1.9.1.8
.1.3.6.1.2.1.153.1.9.1.9
.1.3.6.1.2.1.153.2
.1.3.6.1.2.1.153.2.0
.1.3.6.1.2.1.153.2.1
.1.3.6.1.2.1.153.2.1.1
.1.3.6.1.2.1.153.2.1.2
.1.3.6.1.2.1.153.2.1.3
.1.3.6.1.2.1.153.2.1.4
.1.3.6.1.2.1.153.2.1.5
.1.3.6.1.2.1.153.2.1.6
.1.3.6.1.2.1.153.2.1.7
.1.3.6.1.2.1.153.2.1.8
OctetString
.1.3.6.1.2.1.153.2.1.9
.1.3.6.1.2.1.153.3
.1.3.6.1.2.1.153.3.1
.1.3.6.1.2.1.153.3.2
.1.3.6.1.2.1.153.4
Dependencies (11) 7 direct · 4 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (4)
Enumeration
enabled(1)
disabled(2)
Enumeration
or(1)
and(2)
Integer32 range: -1..65535
OctetString range: 0..31
Conformance Groups (13)
This group is made up of objects from the IPsec Policy
Endpoint Table.
.1.3.6.1.2.1.153.3.2.1
This group is made up of objects from the IPsec Policy
Group Contents Table.
.1.3.6.1.2.1.153.3.2.2
This group is made up of objects represent the System
Policy Group Names.
.1.3.6.1.2.1.153.3.2.3
This group is made up of objects from the IPsec Policy Rule
Definition Table.
.1.3.6.1.2.1.153.3.2.4
This group is made up of objects from the IPsec Policy
Compound Filter Table and Sub-Filter Table Group.
.1.3.6.1.2.1.153.3.2.5
The static filter group. Currently this is just a true
filter.
.1.3.6.1.2.1.153.3.2.6
This group is made up of objects from the IPsec Policy IP
Offset Filter Table.
.1.3.6.1.2.1.153.3.2.7
This group is made up of objects from the IPsec Policy Time
Filter Table.
.1.3.6.1.2.1.153.3.2.8
This group is made up of objects from the IPsec Policy IPSO
Header Filter Table.
.1.3.6.1.2.1.153.3.2.9
This group is made up of objects from the IPsec Policy
Static Actions.
.1.3.6.1.2.1.153.3.2.10
The IPsec Policy Compound Action Table and Actions In

Compound Action Table Group.
.1.3.6.1.2.1.153.3.2.11
This group is made up of all the Notification objects for
this MIB.
.1.3.6.1.2.1.153.3.2.12
This group is made up of all the Notifications for this MIB.
.1.3.6.1.2.1.153.3.2.13
Compliance Statements (3)

OID .1.3.6.1.2.1.153.3.1.1
The compliance statement for SNMP entities that include
an IPsec MIB implementation with Endpoint, Rules, and
filters support.

When this MIB is implemented with support for read-create,
then such an implementation can claim full compliance. Such
devices can then be both monitored and configured with this
MIB.
Required groups
mandatory spdEndpointGroup
mandatory spdGroupContentsGroup
mandatory spdRuleDefinitionGroup
mandatory spdStaticFilterGroup
mandatory spdStaticActionGroup
mandatory DIFFSERV-MIB::diffServMIBMultiFieldClfrGroup
optional spdIpsecSystemPolicyNameGroup This group is mandatory for IPsec Policy
implementations that support a system policy group
name.
optional spdCompoundFilterGroup This group is mandatory for IPsec Policy
implementations that support compound filters.
optional spdIPOffsetFilterGroup This group is mandatory for IPsec Policy
implementations that support IP Offset filters. In
general, this SHOULD be supported by a compliant IPsec

Policy implementation.
optional spdTimeFilterGroup This group is mandatory for IPsec Policy
implementations that support time filters.
optional spdIpsoHeaderFilterGroup This group is mandatory for IPsec Policy
implementations that support IPSO Header filters.
optional spdCompoundActionGroup This group is mandatory for IPsec Policy
implementations that support compound actions.
Object refinements
ObjectAccessSyntaxDescription
spdEndGroupLastChanged noaccess
This object not required for compliance.
spdGroupContComponentType
Enumeration
rule(2)
Support of the value group(1) is only required for
implementations that support Policy Groups within
Policy Groups.
spdGroupContLastChanged noaccess
This object not required for compliance.
spdRuleDefLastChanged noaccess
This object not required for compliance.
spdCompFiltLastChanged noaccess
This object not required for compliance.
spdSubFiltLastChanged noaccess
This object not required for compliance.
spdIpOffFiltLastChanged noaccess
This object not required for compliance.
spdTimeFiltLastChanged noaccess
This object not required for compliance.
spdIpsoHeadFiltLastChanged noaccess
This object not required for compliance.
spdCompActLastChanged noaccess
This object not required for compliance.
spdSubActLastChanged noaccess
This object not required for compliance.
DIFFSERV-MIBdiffServMultiFieldClfrNextFree noaccess
This object is not required for compliance.

OID .1.3.6.1.2.1.153.3.1.2
The compliance statement for SNMP entities that support
sending notifications when actions are invoked.
Required groups

OID .1.3.6.1.2.1.153.3.1.3
The compliance statement for SNMP entities that include
an IPsec MIB implementation with Endpoint, Rules, and
filters support.

If this MIB is implemented without support for read-create
(i.e., in read-only), it is not in full compliance, but it
can claim read-only compliance. Such a device can then be
monitored, but cannot be configured with this MIB.
Required groups
mandatory spdEndpointGroup
mandatory spdGroupContentsGroup
mandatory spdRuleDefinitionGroup
mandatory spdStaticFilterGroup
mandatory spdStaticActionGroup
mandatory DIFFSERV-MIB::diffServMIBMultiFieldClfrGroup
optional spdIpsecSystemPolicyNameGroup This group is mandatory for IPsec Policy
implementations that support a system policy group
name.
optional spdCompoundFilterGroup This group is mandatory for IPsec Policy
implementations that support compound filters.
optional spdIPOffsetFilterGroup This group is mandatory for IPsec Policy
implementations that support IP Offset filters. In
general, this SHOULD be supported by a compliant IPsec
Policy implementation.
optional spdTimeFilterGroup This group is mandatory for IPsec Policy
implementations that support time filters.
optional spdIpsoHeaderFilterGroup This group is mandatory for IPsec Policy

implementations that support IPSO Header filters.
optional spdCompoundActionGroup This group is mandatory for IPsec Policy
implementations that support compound actions.
Object refinements
ObjectAccessSyntaxDescription
spdCompActExecutionStrategy readonly
Write access is not required.
spdCompActLastChanged
This object is not required for compliance.
spdCompActRowStatus readonly
Write access is not required.
spdCompActStorageType readonly
Write access is not required.
spdCompFiltDescription readonly
Write access is not required.
spdCompFiltLastChanged
This object is not required for compliance.
spdCompFiltLogicType readonly
Write access is not required.
spdCompFiltRowStatus readonly
Write access is not required.
spdCompFiltStorageType readonly
Write access is not required.
spdEgressPolicyGroupName readonly
Write access is not required.
spdEndGroupLastChanged
This object is not required for compliance.
spdEndGroupName readonly
Write access is not required.
spdEndGroupRowStatus readonly
Write access is not required.
spdEndGroupStorageType readonly
Write access is not required.
spdGroupContComponentName readonly
Write access is not required.
spdGroupContComponentType readonly
Write access is not required.
spdGroupContFilter readonly
Write access is not required.
spdGroupContLastChanged
This object is not required for compliance.
spdGroupContRowStatus readonly
Write access is not required.
spdGroupContStorageType readonly
Write access is not required.
spdIngressPolicyGroupName readonly
Write access is not required.
spdIpOffFiltLastChanged
This object is not required for compliance.
spdIpOffFiltOffset readonly
Write access is not required.
spdIpOffFiltRowStatus readonly
Write access is not required.
spdIpOffFiltStorageType readonly
Write access is not required.
spdIpOffFiltType readonly
Write access is not required.
spdIpOffFiltValue readonly
Write access is not required.
spdIpsoHeadFiltClassification readonly
Write access is not required.
spdIpsoHeadFiltLastChanged
This object is not required for compliance.
spdIpsoHeadFiltProtectionAuth readonly
Write access is not required.
spdIpsoHeadFiltRowStatus readonly
Write access is not required.
spdIpsoHeadFiltStorageType readonly
Write access is not required.
spdIpsoHeadFiltType readonly
Write access is not required.
spdRuleDefAction readonly
Write access is not required.
spdRuleDefAdminStatus readonly
Write access is not required.
spdRuleDefDescription readonly
Write access is not required.
spdRuleDefFilter readonly
Write access is not required.
spdRuleDefFilterNegated readonly
Write access is not required.
spdRuleDefLastChanged
This object is not required for compliance.
spdRuleDefRowStatus readonly
Write access is not required.
spdRuleDefStorageType readonly
Write access is not required.
spdSubActLastChanged
This object is not required for compliance.
spdSubActRowStatus readonly
Write access is not required.
spdSubActStorageType readonly
Write access is not required.
spdSubActSubActionName readonly
Write access is not required.
spdSubFiltLastChanged
This object is not required for compliance.
spdSubFiltRowStatus readonly
Write access is not required.
spdSubFiltStorageType readonly
Write access is not required.
spdSubFiltSubfilter readonly
Write access is not required.
spdSubFiltSubfilterIsNegated readonly
Write access is not required.
spdTimeFiltDayOfMonthMask readonly
Write access is not required.
spdTimeFiltDayOfWeekMask readonly
Write access is not required.
spdTimeFiltLastChanged
This object is not required for compliance.
spdTimeFiltMonthOfYearMask readonly
Write access is not required.
spdTimeFiltPeriod readonly
Write access is not required.
spdTimeFiltRowStatus readonly
Write access is not required.
spdTimeFiltTimeOfDayMask readonly
Write access is not required.
spdTimeFiltStorageType readonly
Write access is not required.
Notifications / Traps (2)
NameOIDDescription
.1.3.6.1.2.1.153.2.0.1
Notification that an action was executed by a rule.
Only actions with logging enabled will result in this
notification getting sent. The object includes the
spdActionExecuted object, which will indicate which action
was executed within the scope of the rule. Additionally,
the spdIPSourceType, spdIPSourceAddress,
spdIPDestinationType, and spdIPDestinationAddress objects
are included to indicate the packet source and destination
of the packet that triggered the action. Finally, the
spdIPEndpointAddType, spdIPEndpointAddress, and
spdPacketDirection objects indicate which interface the
executed action was associated with, and if the packet was
ingress or egress through the endpoint.

A spdActionNotification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.

Note that compound actions with multiple executed
sub-actions may result in multiple notifications being sent
from a single rule execution.
.1.3.6.1.2.1.153.2.0.2
Notification that a packet passed through a Security
Association (SA). Only SAs created by actions with packet
logging enabled will result in this notification getting
sent. The objects sent MUST include the spdActionExecuted,
which will indicate which action was executed within the
scope of the rule. Additionally, the spdIPSourceType,
spdIPSourceAddress, spdIPDestinationType, and
spdIPDestinationAddress objects MUST be included to
indicate the packet source and destination of the packet
that triggered the action. The spdIPEndpointAddType,
spdIPEndpointAddress, and spdPacketDirection objects are
included to indicate which endpoint the packet was
associated with. Finally, spdPacketPart is included to
enable sending a variable sized part of the front of the
packet with the size dependent on the value of the object of
TC syntax 'SpdIPPacketLogging', which indicated that logging
should be done.

A spdPacketNotification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.

An action notification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.