JNX-IPSEC-MONITOR-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
3
Rows
3
Columns
68
.1.3.6.1.4.1.2636.3.22.1.2.1 · 1 row entry · 25 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIkeTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JNX-IPSEC-MONITOR-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JNX-IPSEC-MONITOR-MIB::jnxIkeTunnelTable'
The IPsec Phase-1 Internet Key Exchange Tunnel Table.
There is one entry in this table for each active IPsec
Phase-1 IKE Tunnel.
jnxIkeTunnelEntry row .1.3.6.1.4.1.2636.3.22.1.2.1.1
Each entry contains the attributes associated with
an active IPsec Phase-1 IKE Tunnel.
Column Syntax OID
The index of the IPsec Phase-1 IKE Tunnel Table.
The value of the index is a number which begins
at one and is incremented with each tunnel that
is created. The value of this object will
wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.22.1.2.1.1.1
The role of local peer identity. The Role of
the local peer can be:
1. initiator.
2. or responder.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkePeerRole
Type Values:
1initiator
2responder
.1.3.6.1.4.1.2636.3.22.1.2.1.1.2
The state of the current negotiation , It can be
1. matured
2. not matured
JnxIkeNegState
Type Values:
1matured
2notmatured
.1.3.6.1.4.1.2636.3.22.1.2.1.1.3
Cookie as generated by the peer that initiated the IKE Phase-1
negotiation. This cookie is carried in the ISAKMP header.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.2.1.1.4
Cookie as generated by the peer responding to the IKE Phase-1
negotiation initiated by the remote peer. This cookie is carried
in the ISAKMP header.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.2.1.1.5
The type of local peer identity. The local
peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.22.1.2.1.1.6
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is id_fqdn, then this is
t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.2.1.1.7
The IP address type of the local endpoint (gateway) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.22.1.2.1.1.8
The IP address of the local endpoint (gateway) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.22.1.2.1.1.9
Name of the certificate used for authentication of the local
tunnel endpoint. This object will have some valid value only
if negotiated IKE authentication method is other than pre-saherd
key. If the IKE negotiation do n…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.2.1.1.10
The type of remote peer identity.
The remote peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.22.1.2.1.1.11
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is id_fqdn, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.2.1.1.12
The IP address type of the remote gateway (endpoint) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.22.1.2.1.1.13
The IP address of the remote gateway (endpoint) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.22.1.2.1.1.14
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkeNegoMode
Type Values:
1main
2aggressive
3ikev2
.1.3.6.1.4.1.2636.3.22.1.2.1.1.15
The Diffie Hellman Group used in IPsec Phase-1 IKE
negotiations.
JUNIPER-IPSEC-FLOW-MON-MIBJnxDiffHellmanGrp
Type Values:
0unknown
1modp768
2modp1024
5modp1536
14modp2048
15modp3072
16modp4096
19ecmodp256
20ecmodp384
21ecmodp521
24modp2048s256
.1.3.6.1.4.1.2636.3.22.1.2.1.1.16
The encryption algorithm used in IPsec Phase-1 IKE
negotiations.
JUNIPER-IPSEC-FLOW-MON-MIBJnxEncryptAlgo
Type Values:
1espDes
2esp3des
3espNull
4espAes128
5espAes192
6espAes256
7espAesGcm128
8espAesGcm192
9espAesGcm256
10espChaCha20Poly1305
.1.3.6.1.4.1.2636.3.22.1.2.1.1.17
The hash algorithm used in IPsec Phase-1 IKE
negotiations.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkeHashAlgo
Type Values:
1md5
2sha
3sha256
4sha384
5sha512
.1.3.6.1.4.1.2636.3.22.1.2.1.1.18
The authentication method used in IPsec Phase-1 IKE
negotiations.
JUNIPER-IPSEC-FLOW-MON-MIBJnxIkeAuthMethod
Type Values:
1preSharedKey
2dssSignature
3rsaSignature
4rsaEncryption
5revRsaEncryption
6xauthPreSharedKey
7xauthDssSignature
8xauthRsaSignature
9xauthRsaEncryption
10xauthRevRsaEncryption
11ecdsa256Signature
12ecdsa384Signature
13ecdsa521Signature
14digitalSignature
.1.3.6.1.4.1.2636.3.22.1.2.1.1.19
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel
in seconds.
secondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.22.1.2.1.1.20
The length of time the IPsec Phase-1 IKE tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.2636.3.22.1.2.1.1.21
The total number of octets received by
this IPsec Phase-1 IKE security association.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.2.1.1.22
The total number of packets received by
this IPsec Phase-1 IKE security association.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.2636.3.22.1.2.1.1.23
The total number of octets sent by this IPsec Phase-1
IKE security association.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.2.1.1.24
The total number of packets sent by this IPsec Phase-1
IKE security association.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.2636.3.22.1.2.1.1.25
.1.3.6.1.4.1.2636.3.22.1.3.1 · 1 row entry · 27 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIpSecTunnelTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JNX-IPSEC-MONITOR-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JNX-IPSEC-MONITOR-MIB::jnxIpSecTunnelTable'
The IPsec Phase-2 Tunnel Table.
There is one entry in this table for
each active IPsec Phase-2 Tunnel.
jnxIpSecTunnelEntry row .1.3.6.1.4.1.2636.3.22.1.3.1.1
Each entry contains the attributes
associated with an active IPsec Phase-2 Tunnel.
Column Syntax OID
The index of the IPsec Phase-2 Tunnel Table.
The value of the index is a number which begins
at one and is incremented with each tunnel that
is created. The value of this object will wrap
at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.22.1.3.1.1.1
Name of the rule configured in IPSec configuration.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.3.1.1.2
Name of the term configured under IPSec rule.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.3.1.1.3
The IP address type of the local gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.22.1.3.1.1.4
The IP address of the local gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.22.1.3.1.1.5
The IP address type of the remote gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.22.1.3.1.1.6
The IP address of the remote gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.22.1.3.1.1.7
Identifier for the local end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.3.1.1.8
Identifier for the remote end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.22.1.3.1.1.9
The type of key used by the IPsec Phase-2 Tunnel. It can be
one of the following two types:
- IKE negotiated
- Manually installed
JUNIPER-IPSEC-FLOW-MON-MIBJnxKeyType
Type Values:
0unknown
1keyIke
2keyManual
.1.3.6.1.4.1.2636.3.22.1.3.1.1.10
The type of the remote peer gateway (endpoint). It can be one
of the following two types:
- static (Remote peer whose IP address is known beforehand)
- dynamic (Remote peer whose IP address is not known
JUNIPER-IPSEC-FLOW-MON-MIBJnxRemotePeerType
Type Values:
0unknown
1static
2dynamic
.1.3.6.1.4.1.2636.3.22.1.3.1.1.11
MTU value of this Phase-2 tunnel.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.22.1.3.1.1.12
Number of bytes encrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.13
Number of packets encrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.14
Number of bytes decrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.15
Number of packets decrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.16
Number of incoming bytes authenticated using AH by this Phase-2
tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.17
Number of incoming packets authenticated using AH by this Phase-2
tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.18
Number of outgoing bytes applied AH by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.19
Number of outgoing packets applied AH by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.20
Number of packets dropped by this Phase-2 tunnel due to
anti replay check failure.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.21
Number of packets received by this Phase-2 tunnel that
failed AH authentication.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.22
Number of packets received by this Phase-2 tunnel that
failed ESP authentication.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.23
Number of packets received by this Phase-2 tunnel that
failed decryption.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.24
Number of packets received by this Phase-2 tunnel that
failed due to bad headers.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.25
Number of packets received by this Phase-2 tunnel that
failed due to bad ESP trailers.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.26
Total number of dropped packets for this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.22.1.3.1.1.27
.1.3.6.1.4.1.2636.3.22.1.3.2 · 1 row entry · 16 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIpSecSaTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JNX-IPSEC-MONITOR-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JNX-IPSEC-MONITOR-MIB::jnxIpSecSaTable'
The IPsec Phase-2 Security Association Table.
This table identifies the structure (in terms of
component SAs) of each active Phase-2 IPsec tunnel.
This table contains an entry for each active and
expiring security association and maps each entry
in the active Phase-2 tunnel table (ipSecTunTable)
into a number of entries in this table. The index of this
table reflects the
          
    <destination-address, protocol, spi>
          
rule for identifying Security Associations.
jnxIpSecSaEntry row .1.3.6.1.4.1.2636.3.22.1.3.2.1
Each entry contains the attributes associated with
active and expiring IPsec Phase-2
security associations.
Column Syntax OID
The index, represents the security protocol (AH, ESP or
IPComp) for which this security association was setup.
Enumeration
Enumerated Values:
1ah
2esp
.1.3.6.1.4.1.2636.3.22.1.3.2.1.1
The index, in the context of the IPsec tunnel ipSecTunIndex,
of the security association represented by this table entry.
The value of this index is a number which begins at one and
is incremented with each SPI associat…
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.22.1.3.2.1.2
The value of the incoming SPI.
JnxSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.22.1.3.2.1.3
The value of the outgoing SPI.
JnxSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.22.1.3.2.1.4
The value of the incoming auxiliary SPI. This is valid for AH
and ESP bundles.
JnxSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.22.1.3.2.1.5
The value of the outgoing auxiliary SPI. This is valid for AH
and ESP bundles.
JnxSpi
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.22.1.3.2.1.6
This field represents the type of security associations
which can be either manual or dynamic
JUNIPER-IPSEC-FLOW-MON-MIBJnxSAType
Type Values:
0unknown
1manual
2dynamic
.1.3.6.1.4.1.2636.3.22.1.3.2.1.7
The encapsulation mode used by an IPsec Phase-2 Tunnel.
JUNIPER-IPSEC-FLOW-MON-MIBJnxEncapMode
Type Values:
0unknown
1tunnel
2transport
.1.3.6.1.4.1.2636.3.22.1.3.2.1.8
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.22.1.3.2.1.9
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.22.1.3.2.1.10
The length of time the IPsec Phase-2 Tunnel has been active in seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.2636.3.22.1.3.2.1.11
The security association LifeSize refresh threshold in kilobytes.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.22.1.3.2.1.12
The security association LifeTime refresh threshold in seconds.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.22.1.3.2.1.13
The Encryption algorithm used to encrypt
the packets which can be either es-cbc or 3des-cbc.
JUNIPER-IPSEC-FLOW-MON-MIBJnxEncryptAlgo
Type Values:
1espDes
2esp3des
3espNull
4espAes128
5espAes192
6espAes256
7espAesGcm128
8espAesGcm192
9espAesGcm256
10espChaCha20Poly1305
.1.3.6.1.4.1.2636.3.22.1.3.2.1.14
The algorithm used for authentication of packets which
can be hmac-md5-96 or hmac-sha1-96
JUNIPER-IPSEC-FLOW-MON-MIBJnxAuthAlgo
Type Values:
0unknown
1hmacMd5
2hmacSha
3hmacSha256
4hmacSha384
5hmacSha512
6aesGcm128
7aesGcm192
8aesGcm256
9chacha20Poly1305
.1.3.6.1.4.1.2636.3.22.1.3.2.1.15
This column represents the status of the security association
represented by this table entry. If the status of the SA is
'active', the SA is ready for active use. The status
'expiring' represents any of the various sta…
Enumeration
Enumerated Values:
0unknown
1active
2expiring
.1.3.6.1.4.1.2636.3.22.1.3.2.1.16