JUNIPER-IPSEC-FLOW-MON-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
8
Rows
8
Columns
198
.1.3.6.1.4.1.2636.3.52.1.1.2 · 1 row entry · 47 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIkeTunnelMonTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIkeTunnelMonTable'
The IPsec Phase-1 Internet Key Exchange Tunnel Table.
There is one entry in this table for each active IPsec
Phase-1 IKE Tunnel.
jnxIkeTunnelMonEntry row .1.3.6.1.4.1.2636.3.52.1.1.2.1
Each entry contains the attributes associated with
an active IPsec Phase-1 IKE Tunnel.
Column Syntax OID
The IP address type of the remote gateway (endpoint) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.2.1.1
The IP address of the remote gateway (endpoint) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.2.1.2
The index of the IPsec Phase-1 IKE Tunnel Table.
The value of the index is a number which begins
at one and is incremented with each tunnel that
is created. The value of this object will
wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.2.1.3
The IP address of the local endpoint (gateway) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.2.1.4
The IP address type of the local endpoint (gateway) for the IPsec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.2.1.5
The state of the IKE tunnel, It can be:
1. up - negotiation completed
2. down- being negotiated
JnxIkeTunStateType
Type Values:
1up
2down
.1.3.6.1.4.1.2636.3.52.1.1.2.1.6
Cookie as generated by the peer that initiated the IKE Phase-1
negotiation. This cookie is carried in the ISAKMP header.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.7
Cookie as generated by the peer responding to the IKE Phase-1
negotiation initiated by the remote peer. This cookie is carried
in the ISAKMP header.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.8
The role of local peer identity. The Role of the local peer can be:
1. initiator.
2. or responder.
JnxIkePeerRole
Type Values:
1initiator
2responder
.1.3.6.1.4.1.2636.3.52.1.1.2.1.9
The type of local peer identity. The local
peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.2.1.10
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is id_fqdn, then this is
t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.11
Name of the certificate used for authentication of the local
tunnel endpoint. This object will have some valid value only
if negotiated IKE authentication method is other than pre-saherd
key. If the IKE negotiation do n…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.12
The type of remote peer identity.
The remote peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.2.1.13
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is id_fqdn, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.14
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
JnxIkeNegoMode
Type Values:
1main
2aggressive
3ikev2
.1.3.6.1.4.1.2636.3.52.1.1.2.1.15
The Diffie Hellman Group used in IPsec Phase-1 IKE
negotiations.
JnxDiffHellmanGrp
Type Values:
0unknown
1modp768
2modp1024
5modp1536
14modp2048
15modp3072
16modp4096
19ecmodp256
20ecmodp384
21ecmodp521
24modp2048s256
.1.3.6.1.4.1.2636.3.52.1.1.2.1.16
The encryption algorithm used in IPsec Phase-1 IKE negotiations.
JnxEncryptAlgo
Type Values:
1espDes
2esp3des
3espNull
4espAes128
5espAes192
6espAes256
7espAesGcm128
8espAesGcm192
9espAesGcm256
10espChaCha20Poly1305
.1.3.6.1.4.1.2636.3.52.1.1.2.1.17
The hash algorithm used in IPsec Phase-1 IKE negotiations.
JnxIkeHashAlgo
Type Values:
1md5
2sha
3sha256
4sha384
5sha512
.1.3.6.1.4.1.2636.3.52.1.1.2.1.18
The authentication method used in IPsec Phase-1 IKE
negotiations.
JnxIkeAuthMethod
Type Values:
1preSharedKey
2dssSignature
3rsaSignature
4rsaEncryption
5revRsaEncryption
6xauthPreSharedKey
7xauthDssSignature
8xauthRsaSignature
9xauthRsaEncryption
10xauthRevRsaEncryption
11ecdsa256Signature
12ecdsa384Signature
13ecdsa521Signature
14digitalSignature
.1.3.6.1.4.1.2636.3.52.1.1.2.1.19
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel
in seconds.
secondsInteger32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.2.1.20
The length of time the IPsec Phase-1 IKE tunnel has been
active in hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.2636.3.52.1.1.2.1.21
The total number of octets received by this IPsec Phase-1
IKE security association.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.22
The total number of packets received by this IPsec Phase-1
IKE security association.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.2636.3.52.1.1.2.1.23
The total number of octets sent by this IPsec Phase-1
IKE security association.
OctetsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.24
The total number of packets sent by this IPsec Phase-1
IKE security association.
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.2636.3.52.1.1.2.1.25
The extended Authentication (XAuth) User Identifier, identifies the
user associated with this IPSec Phase negotiation.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.26
The number of times that the remote peer is detected
in a dead (or down) state. This attribute is obsolete
PacketsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.2636.3.52.1.1.2.1.27
The number of IPSec SA rekey CREATE_CHILD_SA request
message sent by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.28
The number of IPSec SA rekey CREATE_CHILD_SA response
message received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.29
The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN
Notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.30
The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.31
The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE
notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.32
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of peer SA failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.33
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of DH group failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.34
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of TS failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.35
The number of IPSec SA rekey CREATE_CHILD_SA response message
Diffie-Hellman compute key failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.36
The number of IPSec SA rekey CREATE_CHILD_SA request
message received by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.37
The number of IPSec SA rekey CREATE_CHILD_SA response
message sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.38
The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN
Notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.39
The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD
Notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.40
The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE
notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.41
The number of IPSec SA rekey CREATE_CHILD_SA response message
Diffie-Hellman compute key failed at Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.2.1.42
The gateway name
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.2.1.43
The Tunnel type. It can be regular (1) or ha-link (2)
JnxIkeTunType
Type Values:
1regular
2halink
.1.3.6.1.4.1.2636.3.52.1.1.2.1.44
The signature hash algorithm used locally in IPsec Phase-1 IKE negotiations.
JnxIkeLocalSignatureHashAlgo
Type Values:
1sha1
2sha256
3sha384
4sha512
.1.3.6.1.4.1.2636.3.52.1.1.2.1.45
The signature hash algorithm used by remote peer in IPsec Phase-1 IKE negotiations.
JnxIkeRemoteSignatureHashAlgo
Type Values:
1sha1
2sha256
3sha384
4sha512
.1.3.6.1.4.1.2636.3.52.1.1.2.1.46
Signature key RSA/DSA/ECDSA used for digital-signature auth method.
JnxIkeDigitalSignAuthKey
Type Values:
1signAuthRsa
2signAuthDsa
3signAuthEcdsa
.1.3.6.1.4.1.2636.3.52.1.1.2.1.47
.1.3.6.1.4.1.2636.3.52.1.1.4 · 1 row entry · 9 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIkePeerAddrTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIkePeerAddrTable'
The IKE Key Exchange Peer Address Table. There is one entry in this table
for each IKE peer with which the managed entity is currently associated.
jnxIkePeerAddrEntry row .1.3.6.1.4.1.2636.3.52.1.1.4.1
Each entry contains the attributes associated with
an IKE Peer.
Column Syntax OID
The state of the peer, it can be:
1. active - The IKE peer is currently associated by an active IKE SA.
There is at least one active IKE SA or Tunnel
termination on the managed entity from the pe…
JnxPeerStateType
Type Values:
1active
2inactive
.1.3.6.1.4.1.2636.3.52.1.1.4.1.1
The IP address type of the remote gateway (endpoint) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.4.1.2
The IP address of the remote gateway (endpoint) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.4.1.3
The port number of the remote gateway (endpoint) for the IKE
SA negotiation. The port number zero means the input value is
ignored for this object and the default port is considered.
INET-ADDRESS-MIBInetPortNumber
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.2636.3.52.1.1.4.1.4
The IP address type of the local endpoint (gateway) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.4.1.5
The IP address of the local endpoint (gateway) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.4.1.6
The port number of the local gateway (endpoint) for the IKE SA
negotiation. The port number zero means the input value is
ignored for this object and the default port is considered.
INET-ADDRESS-MIBInetPortNumber
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.2636.3.52.1.1.4.1.7
The VR ID.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.4.1.8
The index of the IPSec Phase-1 key exchange Peer Table.
The value of the index is a number which begins
at one and is incremented with each peer that is created
due to an association. The value of this object will wrap
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.2636.3.52.1.1.4.1.9
.1.3.6.1.4.1.2636.3.52.1.1.5 · 1 row entry · 8 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIkePeerIdTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIkePeerIdTable'
The IKE Key Exchange Peer ID Table. There is one entry in this table
for each IKE peer with which the managed entity is currently associated.
In the index truncated value for Remote ID value, Local ID value and AAA
username is used to restrict the length of the SNMP index to a legal
size. In the index, for jnxIkePeerIdRemoteId and jnxIkePeerIdLocalId, any
string longer than 41 bytes will be truncated and only 41 bytes would be
considered. Similarly in the index, for jnxIkePeerIdAAAUserName, any
string longer than 25 bytes will be truncated and only 25 bytes would be
considered. Because of the truncation, the index may become same for
different peers, to keep the index unique, jnxIkePeerInternalIndex is
used to uniquely identify each peer.
jnxIkePeerIdEntry row .1.3.6.1.4.1.2636.3.52.1.1.5.1
Each entry contains the attributes associated with
an IKE Peer.
Column Syntax OID
The state of the peer, it can be:
1. active - The IKE peer is currently associated by an active IKE SA.
There is at least one active IKE SA or Tunnel
termination on the managed entity from the pe…
JnxPeerStateType
Type Values:
1active
2inactive
.1.3.6.1.4.1.2636.3.52.1.1.5.1.1
The type of remote peer identity.
The remote peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.5.1.2
The value of the remote peer identity.

If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.

If the remote peer type is id_fqdn, then this …
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.5.1.3
The type of local peer identity. The local
peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.5.1.4
The value of the local peer identity.

If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.

If the local peer type is id_fqdn, then this is
t…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.5.1.5
Identifies the user with the specified authentication,
authorization and accounting (AAA) username, associated
with the IKE SA negotiation.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.5.1.6
The internal index of the Peer Id table.
This index is used to uniquely identify multiple
entry for the same truncated ids.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.5.1.7
The index of the IPSec Phase-1 key exchange Peer Table.
The value of the index is a number which begins
at one and is incremented with each peer that is created
due to an association. The value of this object will wrap
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.2636.3.52.1.1.5.1.8
.1.3.6.1.4.1.2636.3.52.1.1.6 · 1 row entry · 76 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIkePeerStatsTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIkePeerStatsTable'
The IKE Key Exchange Peer Stats Table. There is one entry in this table
for each IKE peer with which the managed entity is currently associated.
jnxIkePeerStatsEntry row .1.3.6.1.4.1.2636.3.52.1.1.6.1
Each entry contains the attributes associated with an IKE Peer.
Column Syntax OID
The state of the peer, it can be:
1. active - The IKE peer is currently associated by an active IKE SA.
There is at least one active IKE SA or Tunnel
termination on the managed entity from the pe…
JnxPeerStateType
Type Values:
1active
2inactive
.1.3.6.1.4.1.2636.3.52.1.1.6.1.1
The index of the IPSec Phase-1 key exchange Peer Table.
The value of the index is a number which begins
at one and is incremented with each peer that is created
due to an association. The value of this object will wrap
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.2636.3.52.1.1.6.1.2
The IP address type of the remote gateway (endpoint) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.6.1.3
The IP address of the remote gateway (endpoint) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.6.1.4
The value specifying a port associated with the remote gateway
(endpoint) for the IKE Tunnel. A value of zero means that the port should
be ignored.
INET-ADDRESS-MIBInetPortNumber
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.2636.3.52.1.1.6.1.5
The IP address type of the local endpoint (gateway) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.1.6.1.6
The IP address of the local endpoint (gateway) for the IPSec
Phase-1 IKE Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.1.6.1.7
The value specifying a port associated with the local endpoint
(gateway) for the IKE Tunnel. A value of zero means that the port should
be ignored.
INET-ADDRESS-MIBInetPortNumber
Type Constraints:
range: 0..65535
.1.3.6.1.4.1.2636.3.52.1.1.6.1.8
The VR ID.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.6.1.9
The type of remote peer identity.
The remote peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.6.1.10
The value of the remote peer identity.
If the remote peer type is an IP Address, then this
is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is
the FQDN of the remote peer…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.6.1.11
The type of local peer identity. The local
peer may be identified by:
1. an IP address, or
2. or a fully qualified domain name string.
3. or a distinguished name string.
JnxIkePeerType
Type Values:
0unknown
1idIpv4Addr
2idFqdn
3idDn
4idUfqdn
5idIpv6Addr
.1.3.6.1.4.1.2636.3.52.1.1.6.1.12
The value of the local peer identity.
If the local peer type is an IP Address, then this
is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is
the FQDN of the remote peer.
If…
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.6.1.13
The extended authentication User Name, identifies the
user associated with the IKE SA negotiation.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.6.1.14
The gateway name
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.1.6.1.15
The number of IKE_SA_INIT request message sent by
Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.16
The number of IKE_SA_INIT response message received by
Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.17
The number of IKE_SA_INIT response message containing invalid
SPI received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.18
The total number of IKE_SA_INIT INVALID_KE_PAYLOAD received by
Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.19
The number of IKE_SA_INIT NO_PROPSAL_CHOSEN received
by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.20
The number of IKE_SA_INIT response message verification
of peer SA failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.21
The number of IKE_SA_INIT response message IKE_SA fill operation
failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.22
The number of IKE_SA_INIT response message verification of
DH group failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.23
The total number of IKE_SA_INIT COOKIE notification request
message received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.24
The total number of IKE_SA_INIT COOKIE notification
response message sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.25
Number of IKE SA rekey response message
Diffie-Hellman compute key failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.26
The number of IKE_SA_INIT request message received by
Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.27
The number of IKE_SA_INIT response message sent by
Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.28
The number of IKE_SA_INIT NO_PROPSAL_CHOSEN notification
sent by Responder
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.29
The number of IKE_SA_INIT INVALID_KE_PAYLOAD notification sent by
Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.30
The number of IKE_SA_INIT response message invalid DH group
configured at Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.31
The number of IKE_SA_INIT response message Diffie-Hellman
generate key failed at Responder
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.32
The number of IKE_SA_INIT response message get CAs failed at
Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.33
The number of IKE_SA_INIT response message get vendor ID request
failed at Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.34
The number of IKE_SA_INIT response message Diffie-Hellman
compute key failed at Responder
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.35
The number of IKE_SA_INIT COOKIE notification request
sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.36
The number of IKE_SA_INIT COOKIE notification response
message received by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.37
The total number of IKE_AUTH request message sent by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.38
The total number of IKE_AUTH response message received by
Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.39
The number of IKE_AUTH NO_PROPSAL_CHOSEN notification
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.40
The number of IKE_AUTH TS_UNACCEPTABLE notification
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.41
The number of IKE_AUTH AUTHENTICATION_FAILED
notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.42
The number of IKE_AUTH request message received by
Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.43
The number of IKE_AUTH response message sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.44
The number of IKE_AUTH request message AUTHENTICATION_FAILED
notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.45
The number of IKE_AUTH NO_PROPSAL_CHOSEN notification
sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.46
The number of IKE_AUTH TS_UNACCEPTABLE notification
sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.47
The number of IKE_SA rekey CREATE_CHILD_SA request message
sent by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.48
The number of IKE_SA rekey CREATE_CHILD_SA response message
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.49
The number of CREATE_CHILD_SA IKE SA rekey NO_PROPSAL_CHOSEN
notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.50
The number of CREATE_CHILD_SA IKE SA rekey INVALID_KE_PAYLOAD
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.51
The number of CREATE_CHILD_SA IKE SA rekey response message
verification of peer SA failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.52
The number of IKE_SA rekey CREATE_CHILD_SA response message
fill IKE_SA failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.53
The number of CREATE_CHILD_SA IKE SA rekey response message
verification of DH group failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.54
The number of CREATE_CHILD_SA IKE SA rekey response message
Diffie-Hellman compute key failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.55
The number of IKE_SA rekey CREATE_CHILD_SA request message
received by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.56
The number of IKE_SA rekey CREATE_CHILD_SA response message
sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.57
The number of CREATE_CHILD_SA IKE rekey NO_PROPSAL_CHOSEN
notification sent by Responder
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.58
The number of IKE_SA rekey CREATE_CHILD_SA
INVALID_KE_PAYLOAD sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.59
The number of CREATE_CHILD_SA IKE rekey response message
Diffie-Hellman compute key failed at Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.60
The number of IPSec SA rekey CREATE_CHILD_SA request
message sent by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.61
The number of IPSec SA rekey CREATE_CHILD_SA response
message received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.62
The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN
notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.63
The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD
received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.64
The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE
notification received by Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.65
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of peer SA failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.66
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of DH group failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.67
The number of IPSec SA rekey CREATE_CHILD_SA response message
verification of TS failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.68
The number of IPSec SA rekey CREATE_CHILD_SA response message
Diffie-Hellman compute key failed at Initiator.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.69
The total number of IPSec SA rekey CREATE_CHILD_SA request
message received by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.70
The total number of IPSec SA rekey CREATE_CHILD_SA response
message sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.71
The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN
Notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.72
The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD
Notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.73
The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE
notification sent by Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.74
The number of IPSec SA rekey CREATE_CHILD_SA response message
Diffie-Hellman compute key failed at Responder.
MessagesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.1.6.1.75
The Tunnel type. It can be regular (1) or ha-link (2).
JnxIkeTunType
Type Values:
1regular
2halink
.1.3.6.1.4.1.2636.3.52.1.1.6.1.76
.1.3.6.1.4.1.2636.3.52.1.1.7 · 1 row entry · 3 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxPeerIkeSaCorrTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxPeerIkeSaCorrTable'
The Peer Association to active IKE SA - Correlation Table.
There is one entry in this table for each active IKE SA.
jnxPeerIkeSaCorrEntry row .1.3.6.1.4.1.2636.3.52.1.1.7.1
Each entry contains the attributes of an
Peer Association to active IKE SA Correlation.
Column Syntax OID
The index of the Peer (jnxPeerIndex in the
jnxIkePeerTable).
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.7.1.1
The internal index of the Peer and IKE SA association.
This internal index is used to uniquely identify multiple
Instances of a unique association between the peer
and IKE SA.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.7.1.2
The index of the active IKE SA (jnxIkeTunMonIndex in
the jnxIkeTunnelMonTable) for this Peer association.
Unsigned32
Constraints:
range: 1-4294967295
.1.3.6.1.4.1.2636.3.52.1.1.7.1.3
.1.3.6.1.4.1.2636.3.52.1.1.8 · 1 row entry · 3 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxPeerIPSecTunnelCorrTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxPeerIPSecTunnelCorrTable'
The Peer Association to IPSec Tunnel Correlation Table.
There is one entry in this table
for each active IPSec Tunnel.
jnxPeerIPSecTunnelCorrEntry row .1.3.6.1.4.1.2636.3.52.1.1.8.1
Each entry contains the attributes of an
Peer Association to active IPSec Tunnel Correlation.
Column Syntax OID
The index of the Peer (jnxPeerIndex in the
jnxIkePeerTable).
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.8.1.1
The internal index of the Peer and IPSec Tunnel association.
This index is used to uniquely identify multiple
association between the peer and IPSec Tunnel.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.8.1.2
The index of the active IPSec Tunnel (jnxIpSecTunMonIndex in
the jnxIpSecTunnelMonTable) for this association between
Peer and IPSec Tunnel.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.1.8.1.3
.1.3.6.1.4.1.2636.3.52.1.2.2 · 1 row entry · 36 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIpSecTunnelMonTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIpSecTunnelMonTable'
The IPsec Phase-2 Tunnel Table.
There is one entry in this table for each active IPsec Phase-2 
Tunnel.  If the tunnel is terminated, then the entry is no longer 
available after the table has been refreshed.
jnxIpSecTunnelMonEntry row .1.3.6.1.4.1.2636.3.52.1.2.2.1
Each entry contains the attributes
associated with an active IPsec Phase-2 Tunnel.
Column Syntax OID
The IP address type of the remote gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.2.2.1.1
The IP address of the remote gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.2.2.1.2
The index of the IPsec Phase-2 Tunnel Table.
The value of the index is a number which begins at one and
is incremented with each tunnel that is created. The value of
this object will wrap at 2,147,483,647.
Integer32
Constraints:
range: 1-2147483647
.1.3.6.1.4.1.2636.3.52.1.2.2.1.3
The IP address type of the local gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddressType
Type Values:
0unknown
1ipv4
2ipv6
3ipv4z
4ipv6z
16dns
25l2vpn
.1.3.6.1.4.1.2636.3.52.1.2.2.1.4
The IP address of the local gateway (endpoint) for the IPsec
Phase-2 Tunnel.
INET-ADDRESS-MIBInetAddress
Type Constraints:
range: 0..255
.1.3.6.1.4.1.2636.3.52.1.2.2.1.5
Identifier for the local end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.6
Identifier for the remote end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.7
The type of key used by the IPsec Phase-2 Tunnel. It can be
one of the following two types:
- IKE negotiated
- Manually installed
JnxKeyType
Type Values:
0unknown
1keyIke
2keyManual
.1.3.6.1.4.1.2636.3.52.1.2.2.1.8
The type of the remote peer gateway (endpoint). It can be one
of the following two types:
- static (Remote peer whose IP address is known beforehand)
- dynamic (Remote peer whose IP address is not known
JnxRemotePeerType
Type Values:
0unknown
1static
2dynamic
.1.3.6.1.4.1.2636.3.52.1.2.2.1.9
Number of bytes encrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.10
Number of packets encrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.11
Number of bytes decrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.12
Number of packets decrypted by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.13
Number of incoming bytes authenticated using AH by this Phase-2
tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.14
Number of incoming packets authenticated using AH by this Phase-2
tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.15
Number of outgoing bytes applied AH by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.16
Number of outgoing packets applied AH by this Phase-2 tunnel.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.17
Number of packets dropped by this Phase-2 tunnel due to
anti replay check failure.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.18
Number of packets received by this Phase-2 tunnel that
failed AH authentication.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.19
Number of packets received by this Phase-2 tunnel that
failed ESP authentication.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.20
Number of packets received by this Phase-2 tunnel that
failed decryption.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.21
Number of packets received by this Phase-2 tunnel that
failed due to bad headers.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.22
Number of packets received by this Phase-2 tunnel that
failed due to bad ESP trailers.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.23
Total number of dropped packets for this Phase-2 tunnel.
This attribute is obsolete.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.26
VPN tunnel name.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.27
Traffic selector name.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.28
Multi-SA Configuration Status.
Enumeration
Enumerated Values:
0disable
1enable
.1.3.6.1.4.1.2636.3.52.1.2.2.1.29
Total number of Invalid SPI for this IPSec tunnel.
PacketsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.30
Total number of TS check fail for this IPSec tunnel.
PacketsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.31
Total number of discarded packets for this IPSec tunnel.
PacketsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.32
The Tunnel type. It can be regular (1) or ha-link (2).
JnxIkeTunType
Type Values:
1regular
2halink
.1.3.6.1.4.1.2636.3.52.1.2.2.1.33
The TS type. It can be proxyId (1) or trafficSelector (2).
JnxIpSecTsType
Type Values:
1proxyId
2trafficSelector
.1.3.6.1.4.1.2636.3.52.1.2.2.1.34
Negotiated Traffic Selector or Proxy ID for the local end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.35
Negotiated Traffic Selector or Proxy ID for the remote end.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.2.1.36
The maximum transmit packet size (256..9192) for IPSec
tunnels. The value of this object will be 0, if tunnel
MTU is not configured.
Integer32
Constraints:
range: 0-9192
.1.3.6.1.4.1.2636.3.52.1.2.2.1.37
Number of packets received by this Phase-2 tunnel that
failed due to Exceeding Tunnel MTU.
PacketsSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.2636.3.52.1.2.2.1.38
.1.3.6.1.4.1.2636.3.52.1.2.3 · 1 row entry · 16 columns
Uses the juniper variant from /opt/observium/mibs/juniper.
Command help
Walk jnxIpSecSaMonTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'JUNIPER-IPSEC-FLOW-MON-MIB' -M '/opt/observium/mibs/juniper:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'JUNIPER-IPSEC-FLOW-MON-MIB::jnxIpSecSaMonTable'
The IPsec Phase-2 Security Association Table.
This table identifies the structure (in terms of
component SAs) of each active Phase-2 IPsec tunnel.
This table contains an entry for each active and
expiring security association and maps each entry
in the active Phase-2 tunnel table (ipSecTunTable)
into a number of entries in this table. 
          
SA contains the information negotiated by IKE. The SA 
is like a contract laying out the rules of the VPN 
connection for the duration of the SA. An SA is assigned 
a 32-bit number that, when used in conjunction with the 
destination IP address, uniquely identifies the SA. This 
number is called the Security Parameters Index or SPI.
          
IPSec SAs area unidirectional and they are unique in 
each security protocol. A set of SAs are needed for a 
protected data pipe, one per direction per protocol.
jnxIpSecSaMonEntry row .1.3.6.1.4.1.2636.3.52.1.2.3.1
Each entry contains the attributes associated with
active and expiring IPsec Phase-2
security associations.
Column Syntax OID
The index, in the context of the IPsec tunnel ipSecTunIndex,
of the security association represented by this table entry.
The value of this index is a number which begins at one and
is incremented with each SPI associat…
Integer32
Constraints:
range: 1-65535
.1.3.6.1.4.1.2636.3.52.1.2.3.1.1
The index, represents the security protocol (AH, ESP or
IPComp) for which this security association was setup.
Enumeration
Enumerated Values:
1ah
2esp
.1.3.6.1.4.1.2636.3.52.1.2.3.1.2
The value of the incoming SPI.
JnxSpiType
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.52.1.2.3.1.3
The value of the outgoing SPI.
JnxSpiType
Type Constraints:
range: 256..4294967295
.1.3.6.1.4.1.2636.3.52.1.2.3.1.4
This field represents the type of security associations
which can be either manual or dynamic
JnxSAType
Type Values:
0unknown
1manual
2dynamic
.1.3.6.1.4.1.2636.3.52.1.2.3.1.5
The encapsulation mode used by an IPsec Phase-2 Tunnel.
JnxEncapMode
Type Values:
0unknown
1tunnel
2transport
.1.3.6.1.4.1.2636.3.52.1.2.3.1.6
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.52.1.2.3.1.7
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.52.1.2.3.1.8
The length of time the IPsec Phase-2 Tunnel has been active in
hundredths of seconds.
SNMPv2-TCTimeInterval
Type Constraints:
range: 0..2147483647
Description:
A period of time, measured in units of 0.01 seconds.
.1.3.6.1.4.1.2636.3.52.1.2.3.1.9
The security association LifeSize refresh threshold in kilobytes.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.52.1.2.3.1.10
The security association LifeTime refresh threshold in seconds.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.2636.3.52.1.2.3.1.11
The Encryption algorithm used to encrypt the packets.
JnxEncryptAlgo
Type Values:
1espDes
2esp3des
3espNull
4espAes128
5espAes192
6espAes256
7espAesGcm128
8espAesGcm192
9espAesGcm256
10espChaCha20Poly1305
.1.3.6.1.4.1.2636.3.52.1.2.3.1.12
The algorithm used for authentication of packets which
can be hmac-md5-96 or hmac-sha1-96 or hmac-sha-256-128
JnxAuthAlgo
Type Values:
0unknown
1hmacMd5
2hmacSha
3hmacSha256
4hmacSha384
5hmacSha512
6aesGcm128
7aesGcm192
8aesGcm256
9chacha20Poly1305
.1.3.6.1.4.1.2636.3.52.1.2.3.1.13
This column represents the status of the security association
represented by this table entry. If the status of the SA is
'active', the SA is ready for active use. The status
'expiring' represents any of the various sta…
Enumeration
Enumerated Values:
0unknown
1active
2expiring
.1.3.6.1.4.1.2636.3.52.1.2.3.1.14
Class-Of-Service Forwarding Class name.
SNMPv2-TCDisplayString
Type Constraints:
range: 0..255
Description:
Represents textual information taken from the NVT ASCII

character set, as defined in pages 4, 10-11 of RFC 854.

To summarize RFC 854, the NVT ASCII repertoire specifies:

- the use of c…
.1.3.6.1.4.1.2636.3.52.1.2.3.1.15
This field represents whether IPSec extended sequence number
support is enabled or disabled
JnxEsnMode
Type Values:
0none
1enable
2disable
.1.3.6.1.4.1.2636.3.52.1.2.3.1.16