WATCHGUARD-IPSEC-SA-MON-MIB-EXT Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
120
.1.3.6.1.4.1.3097.3.1.1.1 · 1 row entry · 26 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaEspInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaEspInTable'
The (conceptual) table containing information on IPSec
inbound ESP SAs.
          
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaEspInEntry row .1.3.6.1.4.1.3097.3.1.1.1.1
An entry (conceptual row) containing the information on a
particular IPSec inbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Column Syntax OID
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.1.1.1
The security parameters index of the SA.
Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.2
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creation negot…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.1.1.3
The type of identifier presented by 'wgIpsecSaEspInDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.1.1.4
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.1.1.5
The type of identifier presented by 'wgIpsecSaEspInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.1.1.6
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.1.1.7
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.1.1.8
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.1.1.9
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.1.1.10
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.1.1.11
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.3097.3.1.1.1.1.12
The length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspInEncAlg' object, or 0
if the key length is implicit in the specified algorithm or
there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.3097.3.1.1.1.1.13
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.3097.3.1.1.1.1.14
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncate…
secondsSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.1.1.15
The maximum traffic in kilobytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that…
kilobytesSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.1.1.16
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.17
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.1.1.18
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.19
The number of packets handled by the SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.1.1.20
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.21
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.22
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.23
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.24
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.25
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.26
.1.3.6.1.4.1.3097.3.1.1.2 · 1 row entry · 22 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaAhInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaAhInTable'
The (conceptual) table containing information on IPSec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaAhInEntry row .1.3.6.1.4.1.3097.3.1.1.2.1
An entry (conceptual row) containing the information on a
particular IPSec inbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Column Syntax OID
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.2.1.1
The security parameters index of the SA.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.2
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negoti…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.2.1.3
The type of identifier presented by 'wgIpsecSaAhInDestId', or
0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.2.1.4
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.2.1.5
The type of identifier presented by 'wgIpsecSaAhInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.2.1.6
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.2.1.7
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.2.1.8
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.2.1.9
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.2.1.10
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.2.1.11
A unique value representing the hash algorithm applied to
traffic carried by this SA if it uses ESP or 0 if there is
no authentication applied by ESP.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.3097.3.1.1.2.1.12
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.13
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.14
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.15
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.2.1.16
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.17
The number of packets handled by the SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.2.1.18
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.19
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.20
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.21
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.22
.1.3.6.1.4.1.3097.3.1.1.3 · 1 row entry · 17 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaIpcompInTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaIpcompInTable'
The (conceptual) table containing information on IPSec
inbound IPCOMP SAs.
          
There should be one row for every inbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaIpcompInEntry row .1.3.6.1.4.1.3097.3.1.1.3.1
An entry (conceptual row) containing the information on a
particular IPSec inbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Column Syntax OID
Deprecated, currently unused.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.3.1.1
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.3.1.2
Deprecated, currently unused.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.3.1.3
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.3.1.4
Deprecated, currently unused.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.3.1.5
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.3.1.6
Deprecated, currently unused.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.3.1.7
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.3.1.8
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.3.1.9
Deprecated, currently unused.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.3.1.10
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.3.1.11
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.3.1.12
Deprecated, currently unused.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.13
Deprecated, currently unused.
bytesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.14
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.15
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.16
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.17
.1.3.6.1.4.1.3097.3.1.1.4 · 1 row entry · 21 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaEspOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaEspOutTable'
The (conceptual) table containing information on IPSec
Outbound ESP SAs.
          
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaEspOutEntry row .1.3.6.1.4.1.3097.3.1.1.4.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Column Syntax OID
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.4.1.1
The security parameters index of the SA.
Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.4.1.2
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.4.1.3
The type of identifier presented by
'wgIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.4.1.4
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.4.1.5
The type of identifier presented by 'wgIpsecSaEspOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.4.1.6
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.4.1.7
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.4.1.8
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.4.1.9
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.4.1.10
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.4.1.11
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.3097.3.1.1.4.1.12
The length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspOutEncAlg' object, or
0 if the key length is implicit in the specified algorithm
or there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.3097.3.1.1.4.1.13
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.3097.3.1.1.4.1.14
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.4.1.15
The maximum traffic in kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.4.1.16
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.4.1.17
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.18
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.19
The number of packets handled by the SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.20
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.4.1.21
.1.3.6.1.4.1.3097.3.1.1.5 · 1 row entry · 19 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaAhOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaAhOutTable'
The (conceptual) table containing information on IPSec
Outbound AH SAs.
          
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaAhOutEntry row .1.3.6.1.4.1.3097.3.1.1.5.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Column Syntax OID
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.5.1.1
The security parameters index of the SA.
SNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.2
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.5.1.3
The type of identifier presented by 'wgIpsecSaAhOutSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.5.1.4
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.5.1.5
The type of identifier presented by 'wgIpsecSaAhOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.5.1.6
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.5.1.7
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.5.1.8
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.5.1.9
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.5.1.10
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.5.1.11
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.3097.3.1.1.5.1.12
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.13
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.14
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.5.1.15
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.16
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.17
The number of packets handled by the SA.
SNMPv2-SMICounter64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.18
Deprecated, currently unused.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.5.1.19
.1.3.6.1.4.1.3097.3.1.1.6 · 1 row entry · 15 columns
Uses the watchguard variant from /opt/observium/mibs/watchguard.
Command help
Walk wgIpsecSaIpcompOutTable
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT' -M '/opt/observium/mibs/watchguard:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'WATCHGUARD-IPSEC-SA-MON-MIB-EXT::wgIpsecSaIpcompOutTable'
Deprecated, currently unused.
wgIpsecSaIpcompOutEntry row .1.3.6.1.4.1.3097.3.1.1.6.1
Deprecated, currently unused.
Column Syntax OID
Deprecated, currently unused.
SNMPv2-SMIIpAddress
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.6.1.1
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.6.1.2
Deprecated, currently unused.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.6.1.3
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.6.1.4
Deprecated, currently unused.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.6.1.5
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.6.1.6
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.6.1.7
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.6.1.8
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.6.1.9
Deprecated, currently unused.
IpsecSaCreatorIdent
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.6.1.10
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.6.1.11
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.6.1.12
Deprecated, currently unused.
secondsSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.13
Deprecated, currently unused.
bytesSNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.14
The number of packets handled by the SA.
SNMPv2-SMICounter32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.15