tIPsecRUTnlPfsDHGroup
TIMETRA-IPSEC-MIB ·
.1.3.6.1.4.1.6527.3.1.2.48.20.1.9
Object
The value of tIPsecRUTnlPfsDHGroup indicates the new Diffie-hellman key exchange each time the SA(Security Association) key is renegotiated. After the SA expires, the key is forgotten and another key is generated (if the SA remains up). This means that an attacker who cracks part of the exchange can only read the part that used the key before the key changed. There is no advantage of cracking the other parts if the attacker has already cracked one.
Context
- MIB
- TIMETRA-IPSEC-MIB
- OID
.1.3.6.1.4.1.6527.3.1.2.48.20.1.9- Type
- column
- Access
- readonly
- Status
- current
- Parent
- tIPsecRUTnlEntry
- Groups
- 3
Net-SNMP examples
How SNMP and these commands workWalk the column to discover its indexed instances, or supply every index to read one instance.
Walk the column
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup'
More examples
Read one indexed instance
/usr/bin/snmpget -v2c -c '<community>' -Pud -Ir -OQUv -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup.<svcId>.<sapPortId>.<sapEncapValue>.<tIPsecRUTnlInetAddrType>.<tIPsecRUTnlInetAddress>.<tIPsecRUTnlPort>'
Translate to a numeric OID
/usr/bin/snmptranslate -Pud -Ir -On -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup'
Syntax
- Source
- TIMETRA-TC-MIBTmnxIkePolicyDHGroupOrZero
- Base type
Enumeration
Values & Constraints
Type Values
0 | unspecified |
1 | group1 |
2 | group2 |
5 | group5 |
14 | group14 |
15 | group15 |
19 | group19 |
20 | group20 |
21 | group21 |