tIPsecRUTnlPfsDHGroup

TIMETRA-IPSEC-MIB · .1.3.6.1.4.1.6527.3.1.2.48.20.1.9

Object

The value of tIPsecRUTnlPfsDHGroup indicates the new
Diffie-hellman key exchange each time the SA(Security Association)
key is renegotiated.  After the SA expires, the key is forgotten
and another key is generated (if the SA remains up).  This means
that an attacker who cracks part of the exchange can only read the
part that used the key before the key changed.  There is no
advantage of cracking the other parts if the attacker has already
cracked one.

Context

MIB
TIMETRA-IPSEC-MIB
OID
.1.3.6.1.4.1.6527.3.1.2.48.20.1.9
Type
column
Access
readonly
Status
current
Parent
tIPsecRUTnlEntry
Groups
3

Walk the column to discover its indexed instances, or supply every index to read one instance.

Walk the column
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup'
More examples
Read one indexed instance
/usr/bin/snmpget -v2c -c '<community>' -Pud -Ir -OQUv -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup.<svcId>.<sapPortId>.<sapEncapValue>.<tIPsecRUTnlInetAddrType>.<tIPsecRUTnlInetAddress>.<tIPsecRUTnlPort>'
Translate to a numeric OID
/usr/bin/snmptranslate -Pud -Ir -On -m 'TIMETRA-IPSEC-MIB' -M '/opt/observium/mibs/nokia:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'TIMETRA-IPSEC-MIB::tIPsecRUTnlPfsDHGroup'

Values & Constraints

Type Values
0unspecified
1group1
2group2
5group5
14group14
15group15
19group19
20group20
21group21