CISCO-IKE-CONFIGURATION-MIB

        This is a MIB Module for configuring and viewing IKE 
parameters and policies. 
        
Acronyms
The following acronyms are used in this document:
        
IPsec:      Secure IP Protocol
        
VPN:        Virtual Private Network
        
ISAKMP:     Internet Security Association and Key Exchange
            Protocol
        
IKE:        Internet Key Exchange Protocol
        
DOI:        Domain of Interpretation (of the attributes
            of IKE protocol in the context of a specific 
            Phase-2 protocol).
        
SA:         Security Association
            (ref: rfc2408).
        
SPI:        Security Parameter Index is the pointer or
            identifier used in accessing SA attributes
            (ref: rfc2408).
        
MM:         Main Mode - the process of setting up
            a Phase 1 SA to secure the exchanges
            required to setup Phase 2 SAs
        
Phase 1 Tunnel:
            An ISAKMP SA can be regarded as representing
            a flow of ISAKMP/IKE traffic. Hence an ISAKMP
            is referred to as a 'Phase 1 Tunnel' in this
            document. 
        
Phase 2 Tunnel:
            A Phase 2 Tunnel is an instance of a
            non-ISAKMP SA bundle in which all the SA
            share the same proxy identifiers (IDii,IDir)
            and protect the same stream of application
            traffic.
            Note that a Phase 2 tunnel may comprise one
            SA bundle at any given point of time, but 
            the SA bundle changes with time due to 
            key refresh.
        
        
History of the MIB
This MIB was originally written as CISCO-IPSEC-MIB
which combined the configuration of IKE and IPsec
protocols into a single MIB.
    
ciscoIkeConfigMIB 1.3.6.1.4.1.9.9.423
Imported Objects
CISCO-IPSEC-TC CIKEIsakmpDoi CIKELifesize CIKELifetime CIPsecControlProtocol CIPsecDiffHellmanGrp CIPsecEncryptAlgorithm CIPsecIkeAuthMethod CIPsecIkeHashAlgorithm CIPsecIkePRFAlgorithm CIPsecPhase1PeerIdentityType
CISCO-SMI ciscoMgmt
INET-ADDRESS-MIB InetAddress InetAddressPrefixLength InetAddressType
SNMPv2-CONF MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP
SNMPv2-SMI MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32
SNMPv2-TC RowStatus TEXTUAL-CONVENTION TruthValue
Type Definitions (2)
CicIkeConfigInitiatorIndex Unsigned32 range: 1..65535
CicIkeConfigPskIndex Unsigned32 range: 1..65535
Objects (72)
ciscoIkeConfigMIB .1.3.6.1.4.1.9.9.423
cicIkeConfigMIBNotifs .1.3.6.1.4.1.9.9.423.0
cicIkeConfigMIBObjects .1.3.6.1.4.1.9.9.423.1
cicIkeCfgOperations .1.3.6.1.4.1.9.9.423.1.1
cicIkeEnabled r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.1.1
cicIkeAggressModeEnabled r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.1.2
cicIkeCfgIdentities .1.3.6.1.4.1.9.9.423.1.2
cicIkeCfgIdentityTable .1.3.6.1.4.1.9.9.423.1.2.1
cicIkeCfgIdentityEntry cicIkeCfgIdentityDoi .1.3.6.1.4.1.9.9.423.1.2.1.1
cicIkeCfgIdentityDoi CISCO-IPSEC-TCCIKEIsakmpDoi .1.3.6.1.4.1.9.9.423.1.2.1.1.1
cicIkeCfgIdentityType r/w CISCO-IPSEC-TCCIPsecPhase1PeerIdentityType .1.3.6.1.4.1.9.9.423.1.2.1.1.2
cicIkeCfgInitiatorNextAvailTable .1.3.6.1.4.1.9.9.423.1.2.2
cicIkeCfgInitiatorNextAvailEntry .1.3.6.1.4.1.9.9.423.1.2.2.1
cicIkeCfgInitiatorNextAvailIndex CicIkeConfigInitiatorIndex .1.3.6.1.4.1.9.9.423.1.2.2.1.1
cicIkeCfgInitiatorTable .1.3.6.1.4.1.9.9.423.1.2.3
cicIkeCfgInitiatorEntry cicIkeCfgIdentityDoicicIkeCfgInitiatorIndex .1.3.6.1.4.1.9.9.423.1.2.3.1
cicIkeCfgInitiatorIndex CicIkeConfigInitiatorIndex .1.3.6.1.4.1.9.9.423.1.2.3.1.1
cicIkeCfgInitiatorPAddrType r/w CISCO-IPSEC-TCCIPsecPhase1PeerIdentityType .1.3.6.1.4.1.9.9.423.1.2.3.1.2
cicIkeCfgInitiatorPAddr r/w OctetString .1.3.6.1.4.1.9.9.423.1.2.3.1.3
cicIkeCfgInitiatorVer r/w CISCO-IPSEC-TCCIPsecControlProtocol .1.3.6.1.4.1.9.9.423.1.2.3.1.4
cicIkeCfgInitiatorStatus r/w SNMPv2-TCRowStatus .1.3.6.1.4.1.9.9.423.1.2.3.1.5
cicIkeCfgFailureRecovery .1.3.6.1.4.1.9.9.423.1.3
cicIkeCfgFailureRecovConfigTable .1.3.6.1.4.1.9.9.423.1.3.1
cicIkeCfgFailureRecovConfigEntry .1.3.6.1.4.1.9.9.423.1.3.1.1
cicIkeKeepAliveEnabled r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.3.1.1.1
cicIkeKeepAliveType r/w Enumeration .1.3.6.1.4.1.9.9.423.1.3.1.1.2
cicIkeKeepAliveInterval r/w secondsUnsigned32 .1.3.6.1.4.1.9.9.423.1.3.1.1.3
cicIkeKeepAliveRetryInterval r/w secondsUnsigned32 .1.3.6.1.4.1.9.9.423.1.3.1.1.4
cicIkeInvalidSpiNotify r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.3.1.1.5
cicIkeCfgPeerAuth .1.3.6.1.4.1.9.9.423.1.4
cicIkeCfgPskAuthConfig .1.3.6.1.4.1.9.9.423.1.4.1
cicIkeCfgPskNextAvailTable .1.3.6.1.4.1.9.9.423.1.4.1.1
cicIkeCfgPskNextAvailEntry .1.3.6.1.4.1.9.9.423.1.4.1.1.1
cicIkeCfgPskNextAvailIndex CicIkeConfigPskIndex .1.3.6.1.4.1.9.9.423.1.4.1.1.1.1
cicIkeCfgPskTable .1.3.6.1.4.1.9.9.423.1.4.1.2
cicIkeCfgPskEntry cicIkeCfgIdentityDoicicIkeCfgPskIndex .1.3.6.1.4.1.9.9.423.1.4.1.2.1
cicIkeCfgPskIndex CicIkeConfigPskIndex .1.3.6.1.4.1.9.9.423.1.4.1.2.1.1
cicIkeCfgPskKey r/w OctetString .1.3.6.1.4.1.9.9.423.1.4.1.2.1.2
cicIkeCfgPskRemIdentType r/w CISCO-IPSEC-TCCIPsecPhase1PeerIdentityType .1.3.6.1.4.1.9.9.423.1.4.1.2.1.3
cicIkeCfgPskRemIdentTypeStand INET-ADDRESS-MIBInetAddressType .1.3.6.1.4.1.9.9.423.1.4.1.2.1.4
cicIkeCfgPskRemIdentity r/w OctetString .1.3.6.1.4.1.9.9.423.1.4.1.2.1.5
cicIkeCfgPskRemIdAddrOrRg1OrSn r/w INET-ADDRESS-MIBInetAddress .1.3.6.1.4.1.9.9.423.1.4.1.2.1.6
cicIkeCfgPskRemIdAddrRange2 r/w INET-ADDRESS-MIBInetAddress .1.3.6.1.4.1.9.9.423.1.4.1.2.1.7
cicIkeCfgPskRemIdSubnetMask r/w INET-ADDRESS-MIBInetAddressPrefixLength .1.3.6.1.4.1.9.9.423.1.4.1.2.1.8
cicIkeCfgPskStatus r/w SNMPv2-TCRowStatus .1.3.6.1.4.1.9.9.423.1.4.1.2.1.9
cicIkeCfgNonceAuthConfig .1.3.6.1.4.1.9.9.423.1.4.2
cicIkeCfgPkiAuthConfig .1.3.6.1.4.1.9.9.423.1.4.3
cicIkeCfgPolicies .1.3.6.1.4.1.9.9.423.1.5
cicIkeCfgPolicyTable .1.3.6.1.4.1.9.9.423.1.5.1
cicIkeCfgPolicyEntry cicIkeCfgIdentityDoicicIkeCfgPolicyPriority .1.3.6.1.4.1.9.9.423.1.5.1.1
cicIkeCfgPolicyPriority Unsigned32 .1.3.6.1.4.1.9.9.423.1.5.1.1.1
cicIkeCfgPolicyEncr r/w CISCO-IPSEC-TCCIPsecEncryptAlgorithm .1.3.6.1.4.1.9.9.423.1.5.1.1.2
cicIkeCfgPolicyHash r/w CISCO-IPSEC-TCCIPsecIkeHashAlgorithm .1.3.6.1.4.1.9.9.423.1.5.1.1.3
cicIkeCfgPolicyPRF r/w CISCO-IPSEC-TCCIPsecIkePRFAlgorithm .1.3.6.1.4.1.9.9.423.1.5.1.1.4
cicIkeCfgPolicyAuth r/w CISCO-IPSEC-TCCIPsecIkeAuthMethod .1.3.6.1.4.1.9.9.423.1.5.1.1.5
cicIkeCfgPolicyDHGroup r/w CISCO-IPSEC-TCCIPsecDiffHellmanGrp .1.3.6.1.4.1.9.9.423.1.5.1.1.6
cicIkeCfgPolicyLifetime r/w secondsCISCO-IPSEC-TCCIKELifetime .1.3.6.1.4.1.9.9.423.1.5.1.1.7
cicIkeCfgPolicyLifesize r/w kbytesCISCO-IPSEC-TCCIKELifesize .1.3.6.1.4.1.9.9.423.1.5.1.1.8
cicIkeCfgPolicyStatus r/w SNMPv2-TCRowStatus .1.3.6.1.4.1.9.9.423.1.5.1.1.9
cicIkeCfgServiceControl .1.3.6.1.4.1.9.9.423.1.6
cicIkeCfgCallAdmssionnCtrl .1.3.6.1.4.1.9.9.423.1.6.1
cicIkeCfgQoSControl .1.3.6.1.4.1.9.9.423.1.6.2
cicIkeConfigMibNotifCntl .1.3.6.1.4.1.9.9.423.1.7
cicNotifCntlIkeAllNotifs r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.1
cicNotifCntlIkeOperStateChanged r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.2
cicNotifCntlIkePskAdded r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.3
cicNotifCntlIkePskDeleted r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.4
cicNotifCntlIkePolicyAdded r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.5
cicNotifCntlIkePolicyDeleted r/w SNMPv2-TCTruthValue .1.3.6.1.4.1.9.9.423.1.7.6
cicIkeConfigMIBConform .1.3.6.1.4.1.9.9.423.2
cicIkeCfgMIBGroups .1.3.6.1.4.1.9.9.423.2.1
cicIkeCfgMIBCompliances .1.3.6.1.4.1.9.9.423.2.2
Notifications / Traps (5)
NameOIDDescription
ciscoIkeConfigOperStateChanged .1.3.6.1.4.1.9.9.423.0.1
The notification is generated when the operational
state of IKE entity on the managed device has
been changed.
ciscoIkeConfigPskAdded .1.3.6.1.4.1.9.9.423.0.2
This notification is generated when a new preshared
key is configured on the managed device.
ciscoIkeConfigPskDeleted .1.3.6.1.4.1.9.9.423.0.3
This notification is generated when an existing
preshared key is configured on the managed device is
about to be deleted.
ciscoIkeConfigPolicyAdded .1.3.6.1.4.1.9.9.423.0.4
This notification is generated when a new ISAKMP
policy is configured on the managed device.
ciscoIkeConfigPolicyDeleted .1.3.6.1.4.1.9.9.423.0.5
This notification is issued when an existing ISAKMP
policy configured on the managed device is about
to be deleted.