FEC-IKEV2-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
2
Rows
2
Columns
31
.0.21 · 1 row entry · 23 columns
This table contains the list of currently active IKE security
associations, that are created using IKEv2 protocol.
ikev2SaEntry entry .0.21.1
This object contains an IKE security association.
Indexes
ikev2SaIndex
Column Syntax OID
ikev2SaIndex
A unique index for this entry.
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.1
ikev2SaState
This object specifies the state of the SA.
Possible values:
negotiating(1), -- the SA is still being negotiated
established(2), -- the SA negotiation is finished
waiting-for-remove(3), -- the SA is wait…
Enumerationr/w
Enumerated Values:
1negotiating
2established
3waiting-for-remove
7delete
.0.21.1.2
ikev2SaAuthMethod
The authentication method used when creating this SA.
Possible values:
pre-sh-key(1), -- Authentication using pre shared keys
dss-sig(2), -- Authentication using DSS signatures
rsa-sig(3), -- Authentication us…
Enumeration
Enumerated Values:
1pre-sh-key
2dss-sig
3rsa-sig
4rsa-enc
5rsa-enc-rev
.0.21.1.3
ikev2SaEncAlg
The encryption algorithm used for the IKE_SA.
Possible values:
des(2),
des3(3),
rc5(4),
idea(5),
cast(6),
blowfish(7),
aes-cbc(12),
aes-ctr(13)
Enumeration
Enumerated Values:
2des
3des3
4rc5
5idea
6cast
7blowfish
12aes-cbc
13aes-ctr
.0.21.1.4
ikev2SaIntegAlg
The integrity protection algorithm used for the IKE_SA.
Possible values:
hmac-md5-96(1),
hmac-sha1-96(2)
Enumeration
Enumerated Values:
1hmac-md5-96
2hmac-sha1-96
.0.21.1.5
ikev2SaPrfAlg
The hash algorithm used for the pseudo random function.
Possible values:
hmac-md5(1),
hmac-sha1(2)
Enumeration
Enumerated Values:
1hmac-md5
2hmac-sha1
.0.21.1.6
ikev2SaGroup
The Diffie-Hellman group used for the IKE_SA.
Possible values:
1 - DH-group 768-bit MODP,
2 - DH-group 1024-bit MODP
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.7
ikev2SaRole
This object specifies by which side the SA
negotiation was initiated.
Possible values:
initiator(1), -- this end initiated the SA negotiation
responder(2) -- the remote end initiated the SA negotiation.
Enumeration
Enumerated Values:
1initiator
2responder
.0.21.1.8
ikev2SaLocalId
The local ID used for authentication.
SNMPv2-TCDisplayString
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.0.21.1.9
ikev2SaRemoteId
The remote ID used for authentication.
SNMPv2-TCDisplayString
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.0.21.1.10
ikev2SaLocalIp
The local IP address used in the IKE communication.
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.0.21.1.11
ikev2SaRemoteIp
The remote IP address used in the IKE communication.
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.0.21.1.12
ikev2SaSpiI
The SPI of the initiator.
OctetString .0.21.1.13
ikev2SaSpiR
The SPI of the responder.
OctetString .0.21.1.14
ikev2SaCreated
Time the SA was created.
.0.21.1.15
ikev2SaLastUsed
Time the SA was used last.
.0.21.1.16
ikev2SaExpires
Time the SA will expire.
.0.21.1.17
ikev2SaNumCerts
The number of certificates received from the remote
side when negotiating this SA.
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.18
ikev2SaNumNegotiations
This object specifies the number of currently active
negotiations for this SA.
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.19
ikev2SaBytes
Number of bytes transmitted using this SA.
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.20
ikev2SaPeerIndex
The index of the peer for which this SA was created.
Integer32
Textual Convention: COPS-PR-SPPIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.0.21.1.21
ikev2SaLocalPort
Local port currently used for the SA.
Integer32
Constraints:
range: 0-65535
.0.21.1.22
ikev2SaRemotePort
Remote port currently used for the SA.
Integer32
Constraints:
range: 0-65535
.0.21.1.23
.0.22 · 1 row entry · 8 columns
This table contains the list of IKE_SA profiles.
these profiles are neede when using IKEv2 protocol.
ikev2ProfileEntry entry .0.22.1
This object contains an IKE_SA profile.
Indexes
ikev2PrfIndex
Column Syntax OID
ikev2PrfIndex
A unique index identifying this entry.
Unsigned32r/w
Constraints:
range: 1-4294967295
.0.22.1.1
ikev2PrfDescription
An optional description for this profile.
SNMPv2-TCDisplayStringr/w
Textual Convention: SNMPv2-TCDisplayString OctetString
Type Constraints:
range: 0..255
.0.22.1.2
ikev2PrfProposal
The index of the first IKE proposal which may be used
for IKE SA negotiation with this profile.
SNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.0.22.1.3
ikev2PrfBlockTime
This object specifies the time in seconds for which a peer is
blocked for any IPSec operations after a phase 1 initiator
negotiation failed.
Special values:
-1: use settings from global profile (do not block by defau…
secondsInteger32r/w
Constraints:
range: -1-86400
.0.22.1.4
ikev2PrfNatT
This object specifies whether NAT-Traversal is enabled
Possible values:
enabled(1), -- enable Nat-Traversal
disabled(2), -- disable Nat-Traversal
default(3) -- use value from default profile
-- (disa…
Enumerationr/w
Enumerated Values:
1enabled
2disabled
3default
4delete
.0.22.1.5
ikev2PrfMtuMax
The maximum MTU value allowed for ipsecPeerMtu.
Zero means use value from global profile,
if this is the global profile, 1418 is assumed.
Nonzero values smaller than 214 are reset to the minimum of 214.
Integer32r/w
Constraints:
range: 0-65535
.0.22.1.6
ikev2PrfLifeSeconds
The time (in seconds) after which an SA will be rekeyed.
secondsSNMPv2-SMIUnsigned32r/w
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.0.22.1.7
ikev2PrfAliveCheck
This object specifies if a check is done to see whether the
other endpoint is alive.
(only for IKEv2).
Enumerationr/w
Enumerated Values:
1enabled
2disabled
.0.22.1.8