IPSEC-SA-MON-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
127
.1.3.6.1.2.1.500.1.1.1 · 1 row entry · 28 columns
The (conceptual) table containing information on IPsec
inbound ESP SAs.
          
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaEspInEntry entry .1.3.6.1.2.1.500.1.1.1.1
An entry (conceptual row) containing the information on a
particular IPsec inbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaEspInAddress ipsecSaEspInSpi
Column Syntax OID
ipsecSaEspInAddress
The destination address of the SA.

IPv4 entities will prefix the IP address with
'0000:0000:0000:0000:0000:FFFF::'.
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.1.1.1
ipsecSaEspInSpi
The security parameters index of the SA.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.2
ipsecSaEspInDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creatio…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.1.1.3
ipsecSaEspInDestIdType
The type of identifier presented by 'ipsecSaEspInDestId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.1.1.4
ipsecSaEspInSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creation neg…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.1.1.5
ipsecSaEspInSourceIdType
The type of identifier presented by 'ipsecSaEspInSourceId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.1.1.6
ipsecSaEspInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.1.1.7
ipsecSaEspInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.1.1.8
ipsecSaEspInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.1.1.9
ipsecSaEspInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.1.1.10
ipsecSaEspInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.1.1.11
ipsecSaEspInEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.2.1.500.1.1.1.1.12
ipsecSaEspInEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'ipsecSaEspInEncAlg' object. It
may be 0 if the key length is implicit in the specified
algorithm or there is no encryption specified.
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.1.1.13
ipsecSaEspInAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.2.1.500.1.1.1.1.14
ipsecSaEspInAuthKeyLength
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaEspInAuthAlg'. It may be
0 if the key length is implicit in the specified algorithm
or there is no authentication specified.
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.1.1.15
ipsecSaEspInRepWinSize
The size of the anti-replay window used by this SA, or 0 if
anti-replay checking is not being done.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.16
ipsecSaEspInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.17
ipsecSaEspInLimitKbytes
The maximum traffic in kilobytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that…
kilobytesSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.18
ipsecSaEspInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.19
ipsecSaEspInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in
kilobytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.20
ipsecSaEspInUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the decrypted IP
packet, including the original IP header of that decrypted
packet.

This is not necessa…
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.1.1.21
ipsecSaEspInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.1.1.22
ipsecSaEspInDecryptErrors
The number of packets discarded by the SA due to detectable
decryption errors. Not all decryption errors are detectable
within SA processing, so this count should not be considered
definitive.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.23
ipsecSaEspInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.24
ipsecSaEspInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.25
ipsecSaEspInPolicyErrors
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.26
ipsecSaEspInPadErrors
The number of packets discarded by the SA due to pad value
errors.

Implementations that do not check this must not support this
object.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.27
ipsecSaEspInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decryption, authentication, replay errors or,
when supported, invalid padding errors. This may include
packets dropped due to a lack of receive buffers,…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.1.1.28
.1.3.6.1.2.1.500.1.1.2 · 1 row entry · 24 columns
The (conceptual) table containing information on IPsec
inbound AH SAs.
          
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaAhInEntry entry .1.3.6.1.2.1.500.1.1.2.1
An entry (conceptual row) containing the information on a
particular IPsec inbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaAhInAddress ipsecSaAhInSpi
Column Syntax OID
ipsecSaAhInAddress
The destination address of the SA.

IPv4 entities will prefix the IP address with
'0000:0000:0000:0000:0000:FFFF::'.
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.2.1.1
ipsecSaAhInSpi
The security parameters index of the SA.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.2
ipsecSaAhInDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creatio…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.2.1.3
ipsecSaAhInDestIdType
The type of identifier presented by 'ipsecSaAhInDestId'. It
may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.2.1.4
ipsecSaAhInSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creation neg…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.2.1.5
ipsecSaAhInSourceIdType
The type of identifier presented by 'ipsecSaAhInSourceId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.2.1.6
ipsecSaAhInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.2.1.7
ipsecSaAhInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.2.1.8
ipsecSaAhInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.2.1.9
ipsecSaAhInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.2.1.10
ipsecSaAhInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.2.1.11
ipsecSaAhInAuthAlg
A unique value representing the hash algorithm applied to
traffic carried by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.2.1.500.1.1.2.1.12
ipsecSaAhInAuthKeyLength
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaAhInAuthAlg' object. It
may be 0 if the key length is implicit in the specified
algorithm.
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.2.1.13
ipsecSaAhInRepWinSize
The size of the anti-replay window used by this SA, or 0 if
anti-replay checking is not being done.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.14
ipsecSaAhInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.15
ipsecSaAhInLimitKbytes
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that val…
kilobytesSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.16
ipsecSaAhInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.17
ipsecSaAhInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in
kilobytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.18
ipsecSaAhInUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the de-processed
IP packet, including the original IP header of that de-
processed packet.

This is not …
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.2.1.19
ipsecSaAhInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.2.1.20
ipsecSaAhInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.21
ipsecSaAhInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.22
ipsecSaAhInPolicyErrors
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.23
ipsecSaAhInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to c…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.2.1.24
.1.3.6.1.2.1.500.1.1.3 · 1 row entry · 17 columns
The (conceptual) table containing information on IPsec
inbound IPcomp SAs.
          
There should be one row for every inbound IPcomp (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaIpcompInEntry entry .1.3.6.1.2.1.500.1.1.3.1
An entry (conceptual row) containing the information on a
particular IPsec inbound IPcomp SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaIpcompInAddress ipsecSaIpcompInCpi
Column Syntax OID
ipsecSaIpcompInAddress
The destination address of the SA.

IPv4 entities will prefix the IP address with
'0000:0000:0000:0000:0000:FFFF::'.
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.3.1.1
ipsecSaIpcompInCpi
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.2.1.500.1.1.3.1.2
ipsecSaIpcompInDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode, or 0 if this SA is
used with multiple SAs in security association suites.
This value, if non-zero, is taken directly from th…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.3.1.3
ipsecSaIpcompInDestIdType
The type of identifier presented by
'ipsecSaIpcompInDestId'. It may be 0 if unknown or if the SA
uses transport mode, or if this SA is used with multiple SAs
in security association suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.3.1.4
ipsecSaIpcompInSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation, or 0 if this SA
is used with multiple SAs in security association suites.

This value, if non-zero, i…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.3.1.5
ipsecSaIpcompInSourceIdType
The type of identifier presented by
'ipsecSaIpcompInSourceId'. It may be 0 if unknown or if the
SA uses transport mode encapsulation, or if this SA is used
with multiple SAs in security association suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.3.1.6
ipsecSaIpcompInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.3.1.7
ipsecSaIpcompInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.3.1.8
ipsecSaIpcompInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.3.1.9
ipsecSaIpcompInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.3.1.10
ipsecSaIpcompInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.3.1.11
ipsecSaIpcompInDecompAlg
A unique value representing the decompression algorithm
applied to traffic.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.2.1.500.1.1.3.1.12
ipsecSaIpcompInSeconds
The number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.3.1.13
ipsecSaIpcompInUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the uncompressed
IP packet, including the original IP header of that
uncompressed packet.

Packets which…
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.3.1.14
ipsecSaIpcompInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.3.1.15
ipsecSaIpcompInDecompErrors
The number of packets discarded by the SA due to
decompression errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.3.1.16
ipsecSaIpcompInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decompression errors. This may include packets
dropped due to a lack of receive buffers, and packets
dropped due to congestion at the decompression elem…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.3.1.17
.1.3.6.1.2.1.500.1.1.4 · 1 row entry · 22 columns
The (conceptual) table containing information on IPsec
Outbound ESP SAs.
          
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaEspOutEntry entry .1.3.6.1.2.1.500.1.1.4.1
An entry (conceptual row) containing the information on a
particular IPsec Outbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaEspOutAddress ipsecSaEspOutSpi
Column Syntax OID
ipsecSaEspOutAddress
The destination address of the SA.

IPv4 entities will prefix the IP address with
'0000:0000:0000:0000:0000:FFFF::'.
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.4.1.1
ipsecSaEspOutSpi
The security parameters index of the SA.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.2
ipsecSaEspOutSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during phase 2 negotia…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.4.1.3
ipsecSaEspOutSourceIdType
The type of identifier presented by
'ipsecSaEspOutSourceId'. It may be 0 if unknown or if the SA
uses transport mode encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.4.1.4
ipsecSaEspOutDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during phase 2 ne…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.4.1.5
ipsecSaEspOutDestIdType
The type of identifier presented by 'ipsecSaEspOutDestId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.4.1.6
ipsecSaEspOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.4.1.7
ipsecSaEspOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.4.1.8
ipsecSaEspOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.4.1.9
ipsecSaEspOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.4.1.10
ipsecSaEspOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.4.1.11
ipsecSaEspOutEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.2.1.500.1.1.4.1.12
ipsecSaEspOutEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'ipsecSaEspOutEncAlg' object. It
may be 0 if the key length is implicit in the specified
algorithm or there is no encryption specified.
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.4.1.13
ipsecSaEspOutAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.2.1.500.1.1.4.1.14
ipsecSaEspOutAuthKeyLength
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaEspOutAuthAlg' object. It
may be 0 if the key length is implicit in the specified
algorithm or there is no authentication spec…
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.4.1.15
ipsecSaEspOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.16
ipsecSaEspOutLimitKbytes
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that val…
kilobytesSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.17
ipsecSaEspOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.18
ipsecSaEspOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in
kilobytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.19
ipsecSaEspOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the unencrypted IP
packet, including the original IP header of that unencrypted
packet.

This is not nec…
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.4.1.20
ipsecSaEspOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.4.1.21
ipsecSaEspOutSendErrors
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.4.1.22
.1.3.6.1.2.1.500.1.1.5 · 1 row entry · 20 columns
The (conceptual) table containing information on IPsec
Outbound AH SAs.
          
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaAhOutEntry entry .1.3.6.1.2.1.500.1.1.5.1
An entry (conceptual row) containing the information on a
particular IPsec Outbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaAhOutAddress ipsecSaAhOutSpi
Column Syntax OID
ipsecSaAhOutAddress
The destination address of the SA.

IPv4 entities will prefix the IP address with
'0000:0000:0000:0000:0000:FFFF::'.
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.5.1.1
ipsecSaAhOutSpi
The security parameters index of the SA.
SNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.2
ipsecSaAhOutSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during phase 2 negotia…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.5.1.3
ipsecSaAhOutSourceIdType
The type of identifier presented by 'ipsecSaAhOutSourceId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.5.1.4
ipsecSaAhOutDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during phase 2 ne…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.5.1.5
ipsecSaAhOutDestIdType
The type of identifier presented by 'ipsecSaAhOutDestId'.
It may be 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.5.1.6
ipsecSaAhOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.5.1.7
ipsecSaAhOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.5.1.8
ipsecSaAhOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.5.1.9
ipsecSaAhOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.5.1.10
ipsecSaAhOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.5.1.11
ipsecSaAhOutAuthAlg
A unique value representing the hash algorithm applied to
traffic carried by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.2.1.500.1.1.5.1.12
ipsecSaAhOutAuthKeyLength
The length of the authentication key in bits used for the
algorithm specified in the 'ipsecSaAhOutAuthAlg' object. It
may be 0 if the key length is implicit in the specified
algorithm.
bitsUnsigned32
Constraints:
range: 0-65531
.1.3.6.1.2.1.500.1.1.5.1.13
ipsecSaAhOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.14
ipsecSaAhOutLimitKbytes
The maximum traffic in bytes that the SA is allowed to
process, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that val…
kilobytesSNMPv2-SMIUnsigned32
Textual Convention: SNMPv2-SMIUnsigned32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.15
ipsecSaAhOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.16
ipsecSaAhOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in
kilobytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.17
ipsecSaAhOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the unprocessed IP
packet, including the original IP header of that unprocessed
packet.

This is not nec…
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.5.1.18
ipsecSaAhOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.5.1.19
ipsecSaAhOutSendErrors
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.5.1.20
.1.3.6.1.2.1.500.1.1.6 · 1 row entry · 16 columns
The (conceptual) table containing information on IPsec
Outbound IPcomp SAs.
          
There should be one row for every outbound IPcomp (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
ipsecSaIpcompOutEntry entry .1.3.6.1.2.1.500.1.1.6.1
An entry (conceptual row) containing the information on a
particular IPsec Outbound IPcomp SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
ipsecSaIpcompOutAddress ipsecSaIpcompOutCpi
Column Syntax OID
ipsecSaIpcompOutAddress
The destination address of the SA.

If the IPcomp SA is shared across multiple SAs in security
association suites, this value may be 0.

IPv4 entities will prefix the IP address with
'0000:00…
IpsecIpv6Address
Textual Convention: IpsecIpv6Address OctetString
Type Constraints:
range: 16
.1.3.6.1.2.1.500.1.1.6.1.1
ipsecSaIpcompOutCpi
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.2.1.500.1.1.6.1.2
ipsecSaIpcompOutSourceId
The source identifier of the SA. It may be 0 if unknown or
if the SA uses transport mode encapsulation, or if this SA
is used with multiple SAs in security association suites.

This value, if non-zero, is …
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.6.1.3
ipsecSaIpcompOutSourceIdType
The type of identifier presented by
'ipsecSaIpcompOutSourceId'. It may be 0 if unknown or if the
SA uses transport mode encapsulation, or if this SA is used
with multiple SAs in security association suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.6.1.4
ipsecSaIpcompOutDestId
The destination identifier of the SA. It may be 0 if
unknown or if the SA uses transport mode encapsulation, or
if this SA is used with multiple SAs in security association
suites.

This value, if non-zero…
IpsecRawId
Textual Convention: IpsecRawId OctetString
Type Constraints:
range: 0..255
.1.3.6.1.2.1.500.1.1.6.1.5
ipsecSaIpcompOutDestIdType
The type of identifier presented by
'ipsecSaIpcompOutDestId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in security association suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.2.1.500.1.1.6.1.6
ipsecSaIpcompOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.2.1.500.1.1.6.1.7
ipsecSaIpcompOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.6.1.8
ipsecSaIpcompOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.2.1.500.1.1.6.1.9
ipsecSaIpcompOutCreator
The creator of this SA.
This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.2.1.500.1.1.6.1.10
ipsecSaIpcompOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.2.1.500.1.1.6.1.11
ipsecSaIpcompOutCompAlg
A unique value representing the compression algorithm
applied to traffic.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.2.1.500.1.1.6.1.12
ipsecSaIpcompOutSeconds
The number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.2.1.500.1.1.6.1.13
ipsecSaIpcompOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA. This is the number of bytes of the decompressed
IP packet, including the original IP header of that
decompressed packet.
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.6.1.14
ipsecSaIpcompOutOutputOctets
The amount of traffic measured in bytes output by the SA.
This includes byte counts from packets compressed by the SA
and also packets not modified by the SA.

This object can be divided into the
'ipsecSaI…
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.6.1.15
ipsecSaIpcompOutPackets
The number of packets handled by the SA. This includes
packets that were both compressed and not compressed.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.2.1.500.1.1.6.1.16