RAPID-IPSEC-SA-MON-MIB-EXT Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
120
.1.3.6.1.4.1.4355.3.1.1.1 · 1 row entry · 26 columns
The (conceptual) table containing information on IPSec
inbound ESP SAs.
          
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaEspInEntry entry .1.3.6.1.4.1.4355.3.1.1.1.1
An entry (conceptual row) containing the information on a
particular IPSec inbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaEspInAddress rsIpsecSaEspInSpi
Column Syntax OID
rsIpsecSaEspInAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.1.1.1
rsIpsecSaEspInSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.1.1.2
rsIpsecSaEspInDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creation negot…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.1.1.3
rsIpsecSaEspInDestIdType
The type of identifier presented by 'rsIpsecSaEspInDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.1.1.4
rsIpsecSaEspInSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.1.1.5
rsIpsecSaEspInSourceIdType
The type of identifier presented by 'rsIpsecSaEspInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.1.1.6
rsIpsecSaEspInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.1.1.7
rsIpsecSaEspInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.1.1.8
rsIpsecSaEspInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.1.1.9
rsIpsecSaEspInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.1.1.10
rsIpsecSaEspInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.1.1.11
rsIpsecSaEspInEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.4355.3.1.1.1.1.12
rsIpsecSaEspInEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'rsIpsecSaEspInEncAlg' object, or 0
if the key length is implicit in the specified algorithm or
there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.4355.3.1.1.1.1.13
rsIpsecSaEspInAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.4355.3.1.1.1.1.14
rsIpsecSaEspInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncate…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.1.1.15
rsIpsecSaEspInLimitKbytes
The maximum traffic in kilobytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.1.1.16
rsIpsecSaEspInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.17
rsIpsecSaEspInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.18
rsIpsecSaEspInUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.19
rsIpsecSaEspInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.20
rsIpsecSaEspInDecryptErrors
The number of packets discarded by the SA due to decryption
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.21
rsIpsecSaEspInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.22
rsIpsecSaEspInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.23
rsIpsecSaEspInPolicyErrors
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.24
rsIpsecSaEspInPadErrors
The number of packets discarded by the SA due to pad value
errors.

Implementations that do not check this must not support this
object.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.25
rsIpsecSaEspInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to c…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.1.1.26
.1.3.6.1.4.1.4355.3.1.1.2 · 1 row entry · 22 columns
The (conceptual) table containing information on IPSec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaAhInEntry entry .1.3.6.1.4.1.4355.3.1.1.2.1
An entry (conceptual row) containing the information on a
particular IPSec inbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaAhInAddress rsIpsecSaAhInSpi
Column Syntax OID
rsIpsecSaAhInAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.2.1.1
rsIpsecSaAhInSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.2.1.2
rsIpsecSaAhInDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negoti…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.2.1.3
rsIpsecSaAhInDestIdType
The type of identifier presented by 'rsIpsecSaAhInDestId', or
0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.2.1.4
rsIpsecSaAhInSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.2.1.5
rsIpsecSaAhInSourceIdType
The type of identifier presented by 'rsIpsecSaAhInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.2.1.6
rsIpsecSaAhInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.2.1.7
rsIpsecSaAhInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.2.1.8
rsIpsecSaAhInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.2.1.9
rsIpsecSaAhInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.2.1.10
rsIpsecSaAhInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.2.1.11
rsIpsecSaAhInAuthAlg
A unique value representing the hash algorithm applied to
traffic carried by this SA if it uses ESP or 0 if there is
no authentication applied by ESP.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.4355.3.1.1.2.1.12
rsIpsecSaAhInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.2.1.13
rsIpsecSaAhInLimitKbytes
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.2.1.14
rsIpsecSaAhInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.15
rsIpsecSaAhInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.16
rsIpsecSaAhInUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.17
rsIpsecSaAhInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.18
rsIpsecSaAhInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.19
rsIpsecSaAhInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.20
rsIpsecSaAhInPolicyErrors
The number of packets discarded by the SA due to policy
errors. This includes packets where the next protocol is
invalid.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.21
rsIpsecSaAhInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decryption, authentication or replay errors. This
may include packets dropped due to a lack of receive
buffers, and may include packets dropped due to c…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.2.1.22
.1.3.6.1.4.1.4355.3.1.1.3 · 1 row entry · 17 columns
The (conceptual) table containing information on IPSec
inbound IPCOMP SAs.
          
There should be one row for every inbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaIpcompInEntry entry .1.3.6.1.4.1.4355.3.1.1.3.1
An entry (conceptual row) containing the information on a
particular IPSec inbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaIpcompInAddress rsIpsecSaIpcompInCpi
Column Syntax OID
rsIpsecSaIpcompInAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
Specifically, …
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.3.1.1
rsIpsecSaIpcompInCpi
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.4355.3.1.1.3.1.2
rsIpsecSaIpcompInDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode, or 0 if this SA is used with
multiple SAs in protection suites.

This value, if non-zero, is taken directly from the …
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.3.1.3
rsIpsecSaIpcompInDestIdType
The type of identifier presented by
'rsIpsecSaIpcompInDestId', or 0 if unknown or if the SA uses
transport mode, or 0 if this SA is used with multiple SAs in
protection suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.3.1.4
rsIpsecSaIpcompInSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.

This value, if non-zero, is taken directly …
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.4355.3.1.1.3.1.5
rsIpsecSaIpcompInSourceIdType
The type of identifier presented by
'rsIpsecSaIpcompInSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.3.1.6
rsIpsecSaIpcompInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.3.1.7
rsIpsecSaIpcompInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.3.1.8
rsIpsecSaIpcompInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.3.1.9
rsIpsecSaIpcompInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.3.1.10
rsIpsecSaIpcompInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.3.1.11
rsIpsecSaIpcompInDecompAlg
A unique value representing the decompression algorithm
applied to traffic.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.4355.3.1.1.3.1.12
rsIpsecSaIpcompInSeconds
The number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.3.1.13
rsIpsecSaIpcompInUserOctets
The amount of user level traffic measured in bytes handled
by the SA.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.3.1.14
rsIpsecSaIpcompInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.3.1.15
rsIpsecSaIpcompInDecompErrors
The number of packets discarded by the SA due to
decompression errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.3.1.16
rsIpsecSaIpcompInOtherReceiveErrors
The number of packets discarded by the SA due to errors
other than decompression errors. This may include packets
dropped due to a lack of receive buffers, and packets
dropped due to congestion at the decompression elem…
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.3.1.17
.1.3.6.1.4.1.4355.3.1.1.4 · 1 row entry · 21 columns
The (conceptual) table containing information on IPSec
Outbound ESP SAs.
          
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaEspOutEntry entry .1.3.6.1.4.1.4355.3.1.1.4.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaEspOutAddress rsIpsecSaEspOutSpi
Column Syntax OID
rsIpsecSaEspOutAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.4.1.1
rsIpsecSaEspOutSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.4.1.2
rsIpsecSaEspOutSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.4.1.3
rsIpsecSaEspOutSourceIdType
The type of identifier presented by
'rsIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.4.1.4
rsIpsecSaEspOutDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.4.1.5
rsIpsecSaEspOutDestIdType
The type of identifier presented by 'rsIpsecSaEspOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.4.1.6
rsIpsecSaEspOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.4.1.7
rsIpsecSaEspOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.4.1.8
rsIpsecSaEspOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.4.1.9
rsIpsecSaEspOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.4.1.10
rsIpsecSaEspOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.4.1.11
rsIpsecSaEspOutEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.4355.3.1.1.4.1.12
rsIpsecSaEspOutEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'rsIpsecSaEspOutEncAlg' object, or
0 if the key length is implicit in the specified algorithm
or there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.4355.3.1.1.4.1.13
rsIpsecSaEspOutAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.4355.3.1.1.4.1.14
rsIpsecSaEspOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.4.1.15
rsIpsecSaEspOutLimitKbytes
The maximum traffic in kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.4.1.16
rsIpsecSaEspOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.4.1.17
rsIpsecSaEspOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.4.1.18
rsIpsecSaEspOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.4.1.19
rsIpsecSaEspOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.4.1.20
rsIpsecSaEspOutSendErrors
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.4.1.21
.1.3.6.1.4.1.4355.3.1.1.5 · 1 row entry · 19 columns
The (conceptual) table containing information on IPSec
Outbound AH SAs.
          
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaAhOutEntry entry .1.3.6.1.4.1.4355.3.1.1.5.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaAhOutAddress rsIpsecSaAhOutSpi
Column Syntax OID
rsIpsecSaAhOutAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.5.1.1
rsIpsecSaAhOutSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.5.1.2
rsIpsecSaAhOutSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.5.1.3
rsIpsecSaAhOutSourceIdType
The type of identifier presented by 'rsIpsecSaAhOutSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.5.1.4
rsIpsecSaAhOutDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.5.1.5
rsIpsecSaAhOutDestIdType
The type of identifier presented by 'rsIpsecSaAhOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.5.1.6
rsIpsecSaAhOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.5.1.7
rsIpsecSaAhOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.5.1.8
rsIpsecSaAhOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.5.1.9
rsIpsecSaAhOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.5.1.10
rsIpsecSaAhOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.5.1.11
rsIpsecSaAhOutAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.4355.3.1.1.5.1.12
rsIpsecSaAhOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.5.1.13
rsIpsecSaAhOutLimitKbytes
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.4355.3.1.1.5.1.14
rsIpsecSaAhOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.5.1.15
rsIpsecSaAhOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.5.1.16
rsIpsecSaAhOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.5.1.17
rsIpsecSaAhOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.5.1.18
rsIpsecSaAhOutSendErrors
The number of packets discarded by the SA due to any error.
This may include errors due to a lack of transmit buffers.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.5.1.19
.1.3.6.1.4.1.4355.3.1.1.6 · 1 row entry · 15 columns
The (conceptual) table containing information on IPSec
Outbound IPCOMP SAs.
          
There should be one row for every outbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
rsIpsecSaIpcompOutEntry entry .1.3.6.1.4.1.4355.3.1.1.6.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound IPCOMP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
rsIpsecSaIpcompOutAddress rsIpsecSaIpcompOutCpi
Column Syntax OID
rsIpsecSaIpcompOutAddress
The destination address of the SA.

If the IPCOMP SA is shared across multiple SAs in protection
suites, this value may be 0.

For implementations that do not support IPv6, this address
shoul…
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.4355.3.1.1.6.1.1
rsIpsecSaIpcompOutCpi
The CPI of the SA. Since the lower values of CPIs are
reserved to be the same as the algorithm, the syntax for
this object is the same as the transform.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.4355.3.1.1.6.1.2
rsIpsecSaIpcompOutSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.

This value, if non-zero, is taken directly …
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.6.1.3
rsIpsecSaIpcompOutSourceIdType
The type of identifier presented by
'rsIpsecSaIpcompOutSourceId', or 0 if unknown or if the SA
uses transport mode encapsulation, or 0 if this SA is used
with multiple SAs in protection suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.6.1.4
rsIpsecSaIpcompOutDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation, or 0 if this SA is
used with multiple SAs in protection suites.

This value, if non-zero, is taken dire…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.4355.3.1.1.6.1.5
rsIpsecSaIpcompOutDestIdType
The type of identifier presented by
'rsIpsecSaIpcompOutDestId', or 0 if unknown or if the SA uses
transport mode encapsulation, or 0 if this SA is used with
multiple SAs in protection suites.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.4355.3.1.1.6.1.6
rsIpsecSaIpcompOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.4355.3.1.1.6.1.7
rsIpsecSaIpcompOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.6.1.8
rsIpsecSaIpcompOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.4355.3.1.1.6.1.9
rsIpsecSaIpcompOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.4355.3.1.1.6.1.10
rsIpsecSaIpcompOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.4355.3.1.1.6.1.11
rsIpsecSaIpcompOutCompAlg
A unique value representing the compression algorithm
applied to traffic.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.4355.3.1.1.6.1.12
rsIpsecSaIpcompOutSeconds
The number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.6.1.13
rsIpsecSaIpcompOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.6.1.14
rsIpsecSaIpcompOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.4355.3.1.1.6.1.15