WATCHGUARD-IPSEC-SA-MON-MIB-EXT Table View

Table-centric layout grouping table, row, and column objects.

Tables
6
Rows
6
Columns
120
.1.3.6.1.4.1.3097.3.1.1.1 · 1 row entry · 26 columns
The (conceptual) table containing information on IPSec
inbound ESP SAs.
          
There should be one row for every inbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaEspInEntry entry .1.3.6.1.4.1.3097.3.1.1.1.1
An entry (conceptual row) containing the information on a
particular IPSec inbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
wgIpsecSaEspInAddress wgIpsecSaEspInSpi
Column Syntax OID
wgIpsecSaEspInAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.1.1.1
wgIpsecSaEspInSpi
The security parameters index of the SA.
Unsigned32
Textual Convention: CISCO-ATM-SWITCH-CUG-MIBUnsigned32 Unsigned32
.1.3.6.1.4.1.3097.3.1.1.1.1.2
wgIpsecSaEspInDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchanged during SA creation negot…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.1.1.3
wgIpsecSaEspInDestIdType
The type of identifier presented by 'wgIpsecSaEspInDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.1.1.4
wgIpsecSaEspInSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.1.1.5
wgIpsecSaEspInSourceIdType
The type of identifier presented by 'wgIpsecSaEspInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.1.1.6
wgIpsecSaEspInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.1.1.7
wgIpsecSaEspInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.1.1.8
wgIpsecSaEspInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.1.1.9
wgIpsecSaEspInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.1.1.10
wgIpsecSaEspInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.1.1.11
wgIpsecSaEspInEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.3097.3.1.1.1.1.12
wgIpsecSaEspInEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspInEncAlg' object, or 0
if the key length is implicit in the specified algorithm or
there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.3097.3.1.1.1.1.13
wgIpsecSaEspInAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.3097.3.1.1.1.1.14
wgIpsecSaEspInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.
The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value will be
truncate…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.1.1.15
wgIpsecSaEspInLimitKbytes
The maximum traffic in kilobytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.1.1.16
wgIpsecSaEspInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.17
wgIpsecSaEspInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.1.1.18
wgIpsecSaEspInUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.19
wgIpsecSaEspInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.1.1.20
wgIpsecSaEspInDecryptErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.21
wgIpsecSaEspInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.22
wgIpsecSaEspInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.23
wgIpsecSaEspInPolicyErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.24
wgIpsecSaEspInPadErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.25
wgIpsecSaEspInOtherReceiveErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.1.1.26
.1.3.6.1.4.1.3097.3.1.1.2 · 1 row entry · 22 columns
The (conceptual) table containing information on IPSec
inbound AH SAs.
There should be one row for every inbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaAhInEntry entry .1.3.6.1.4.1.3097.3.1.1.2.1
An entry (conceptual row) containing the information on a
particular IPSec inbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
wgIpsecSaAhInAddress wgIpsecSaAhInSpi
Column Syntax OID
wgIpsecSaAhInAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.2.1.1
wgIpsecSaAhInSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.2
wgIpsecSaAhInDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negoti…
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.2.1.3
wgIpsecSaAhInDestIdType
The type of identifier presented by 'wgIpsecSaAhInDestId', or
0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.2.1.4
wgIpsecSaAhInSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during SA creation negotiation.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.2.1.5
wgIpsecSaAhInSourceIdType
The type of identifier presented by 'wgIpsecSaAhInSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.2.1.6
wgIpsecSaAhInProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.2.1.7
wgIpsecSaAhInDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.2.1.8
wgIpsecSaAhInSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.2.1.9
wgIpsecSaAhInCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.2.1.10
wgIpsecSaAhInEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.2.1.11
wgIpsecSaAhInAuthAlg
A unique value representing the hash algorithm applied to
traffic carried by this SA if it uses ESP or 0 if there is
no authentication applied by ESP.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.3097.3.1.1.2.1.12
wgIpsecSaAhInLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.13
wgIpsecSaAhInLimitKbytes
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.2.1.14
wgIpsecSaAhInAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.15
wgIpsecSaAhInAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.
This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.2.1.16
wgIpsecSaAhInUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.17
wgIpsecSaAhInPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.2.1.18
wgIpsecSaAhInAuthErrors
The number of packets discarded by the SA due to
authentication errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.19
wgIpsecSaAhInReplayErrors
The number of packets discarded by the SA due to replay
errors.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.20
wgIpsecSaAhInPolicyErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.21
wgIpsecSaAhInOtherReceiveErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.2.1.22
.1.3.6.1.4.1.3097.3.1.1.3 · 1 row entry · 17 columns
The (conceptual) table containing information on IPSec
inbound IPCOMP SAs.
          
There should be one row for every inbound IPCOMP (security)
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaIpcompInEntry entry .1.3.6.1.4.1.3097.3.1.1.3.1
An entry (conceptual row) containing the information on a
particular IPSec inbound IPCOMP SA.
A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
wgIpsecSaIpcompInAddress wgIpsecSaIpcompInCpi
Column Syntax OID
wgIpsecSaIpcompInAddress
Deprecated, currently unused.
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.3.1.1
wgIpsecSaIpcompInCpi
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.3.1.2
wgIpsecSaIpcompInDestId
Deprecated, currently unused.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.3.1.3
wgIpsecSaIpcompInDestIdType
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.3.1.4
wgIpsecSaIpcompInSourceId
Deprecated, currently unused.
OctetString
Constraints:
range: 1-255
.1.3.6.1.4.1.3097.3.1.1.3.1.5
wgIpsecSaIpcompInSourceIdType
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.3.1.6
wgIpsecSaIpcompInProtocol
Deprecated, currently unused.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.3.1.7
wgIpsecSaIpcompInDestPort
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.3.1.8
wgIpsecSaIpcompInSourcePort
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.3.1.9
wgIpsecSaIpcompInCreator
Deprecated, currently unused.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.3.1.10
wgIpsecSaIpcompInEncapsulation
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.3.1.11
wgIpsecSaIpcompInDecompAlg
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.3.1.12
wgIpsecSaIpcompInSeconds
Deprecated, currently unused.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.13
wgIpsecSaIpcompInUserOctets
Deprecated, currently unused.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.14
wgIpsecSaIpcompInPackets
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.15
wgIpsecSaIpcompInDecompErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.16
wgIpsecSaIpcompInOtherReceiveErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.3.1.17
.1.3.6.1.4.1.3097.3.1.1.4 · 1 row entry · 21 columns
The (conceptual) table containing information on IPSec
Outbound ESP SAs.
          
There should be one row for every outbound ESP security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaEspOutEntry entry .1.3.6.1.4.1.3097.3.1.1.4.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound ESP SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
wgIpsecSaEspOutAddress wgIpsecSaEspOutSpi
Column Syntax OID
wgIpsecSaEspOutAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.4.1.1
wgIpsecSaEspOutSpi
The security parameters index of the SA.
Unsigned32
Textual Convention: CISCO-ATM-SWITCH-CUG-MIBUnsigned32 Unsigned32
.1.3.6.1.4.1.3097.3.1.1.4.1.2
wgIpsecSaEspOutSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.4.1.3
wgIpsecSaEspOutSourceIdType
The type of identifier presented by
'wgIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses
transport mode encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.4.1.4
wgIpsecSaEspOutDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.4.1.5
wgIpsecSaEspOutDestIdType
The type of identifier presented by 'wgIpsecSaEspOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.4.1.6
wgIpsecSaEspOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.4.1.7
wgIpsecSaEspOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.4.1.8
wgIpsecSaEspOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.4.1.9
wgIpsecSaEspOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.4.1.10
wgIpsecSaEspOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.4.1.11
wgIpsecSaEspOutEncAlg
A unique value representing the encryption algorithm
applied to traffic or 0 if there is no encryption used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEspTransform Enumeration
Type Values:
0reserved
1espDesIv64
2espDes
3esp3Des
4espRc5
5espIdea
6espCast
7espBlowfish
8esp3Idea
9espDesIv32
10espRc4
11espNull
.1.3.6.1.4.1.3097.3.1.1.4.1.12
wgIpsecSaEspOutEncKeyLength
The length of the encryption key in bits used for the
algorithm specified in the 'wgIpsecSaEspOutEncAlg' object, or
0 if the key length is implicit in the specified algorithm
or there is no encryption specified.
bitsInteger32
Constraints:
range: 0-65531
.1.3.6.1.4.1.3097.3.1.1.4.1.13
wgIpsecSaEspOutAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAuthAlgorithm Enumeration
Type Values:
0reserved
1hmacMd5
2hmacSha
3desMac
4kpdk
.1.3.6.1.4.1.3097.3.1.1.4.1.14
wgIpsecSaEspOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.4.1.15
wgIpsecSaEspOutLimitKbytes
The maximum traffic in kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.4.1.16
wgIpsecSaEspOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.4.1.17
wgIpsecSaEspOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.18
wgIpsecSaEspOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.19
wgIpsecSaEspOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.4.1.20
wgIpsecSaEspOutSendErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.4.1.21
.1.3.6.1.4.1.3097.3.1.1.5 · 1 row entry · 19 columns
The (conceptual) table containing information on IPSec
Outbound AH SAs.
          
There should be one row for every outbound AH security
association that exists in the entity. The maximum number of
rows is implementation dependent.
wgIpsecSaAhOutEntry entry .1.3.6.1.4.1.3097.3.1.1.5.1
An entry (conceptual row) containing the information on a
particular IPSec Outbound AH SA.

A row in this table cannot be created or deleted by SNMP
operations on columns of the table.
Indexes
wgIpsecSaAhOutAddress wgIpsecSaAhOutSpi
Column Syntax OID
wgIpsecSaAhOutAddress
The destination address of the SA.

For implementations that do not support IPv6, this address
should appear as one of the IPv4-mapped IPv6 addresses as
defined in Section 2.5.4 of [IPV6AA].
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.5.1.1
wgIpsecSaAhOutSpi
The security parameters index of the SA.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.2
wgIpsecSaAhOutSourceId
The source identifier of the SA, or 0 if unknown or if the
SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiations.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.5.1.3
wgIpsecSaAhOutSourceIdType
The type of identifier presented by 'wgIpsecSaAhOutSourceId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.5.1.4
wgIpsecSaAhOutDestId
The destination identifier of the SA, or 0 if unknown or if
the SA uses transport mode encapsulation.

This value is taken directly from the optional ID payloads
that are exchange during phase 2 negotiatio…
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.5.1.5
wgIpsecSaAhOutDestIdType
The type of identifier presented by 'wgIpsecSaAhOutDestId',
or 0 if unknown or if the SA uses transport mode
encapsulation.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.5.1.6
wgIpsecSaAhOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.5.1.7
wgIpsecSaAhOutSourcePort
The source port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.5.1.8
wgIpsecSaAhOutDestPort
The destination port number of the protocol that this SA
carries, or 0 if it carries any port number.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.5.1.9
wgIpsecSaAhOutCreator
The creator of this SA.

This MIB makes no assumptions about how the SAs are created.
They may be created statically, or by a key exchange
protocol such as IKE, or by some other method.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.5.1.10
wgIpsecSaAhOutEncapsulation
The type of encapsulation used by this SA.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.5.1.11
wgIpsecSaAhOutAuthAlg
A unique value representing the hash algorithm applied to
traffic or 0 if there is no authentication used.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiAhTransform Enumeration
Type Values:
0reserved
1reserved1
2ahMd5
3ahSha
4ahDes
.1.3.6.1.4.1.3097.3.1.1.5.1.12
wgIpsecSaAhOutLimitSeconds
The maximum lifetime in seconds of the SA, or 0 if there is
no time constraint on its expiration.

The display value is limited to 4294967295 seconds (more
than 136 years); values greater than that value w…
secondsSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.13
wgIpsecSaAhOutLimitKbytes
The maximum traffic in Kbytes that the SA is allowed to
support, or 0 if there is no traffic constraint on its
expiration.

The display value is limited to 4294967295 kilobytes; values
greater than that va…
kilobytesSNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3097.3.1.1.5.1.14
wgIpsecSaAhOutAccSeconds
The number of seconds accumulated against the SA's
expiration by time.

This is also the number of seconds that the SA has existed.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.5.1.15
wgIpsecSaAhOutAccKbytes
The amount of traffic accumulated that counts against the
SA's expiration by traffic limitation, measured in Kbytes.

This value may be 0 if the SA does not expire based on
traffic.
kilobytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.16
wgIpsecSaAhOutUserOctets
The amount of user level traffic measured in bytes handled
by the SA.

This is not necessarily the same as the amount of traffic
applied against the traffic expiration limit.
bytesSNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.17
wgIpsecSaAhOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter64
Textual Convention: SNMPv2-SMICounter64 Unsigned64
Type Constraints:
range: 0..18446744073709551615
.1.3.6.1.4.1.3097.3.1.1.5.1.18
wgIpsecSaAhOutSendErrors
Deprecated, currently unused.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.5.1.19
.1.3.6.1.4.1.3097.3.1.1.6 · 1 row entry · 15 columns
Deprecated, currently unused.
wgIpsecSaIpcompOutEntry entry .1.3.6.1.4.1.3097.3.1.1.6.1
Deprecated, currently unused.
Indexes
wgIpsecSaIpcompOutAddress wgIpsecSaIpcompOutCpi
Column Syntax OID
wgIpsecSaIpcompOutAddress
Deprecated, currently unused.
SNMPv2-SMIIpAddress
Textual Convention: SNMPv2-SMIIpAddress OctetString
Type Constraints:
range: 4
.1.3.6.1.4.1.3097.3.1.1.6.1.1
wgIpsecSaIpcompOutCpi
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.6.1.2
wgIpsecSaIpcompOutSourceId
Deprecated, currently unused.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.6.1.3
wgIpsecSaIpcompOutSourceIdType
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.6.1.4
wgIpsecSaIpcompOutDestId
Deprecated, currently unused.
OctetString
Constraints:
range: 4-255
.1.3.6.1.4.1.3097.3.1.1.6.1.5
wgIpsecSaIpcompOutDestIdType
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIdentType Enumeration
Type Values:
0reserved
1idIpv4Addr
2idFqdn
3idUserFqdn
4idIpv4AddrSubnet
5idIpv6Addr
6idIpv6AddrSubnet
7idIpv4AddrRange
8idIpv6AddrRange
9idDerAsn1Dn
10idDerAsn1Gn
11idKeyId
.1.3.6.1.4.1.3097.3.1.1.6.1.6
wgIpsecSaIpcompOutProtocol
The transport-layer protocol number that this SA carries,
or 0 if it carries any protocol.
Integer32
Constraints:
range: 0-255
.1.3.6.1.4.1.3097.3.1.1.6.1.7
wgIpsecSaIpcompOutSourcePort
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.6.1.8
wgIpsecSaIpcompOutDestPort
Deprecated, currently unused.
Integer32
Constraints:
range: 0-65535
.1.3.6.1.4.1.3097.3.1.1.6.1.9
wgIpsecSaIpcompOutCreator
Deprecated, currently unused.
IpsecSaCreatorIdent
Textual Convention: IpsecSaCreatorIdent Enumeration
Type Values:
0unknown
1static
2ike
3other
.1.3.6.1.4.1.3097.3.1.1.6.1.10
wgIpsecSaIpcompOutEncapsulation
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiEncapsulationMode Enumeration
Type Values:
0reserved
1tunnel
2transport
.1.3.6.1.4.1.3097.3.1.1.6.1.11
wgIpsecSaIpcompOutCompAlg
Deprecated, currently unused.
IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform
Textual Convention: IPSEC-ISAKMP-IKE-DOI-TCIpsecDoiIpcompTransform Enumeration
Type Values:
0reserved
1ipcompOui
2ipcompDeflate
3ipcompLzs
.1.3.6.1.4.1.3097.3.1.1.6.1.12
wgIpsecSaIpcompOutSeconds
Deprecated, currently unused.
secondsSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.13
wgIpsecSaIpcompOutUserOctets
Deprecated, currently unused.
bytesSNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.14
wgIpsecSaIpcompOutPackets
The number of packets handled by the SA.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3097.3.1.1.6.1.15