EZ5 MIB Catalog

CISCO-ENHANCED-IPSEC-FLOW-MIB

2013-06-28

This is a MIB Module for monitoring the structures and status of IPSec-based networks. The MIB has been designed to be adopted as an IETF standard. Hence vendor-specific features of IPSec protocol are excluded from this MIB. Acronyms The following acronyms are used in this document: IPsec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol SA: Security Association (ref: rfc2408). SPI: Security Parameter Index is the pointer or identifier used in accessing SA attributes (ref: rfc2408). MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. Phase 1 Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document. Control Tunnel: Another term for a Phase 1 Tunnel. Phase 2 Tunnel: An instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh). MTU: Maximum Transmission Unit (of an IPsec tunnel). History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. During late 1999, Cisco adopted the MIB and together with Tivoli publised the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms. With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt. With the emergence of multiple IPsec signaling protocols, it became apparent that the signaling aspects of IPsec need to be instrumented separately in their own right. Thus, the IPsec control attributes and metrics were separated out into CISCO-IPSEC-SIGNALING-MIB and CISCO-IKE-FLOW-MIB. This version of the draft is the version of the draft that models that IPsec data protocol, structures and activity alone. Overview of MIB The MIB contains four major groups of objects which are used to manage the IPsec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPsec MIB. The Phase 2 group models objects pertaining to IPsec data tunnels. The History group is to aid applications that do trending analysis. The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid detection of potential security violations. In addition to the three major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPsec TRAPs.

Download CISCO-ENHANCED-IPSEC-FLOW-MIB.txt Open CISCO-ENHANCED-IPSEC-FLOW-MIB.txt in a new tab

SCALARS (52) · TABLES (8) · TRAPS (7)

Scalars (52)

NameOID
ceipSecGlobalActiveTunnels1.3.6.1.4.1.9.9.432.1.1.1.1
ceipSecGlobalPreviousTunnels1.3.6.1.4.1.9.9.432.1.1.1.2
ceipSecGlobalInOctets1.3.6.1.4.1.9.9.432.1.1.1.3
ceipSecGlobalInDecompOctets1.3.6.1.4.1.9.9.432.1.1.1.4
ceipSecGlobalInPkts1.3.6.1.4.1.9.9.432.1.1.1.5
ceipSecGlobalInDrops1.3.6.1.4.1.9.9.432.1.1.1.6
ceipSecGlobalInReplayDrops1.3.6.1.4.1.9.9.432.1.1.1.7
ceipSecGlobalInAuths1.3.6.1.4.1.9.9.432.1.1.1.8
ceipSecGlobalInAuthFails1.3.6.1.4.1.9.9.432.1.1.1.9
ceipSecGlobalInDecrypts1.3.6.1.4.1.9.9.432.1.1.1.10
ceipSecGlobalInDecryptFails1.3.6.1.4.1.9.9.432.1.1.1.11
ceipSecGlobalOutOctets1.3.6.1.4.1.9.9.432.1.1.1.12
ceipSecGlobalOutUncompOctets1.3.6.1.4.1.9.9.432.1.1.1.13
ceipSecGlobalOutPkts1.3.6.1.4.1.9.9.432.1.1.1.14
ceipSecGlobalOutDrops1.3.6.1.4.1.9.9.432.1.1.1.15
ceipSecGlobalOutAuths1.3.6.1.4.1.9.9.432.1.1.1.16
ceipSecGlobalOutAuthFails1.3.6.1.4.1.9.9.432.1.1.1.17
ceipSecGlobalOutEncrypts1.3.6.1.4.1.9.9.432.1.1.1.18
ceipSecGlobalOutEncryptFails1.3.6.1.4.1.9.9.432.1.1.1.19
ceipSecGlobalProtocolUseFails1.3.6.1.4.1.9.9.432.1.1.1.20
ceipSecGlobalNoSaFails1.3.6.1.4.1.9.9.432.1.1.1.21
ceipSecGlobalSysCapFails1.3.6.1.4.1.9.9.432.1.1.1.22
ceipSecGlobalOutCompressedPkts1.3.6.1.4.1.9.9.432.1.1.1.23
ceipSecGlobalOutCompSkippedPkts1.3.6.1.4.1.9.9.432.1.1.1.24
ceipSecGlobalOutCompFailPkts1.3.6.1.4.1.9.9.432.1.1.1.25
ceipSecGlobalOutCompTooSmallPkts1.3.6.1.4.1.9.9.432.1.1.1.26
ceipSecGlobalThroughputUtilizatioinTimeInterval1.3.6.1.4.1.9.9.432.1.1.1.27
ceipSecGlobalThroughputLastUpdatedTime1.3.6.1.4.1.9.9.432.1.1.1.28
ceipSecGlobalLastAveragePacketSize1.3.6.1.4.1.9.9.432.1.1.1.29
ceipSecGlobalLastThroughputInMbps1.3.6.1.4.1.9.9.432.1.1.1.30
ceipSecGlobalLastThroughputInKpps1.3.6.1.4.1.9.9.432.1.1.1.31
ceipSecGlobalLastThroughputUtilization1.3.6.1.4.1.9.9.432.1.1.1.32
ceipSecGlobalPeakThroughputUtilization1.3.6.1.4.1.9.9.432.1.1.1.33
ceipSecGlobalPeakThroughputDateAndTime1.3.6.1.4.1.9.9.432.1.1.1.34
ceipSecGlobalPeakThroughputInMbps1.3.6.1.4.1.9.9.432.1.1.1.35
ceipSecGlobalPeakAvgPacketSize1.3.6.1.4.1.9.9.432.1.1.1.36
ceipSecHistTableSize1.3.6.1.4.1.9.9.432.1.2.1.1.1
ceipSecFailTableSize1.3.6.1.4.1.9.9.432.1.3.1.1.1
ceipSecNotiCntlIpSecAllNotifs1.3.6.1.4.1.9.9.432.1.5.1
ceipSecNotifCntlIpSecTunnelStart1.3.6.1.4.1.9.9.432.1.5.2
ceipSecNotifCntlIpSecTunnelStop1.3.6.1.4.1.9.9.432.1.5.3
ceipSecNotifCntlIpSecSysFailure1.3.6.1.4.1.9.9.432.1.5.4
ceipSecNotifCntlIpSecSetUpFail1.3.6.1.4.1.9.9.432.1.5.5
ceipSecNotifCntlIpSecBadSa1.3.6.1.4.1.9.9.432.1.5.6
ceipSecNotifCntlCertExpiry1.3.6.1.4.1.9.9.432.1.5.7
ceipSecNotifCntlCertRenewal1.3.6.1.4.1.9.9.432.1.5.8
ceipSecCertSubjectName1.3.6.1.4.1.9.9.432.1.6.1
ceipSecCertSerialNumber1.3.6.1.4.1.9.9.432.1.6.2
ceipSecCertIssuerName1.3.6.1.4.1.9.9.432.1.6.3
ceipSecCertExpiryTime1.3.6.1.4.1.9.9.432.1.6.4
ceipSecCertRenewalStatus1.3.6.1.4.1.9.9.432.1.6.5
ceipSecCertExpiryStatus1.3.6.1.4.1.9.9.432.1.6.6

Tables (8)

NameOID
ceipSecTunnelTable1.3.6.1.4.1.9.9.432.1.1.2
ceipSecEndPtTable1.3.6.1.4.1.9.9.432.1.1.3
ceipSecSaTable1.3.6.1.4.1.9.9.432.1.1.4
ceipSecTunnelSaTable1.3.6.1.4.1.9.9.432.1.1.5
ceipSecIfTunnelTable1.3.6.1.4.1.9.9.432.1.1.6
ceipSecTunnelHistTable1.3.6.1.4.1.9.9.432.1.2.2
ceipSecEndPtHistTable1.3.6.1.4.1.9.9.432.1.2.3
ceipSecFailTable1.3.6.1.4.1.9.9.432.1.3.2

Traps (7)

NameOID
ciscoEnhIpsecFlowTunnelStart1.3.6.1.4.1.9.9.432.0.1
ciscoEnhIpsecFlowTunnelStop1.3.6.1.4.1.9.9.432.0.2
ciscoEnhIpsecFlowSysFailure1.3.6.1.4.1.9.9.432.0.3
ciscoEnhIpsecFlowSetupFail1.3.6.1.4.1.9.9.432.0.4
ciscoEnhIpsecFlowBadSa1.3.6.1.4.1.9.9.432.0.5
ciscoEnhIpsecFlowCertExpiry1.3.6.1.4.1.9.9.432.0.6
ciscoEnhIpsecFlowCertRenewal1.3.6.1.4.1.9.9.432.0.7

END OF TOC

Scalar details

ceipSecGlobalActiveTunnels

1.3.6.1.4.1.9.9.432.1.1.1.1

Gauge32 · Tunnels

The total number of currently active IPsec Phase-2 Tunnels.

ceipSecGlobalPreviousTunnels

1.3.6.1.4.1.9.9.432.1.1.1.2

Counter64 (0..18446744073709551615) · Tunnels

The total number of previously active IPsec Phase-2 Tunnels.

ceipSecGlobalInOctets

1.3.6.1.4.1.9.9.432.1.1.1.3

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

ceipSecGlobalInDecompOctets

1.3.6.1.4.1.9.9.432.1.1.1.4

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecGlobalInOctets.

ceipSecGlobalInPkts

1.3.6.1.4.1.9.9.432.1.1.1.5

Counter64 (0..18446744073709551615) · Packets

The total number of packets received by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalInDrops

1.3.6.1.4.1.9.9.432.1.1.1.6

Counter64 (0..18446744073709551615) · Packets

The total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.

ceipSecGlobalInReplayDrops

1.3.6.1.4.1.9.9.432.1.1.1.7

Counter64 (0..18446744073709551615) · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalInAuths

1.3.6.1.4.1.9.9.432.1.1.1.8

Counter64 (0..18446744073709551615) · Events

The total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalInAuthFails

1.3.6.1.4.1.9.9.432.1.1.1.9

Counter64 (0..18446744073709551615) · Failures

The total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalInDecrypts

1.3.6.1.4.1.9.9.432.1.1.1.10

Counter64 (0..18446744073709551615) · Packets

The total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalInDecryptFails

1.3.6.1.4.1.9.9.432.1.1.1.11

Counter64 (0..18446744073709551615) · Failures

The total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutOctets

1.3.6.1.4.1.9.9.432.1.1.1.12

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed.

ceipSecGlobalOutUncompOctets

1.3.6.1.4.1.9.9.432.1.1.1.13

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecGlobalOutOctets.

ceipSecGlobalOutPkts

1.3.6.1.4.1.9.9.432.1.1.1.14

Counter64 (0..18446744073709551615) · Packets

The total number of packets sent by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutDrops

1.3.6.1.4.1.9.9.432.1.1.1.15

Counter64 (0..18446744073709551615) · Packets

The total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutAuths

1.3.6.1.4.1.9.9.432.1.1.1.16

Counter64 (0..18446744073709551615) · Events

The total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutAuthFails

1.3.6.1.4.1.9.9.432.1.1.1.17

Counter64 (0..18446744073709551615) · Failures

The total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutEncrypts

1.3.6.1.4.1.9.9.432.1.1.1.18

Counter64 (0..18446744073709551615) · Packets

The total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalOutEncryptFails

1.3.6.1.4.1.9.9.432.1.1.1.19

Counter64 (0..18446744073709551615) · Failures

The total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalProtocolUseFails

1.3.6.1.4.1.9.9.432.1.1.1.20

Counter64 (0..18446744073709551615) · Failures

The total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

ceipSecGlobalNoSaFails

1.3.6.1.4.1.9.9.432.1.1.1.21

Counter64 (0..18446744073709551615) · Failures

The total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.

ceipSecGlobalSysCapFails

1.3.6.1.4.1.9.9.432.1.1.1.22

Counter64 (0..18446744073709551615) · Failures

The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

ceipSecGlobalOutCompressedPkts

1.3.6.1.4.1.9.9.432.1.1.1.23

Counter64 (0..18446744073709551615) · Packets

The cumulative number of outbound packets across all IPsec flows terminating at this device which were successfully compressed.

ceipSecGlobalOutCompSkippedPkts

1.3.6.1.4.1.9.9.432.1.1.1.24

Counter64 (0..18446744073709551615) · Packets

The total number of outbound packets across all IPsec flows terminating at this devices that were to be compressed but which were skipped due to the compression hysteresis.

ceipSecGlobalOutCompFailPkts

1.3.6.1.4.1.9.9.432.1.1.1.25

Counter64 (0..18446744073709551615) · Packets

The total number of outbound packets across all IPsec flows terminating at this device that failed compression because they grew in size after compression.

ceipSecGlobalOutCompTooSmallPkts

1.3.6.1.4.1.9.9.432.1.1.1.26

Counter64 (0..18446744073709551615) · Packets

The total number of outbound packets across all IPsec flows terminating at this device that were to be compressed but were smaller than the compression threshold size. This number is cumulative since the last system start.

ceipSecGlobalThroughputUtilizatioinTimeInterval

1.3.6.1.4.1.9.9.432.1.1.1.27

Unsigned32 · Seconds

The object is the length of the time interval to measure the throughtput utilization.

ceipSecGlobalThroughputLastUpdatedTime

1.3.6.1.4.1.9.9.432.1.1.1.28

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The timestamp is the end of the last throughput utilization time interval.

ceipSecGlobalLastAveragePacketSize

1.3.6.1.4.1.9.9.432.1.1.1.29

Unsigned32 · bytes

This object is the average packet size in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.

ceipSecGlobalLastThroughputInMbps

1.3.6.1.4.1.9.9.432.1.1.1.30

Unsigned32 · Mbps

The object is the total throughput in Mbps in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.

ceipSecGlobalLastThroughputInKpps

1.3.6.1.4.1.9.9.432.1.1.1.31

Unsigned32 · Kpps

The object is the total throughput in Kpps in the last throughput utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.

ceipSecGlobalLastThroughputUtilization

1.3.6.1.4.1.9.9.432.1.1.1.32

Unsigned32 · Percent

The object is the throughput utilization in percentage in the last performance utilization time interval that ended at ceipSecGlobalThroughputLastUpdatedTime.

ceipSecGlobalPeakThroughputUtilization

1.3.6.1.4.1.9.9.432.1.1.1.33

Unsigned32 · Percent

The object is the peak throughput utilization in percentage since the managed system is active. It was observed in the throughput utilization time interval that ended at ceipSecGlobalPeakThroughputDateAndTime.

ceipSecGlobalPeakThroughputDateAndTime

1.3.6.1.4.1.9.9.432.1.1.1.34

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The date and time when ceipSecGlobalPeakThroughputUtilization is updated.

ceipSecGlobalPeakThroughputInMbps

1.3.6.1.4.1.9.9.432.1.1.1.35

Unsigned32 · Mbps

The object indicates the peak value of throughput in Mbps.

ceipSecGlobalPeakAvgPacketSize

1.3.6.1.4.1.9.9.432.1.1.1.36

Unsigned32 · bytes

This object indicates the average packet size in bytes in the throughput utilization time interval that ended at ceipSecGlobalPeakThroughputDateAndTime.

ceipSecHistTableSize

1.3.6.1.4.1.9.9.432.1.2.1.1.1

Unsigned32

The window size of the IPsec Phase-2 History Tables. The IPsec Phase-2 History Tables are implemented as a sliding window in which only the last 'N' entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-2 History Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, in appropriate SNMP error code should be returned. Setting this value to zero is equivalent to deleting all conceptual rows in the archiving tables ('ceipSecHistTable' and 'ceipSecEndPtHistTable') and disabling the archiving of entries in the tables.

ceipSecFailTableSize

1.3.6.1.4.1.9.9.432.1.3.1.1.1

Unsigned32

The window size of the IPsec Phase-2 Failure Table. The IPsec Phase-2 Failure Tables are implemented as a sliding window in which only the last N entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-2 Failure Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, an appropriate SNMP error vode must be returned. Setting this value to zero is equivalent to deleting all conceptual rows in the archiving table 'ceipSecFailTable' and disabling the archiving of entries in these tables.

ceipSecNotiCntlIpSecAllNotifs

1.3.6.1.4.1.9.9.432.1.5.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object sending any notification defined in this MIB module. That is, a particular notification 'foo' defined in this MIB module is enabled if and only if the expression (ceipSecNotiCntlIpSecAllNotifs && ceipSecNotiCntl<foo>) evaluates to 'true', where ceipSecNotiCntl<foo> is a notification defined in this MIB module.

ceipSecNotifCntlIpSecTunnelStart

1.3.6.1.4.1.9.9.432.1.5.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Tunnel Start TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowTunnelStart' is enabled.

ceipSecNotifCntlIpSecTunnelStop

1.3.6.1.4.1.9.9.432.1.5.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Tunnel Stop TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowTunnelStop' is enabled.

ceipSecNotifCntlIpSecSysFailure

1.3.6.1.4.1.9.9.432.1.5.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 System Failure TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowSysFailure' is enabled.

ceipSecNotifCntlIpSecSetUpFail

1.3.6.1.4.1.9.9.432.1.5.5

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Set Up Failure TRAP. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowSetupFail' is enabled.

ceipSecNotifCntlIpSecBadSa

1.3.6.1.4.1.9.9.432.1.5.6

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 No Security Association trap. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowBadSa' is enabled.

ceipSecNotifCntlCertExpiry

1.3.6.1.4.1.9.9.432.1.5.7

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPSec certificate expiry notification. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowCertExpiry' is enabled, otherwise notification 'ciscoEnhIpsecFlowCertExpiry' is disabled.

ceipSecNotifCntlCertRenewal

1.3.6.1.4.1.9.9.432.1.5.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the IPSec X.509 certificate renewal status notification. If the value of this object is 'true', the issuing of the notification 'ciscoEnhIpsecFlowCertRenewal' is enabled, otherwise notification 'ciscoEnhIpsecFlowCertRenewal' is disabled.

ceipSecCertSubjectName

1.3.6.1.4.1.9.9.432.1.6.1

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.6 Subject RFC 3280 section 4.2.1.7 Subject Alternative Name

This object provides the subject name from the X.509 certificate, or the alternate subject name if it is available. The subject name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. Example Subject Name: C=US, OU=DEV, CN=Test-01 Example Subject Alternative Name: 2001:0022:0022:0020:0000:0000:0000:0102

ceipSecCertSerialNumber

1.3.6.1.4.1.9.9.432.1.6.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.2 Serial number

This object provides the serial number from the X.509 certificate. The serial number is formatted as a character string matching the output of a ssh-certview command-line application. The issuer name and the serial number identify a unique certificate. Example: 1000655533

ceipSecCertIssuerName

1.3.6.1.4.1.9.9.432.1.6.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 5.1.2.3 Issuer Name

This object provides the issuer name from the X.509 certificate. The issuer name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. The issuer name and the serial number identify a unique certificate. Example: C=US, O=Cisco, OU=MITG, CN=Lnx-Insta-RootCA-1

ceipSecCertExpiryTime

1.3.6.1.4.1.9.9.432.1.6.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.5 Validity

This object provides the validity notAfter time from the X.509 certificate. The notAfter time is the time after which the certificate is not valid. The time is formatted as a character string matching the output of a ssh-certview command-line application. Example: 2012 Apr 14th, 19:01:45 GMT

ceipSecCertRenewalStatus

1.3.6.1.4.1.9.9.432.1.6.5

INTEGER1 = renewalNotNeeded2 = renewalRequestNeeded3 = renewalRequested4 = renewalSuccess5 = renewalFailedUpdate6 = renewalFailedExpired · Integer32

This object provides the renewal status of the X.509 certificate on the application sending the notification. renewalNotNeeded(1) = certificate is OK and does not need to be renewed renewalRequestNeeded(2) = certificate renewal request is needed renewalRequested(3) = certificate renewal has been requested and the renewal process is proceeding renewalSuccess(4) = certificate has been renewed and will be OK (renewalNotNeeded) renewalFailedUpdate(5) = certificate renewal failed, but certificate is still usable until the validity expiration time provided in the notification, or otherwise restricted by the application renewalFailedExpired(6) = certificate is no longer valid, the current time is after the certificate's validity notAfter time, which is provided in this notification

ceipSecCertExpiryStatus

1.3.6.1.4.1.9.9.432.1.6.6

INTEGER1 = certOK2 = certGoingExpired3 = certExpired · Integer32

This object provides the expiration status of the X.509 certificate on the application sending the notification. The notification is sent when the value of this object is changed from certOK(1) to certGoingExpired(2). certOK(1) = certificate is OK and is not within the configured time threshold for going to expire certGoingExpired(2) = certificate is within the configured time threshold for going to expire certExpired(3) = certificate has expired, the current time is after the certificate's validity notAfter time

Table details

ceipSecTunnelTable

1.3.6.1.4.1.9.9.432.1.1.2

Index: ceipSecTunIndex

The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.

ceipSecTunIndex

1.3.6.1.4.1.9.9.432.1.1.2.1.1

CIPsecPhase2TunnelIndexThe type of the index of the IPsec Phase-2 Tunnel Table. An index of this type is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32

The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. Since this object must correspond to a valid Phase-2 IPsec tunnel, this object may not assume the value of 0.

ceipSecTunLocalAddressType

1.3.6.1.4.1.9.9.432.1.1.2.1.2

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address of the local endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunLocalAddress

1.3.6.1.4.1.9.9.432.1.1.2.1.3

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunRemoteAddressType

1.3.6.1.4.1.9.9.432.1.1.2.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunRemoteAddress

1.3.6.1.4.1.9.9.432.1.1.2.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunControlProtocol

1.3.6.1.4.1.9.9.432.1.1.2.1.6

CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized. The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols. Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling). cpIkev1: Denotes keying signaling using IKEv1 protocol. cpIkev2: Denotes keying signaling using IKEv2 protocol. cpKink: Denotes keying signaling using KINK. cpPhoturis: Denotes keying signaling using Photuris. · Integer32

Identifies the protocol used to setup and administer this Phase-2 IPsec tunnel. In case this tunnel was spawned by an IPsec signaling protocol, this MIB object contains the value of the object 'cisgIpsSgProtocol' defined in CISCO-IPSEC-SIGNALING-MIB in the table 'cisgIpsSgTunnelTable' in the row corresponding to the control tunnel. A value of 'cpManual' is indicative of a manually installed and administered Phase-2 tunnel.

ceipSecTunControlTunnelIndex

1.3.6.1.4.1.9.9.432.1.1.2.1.7

CIPsecPhase1TunnelIndexOrZeroThis type defines a range of values for index of the IPsec Phase-1 (IKE) Tunnel Table, including the invalid index '0'. An object of this type is used to implement a soft reference to an IKE tunnel. The value of zero is used to denote the fact that the reference points to a non-existent IKE tunnel. (0..2147483647) · Unsigned32

The index of the associated IPsec Phase-1 Tunnel. In case this tunnel was spawned by an IPsec signaling protocol, this MIB object contains the value of the object 'cisgIpsSgTunIndex' defined in CISCO-IPSEC-SIGNALING-MIB in the table 'cisgIpsSgTunnelTable' in the row corresponding to the control tunnel. A value of 0 identifies that this Phase-2 tunnel was setup manually.

ceipSecTunControlTunnelAlive

1.3.6.1.4.1.9.9.432.1.1.2.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

An indicator which specifies whether or not the IPsec Phase-1 Tunnel that spawned this Phase-2 tunnel currently exists.

ceipSecTunEncapMode

1.3.6.1.4.1.9.9.432.1.1.2.1.9

CIPsecEncapMode1 = encapTunnel2 = encapTransportThe encapsulation mode used by an IPsec Phase-2 Tunnel. The type enumerates values to denote the two modes of encapsulation of payload used by IPsec, viz., transport mode (encapTunnel) and tunnel mode (encapTransport).Reference: rfc2408 and rfc2409 · Integer32

The encapsulation mode used by the IPsec Phase-2 Tunnel.

ceipSecTunNATTraversalMode

1.3.6.1.4.1.9.9.432.1.1.2.1.10

CIPsecNATTraversalMode1 = natEncapNone2 = natEncapOther3 = natEncapIPsecOverUdp4 = natEncapIPsecOverTcp5 = natEncapNATTThe encapsulation mode used to implement NAT traversal. Both 'EncapMode' and 'NATTraversalMode' are attributes of a Phase-2 IPsec tunnel. Value of an object of this type is constrained based on the value of its tunnel encapsulation mode: if the tunnel encapsulation mode is 'encapTransport', then the value of this attribute may be one of 'natEncapNone' or 'natEncapNATT'. Description of enum constants of this type: natEncapIPsecOverUdp: IPsec encapsulation over UDP. natEncapIPsecOverTcp: IPsec encapsulation over TCP. natEncapNATT: IPsec encapsulation over NAT-T protocol. · Integer32

The encapsulation used by the IPsec Phase-2 tunnel for NAT traversal. The value of this object is constrained based on the value of the column 'ceipSecTunEncapMode'. If the value of 'ceipSecTunEncapMode' is 'encapTransport', then this object may not assume the values 'natEncapIPsecOverUdp' or 'natEncapIPsecOverTcp'.

ceipSecTunLifeSize

1.3.6.1.4.1.9.9.432.1.1.2.1.11

Unsigned32 (1..4294967295) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

ceipSecTunLifeTime

1.3.6.1.4.1.9.9.432.1.1.2.1.12

Unsigned32 · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds. If the tunnel was setup manually, the value of this MIB element should be 0.

ceipSecTunActiveTime

1.3.6.1.4.1.9.9.432.1.1.2.1.13

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

ceipSecTunSaLifeSizeThreshold

1.3.6.1.4.1.9.9.432.1.1.2.1.14

Unsigned32 · KBytes

The security association LifeSize refresh threshold in kilobytes. If the tunnel was setup manually, the value of this MIB element should be 0.

ceipSecTunSaLifeTimeThreshold

1.3.6.1.4.1.9.9.432.1.1.2.1.15

Unsigned32 · Seconds

The security association LifeTime refresh threshold in seconds. If the tunnel was setup manually, the value of this MIB element should be 0.

ceipSecTunTotalRefreshes

1.3.6.1.4.1.9.9.432.1.1.2.1.16

Counter32 · QM Exchanges

The total number of security association refreshes performed.

ceipSecTunExpiredSaInstances

1.3.6.1.4.1.9.9.432.1.1.2.1.17

Counter32 · SAs

The total number of security associations which have expired. If the tunnel was setup manually, the value of this MIB element should be 0.

ceipSecTunCurrentSaInstances

1.3.6.1.4.1.9.9.432.1.1.2.1.18

Gauge32

The number of security associations which are currently active or expiring.

ceipSecTunInSaDHGrp

1.3.6.1.4.1.9.9.432.1.1.2.1.19

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel. If the tunnel was setup manually, the value of this MIB element would be `none'.

ceipSecTunInSaEncryptAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.20

CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'. Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES. esp3des: Payload encryption using 168-bit 3DES. espRc5: Payload encryption using RC5. espIdea: Payload encryption using International Data Encryption Algorithm. espCast: Payload encryption using CAST. espTwofish: Payload encryption using TwoFish. espBlowfish: Payload encryption using BlowFish. esp3idea: Payload encryption using International Data Encryption Algorithm. espRc4: Payload encryption using RC4. espNull: NULL Payload encryption. espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys. espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32

The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunInSaEncryptKeySize

1.3.6.1.4.1.9.9.432.1.1.2.1.21

CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform. The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits

The key size in bits of the negotiated key to be used with the algorithm denoted by 'ceipSecTunInSaEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.

ceipSecTunInSaAhAuthAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.22

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

ceipSecTunInSaEspAuthAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.23

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound ecapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

ceipSecTunInSaDecompAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.24

CIPsecCompAlgorithm1 = none2 = other3 = compOui4 = compDeflate5 = compLzs6 = compLzjhThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: compOui: IP payload compression using a proprietary algorithm identified using an Organization Unique Identifier (OUI). compDeflate: IP payload compression using deflate algorithm. compLzs: IP payload compression using LZS algorithm. compLzjh: IP payload compression using LZJH algorithm. · Integer32

The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunOutSaDHGrp

1.3.6.1.4.1.9.9.432.1.1.2.1.25

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel. If the tunnel was setup manually, the value of this MIB element would be 'none'.

ceipSecTunOutSaEncryptAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.26

CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'. Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES. esp3des: Payload encryption using 168-bit 3DES. espRc5: Payload encryption using RC5. espIdea: Payload encryption using International Data Encryption Algorithm. espCast: Payload encryption using CAST. espTwofish: Payload encryption using TwoFish. espBlowfish: Payload encryption using BlowFish. esp3idea: Payload encryption using International Data Encryption Algorithm. espRc4: Payload encryption using RC4. espNull: NULL Payload encryption. espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys. espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32

The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunOutSaEncryptKeySize

1.3.6.1.4.1.9.9.432.1.1.2.1.27

CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform. The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits

The key size in bits of the negotiated key to be used with the algorithm denoted by 'ceipSecTunOutSaEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.

ceipSecTunOutSaAhAuthAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.28

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

ceipSecTunOutSaEspAuthAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.29

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

ceipSecTunOutSaCompAlgo

1.3.6.1.4.1.9.9.432.1.1.2.1.30

CIPsecCompAlgorithm1 = none2 = other3 = compOui4 = compDeflate5 = compLzs6 = compLzjhThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: compOui: IP payload compression using a proprietary algorithm identified using an Organization Unique Identifier (OUI). compDeflate: IP payload compression using deflate algorithm. compLzs: IP payload compression using LZS algorithm. compLzjh: IP payload compression using LZJH algorithm. · Integer32

The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunPmtu

1.3.6.1.4.1.9.9.432.1.1.2.1.31

CIPsecPmtuThe type of the Path MTU (Maximum Transmission Unit) of an IPsec Phase-2 Tunnel. (68..1500) · Unsigned32 · Octets

The Path MTU for this IPsec Phase-2 tunnel, which has been either learnt from the network or which has been specified by the administrator. The lower end of the range is 68 which is the minimum MTU for IPv4.

ceipSecTunInOctets

1.3.6.1.4.1.9.9.432.1.1.2.1.32

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

ceipSecTunInDecompOctets

1.3.6.1.4.1.9.9.432.1.1.2.1.33

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunInOctets.

ceipSecTunInPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.34

Counter32 · Packets

The total number of packets received by this IPsec Phase-2 Tunnel.

ceipSecTunInDropPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.35

Counter32 · Packets

The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.

ceipSecTunInReplayDropPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.36

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.

ceipSecTunInAuths

1.3.6.1.4.1.9.9.432.1.1.2.1.37

Counter32 · Events

The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.

ceipSecTunInAuthFails

1.3.6.1.4.1.9.9.432.1.1.2.1.38

Counter32 · Failures

The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .

ceipSecTunInDecrypts

1.3.6.1.4.1.9.9.432.1.1.2.1.39

Counter32 · Packets

The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.

ceipSecTunInDecryptFails

1.3.6.1.4.1.9.9.432.1.1.2.1.40

Counter32 · Failures

The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunOutOctets

1.3.6.1.4.1.9.9.432.1.1.2.1.41

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.

ceipSecTunOutUncompOctets

1.3.6.1.4.1.9.9.432.1.1.2.1.42

Counter64 (0..18446744073709551615)

A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecTunOutOctets.

ceipSecTunOutPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.43

Counter32 · Packets

The total number of packets sent by this IPsec Phase-2 Tunnel.

ceipSecTunOutDropPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.44

Counter32 · Packets

The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.

ceipSecTunOutAuths

1.3.6.1.4.1.9.9.432.1.1.2.1.45

Counter32 · Events

The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.

ceipSecTunOutAuthFails

1.3.6.1.4.1.9.9.432.1.1.2.1.46

Counter32 · Failures

The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunOutEncrypts

1.3.6.1.4.1.9.9.432.1.1.2.1.47

Counter32 · Packets

The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.

ceipSecTunOutEncryptFails

1.3.6.1.4.1.9.9.432.1.1.2.1.48

Counter32 · Failures

The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunOutCompressedPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.49

Counter32 · Packets

The total number of outbound packets which were successfully compressed.

ceipSecTunOutCompSkippedPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.50

Counter32 · Packets

The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis.

ceipSecTunOutCompFailPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.51

Counter32 · Packets

The total number of outbound packets that failed compression because they grew in size after compression.

ceipSecTunOutCompTooSmallPkts

1.3.6.1.4.1.9.9.432.1.1.2.1.52

Counter32 · Packets

The total number of outbound packets that were to be compressed but were smaller than the compression threshold size.

ceipSecIfIndex

1.3.6.1.4.1.9.9.432.1.1.2.1.53

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

This object represents the ifIndex of an interface where this tunnel is created. Multiple IPsec tunnels can be created using the same interface.

ceipSecTunStatus

1.3.6.1.4.1.9.9.432.1.1.2.1.54

CIPsecTunnelStatus1 = initializePhase12 = awaitXauth3 = awaitCommit4 = active5 = destroy6 = rekeyThis type represents the status of an IPsec Phase-1 or Phase-2 Tunnel. Objects of this type may be used to bring down the tunnel they represent by setting value of the object to destroy(5). Objects of this type cannot be used to create a tunnel. Description of enum constants of this type: initializePhase1: The tunnel is initializing Phase 1 operations (applies only to IKE tunnels). awaitXauth: The tunnel has concluded peer authentication successfully and is awaiting the completion of extended Authentication (applies only to IKE tunnels). awaitCommit: The tunnel has concluded initialization and is awaiting a signal (commit bit) from the peer to start operations. active: The tunnel is active. destroy: This value is used in SNMP SET operations to tear down the specified tunnel. rekey: This value is used in SNMP SET operations to force a rekeying. · Integer32

The status of the MIB table row. This object can be used to bring the tunnel down or force a rekeying. When the value is set to destroy(5), the SA bundle is destroyed and this row is deleted from this table. When the value is set to rekey(6), then rekeying is forced on this tunnel. When this MIB value is queried, the value of active(4) is always returned, if the instance exists. This object cannot be used to create a MIB table row.

ceipSecEndPtTable

1.3.6.1.4.1.9.9.432.1.1.3

Index: ceipSecTunIndex · ceipSecEndPtIndex

The IPsec Phase-2 Tunnel Endpoint Table. This table contains an entry for each active endpoint associated with an IPsec Phase-2 Tunnel.

ceipSecEndPtIndex

1.3.6.1.4.1.9.9.432.1.1.3.1.1

Unsigned32 (1..4294967295)

The number of the Endpoint associated with the IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 4,294,967,295.

ceipSecEndPtLocalName

1.3.6.1.4.1.9.9.432.1.1.3.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The DNS name of the local Endpoint.

ceipSecEndPtLocalType

1.3.6.1.4.1.9.9.432.1.1.3.1.3

CIPsecEndPtType1 = other2 = idIpv4Addr3 = idIpv4AddrRange4 = idIpv4AddrSubnet5 = idFqdn6 = idUserFqdn7 = idIpv6Addr8 = idIpv6AddrRange9 = idIpv6AddrSubnet10 = idDerAsn1Dn11 = idDerAsn1Gn12 = idKeyIdThe type of identity use to specify an IPsec End Point. For a description of the enum values, please refer to the description of type 'CIPsecPhase1PeerIdentityType'. · Integer32

The type of identity for the local Endpoint.

ceipSecEndPtLocalAddrType1

1.3.6.1.4.1.9.9.432.1.1.3.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this local Endpoint's first IP address.

ceipSecEndPtLocalAddr1

1.3.6.1.4.1.9.9.432.1.1.3.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtLocalType.

ceipSecEndPtLocalAddrType2

1.3.6.1.4.1.9.9.432.1.1.3.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this local Endpoint's second IP address.

ceipSecEndPtLocalAddr2

1.3.6.1.4.1.9.9.432.1.1.3.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtLocalType.

ceipSecEndPtLocalProtocol

1.3.6.1.4.1.9.9.432.1.1.3.1.8

CiscoIpProtocolIP protocol number range.Reference: Internet Protocol. J. Postel. RFC791 (0..255) · Integer32

The protocol number of the local Endpoint's traffic.

ceipSecEndPtLocalPort

1.3.6.1.4.1.9.9.432.1.1.3.1.9

CiscoPortThe TCP or UDP port number range.Reference: Transmission Control Protocol. J. Postel. RFC793, User Datagram Protocol. J. Postel. RFC768 (0..65535) · Integer32

The port number of the local Endpoint's traffic.

ceipSecEndPtRemoteName

1.3.6.1.4.1.9.9.432.1.1.3.1.10

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The DNS name of the remote Endpoint.

ceipSecEndPtRemoteType

1.3.6.1.4.1.9.9.432.1.1.3.1.11

CIPsecEndPtType1 = other2 = idIpv4Addr3 = idIpv4AddrRange4 = idIpv4AddrSubnet5 = idFqdn6 = idUserFqdn7 = idIpv6Addr8 = idIpv6AddrRange9 = idIpv6AddrSubnet10 = idDerAsn1Dn11 = idDerAsn1Gn12 = idKeyIdThe type of identity use to specify an IPsec End Point. For a description of the enum values, please refer to the description of type 'CIPsecPhase1PeerIdentityType'. · Integer32

The type of identity for the remote Endpoint.

ceipSecEndPtRemoteAddrType1

1.3.6.1.4.1.9.9.432.1.1.3.1.12

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this remote Endpoint's first IP address.

ceipSecEndPtRemoteAddr1

1.3.6.1.4.1.9.9.432.1.1.3.1.13

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtRemoteType.

ceipSecEndPtRemoteAddrType2

1.3.6.1.4.1.9.9.432.1.1.3.1.14

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this remote Endpoint's second IP address.

ceipSecEndPtRemoteAddr2

1.3.6.1.4.1.9.9.432.1.1.3.1.15

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from ceipSecEndPtRemoteType.

ceipSecEndPtRemoteProtocol

1.3.6.1.4.1.9.9.432.1.1.3.1.16

CiscoIpProtocolIP protocol number range.Reference: Internet Protocol. J. Postel. RFC791 (0..255) · Integer32

The protocol number of the remote Endpoint's traffic.

ceipSecEndPtRemotePort

1.3.6.1.4.1.9.9.432.1.1.3.1.17

CiscoPortThe TCP or UDP port number range.Reference: Transmission Control Protocol. J. Postel. RFC793, User Datagram Protocol. J. Postel. RFC768 (0..65535) · Integer32

The port number of the remote Endpoint's traffic.

ceipSecSaTable

1.3.6.1.4.1.9.9.432.1.1.4

Index: ceipSecTunIndex · ceipSecSaProtocol · ceipSecSaIndex

The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ceipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations.

ceipSecSaProtocol

1.3.6.1.4.1.9.9.432.1.1.4.1.1

CIPsecProtocol1 = ipsecProtUnknown2 = ipsecProtAh3 = ipsecProtEsp4 = ipsecProtIPcompA protocol used for encapsulating the Phase-2 tunneled traffic. The enumerations correspond to Authentication Header, Encapsulating Security Payload and IP compression protocols. The enum constants used in this denote the standard IPsec protocols, viz., Authentication Header (AH), ESP and IP compression. Description of enum constants of this type: ipsecProtAh: Denotes IPsec Authentication Header (AH) protocol. ipsecProtEsp: Denotes IPsec Encapsulating Security Payload (ESP) protocol. ipsecProtIPcomp: Denotes IPsec Packet Compression protocol.Reference: rfc2402, rfc2406 and rfc2409 · Integer32

This column represents the security protocol (AH, ESP or IPComp) for which this security association was setup.

ceipSecSaIndex

1.3.6.1.4.1.9.9.432.1.1.4.1.2

Unsigned32 (1..4294967295)

The object, in the context of the IPsec tunnel 'ceipSecTunIndex', is an index of security associations comprising the Phase-2 IPsec tunnel represented by the tunnel index 'ceipSecTunIndex'. The value of this index is a number which begins at 1 and is incremented with each SPI associated with the corresponding IPsec Phase-2 Tunnel.

ceipSecSaDirection

1.3.6.1.4.1.9.9.432.1.1.4.1.3

CIPsecPhase2SaDirection1 = saDirectionUnknown2 = saDirectionIn3 = saDirectionOutPhase-2 IPsec security associations are simplex. This textual convention is used as the type of attribute(s) of a Phase-2 security association. Description of enum constants of this type: saDirectionIn: The IPsec security association is used to process incoming traffic. saDirectionOut: The IPsec security association is used to process outgoing traffic.Reference: rfc2409 · Integer32

Phase-2 IPsec security associations are simplex. Hence a particular security association is used either for securing outgoing traffic or decoding incoming traffic. This column identifies the direction of the security association represented by this entry.

ceipSecSaValue

1.3.6.1.4.1.9.9.432.1.1.4.1.4

CIPsecSpiThe type of the SPI (Security Parameter Index) associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32 · hint x

This is the value of the Security Protection Index (SPI) assigned by the system to the security association represented by this entry.

ceipSecSaStatus

1.3.6.1.4.1.9.9.432.1.1.4.1.5

INTEGER1 = unknown2 = active3 = expiring · Integer32

This column represents the status of the security association represented by this conceptual row. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.

ceipSecTunnelSaTable

1.3.6.1.4.1.9.9.432.1.1.5

Index: ceipSecTunIndex · ceipSecTunSaProtocol · ceipSecTunSaIndex · ceipSecTunSaDirection

The IPsec Phase-2 Tunnel Security Association Table. This table identifies the SAs that are currently associated with an active Phase-2 tunnel. This table contains an entry for each active or expiring security association (SA) which is associated with an ceipSecTunnelEntry in 'active' state and provides statistic information of this SA. There might be multiple SAs associated with one ceipSecTunnelEntry.

ceipSecTunSaProtocol

1.3.6.1.4.1.9.9.432.1.1.5.1.1

CIPsecProtocol1 = ipsecProtUnknown2 = ipsecProtAh3 = ipsecProtEsp4 = ipsecProtIPcompA protocol used for encapsulating the Phase-2 tunneled traffic. The enumerations correspond to Authentication Header, Encapsulating Security Payload and IP compression protocols. The enum constants used in this denote the standard IPsec protocols, viz., Authentication Header (AH), ESP and IP compression. Description of enum constants of this type: ipsecProtAh: Denotes IPsec Authentication Header (AH) protocol. ipsecProtEsp: Denotes IPsec Encapsulating Security Payload (ESP) protocol. ipsecProtIPcomp: Denotes IPsec Packet Compression protocol.Reference: rfc2402, rfc2406 and rfc2409 · Integer32

This column represents the security protocol (AH, ESP or IPComp) for which this security association was setup.

ceipSecTunSaIndex

1.3.6.1.4.1.9.9.432.1.1.5.1.2

Unsigned32 (1..4294967295)

The object, in the context of the IPsec tunnel 'ceipSecTunIndex', is an index of security associations comprising the Phase-2 IPsec tunnel represented by the tunnel index 'ceipSecTunIndex'. The value of this index is a number which begins at 1 and is incremented with each SPI associated with the corresponding IPsec Phase-2 Tunnel.

ceipSecTunSaDirection

1.3.6.1.4.1.9.9.432.1.1.5.1.3

CIPsecPhase2SaDirection1 = saDirectionUnknown2 = saDirectionIn3 = saDirectionOutPhase-2 IPsec security associations are simplex. This textual convention is used as the type of attribute(s) of a Phase-2 security association. Description of enum constants of this type: saDirectionIn: The IPsec security association is used to process incoming traffic. saDirectionOut: The IPsec security association is used to process outgoing traffic.Reference: rfc2409 · Integer32

Phase-2 IPsec security associations are simplex. Hence a particular security association is used either for securing outgoing traffic or decoding incoming traffic. This column identifies the direction of the security association represented by this entry.

ceipSecTunSaValue

1.3.6.1.4.1.9.9.432.1.1.5.1.4

CIPsecSpiThe type of the SPI (Security Parameter Index) associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32 · hint x

This is the value of the Security Protection Index (SPI) assigned by the system to the security association represented by this entry.

ceipSecTunSaIfIndex

1.3.6.1.4.1.9.9.432.1.1.5.1.5

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

This object represents the ifIndex of an interface where a tunnel with ceipSecTunIndex is created. Multiple IPsec tunnels can be created using the same interface.

ceipSecTunSaInOctets

1.3.6.1.4.1.9.9.432.1.1.5.1.6

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets received by using this SA. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

ceipSecTunSaInDecompOctets

1.3.6.1.4.1.9.9.432.1.1.5.1.7

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by using this SA. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunSaTunInOctets.

ceipSecTunSaInPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.8

Counter64 (0..18446744073709551615)

The total number of packets received by using this SA.

ceipSecTunSaInDropPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.9

Counter64 (0..18446744073709551615)

The total number of packets dropped during receive process by using this SA. This count does NOT include packets dropped due to Anti-Replay processing.

ceipSecTunSaInReplayDropPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.10

Counter64 (0..18446744073709551615)

The total number of packets dropped during receive processing due to Anti-Replay processing by using this SA.

ceipSecTunSaInAuths

1.3.6.1.4.1.9.9.432.1.1.5.1.11

Counter64 (0..18446744073709551615)

The total number of inbound authentication's performed by using this SA.

ceipSecTunSaInAuthFails

1.3.6.1.4.1.9.9.432.1.1.5.1.12

Counter64 (0..18446744073709551615)

The total number of inbound authentication's which ended in failure by using this SA.

ceipSecTunSaInDecrypts

1.3.6.1.4.1.9.9.432.1.1.5.1.13

Counter64 (0..18446744073709551615)

The total number of inbound decryption's performed by this SA.

ceipSecTunSaInDecryptFails

1.3.6.1.4.1.9.9.432.1.1.5.1.14

Counter64 (0..18446744073709551615)

The total number of inbound decryption's which ended in failure by using this SA.

ceipSecTunSaOutOctets

1.3.6.1.4.1.9.9.432.1.1.5.1.15

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by using this SA. This value is accumulated AFTER determining whether or not the packet should be compressed.

ceipSecTunSaOutUncompOctets

1.3.6.1.4.1.9.9.432.1.1.5.1.16

Counter64 (0..18446744073709551615)

A high capacity count of the total number of uncompressed octets sent by using this SA. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of ceipSecTunSaTunOutOctets.

ceipSecTunSaOutPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.17

Counter64 (0..18446744073709551615)

The total number of packets sent by using this SA.

ceipSecTunSaOutDropPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.18

Counter64 (0..18446744073709551615)

The total number of packets dropped during send processing by using this SA.

ceipSecTunSaOutAuths

1.3.6.1.4.1.9.9.432.1.1.5.1.19

Counter64 (0..18446744073709551615)

The total number of outbound authentication's performed by using this SA.

ceipSecTunSaOutAuthFails

1.3.6.1.4.1.9.9.432.1.1.5.1.20

Counter64 (0..18446744073709551615)

The total number of outbound authentication's which ended in failure by using this SA.

ceipSecTunSaOutEncrypts

1.3.6.1.4.1.9.9.432.1.1.5.1.21

Counter64 (0..18446744073709551615)

The total number of outbound encryption's performed by using this SA.

ceipSecTunSaOutEncryptFails

1.3.6.1.4.1.9.9.432.1.1.5.1.22

Counter64 (0..18446744073709551615)

The total number of outbound encryption's which ended in failure by using this SA.

ceipSecTunSaOutCompressedPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.23

Counter64 (0..18446744073709551615)

The total number of outbound packets which were successfully compressed by using this SA.

ceipSecTunSaOutCompSkippedPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.24

Counter64 (0..18446744073709551615)

The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis when using this SA.

ceipSecTunSaOutCompFailPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.25

Counter64 (0..18446744073709551615)

The total number of outbound packets that failed compression because they grew in size after compression when using this SA.

ceipSecTunSaOutCompTooSmallPkts

1.3.6.1.4.1.9.9.432.1.1.5.1.26

Counter64 (0..18446744073709551615)

The total number of outbound packets that were to be compressed but were smaller than the compression threshold size when using this SA.

ceipSecTunSaStatus

1.3.6.1.4.1.9.9.432.1.1.5.1.27

INTEGER1 = unknown2 = active3 = expiring · Integer32

This column represents the status of the security association represented by this conceptual row. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.

ceipSecIfTunnelTable

1.3.6.1.4.1.9.9.432.1.1.6

Index: ifIndex · ceipSecTunIndex

The IPsec Phase-2 Tunnels to Interface association table. This table contains an entry for each active IPsec Phase-2 Tunnel created under an interface. Multiple IPsec Phase-2 Tunnels can be created using the same interface.

from IF-MIB

ifIndex

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

A unique value, greater than zero, for each interface. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re- initialization.

ceipSecIfTunnelStatus

1.3.6.1.4.1.9.9.432.1.1.6.1.1

CIPsecTunnelStatus1 = initializePhase12 = awaitXauth3 = awaitCommit4 = active5 = destroy6 = rekeyThis type represents the status of an IPsec Phase-1 or Phase-2 Tunnel. Objects of this type may be used to bring down the tunnel they represent by setting value of the object to destroy(5). Objects of this type cannot be used to create a tunnel. Description of enum constants of this type: initializePhase1: The tunnel is initializing Phase 1 operations (applies only to IKE tunnels). awaitXauth: The tunnel has concluded peer authentication successfully and is awaiting the completion of extended Authentication (applies only to IKE tunnels). awaitCommit: The tunnel has concluded initialization and is awaiting a signal (commit bit) from the peer to start operations. active: The tunnel is active. destroy: This value is used in SNMP SET operations to tear down the specified tunnel. rekey: This value is used in SNMP SET operations to force a rekeying. · Integer32

This object corresponds to the status of a IPsec Phase-2 Tunnel in ceipSecTunnelTable indexed by ceipSecTunIndex. The valid status this object can have are 'active' and 'awaitCommit'.

ceipSecTunnelHistTable

1.3.6.1.4.1.9.9.432.1.2.2

Index: ceipSecTunHistIndex

The IPsec Phase-2 Tunnel History Table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'ceipSecHistTableSize'. If the value of 'ceipSecHistTableSize' is 0, archiving of entries in this table is disabled.

ceipSecTunHistIndex

1.3.6.1.4.1.9.9.432.1.2.2.1.1

Unsigned32 (1..4294967295)

The index of the IPsec Phase-2 Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 4,294,967,295.

ceipSecTunHistTermReason

1.3.6.1.4.1.9.9.432.1.2.2.1.2

INTEGER1 = other2 = normal3 = operRequest4 = peerDelRequest5 = peerLost6 = applicationInitiated7 = xauthFailure8 = seqNumRollOver9 = checkPointReq · Integer32

The reason the IPsec Phase-2 Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = applicationInitiated (eg: L2TP requesting the termination) 7 = failure of extended authentication 8 = local failure occurred 9 = operator initiated check point request

ceipSecTunHistActiveIndex

1.3.6.1.4.1.9.9.432.1.2.2.1.3

CIPsecPhase2TunnelIndexThe type of the index of the IPsec Phase-2 Tunnel Table. An index of this type is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32

The index of the previously active IPsec Phase-2 Tunnel. This object must correspond to an expired IPsec tunnel; hence this object may not assume the value of 0.

ceipSecTunHistLocalAddressType

1.3.6.1.4.1.9.9.432.1.2.2.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address of the local endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunHistLocalAddress

1.3.6.1.4.1.9.9.432.1.2.2.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunHistRemoteAddressType

1.3.6.1.4.1.9.9.432.1.2.2.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunHistRemoteAddress

1.3.6.1.4.1.9.9.432.1.2.2.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

ceipSecTunHistControlProtocol

1.3.6.1.4.1.9.9.432.1.2.2.1.8

CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized. The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols. Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling). cpIkev1: Denotes keying signaling using IKEv1 protocol. cpIkev2: Denotes keying signaling using IKEv2 protocol. cpKink: Denotes keying signaling using KINK. cpPhoturis: Denotes keying signaling using Photuris. · Integer32

Identifies the protocol that was used to setup and administer Phase-2 IPsec tunnel.

ceipSecTunHistControlTunnelIndex

1.3.6.1.4.1.9.9.432.1.2.2.1.9

CIPsecPhase1TunnelIndexOrZeroThis type defines a range of values for index of the IPsec Phase-1 (IKE) Tunnel Table, including the invalid index '0'. An object of this type is used to implement a soft reference to an IKE tunnel. The value of zero is used to denote the fact that the reference points to a non-existent IKE tunnel. (0..2147483647) · Unsigned32

The index of the IPsec Phase-1 Tunnel that spawned this Phase-2 tunnel (in case of IKE, this value would refer to 'csikeTunIndex' in the 'csikeTunnelTable'). If the IPsec tunnel corresponding to this entry was setup manually, the value of this object should be zero.

ceipSecTunHistEncapMode

1.3.6.1.4.1.9.9.432.1.2.2.1.10

CIPsecEncapMode1 = encapTunnel2 = encapTransportThe encapsulation mode used by an IPsec Phase-2 Tunnel. The type enumerates values to denote the two modes of encapsulation of payload used by IPsec, viz., transport mode (encapTunnel) and tunnel mode (encapTransport).Reference: rfc2408 and rfc2409 · Integer32

The encapsulation mode used by the IPsec Phase-2 Tunnel.

ceipSecTunHistNATTraversalMode

1.3.6.1.4.1.9.9.432.1.2.2.1.11

CIPsecNATTraversalMode1 = natEncapNone2 = natEncapOther3 = natEncapIPsecOverUdp4 = natEncapIPsecOverTcp5 = natEncapNATTThe encapsulation mode used to implement NAT traversal. Both 'EncapMode' and 'NATTraversalMode' are attributes of a Phase-2 IPsec tunnel. Value of an object of this type is constrained based on the value of its tunnel encapsulation mode: if the tunnel encapsulation mode is 'encapTransport', then the value of this attribute may be one of 'natEncapNone' or 'natEncapNATT'. Description of enum constants of this type: natEncapIPsecOverUdp: IPsec encapsulation over UDP. natEncapIPsecOverTcp: IPsec encapsulation over TCP. natEncapNATT: IPsec encapsulation over NAT-T protocol. · Integer32

The encapsulation used by the IPsec Phase-2 tunnel corresponding to this conceptual row for NAT traversal.

ceipSecTunHistLifeSize

1.3.6.1.4.1.9.9.432.1.2.2.1.12

Unsigned32 (1..4294967295) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

ceipSecTunHistLifeTime

1.3.6.1.4.1.9.9.432.1.2.2.1.13

Unsigned32 (1..4294967295) · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.

ceipSecTunHistStartTime

1.3.6.1.4.1.9.9.432.1.2.2.1.14

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds when the IPsec Phase-2 Tunnel was started.

ceipSecTunHistActiveTime

1.3.6.1.4.1.9.9.432.1.2.2.1.15

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

ceipSecTunHistTotalRefreshes

1.3.6.1.4.1.9.9.432.1.2.2.1.16

Counter32 · QM Exchanges

The total number of security association refreshes performed.

ceipSecTunHistTotalSas

1.3.6.1.4.1.9.9.432.1.2.2.1.17

Counter32 · SAs

The total number of security associations used during the life of the IPsec Phase-2 Tunnel.

ceipSecTunHistInSaDHGrp

1.3.6.1.4.1.9.9.432.1.2.2.1.18

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistInSaEncryptAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.19

CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'. Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES. esp3des: Payload encryption using 168-bit 3DES. espRc5: Payload encryption using RC5. espIdea: Payload encryption using International Data Encryption Algorithm. espCast: Payload encryption using CAST. espTwofish: Payload encryption using TwoFish. espBlowfish: Payload encryption using BlowFish. esp3idea: Payload encryption using International Data Encryption Algorithm. espRc4: Payload encryption using RC4. espNull: NULL Payload encryption. espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys. espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32

The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistInSaEncryptKeySize

1.3.6.1.4.1.9.9.432.1.2.2.1.20

CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform. The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits

The size in bits of the key which was negotiated to be used with the encryption transform used with this tunnel denoted by ceipSecTunHistInSaEncryptAlgo. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.

ceipSecTunHistInSaAhAuthAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.21

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistInSaEspAuthAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.22

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistInSaDecompAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.23

CIPsecCompAlgorithm1 = none2 = other3 = compOui4 = compDeflate5 = compLzs6 = compLzjhThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: compOui: IP payload compression using a proprietary algorithm identified using an Organization Unique Identifier (OUI). compDeflate: IP payload compression using deflate algorithm. compLzs: IP payload compression using LZS algorithm. compLzjh: IP payload compression using LZJH algorithm. · Integer32

The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistOutSaDHGrp

1.3.6.1.4.1.9.9.432.1.2.2.1.24

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistOutSaEncryptAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.25

CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'. Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES. esp3des: Payload encryption using 168-bit 3DES. espRc5: Payload encryption using RC5. espIdea: Payload encryption using International Data Encryption Algorithm. espCast: Payload encryption using CAST. espTwofish: Payload encryption using TwoFish. espBlowfish: Payload encryption using BlowFish. esp3idea: Payload encryption using International Data Encryption Algorithm. espRc4: Payload encryption using RC4. espNull: NULL Payload encryption. espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys. espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32

The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistOutSaEncryptKeySz

1.3.6.1.4.1.9.9.432.1.2.2.1.26

CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform. The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits

The size in bits of the key which was negotiated to be used with the encryption transform used with this tunnel denoted by ceipSecTunHistOutSaEncryptAlgo. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.

ceipSecTunHistOutSaAhAuthAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.27

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistOutSaEspAuthAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.28

CIPsecAuthAlgorithm1 = none2 = other3 = hmacMd54 = hmacSha5 = desMac6 = hmacSha2567 = hmacSha3848 = hmacSha5129 = ripemdThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: hmacMd5: Hash validation using HMAC MD5. hmacSha: Hash validation using HMAC SHA-1. desMac: Hash validation using DES as MAC. hmacSha256: Hash validation using 256-bit SHA-1. hmacSha384: Hash validation using 384-bit SHA-1. hmacSha512: Hash validation using 512-bit SHA-1. ripemd: Hash validation using RIPEMD cryptographic hash function. · Integer32

The authentication algorithm used by the inbound ecapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistOutSaCompAlgo

1.3.6.1.4.1.9.9.432.1.2.2.1.29

CIPsecCompAlgorithm1 = none2 = other3 = compOui4 = compDeflate5 = compLzs6 = compLzjhThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. Description of enum constants of this type: compOui: IP payload compression using a proprietary algorithm identified using an Organization Unique Identifier (OUI). compDeflate: IP payload compression using deflate algorithm. compLzs: IP payload compression using LZS algorithm. compLzjh: IP payload compression using LZJH algorithm. · Integer32

The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

ceipSecTunHistPmtu

1.3.6.1.4.1.9.9.432.1.2.2.1.30

CIPsecPmtuThe type of the Path MTU (Maximum Transmission Unit) of an IPsec Phase-2 Tunnel. (68..1500) · Unsigned32 · Octets

The Path MTU that was determined for this IPsec Phase-2 tunnel.

ceipSecTunHistInOctets

1.3.6.1.4.1.9.9.432.1.2.2.1.31

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

ceipSecTunHistInDecompOctets

1.3.6.1.4.1.9.9.432.1.2.2.1.32

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of ceipSecTunInOctets.

ceipSecTunHistInPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.33

Counter32 · Packets

The total number of packets received by this IPsec Phase-2 Tunnel.

ceipSecTunHistInDropPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.34

Counter32 · Packets

The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.

ceipSecTunHistInReplayDropPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.35

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.

ceipSecTunHistInAuths

1.3.6.1.4.1.9.9.432.1.2.2.1.36

Counter32 · Events

The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.

ceipSecTunHistInAuthFails

1.3.6.1.4.1.9.9.432.1.2.2.1.37

Counter32 · Failures

The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .

ceipSecTunHistInDecrypts

1.3.6.1.4.1.9.9.432.1.2.2.1.38

Counter32 · Packets

The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.

ceipSecTunHistInDecryptFails

1.3.6.1.4.1.9.9.432.1.2.2.1.39

Counter32 · Failures

The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutOctets

1.3.6.1.4.1.9.9.432.1.2.2.1.40

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.

ceipSecTunHistOutUncompOctets

1.3.6.1.4.1.9.9.432.1.2.2.1.41

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of 'ceipSecTunOutOctets'.

ceipSecTunHistOutPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.42

Counter32 · Packets

The total number of packets sent by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutDropPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.43

Counter32 · Packets

The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutAuths

1.3.6.1.4.1.9.9.432.1.2.2.1.44

Counter32 · Events

The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutAuthFails

1.3.6.1.4.1.9.9.432.1.2.2.1.45

Counter32 · Failures

The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutEncrypts

1.3.6.1.4.1.9.9.432.1.2.2.1.46

Counter32 · Packets

The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutEncryptFails

1.3.6.1.4.1.9.9.432.1.2.2.1.47

Counter32 · Failures

The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.

ceipSecTunHistOutCompressedPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.48

Counter32 · Packets

The total number of outbound packets which were successfully compressed.

ceipSecTunHistOutCompSkippedPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.49

Counter32 · Packets

The total number of outbound packets that were to be compressed but which were skipped due to the compression hysteresis.

ceipSecTunHistOutCompFailPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.50

Counter32 · Packets

The total number of outbound packets that failed compression because they grew in size after compression.

ceipSecTunHistOutCompSmallPkts

1.3.6.1.4.1.9.9.432.1.2.2.1.51

Counter32 · Packets

The total number of outbound packets that were to be compressed but were smaller than the compression threshold size.

ceipSecEndPtHistTable

1.3.6.1.4.1.9.9.432.1.2.3

Index: ceipSecEndPtHistIndex

The IPsec Phase-2 Tunnel Endpoint History Table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'ceipSecHistTableSize'. If the value of 'ceipSecHistTableSize' is 0, archiving of entries in this table is disabled.

ceipSecEndPtHistIndex

1.3.6.1.4.1.9.9.432.1.2.3.1.1

Unsigned32 (1..4294967295)

The number of the previously active Endpoint associated with a IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 4,294,967,295.

ceipSecEndPtHistTunIndex

1.3.6.1.4.1.9.9.432.1.2.3.1.2

Unsigned32 (1..4294967295)

The index of the previously active IPsec Phase-2 Tunnel Table.

ceipSecEndPtHistActiveIndex

1.3.6.1.4.1.9.9.432.1.2.3.1.3

Unsigned32 (1..4294967295)

The index of the previously active Endpoint.

ceipSecEndPtHistLocalName

1.3.6.1.4.1.9.9.432.1.2.3.1.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The DNS name of the local Endpoint.

ceipSecEndPtHistLocalType

1.3.6.1.4.1.9.9.432.1.2.3.1.5

CIPsecEndPtType1 = other2 = idIpv4Addr3 = idIpv4AddrRange4 = idIpv4AddrSubnet5 = idFqdn6 = idUserFqdn7 = idIpv6Addr8 = idIpv6AddrRange9 = idIpv6AddrSubnet10 = idDerAsn1Dn11 = idDerAsn1Gn12 = idKeyIdThe type of identity use to specify an IPsec End Point. For a description of the enum values, please refer to the description of type 'CIPsecPhase1PeerIdentityType'. · Integer32

The type of identity for the local Endpoint.

ceipSecEndPtHistLocalAddrType1

1.3.6.1.4.1.9.9.432.1.2.3.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this local Endpoint's first IP address.

ceipSecEndPtHistLocalAddr1

1.3.6.1.4.1.9.9.432.1.2.3.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtLocalType.

ceipSecEndPtHistLocalAddrType2

1.3.6.1.4.1.9.9.432.1.2.3.1.8

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this local Endpoint's second IP address.

ceipSecEndPtHistLocalAddr2

1.3.6.1.4.1.9.9.432.1.2.3.1.9

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtLocalType.

ceipSecEndPtHistLocalProtocol

1.3.6.1.4.1.9.9.432.1.2.3.1.10

CiscoIpProtocolIP protocol number range.Reference: Internet Protocol. J. Postel. RFC791 (0..255) · Integer32

The protocol number of the local Endpoint's traffic.

ceipSecEndPtHistLocalPort

1.3.6.1.4.1.9.9.432.1.2.3.1.11

CiscoPortThe TCP or UDP port number range.Reference: Transmission Control Protocol. J. Postel. RFC793, User Datagram Protocol. J. Postel. RFC768 (0..65535) · Integer32

The port number of the local Endpoint's traffic.

ceipSecEndPtHistRemoteName

1.3.6.1.4.1.9.9.432.1.2.3.1.12

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The DNS name of the remote Endpoint.

ceipSecEndPtHistRemoteType

1.3.6.1.4.1.9.9.432.1.2.3.1.13

CIPsecEndPtType1 = other2 = idIpv4Addr3 = idIpv4AddrRange4 = idIpv4AddrSubnet5 = idFqdn6 = idUserFqdn7 = idIpv6Addr8 = idIpv6AddrRange9 = idIpv6AddrSubnet10 = idDerAsn1Dn11 = idDerAsn1Gn12 = idKeyIdThe type of identity use to specify an IPsec End Point. For a description of the enum values, please refer to the description of type 'CIPsecPhase1PeerIdentityType'. · Integer32

The type of identity for the remote Endpoint.

ceipSecEndPtHistRemoteAddrType1

1.3.6.1.4.1.9.9.432.1.2.3.1.14

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this remote Endpoint's first IP address.

ceipSecEndPtHistRemoteAddr1

1.3.6.1.4.1.9.9.432.1.2.3.1.15

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtRemoteType.

ceipSecEndPtHistRemoteAddrType2

1.3.6.1.4.1.9.9.432.1.2.3.1.16

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address for this remote Endpoint's second IP address.

ceipSecEndPtHistRemoteAddr2

1.3.6.1.4.1.9.9.432.1.2.3.1.17

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range. If the type is an IP address, a range or a subnet, the type of the address can be inferred from cceipSecEndPtRemoteType.

ceipSecEndPtHistRemoteProtocol

1.3.6.1.4.1.9.9.432.1.2.3.1.18

CiscoIpProtocolIP protocol number range.Reference: Internet Protocol. J. Postel. RFC791 (0..255) · Integer32

The protocol number of the remote Endpoint's traffic.

ceipSecEndPtHistRemotePort

1.3.6.1.4.1.9.9.432.1.2.3.1.19

CiscoPortThe TCP or UDP port number range.Reference: Transmission Control Protocol. J. Postel. RFC793, User Datagram Protocol. J. Postel. RFC768 (0..65535) · Integer32

The port number of the remote Endpoint's traffic.

ceipSecFailTable

1.3.6.1.4.1.9.9.432.1.3.2

Index: ceipSecFailIndex

The IPsec Phase-2 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the ceipSecFailTableSize object.

ceipSecFailIndex

1.3.6.1.4.1.9.9.432.1.3.2.1.1

Unsigned32 (1..4294967295)

The IPsec Phase-2 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 4,294,967,295.

ceipSecFailReason

1.3.6.1.4.1.9.9.432.1.3.2.1.2

INTEGER1 = other2 = internalError3 = peerEncodingError4 = proposalFailure5 = protocolUseFail6 = nonExistentSa7 = decryptFailure8 = encryptFailure9 = inAuthFailure10 = outAuthFailure11 = compression12 = sysCapExceeded13 = peerDelRequest14 = peerLost15 = seqNumRollOver16 = operRequest17 = performanceUtilization · Integer32

The reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination 17 = performance utilization exceeding the threshold.

ceipSecFailTime

1.3.6.1.4.1.9.9.432.1.3.2.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds at the time of the failure.

ceipSecFailTunnelIndex

1.3.6.1.4.1.9.9.432.1.3.2.1.4

CIPsecPhase2TunnelIndexThe type of the index of the IPsec Phase-2 Tunnel Table. An index of this type is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32

The Phase-2 Tunnel index (ceipSecTunIndex). If this conceptual row corresponds to an operation failure (that is, the failure of an established Phase-2 IPsec tunnel), then the value of this object may not be zero.

ceipSecFailSaSpi

1.3.6.1.4.1.9.9.432.1.3.2.1.5

CIPsecSpiThe type of the SPI (Security Parameter Index) associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32 · hint x

The security association SPI value. If this conceptual row corresponds to a setup failure (failure to establish the tunnel), the value of this MIB object is undefined.

ceipSecFailPktSrcAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's source IP address.

ceipSecFailPktSrcAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's source IP address.

ceipSecFailPktDstAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.8

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's destination IP address.

ceipSecFailPktDstAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.9

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's destination IP address.

Trap details

ciscoEnhIpsecFlowTunnelStart

1.3.6.1.4.1.9.9.432.0.1

This notification is generated when an IPsec Phase-2 Tunnel becomes active.

ceipSecTunLifeTime

1.3.6.1.4.1.9.9.432.1.1.2.1.12

Unsigned32 · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds. If the tunnel was setup manually, the value of this MIB element should be 0.

ceipSecTunLifeSize

1.3.6.1.4.1.9.9.432.1.1.2.1.11

Unsigned32 (1..4294967295) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

ciscoEnhIpsecFlowTunnelStop

1.3.6.1.4.1.9.9.432.0.2

This notification is generated when an IPsec Phase-2 Tunnel becomes inactive.

ceipSecTunHistTermReason

1.3.6.1.4.1.9.9.432.1.2.2.1.2

INTEGER1 = other2 = normal3 = operRequest4 = peerDelRequest5 = peerLost6 = applicationInitiated7 = xauthFailure8 = seqNumRollOver9 = checkPointReq · Integer32

The reason the IPsec Phase-2 Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = applicationInitiated (eg: L2TP requesting the termination) 7 = failure of extended authentication 8 = local failure occurred 9 = operator initiated check point request

ceipSecTunActiveTime

1.3.6.1.4.1.9.9.432.1.1.2.1.13

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

ciscoEnhIpsecFlowSysFailure

1.3.6.1.4.1.9.9.432.0.3

This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences an internal or system capacity error.

ceipSecFailReason

1.3.6.1.4.1.9.9.432.1.3.2.1.2

INTEGER1 = other2 = internalError3 = peerEncodingError4 = proposalFailure5 = protocolUseFail6 = nonExistentSa7 = decryptFailure8 = encryptFailure9 = inAuthFailure10 = outAuthFailure11 = compression12 = sysCapExceeded13 = peerDelRequest14 = peerLost15 = seqNumRollOver16 = operRequest17 = performanceUtilization · Integer32

The reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination 17 = performance utilization exceeding the threshold.

ceipSecFailPktSrcAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's source IP address.

ceipSecFailPktSrcAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's source IP address.

ceipSecFailPktDstAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.8

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's destination IP address.

ceipSecFailPktDstAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.9

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's destination IP address.

ciscoEnhIpsecFlowSetupFail

1.3.6.1.4.1.9.9.432.0.4

This notification is generated when the setup for an IPsec Phase-2 Tunnel fails.

ceipSecFailReason

1.3.6.1.4.1.9.9.432.1.3.2.1.2

INTEGER1 = other2 = internalError3 = peerEncodingError4 = proposalFailure5 = protocolUseFail6 = nonExistentSa7 = decryptFailure8 = encryptFailure9 = inAuthFailure10 = outAuthFailure11 = compression12 = sysCapExceeded13 = peerDelRequest14 = peerLost15 = seqNumRollOver16 = operRequest17 = performanceUtilization · Integer32

The reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination 17 = performance utilization exceeding the threshold.

ceipSecFailPktSrcAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's source IP address.

ceipSecFailPktSrcAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's source IP address.

ceipSecFailPktDstAddressType

1.3.6.1.4.1.9.9.432.1.3.2.1.8

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the packet's destination IP address.

ceipSecFailPktDstAddress

1.3.6.1.4.1.9.9.432.1.3.2.1.9

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The packet's destination IP address.

ciscoEnhIpsecFlowBadSa

1.3.6.1.4.1.9.9.432.0.5

This notification is generated when the managed entity receives an IPsec packet with a non-existent (non-existant in the local Security Association Database) SPI.

ceipSecFailSaSpi

1.3.6.1.4.1.9.9.432.1.3.2.1.5

CIPsecSpiThe type of the SPI (Security Parameter Index) associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32 · hint x

The security association SPI value. If this conceptual row corresponds to a setup failure (failure to establish the tunnel), the value of this MIB object is undefined.

ciscoEnhIpsecFlowCertExpiry

1.3.6.1.4.1.9.9.432.0.6

This notification is generated to notify that an X.509 certificate is going to expire. The notification is triggered the time threshold configured on the application for notification before the certificate is going to expire, which is when the value of ceipSecCertExpiryStatus is changed from certOK(1) to certGoingExpired(2). The user should take action to renew the certificate identified in the notification prior to the certificate expiration, which is at the validity notAfter time provided in the notification.

ceipSecCertSubjectName

1.3.6.1.4.1.9.9.432.1.6.1

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.6 Subject RFC 3280 section 4.2.1.7 Subject Alternative Name

This object provides the subject name from the X.509 certificate, or the alternate subject name if it is available. The subject name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. Example Subject Name: C=US, OU=DEV, CN=Test-01 Example Subject Alternative Name: 2001:0022:0022:0020:0000:0000:0000:0102

ceipSecCertSerialNumber

1.3.6.1.4.1.9.9.432.1.6.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.2 Serial number

This object provides the serial number from the X.509 certificate. The serial number is formatted as a character string matching the output of a ssh-certview command-line application. The issuer name and the serial number identify a unique certificate. Example: 1000655533

ceipSecCertIssuerName

1.3.6.1.4.1.9.9.432.1.6.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 5.1.2.3 Issuer Name

This object provides the issuer name from the X.509 certificate. The issuer name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. The issuer name and the serial number identify a unique certificate. Example: C=US, O=Cisco, OU=MITG, CN=Lnx-Insta-RootCA-1

ceipSecCertExpiryTime

1.3.6.1.4.1.9.9.432.1.6.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.5 Validity

This object provides the validity notAfter time from the X.509 certificate. The notAfter time is the time after which the certificate is not valid. The time is formatted as a character string matching the output of a ssh-certview command-line application. Example: 2012 Apr 14th, 19:01:45 GMT

ceipSecCertExpiryStatus

1.3.6.1.4.1.9.9.432.1.6.6

INTEGER1 = certOK2 = certGoingExpired3 = certExpired · Integer32

This object provides the expiration status of the X.509 certificate on the application sending the notification. The notification is sent when the value of this object is changed from certOK(1) to certGoingExpired(2). certOK(1) = certificate is OK and is not within the configured time threshold for going to expire certGoingExpired(2) = certificate is within the configured time threshold for going to expire certExpired(3) = certificate has expired, the current time is after the certificate's validity notAfter time

ciscoEnhIpsecFlowCertRenewal

1.3.6.1.4.1.9.9.432.0.7

This notification is generated to report a status transition for an X.509 certificate renewal performed by the application. The notification is generated when the value of ceipSecCertRenewalStatus is changed from 1. renewalNotNeeded(1) to renewalRequestNeeded(2) or renewalRequested(3) 2. renewalRequestNeeded(2) to renewalRequested(3) 3. renewalRequested(3) to renewalSuccess(4) or renewalFailedUpdate(5) or renewalFailedExpired(6) 4. renewalFailedUpdate(5) to renewalFailedExpired(6)

ceipSecCertSubjectName

1.3.6.1.4.1.9.9.432.1.6.1

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.6 Subject RFC 3280 section 4.2.1.7 Subject Alternative Name

This object provides the subject name from the X.509 certificate, or the alternate subject name if it is available. The subject name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. Example Subject Name: C=US, OU=DEV, CN=Test-01 Example Subject Alternative Name: 2001:0022:0022:0020:0000:0000:0000:0102

ceipSecCertSerialNumber

1.3.6.1.4.1.9.9.432.1.6.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.2 Serial number

This object provides the serial number from the X.509 certificate. The serial number is formatted as a character string matching the output of a ssh-certview command-line application. The issuer name and the serial number identify a unique certificate. Example: 1000655533

ceipSecCertIssuerName

1.3.6.1.4.1.9.9.432.1.6.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 5.1.2.3 Issuer Name

This object provides the issuer name from the X.509 certificate. The issuer name is formatted as a character string matching the output of a ssh-certview command-line application, except that the application sending the notification may limit the string length. The issuer name and the serial number identify a unique certificate. Example: C=US, O=Cisco, OU=MITG, CN=Lnx-Insta-RootCA-1

ceipSecCertRenewalStatus

1.3.6.1.4.1.9.9.432.1.6.5

INTEGER1 = renewalNotNeeded2 = renewalRequestNeeded3 = renewalRequested4 = renewalSuccess5 = renewalFailedUpdate6 = renewalFailedExpired · Integer32

This object provides the renewal status of the X.509 certificate on the application sending the notification. renewalNotNeeded(1) = certificate is OK and does not need to be renewed renewalRequestNeeded(2) = certificate renewal request is needed renewalRequested(3) = certificate renewal has been requested and the renewal process is proceeding renewalSuccess(4) = certificate has been renewed and will be OK (renewalNotNeeded) renewalFailedUpdate(5) = certificate renewal failed, but certificate is still usable until the validity expiration time provided in the notification, or otherwise restricted by the application renewalFailedExpired(6) = certificate is no longer valid, the current time is after the certificate's validity notAfter time, which is provided in this notification

ceipSecCertExpiryTime

1.3.6.1.4.1.9.9.432.1.6.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Reference: RFC 3280 section 4.1.2.5 Validity

This object provides the validity notAfter time from the X.509 certificate. The notAfter time is the time after which the certificate is not valid. The time is formatted as a character string matching the output of a ssh-certview command-line application. Example: 2012 Apr 14th, 19:01:45 GMT

↑ To TOC