EZ5 MIB Catalog

CISCO-IKE-FLOW-MIB

2004-09-14

This is a MIB module for monitoring the structures and status of IPsec control flows based on Internet Key Exchange protocol. The MIB models standard aspects of the IKE protocol. Synopsis This MIB module models status, performance and failures of the IKEv1- and IKEv2-based signaling in IPsec, FC-SP(and similar) protocols. In practice, the security protocols such as IPsec, FC-SP and CTS use a signaling protocol such as IKE, KINK, or some such. A number of characteristics of these signaling protocols are generic. The generic attributes and status of signaling activity has been modeled in CISCO-IPSEC-SIGNALING-MIB. This MIB module augments CISCO-IPSEC-SIGNALING-MIB with IKE-specific MIB objects. (Signaling protocols are also referred to this document as 'Control Protocols', since they perform session control.) History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. That MIB instrumented both IKE(v1) and IPsec in a single module. During late 1999, Cisco adopted the MIB and together with Tivoli published the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms. With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt. This version of the draft is a Cisco-ized version that culls out the IKE-specific aspects of the IPsec Flow Monitor MIB. Overview of MIB The MIB contains five major groups of objects which are used to manage the IKE protocol activity. These groups include the global statistics, IKE tunnel table, IKE History Group and a notification Group. The tunnel table and the history table have a sparse-table relationship with the corresponding tables in the CISCO-IPSEC-SIGNALING-MIB (details in the DESCRIPTION of the respective tables). Acronyms The following acronyms are used in this document: Flow, Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document. IPsec: Secure IP Protocol ISAKMP: Internet Security Association and Key Management Protocol IKE: Internet Key Exchange Protocol MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs Phase 2 Tunnel: AN instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh). QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. SA: Security Association (ref: rfc2408). VPN: Virtual Private Network.

Download CISCO-IKE-FLOW-MIB.txt Open CISCO-IKE-FLOW-MIB.txt in a new tab

SCALARS (2) · TABLES (3) · TRAPS (2)

Scalars (2)

NameOID
cifIkeNotifCntlInNewGrpRejected1.3.6.1.4.1.9.9.429.1.3.1
cifIkeNotifCntlOutNewGrpRejected1.3.6.1.4.1.9.9.429.1.3.2

Tables (3)

NameOID
cifIkeGlobalStatsTable1.3.6.1.4.1.9.9.429.1.1.1
cifIkeTunnelTable1.3.6.1.4.1.9.9.429.1.1.3
cifIkeTunnelHistTable1.3.6.1.4.1.9.9.429.1.2.1

Traps (2)

NameOID
ciscoIkeFlowInNewGrpRejected1.3.6.1.4.1.9.9.429.0.1
ciscoIkeFlowOutNewGrpRejected1.3.6.1.4.1.9.9.429.0.2

END OF TOC

Scalar details

cifIkeNotifCntlInNewGrpRejected

1.3.6.1.4.1.9.9.429.1.3.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The generation of the 'ciscoIkeFlowInNewGrpRejected' notification is enabled if and only if this object has the value 'true'.

cifIkeNotifCntlOutNewGrpRejected

1.3.6.1.4.1.9.9.429.1.3.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The generation of the 'ciscoIkeFlowOutNewGrpRejected' notification is enabled if and only if this object has the value 'true'.

Table details

cifIkeGlobalStatsTable

1.3.6.1.4.1.9.9.429.1.1.1

Index: cisgIpsSgProtocol

The Phase-1 IKE Global Statistics Table. There is one entry in this table for each Phase-1 IKE, protocol('cpIkev1' and 'cpIkev2') implemented by the managed entity. For all the counter objects in the table below, initially when the IKE Tunnel becomes active and appears in this table, they would contain a value of zero.

from CISCO-IPSEC-SIGNALING-MIB

cisgIpsSgProtocol

CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized. The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols. Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling). cpIkev1: Denotes keying signaling using IKEv1 protocol. cpIkev2: Denotes keying signaling using IKEv2 protocol. cpKink: Denotes keying signaling using KINK. cpPhoturis: Denotes keying signaling using Photuris. · Integer32

The identity of the signaling protocol used by the control tunnel corresponding to this conceptual row.

cifIkeGlobalInP2Exchgs

1.3.6.1.4.1.9.9.429.1.1.1.1.1

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges received by all currently and previously active Phase-1 Tunnels.

cifIkeGlobalInP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.1.1.1.2

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges which were received and found to be invalid by all currently and previously active Phase-1 Tunnels.

cifIkeGlobalInP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.1.1.1.3

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges which were received and rejected by all currently and previously active Phase-1 Tunnels.

cifIkeGlobalOutP2Exchgs

1.3.6.1.4.1.9.9.429.1.1.1.1.4

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 Tunnels.

cifIkeGlobalOutP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.1.1.1.5

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges which were sent and found to be invalid by all currently and previously active Phase-1 Tunnels.

cifIkeGlobalOutP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.1.1.1.6

Counter64 (0..18446744073709551615) · SA Payloads

The total number of Phase-2 exchanges which were sent and rejected by all currently and previously active Phase-1 IKE Tunnels.

cifIkeGlobalInXauths

1.3.6.1.4.1.9.9.429.1.1.1.1.7

Counter64 (0..18446744073709551615) · Failures

The number of times the extended authentication requests was received by the managed entity from a peer.

cifIkeGlobalInXauthFailures

1.3.6.1.4.1.9.9.429.1.1.1.1.8

Counter64 (0..18446744073709551615) · Failures

The number of times the extended authentication information supplied by an IKE peer was found to be invalid by the local entity.

cifIkeGlobalOutXauthFailures

1.3.6.1.4.1.9.9.429.1.1.1.1.9

Counter64 (0..18446744073709551615) · Failures

The number of times the extended authentication information supplied by the managed entity to an IKE peer was found to be invalid by the remote peer.

cifIkeGlobalInNewGrpReqs

1.3.6.1.4.1.9.9.429.1.1.1.1.10

Counter64 (0..18446744073709551615) · Negotiations

The total number of New Group exchanges initiated remotely.

cifIkeGlobalOutNewGrpReqs

1.3.6.1.4.1.9.9.429.1.1.1.1.11

Counter64 (0..18446744073709551615) · Negotiations

The total number of New Group exchanges initiated locally.

cifIkeGlobalInNewGrpRejectReqs

1.3.6.1.4.1.9.9.429.1.1.1.1.12

Counter64 (0..18446744073709551615) · Negotiations

The total number of New Group exchanges initiated remotely that ended in reject.

cifIkeGlobalOutNewGrpRejectReqs

1.3.6.1.4.1.9.9.429.1.1.1.1.13

Counter64 (0..18446744073709551615) · Negotiations

The total number of New Group exchanges initiated locally that ended in reject.

cifIkeTunnelTable

1.3.6.1.4.1.9.9.429.1.1.3

Index: cisgIpsSgProtocol · cisgIpsSgTunIndex

The Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.

from CISCO-IPSEC-SIGNALING-MIB

cisgIpsSgProtocol

CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized. The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols. Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling). cpIkev1: Denotes keying signaling using IKEv1 protocol. cpIkev2: Denotes keying signaling using IKEv2 protocol. cpKink: Denotes keying signaling using KINK. cpPhoturis: Denotes keying signaling using Photuris. · Integer32

The identity of the signaling protocol used by the control tunnel corresponding to this conceptual row.

cisgIpsSgTunIndex

CIPsecPhase1TunnelIndexThe index of the IPsec Phase-1 (IKE) Tunnel Table. An index of this type is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32

The index of the Phase-1 Tunnel Table. The value of the index is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 4,294,967,296.

cifIkeTunNegoMode

1.3.6.1.4.1.9.9.429.1.1.3.1.1

CIPsecIkeNegoMode1 = mainMode2 = aggressiveModeThe negotiation mode used by IKE protocol in Phase-1. The type enumerates constants to denote the two distinct modes of operation of ISAKMP-based IPsec signaling in Phase-2, viz., Main Mode (mainMode) and Aggressive Mode (aggressiveMode).Reference: rfc2408 and rfc2409 · Integer32

The negotiation mode of the Phase-1 IKE Tunnel.

cifIkeTunDHGrp

1.3.6.1.4.1.9.9.429.1.1.3.1.2

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used in Phase-1 IKE negotiations.

cifIkeTunSaRefreshThreshold

1.3.6.1.4.1.9.9.429.1.1.3.1.3

Unsigned32 (0..2147483647) · seconds

The security association refresh threshold in seconds. If the tunnel does not refresh its security associations, the value of this MIB object is zero.

cifIkeTunTotalRefreshes

1.3.6.1.4.1.9.9.429.1.1.3.1.4

Counter32 · QM Exchanges

The total number of security associations refreshes performed. If the tunnel does not refresh its security associations, the value of this MIB object is never incremented.

cifIkeTunInP2Exchgs

1.3.6.1.4.1.9.9.429.1.1.3.1.5

Counter32 · SA Payloads

The total number of Phase-2 exchanges received by this Phase-1 IKE Tunnel.

cifIkeTunInP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.1.3.1.6

Counter32 · SA Payloads

The total number of Phase-2 exchanges received and found to be invalid by this Phase-1 IKE Tunnel.

cifIkeTunInP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.1.3.1.7

Counter32 · SA Payloads

The total number of Phase-2 exchanges received and rejected by this Phase-1 Tunnel.

cifIkeTunInP2SaDelRequests

1.3.6.1.4.1.9.9.429.1.1.3.1.8

Counter32 · Notification Payloads

The total number of Phase-2 security association delete requests received by this Phase-1 IKE Tunnel.

cifIkeTunOutP2Exchgs

1.3.6.1.4.1.9.9.429.1.1.3.1.9

Counter32 · SA Payloads

The total number of Phase-2 exchanges sent by this Phase-1 IKE Tunnel.

cifIkeTunOutP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.1.3.1.10

Counter32 · SA Payloads

The total number of Phase-2 exchanges sent and found to be invalid by this Phase-1 IKE Tunnel.

cifIkeTunOutP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.1.3.1.11

Counter32 · SA Payloads

The total number of Phase-2 exchanges sent and rejected by this Phase-1 IKE Tunnel.

cifIkeTunInNewGrpReqs

1.3.6.1.4.1.9.9.429.1.1.3.1.12

Counter32 · Negotiations

The total number of New Group exchanges initiated remotely using this IKE tunnel.

cifIkeTunOutNewGrpReqs

1.3.6.1.4.1.9.9.429.1.1.3.1.13

Counter32 · Negotiations

The total number of New Group exchanges initiated locally using this IKE tunnel.

cifIkeTunInNewGrpRejectedReqs

1.3.6.1.4.1.9.9.429.1.1.3.1.14

Counter32 · Negotiations

The total number of New Group exchanges initiated remotely using this IKE tunnel that ended in reject.

cifIkeTunOutNewGrpRejectedReqs

1.3.6.1.4.1.9.9.429.1.1.3.1.15

Counter32 · Negotiations

The total number of New Group exchanges initiated locally using this IKE tunnel that ended in reject.

cifIkeTunInConfigs

1.3.6.1.4.1.9.9.429.1.1.3.1.16

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings received (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.

cifIkeTunOutConfigs

1.3.6.1.4.1.9.9.429.1.1.3.1.17

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings dispatched (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.

cifIkeTunInConfigRejects

1.3.6.1.4.1.9.9.429.1.1.3.1.18

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings which were received (either CFG_REPLY or CFG_SET payloads) and rejected by this entity using the ISAKMP SA represented by this IKE tunnel.

cifIkeTunOutConfigRejects

1.3.6.1.4.1.9.9.429.1.1.3.1.19

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings which were dispatched (either CFG_REPLY or CFG_SET payloads) by this entity and were rejected by the peer (client) using the ISAKMP SA represented by this IKE tunnel.

cifIkeTunnelHistTable

1.3.6.1.4.1.9.9.429.1.2.1

Index: cisgIpsSgProtocol · cisgIpsSgTunHistIndex

The Phase-1 Internet Key Exchange Tunnel history table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'cisgIpsSgHistTableSize' (defined in defined in CISCO-IPSEC-SIGNALING-MIB). If the value of 'cisgIpsSgHistTableSize' is 0, then this table will be empty. For all the counter objects in the table below, initially when the Tunnel entry appears in this table, they would contain a value of zero.

from CISCO-IPSEC-SIGNALING-MIB

cisgIpsSgProtocol

CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized. The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols. Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling). cpIkev1: Denotes keying signaling using IKEv1 protocol. cpIkev2: Denotes keying signaling using IKEv2 protocol. cpKink: Denotes keying signaling using KINK. cpPhoturis: Denotes keying signaling using Photuris. · Integer32

The identity of the signaling protocol used by the control tunnel corresponding to this conceptual row.

cisgIpsSgTunHistIndex

Unsigned32

The index of the Phase-1 Control Tunnel History Table. This object has no relationship to the cisgIpsSgTunIndex of the tunnel when it was active. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 4,294,967,296.

cifIkeTunHistNegoMode

1.3.6.1.4.1.9.9.429.1.2.1.1.1

CIPsecIkeNegoMode1 = mainMode2 = aggressiveModeThe negotiation mode used by IKE protocol in Phase-1. The type enumerates constants to denote the two distinct modes of operation of ISAKMP-based IPsec signaling in Phase-2, viz., Main Mode (mainMode) and Aggressive Mode (aggressiveMode).Reference: rfc2408 and rfc2409 · Integer32

The negotiation mode of the Phase-1 IKE Tunnel.

cifIkeTunHistDHGrp

1.3.6.1.4.1.9.9.429.1.2.1.1.2

CIPsecDiffHellmanGrp1 = other2 = notDH3 = modp7684 = modp10245 = ec2nGP1556 = ec2nGP1857 = modp15368 = ec2nGF1639 = ec2nGF28310 = ec2nGF40911 = ec2nGF57112 = modp2048An indication of whether a Diffie Hellman Group has been specified to be used in negotiations and the type of group as follows. 'notDH' -- indicates no use of a Diffie Hellman 'modp768' -- 768-bit MODP 'modp1024' -- 1024-bit MODP 'modp1536' -- 1536-bit MODP group 'ec2nGP155' -- EC2N group on GP[2^155] 'ec2nGP185' -- EC2N group on GP[2^185] 'ec2nGF163' -- EC2N group over GF[2^163] 'ec2nGF283' -- EC2N group over GF[2^283] 'ec2nGF409' -- EC2N group over GF[2^409] 'ec2nGF571' -- EC2N group over GF[2^571] 'modp2048' -- 2048-bit MODP groupReference: rfc2408, rfc2409 and rfc3526 · Integer32

The Diffie Hellman Group used in Phase-1 IKE negotiations.

cifIkeTunHistTotalRefreshes

1.3.6.1.4.1.9.9.429.1.2.1.1.3

Counter32 · QM Exchanges

The total number of security associations refreshes performed.

cifIkeTunHistTotalSas

1.3.6.1.4.1.9.9.429.1.2.1.1.4

Counter32 · SAs

The total number of security associations used during the life of the Phase-1 IKE Tunnel.

cifIkeTunHistInP2Exchgs

1.3.6.1.4.1.9.9.429.1.2.1.1.5

Counter32 · SA Payloads

The total number of Phase-2 exchanges received by this Phase-1 IKE Tunnel.

cifIkeTunHistInP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.2.1.1.6

Counter32 · SA Payloads

The total number of Phase-2 exchanges received on this tunnel that were found to contain references to unrecognized security parameters.

cifIkeTunHistInP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.2.1.1.7

Counter32 · SA Payloads

The total number of Phase-2 exchanges received on this tunnel that were validated but were rejected by the local policy.

cifIkeTunHistOutP2Exchgs

1.3.6.1.4.1.9.9.429.1.2.1.1.8

Counter32 · Notification Payloads

The total number of Phase-2 security association delete requests received by this Phase-1 IKE Tunnel.

cifIkeTunHistOutP2ExchgInvalids

1.3.6.1.4.1.9.9.429.1.2.1.1.9

Counter32 · SA Payloads

The total number of Phase-2 exchanges sent by this Phase-1 IKE Tunnel.

cifIkeTunHistOutP2ExchgRejects

1.3.6.1.4.1.9.9.429.1.2.1.1.10

Counter32 · SA Payloads

The total number of Phase-2 exchanges sent on this tunnel that were rejected by the peer, because it contained references to security parameters not recognized by the peer.

cifIkeTunHistInNewGrpReqs

1.3.6.1.4.1.9.9.429.1.2.1.1.11

Counter32 · Negotiations

The total number of New Group exchanges initiated remotely using this IKE tunnel during its lifetime.

cifIkeTunHistOutNewGrpReqs

1.3.6.1.4.1.9.9.429.1.2.1.1.12

Counter32 · Negotiations

The total number of New Group exchanges initiated locally using this IKE tunnel during its lifetime.

cifIkeTunHistInNewGrpRejectReqs

1.3.6.1.4.1.9.9.429.1.2.1.1.13

Counter32 · Negotiations

The total number of New Group exchanges initiated remotely using this IKE tunnel during its lifetime that ended in reject.

cifIkeTunHistOutNewGrpRejectReqs

1.3.6.1.4.1.9.9.429.1.2.1.1.14

Counter32 · Negotiations

The total number of New Group exchanges initiated locally using this IKE tunnel during its lifetime that ended in reject.

cifIkeTunHistInConfigs

1.3.6.1.4.1.9.9.429.1.2.1.1.15

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings received (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.

cifIkeTunHistOutConfigs

1.3.6.1.4.1.9.9.429.1.2.1.1.16

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings dispatched (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.

cifIkeTunHistInConfigsRejects

1.3.6.1.4.1.9.9.429.1.2.1.1.17

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings which were received (either CFG_REPLY or CFG_SET payloads) and rejected by this entity using the ISAKMP SA represented by this IKE tunnel.

cifIkeTunHistOutConfigsRejects

1.3.6.1.4.1.9.9.429.1.2.1.1.18

Counter32 · Mode Configuration Setting Payloads

The total number of Mode Configuration settings which were dispatched (either CFG_REPLY or CFG_SET payloads) by this entity and were rejected by the peer (client) using the ISAKMP SA represented by this IKE tunnel.

Trap details

ciscoIkeFlowInNewGrpRejected

1.3.6.1.4.1.9.9.429.0.1

This notification is generated when the managed entity receives and rejects an incoming new group proposal from an IKE peer identified by 'cisgIpsSgFailRemoteAddress'. 'cisgIpsSgFailLocalAddress' identifies the address of the local peer. The ISAKMP context of the exchange can be obtained from the IKE tunnel index which is contained in the index of the varbind objects of this trap.

cisgIpsSgFailLocalAddress

1.3.6.1.4.1.9.9.438.1.4.2.1.8

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t

The address of the local peer. The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.

cisgIpsSgFailRemoteAddress

1.3.6.1.4.1.9.9.438.1.4.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t

The address of the remote peer. The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.

ciscoIkeFlowOutNewGrpRejected

1.3.6.1.4.1.9.9.429.0.2

This notification is generated when the managed entity issues a new group proposal to the remote peer identified by 'cisgIpsSgFailRemoteAddress' and the peer rejects the proposal. 'cisgIpsSgFailLocalAddress' identifies the address of the local peer. The ISAKMP context of the exchange can be obtained from the IKE tunnel index which is contained in the index of the varbind objects of this trap.

cisgIpsSgFailLocalAddress

1.3.6.1.4.1.9.9.438.1.4.2.1.8

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t

The address of the local peer. The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.

cisgIpsSgFailRemoteAddress

1.3.6.1.4.1.9.9.438.1.4.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t

The address of the remote peer. The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.

↑ To TOC