EZ5 MIB Catalog

CISCO-IPSEC-FLOW-MONITOR-MIB

2007-10-24

This is a MIB Module for monitoring the structures in IPSec-based Virtual Private Networks. The MIB has been designed to be adopted as an IETF standard. Hence Cisco-specific features of IPSec protocol are excluded from this MIB. Acronyms The following acronyms are used in this document: IPSec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol SA: Security Association MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. Overview of IPsec MIB The MIB contains six major groups of objects which are used to manage the IPSec Protocol. These groups include a Levels Group, a Phase-1 Group, a Phase-2 Group, a History Group, a Failure Group and a TRAP Control Group. The following table illustrates the structure of the IPSec MIB. The Phase 1 group models objects pertaining to IKE negotiations and tunnels. The Phase 2 group models objects pertaining to IPSec data tunnels. The History group is to aid applications that do trending analysis. The Failure group is to enable an operator to do troubleshooting and debugging of the VPN Router. Further, counters are supported to aid Intrusion Detection. In addition to the five major MIB Groups, there are a number of Notifications. The following table illustrates the name and description of the IPSec TRAPs. For a detailed discussion, please refer to the IETF draft draft-ietf-ipsec-flow-monitoring-mib-00.txt.

Download CISCO-IPSEC-FLOW-MONITOR-MIB.txt Open CISCO-IPSEC-FLOW-MONITOR-MIB.txt in a new tab

SCALARS (73) · TABLES (13) · TRAPS (13)

Scalars (73)

NameOID
cipSecMibLevel1.3.6.1.4.1.9.9.171.1.1.1
cikeGlobalActiveTunnels1.3.6.1.4.1.9.9.171.1.2.1.1
cikeGlobalPreviousTunnels1.3.6.1.4.1.9.9.171.1.2.1.2
cikeGlobalInOctets1.3.6.1.4.1.9.9.171.1.2.1.3
cikeGlobalInPkts1.3.6.1.4.1.9.9.171.1.2.1.4
cikeGlobalInDropPkts1.3.6.1.4.1.9.9.171.1.2.1.5
cikeGlobalInNotifys1.3.6.1.4.1.9.9.171.1.2.1.6
cikeGlobalInP2Exchgs1.3.6.1.4.1.9.9.171.1.2.1.7
cikeGlobalInP2ExchgInvalids1.3.6.1.4.1.9.9.171.1.2.1.8
cikeGlobalInP2ExchgRejects1.3.6.1.4.1.9.9.171.1.2.1.9
cikeGlobalInP2SaDelRequests1.3.6.1.4.1.9.9.171.1.2.1.10
cikeGlobalOutOctets1.3.6.1.4.1.9.9.171.1.2.1.11
cikeGlobalOutPkts1.3.6.1.4.1.9.9.171.1.2.1.12
cikeGlobalOutDropPkts1.3.6.1.4.1.9.9.171.1.2.1.13
cikeGlobalOutNotifys1.3.6.1.4.1.9.9.171.1.2.1.14
cikeGlobalOutP2Exchgs1.3.6.1.4.1.9.9.171.1.2.1.15
cikeGlobalOutP2ExchgInvalids1.3.6.1.4.1.9.9.171.1.2.1.16
cikeGlobalOutP2ExchgRejects1.3.6.1.4.1.9.9.171.1.2.1.17
cikeGlobalOutP2SaDelRequests1.3.6.1.4.1.9.9.171.1.2.1.18
cikeGlobalInitTunnels1.3.6.1.4.1.9.9.171.1.2.1.19
cikeGlobalInitTunnelFails1.3.6.1.4.1.9.9.171.1.2.1.20
cikeGlobalRespTunnelFails1.3.6.1.4.1.9.9.171.1.2.1.21
cikeGlobalSysCapFails1.3.6.1.4.1.9.9.171.1.2.1.22
cikeGlobalAuthFails1.3.6.1.4.1.9.9.171.1.2.1.23
cikeGlobalDecryptFails1.3.6.1.4.1.9.9.171.1.2.1.24
cikeGlobalHashValidFails1.3.6.1.4.1.9.9.171.1.2.1.25
cikeGlobalNoSaFails1.3.6.1.4.1.9.9.171.1.2.1.26
cipSecGlobalActiveTunnels1.3.6.1.4.1.9.9.171.1.3.1.1
cipSecGlobalPreviousTunnels1.3.6.1.4.1.9.9.171.1.3.1.2
cipSecGlobalInOctets1.3.6.1.4.1.9.9.171.1.3.1.3
cipSecGlobalHcInOctets1.3.6.1.4.1.9.9.171.1.3.1.4
cipSecGlobalInOctWraps1.3.6.1.4.1.9.9.171.1.3.1.5
cipSecGlobalInDecompOctets1.3.6.1.4.1.9.9.171.1.3.1.6
cipSecGlobalHcInDecompOctets1.3.6.1.4.1.9.9.171.1.3.1.7
cipSecGlobalInDecompOctWraps1.3.6.1.4.1.9.9.171.1.3.1.8
cipSecGlobalInPkts1.3.6.1.4.1.9.9.171.1.3.1.9
cipSecGlobalInDrops1.3.6.1.4.1.9.9.171.1.3.1.10
cipSecGlobalInReplayDrops1.3.6.1.4.1.9.9.171.1.3.1.11
cipSecGlobalInAuths1.3.6.1.4.1.9.9.171.1.3.1.12
cipSecGlobalInAuthFails1.3.6.1.4.1.9.9.171.1.3.1.13
cipSecGlobalInDecrypts1.3.6.1.4.1.9.9.171.1.3.1.14
cipSecGlobalInDecryptFails1.3.6.1.4.1.9.9.171.1.3.1.15
cipSecGlobalOutOctets1.3.6.1.4.1.9.9.171.1.3.1.16
cipSecGlobalHcOutOctets1.3.6.1.4.1.9.9.171.1.3.1.17
cipSecGlobalOutOctWraps1.3.6.1.4.1.9.9.171.1.3.1.18
cipSecGlobalOutUncompOctets1.3.6.1.4.1.9.9.171.1.3.1.19
cipSecGlobalHcOutUncompOctets1.3.6.1.4.1.9.9.171.1.3.1.20
cipSecGlobalOutUncompOctWraps1.3.6.1.4.1.9.9.171.1.3.1.21
cipSecGlobalOutPkts1.3.6.1.4.1.9.9.171.1.3.1.22
cipSecGlobalOutDrops1.3.6.1.4.1.9.9.171.1.3.1.23
cipSecGlobalOutAuths1.3.6.1.4.1.9.9.171.1.3.1.24
cipSecGlobalOutAuthFails1.3.6.1.4.1.9.9.171.1.3.1.25
cipSecGlobalOutEncrypts1.3.6.1.4.1.9.9.171.1.3.1.26
cipSecGlobalOutEncryptFails1.3.6.1.4.1.9.9.171.1.3.1.27
cipSecGlobalProtocolUseFails1.3.6.1.4.1.9.9.171.1.3.1.28
cipSecGlobalNoSaFails1.3.6.1.4.1.9.9.171.1.3.1.29
cipSecGlobalSysCapFails1.3.6.1.4.1.9.9.171.1.3.1.30
cipSecHistTableSize1.3.6.1.4.1.9.9.171.1.4.1.1.1
cipSecHistCheckPoint1.3.6.1.4.1.9.9.171.1.4.1.1.2
cipSecFailTableSize1.3.6.1.4.1.9.9.171.1.5.1.1.1
cipSecTrapCntlIkeTunnelStart1.3.6.1.4.1.9.9.171.1.6.1
cipSecTrapCntlIkeTunnelStop1.3.6.1.4.1.9.9.171.1.6.2
cipSecTrapCntlIkeSysFailure1.3.6.1.4.1.9.9.171.1.6.3
cipSecTrapCntlIkeCertCrlFailure1.3.6.1.4.1.9.9.171.1.6.4
cipSecTrapCntlIkeProtocolFail1.3.6.1.4.1.9.9.171.1.6.5
cipSecTrapCntlIkeNoSa1.3.6.1.4.1.9.9.171.1.6.6
cipSecTrapCntlIpSecTunnelStart1.3.6.1.4.1.9.9.171.1.6.7
cipSecTrapCntlIpSecTunnelStop1.3.6.1.4.1.9.9.171.1.6.8
cipSecTrapCntlIpSecSysFailure1.3.6.1.4.1.9.9.171.1.6.9
cipSecTrapCntlIpSecSetUpFailure1.3.6.1.4.1.9.9.171.1.6.10
cipSecTrapCntlIpSecEarlyTunTerm1.3.6.1.4.1.9.9.171.1.6.11
cipSecTrapCntlIpSecProtocolFail1.3.6.1.4.1.9.9.171.1.6.12
cipSecTrapCntlIpSecNoSa1.3.6.1.4.1.9.9.171.1.6.13

Tables (13)

NameOID
cikePeerTable1.3.6.1.4.1.9.9.171.1.2.2
cikeTunnelTable1.3.6.1.4.1.9.9.171.1.2.3
cikePeerCorrTable1.3.6.1.4.1.9.9.171.1.2.4
cikePhase1GWStatsTable1.3.6.1.4.1.9.9.171.1.2.5
cipSecTunnelTable1.3.6.1.4.1.9.9.171.1.3.2
cipSecEndPtTable1.3.6.1.4.1.9.9.171.1.3.3
cipSecSpiTable1.3.6.1.4.1.9.9.171.1.3.4
cipSecPhase2GWStatsTable1.3.6.1.4.1.9.9.171.1.3.5
cikeTunnelHistTable1.3.6.1.4.1.9.9.171.1.4.2.1
cipSecTunnelHistTable1.3.6.1.4.1.9.9.171.1.4.3.1
cipSecEndPtHistTable1.3.6.1.4.1.9.9.171.1.4.3.2
cikeFailTable1.3.6.1.4.1.9.9.171.1.5.2.1
cipSecFailTable1.3.6.1.4.1.9.9.171.1.5.3.1

Traps (13)

NameOID
cikeTunnelStart1.3.6.1.4.1.9.9.171.2.0.1
cikeTunnelStop1.3.6.1.4.1.9.9.171.2.0.2
cikeSysFailure1.3.6.1.4.1.9.9.171.2.0.3
cikeCertCrlFailure1.3.6.1.4.1.9.9.171.2.0.4
cikeProtocolFailure1.3.6.1.4.1.9.9.171.2.0.5
cikeNoSa1.3.6.1.4.1.9.9.171.2.0.6
cipSecTunnelStart1.3.6.1.4.1.9.9.171.2.0.7
cipSecTunnelStop1.3.6.1.4.1.9.9.171.2.0.8
cipSecSysFailure1.3.6.1.4.1.9.9.171.2.0.9
cipSecSetUpFailure1.3.6.1.4.1.9.9.171.2.0.10
cipSecEarlyTunTerm1.3.6.1.4.1.9.9.171.2.0.11
cipSecProtocolFailure1.3.6.1.4.1.9.9.171.2.0.12
cipSecNoSa1.3.6.1.4.1.9.9.171.2.0.13

END OF TOC

Scalar details

cipSecMibLevel

1.3.6.1.4.1.9.9.171.1.1.1

Integer32 (1..4096)

The level of the IPsec MIB.

cikeGlobalActiveTunnels

1.3.6.1.4.1.9.9.171.1.2.1.1

Gauge32

The number of currently active IPsec Phase-1 IKE Tunnels.

cikeGlobalPreviousTunnels

1.3.6.1.4.1.9.9.171.1.2.1.2

Counter32 · SAs

The total number of previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInOctets

1.3.6.1.4.1.9.9.171.1.2.1.3

Counter32 · Octets

The total number of octets received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInPkts

1.3.6.1.4.1.9.9.171.1.2.1.4

Counter32 · Packets

The total number of packets received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInDropPkts

1.3.6.1.4.1.9.9.171.1.2.1.5

Counter32 · Packets

The total number of packets which were dropped during receive processing by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInNotifys

1.3.6.1.4.1.9.9.171.1.2.1.6

Counter32 · Notification Payloads

The total number of notifys received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.1.7

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.1.8

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were received and found to be invalid by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.1.9

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were received and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.1.10

Counter32 · Notification Payloads

The total number of IPsec Phase-2 security association delete requests received by all currently and previously active and IPsec Phase-1 IKE Tunnels.

cikeGlobalOutOctets

1.3.6.1.4.1.9.9.171.1.2.1.11

Counter32 · Octets

The total number of octets sent by all currently and previously active and IPsec Phase-1 IKE Tunnels.

cikeGlobalOutPkts

1.3.6.1.4.1.9.9.171.1.2.1.12

Counter32 · Packets

The total number of packets sent by all currently and previously active and IPsec Phase-1 Tunnels.

cikeGlobalOutDropPkts

1.3.6.1.4.1.9.9.171.1.2.1.13

Counter32 · Packets

The total number of packets which were dropped during send processing by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalOutNotifys

1.3.6.1.4.1.9.9.171.1.2.1.14

Counter32 · Notification Payloads

The total number of notifys sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalOutP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.1.15

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalOutP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.1.16

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent and found to be invalid by all currently and previously active IPsec Phase-1 Tunnels.

cikeGlobalOutP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.1.17

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalOutP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.1.18

Counter32 · Notification Payloads

The total number of IPsec Phase-2 SA delete requests sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalInitTunnels

1.3.6.1.4.1.9.9.171.1.2.1.19

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were locally initiated.

cikeGlobalInitTunnelFails

1.3.6.1.4.1.9.9.171.1.2.1.20

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were locally initiated and failed to activate.

cikeGlobalRespTunnelFails

1.3.6.1.4.1.9.9.171.1.2.1.21

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were remotely initiated and failed to activate.

cikeGlobalSysCapFails

1.3.6.1.4.1.9.9.171.1.2.1.22

Counter32 · Failures

The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-1 IKE Tunnels.

cikeGlobalAuthFails

1.3.6.1.4.1.9.9.171.1.2.1.23

Counter32 · Failures

The total number of authentications which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikeGlobalDecryptFails

1.3.6.1.4.1.9.9.171.1.2.1.24

Counter32 · Failures

The total number of decryptions which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikeGlobalHashValidFails

1.3.6.1.4.1.9.9.171.1.2.1.25

Counter32 · Failures

The total number of hash validations which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikeGlobalNoSaFails

1.3.6.1.4.1.9.9.171.1.2.1.26

Counter32 · Failures

The total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-1 IKE Tunnels.

cipSecGlobalActiveTunnels

1.3.6.1.4.1.9.9.171.1.3.1.1

Gauge32

The total number of currently active IPsec Phase-2 Tunnels.

cipSecGlobalPreviousTunnels

1.3.6.1.4.1.9.9.171.1.3.1.2

Counter32 · Phase-2 Tunnels

The total number of previously active IPsec Phase-2 Tunnels.

cipSecGlobalInOctets

1.3.6.1.4.1.9.9.171.1.3.1.3

Counter32 · Octets

The total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecGlobalInOctWraps for the number of times this counter has wrapped.

cipSecGlobalHcInOctets

1.3.6.1.4.1.9.9.171.1.3.1.4

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

cipSecGlobalInOctWraps

1.3.6.1.4.1.9.9.171.1.3.1.5

Counter32 · Integral units

The number of times the global octets received counter (cipSecGlobalInOctets) has wrapped.

cipSecGlobalInDecompOctets

1.3.6.1.4.1.9.9.171.1.3.1.6

Counter32 · Octets

The total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalInOctets. See also cipSecGlobalInDecompOctWraps for the number of times this counter has wrapped.

cipSecGlobalHcInDecompOctets

1.3.6.1.4.1.9.9.171.1.3.1.7

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalHcInOctets.

cipSecGlobalInDecompOctWraps

1.3.6.1.4.1.9.9.171.1.3.1.8

Counter32 · Integral units

The number of times the global decompressed octets received counter (cipSecGlobalInDecompOctets) has wrapped.

cipSecGlobalInPkts

1.3.6.1.4.1.9.9.171.1.3.1.9

Counter32 · Packets

The total number of packets received by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalInDrops

1.3.6.1.4.1.9.9.171.1.3.1.10

Counter32 · Packets

The total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.

cipSecGlobalInReplayDrops

1.3.6.1.4.1.9.9.171.1.3.1.11

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalInAuths

1.3.6.1.4.1.9.9.171.1.3.1.12

Counter32 · Events

The total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalInAuthFails

1.3.6.1.4.1.9.9.171.1.3.1.13

Counter32 · Failures

The total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalInDecrypts

1.3.6.1.4.1.9.9.171.1.3.1.14

Counter32 · Packets

The total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalInDecryptFails

1.3.6.1.4.1.9.9.171.1.3.1.15

Counter32 · Packets

The total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutOctets

1.3.6.1.4.1.9.9.171.1.3.1.16

Counter32 · Octets

The total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecGlobalOutOctWraps for the number of times this counter has wrapped.

cipSecGlobalHcOutOctets

1.3.6.1.4.1.9.9.171.1.3.1.17

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed.

cipSecGlobalOutOctWraps

1.3.6.1.4.1.9.9.171.1.3.1.18

Counter32 · Integral units

The number of times the global octets sent counter (cipSecGlobalOutOctets) has wrapped.

cipSecGlobalOutUncompOctets

1.3.6.1.4.1.9.9.171.1.3.1.19

Counter32 · Octets

The total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalOutOctets. See also cipSecGlobalOutDecompOctWraps for the number of times this counter has wrapped.

cipSecGlobalHcOutUncompOctets

1.3.6.1.4.1.9.9.171.1.3.1.20

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalHcOutOctets.

cipSecGlobalOutUncompOctWraps

1.3.6.1.4.1.9.9.171.1.3.1.21

Counter32 · Integral units

The number of times the global uncompressed octets sent counter (cipSecGlobalOutUncompOctets) has wrapped.

cipSecGlobalOutPkts

1.3.6.1.4.1.9.9.171.1.3.1.22

Counter32 · Packets

The total number of packets sent by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutDrops

1.3.6.1.4.1.9.9.171.1.3.1.23

Counter32 · Packets

The total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutAuths

1.3.6.1.4.1.9.9.171.1.3.1.24

Counter32 · Events

The total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutAuthFails

1.3.6.1.4.1.9.9.171.1.3.1.25

Counter32 · Failures

The total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutEncrypts

1.3.6.1.4.1.9.9.171.1.3.1.26

Counter32 · Packets

The total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalOutEncryptFails

1.3.6.1.4.1.9.9.171.1.3.1.27

Counter32 · Failures

The total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalProtocolUseFails

1.3.6.1.4.1.9.9.171.1.3.1.28

Counter32 · Failures

The total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

cipSecGlobalNoSaFails

1.3.6.1.4.1.9.9.171.1.3.1.29

Counter32 · Failures

The total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.

cipSecGlobalSysCapFails

1.3.6.1.4.1.9.9.171.1.3.1.30

Counter32 · Failures

The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

cipSecHistTableSize

1.3.6.1.4.1.9.9.171.1.4.1.1.1

Integer32 (1..2147483647)

The window size of the IPsec Phase-1 and Phase-2 History Tables. The IPsec Phase-1 and Phase-2 History Tables are implemented as a sliding window in which only the last n entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-1 and Phase-2 History Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, a BAD VALUE may be returned.

cipSecHistCheckPoint

1.3.6.1.4.1.9.9.171.1.4.1.1.2

INTEGER1 = ready2 = checkPoint · Integer32

The current state of check point processing. This object will return ready when the agent is ready to create on-demand history entries for active IPsec Tunnels or checkPoint when the agent is currently creating on-demand history entries for active IPsec Tunnels. By setting this value to checkPoint, the agent will create: a) an entry in the IPsec Phase-1 Tunnel History for each active IPsec Phase-1 Tunnel and b) an entry in the IPsec Phase-2 Tunnel History Table and an entry in the IPsec Phase-2 Tunnel EndPoint History Table for each active IPsec Phase-2 Tunnel.

cipSecFailTableSize

1.3.6.1.4.1.9.9.171.1.5.1.1.1

Integer32 (1..2147483647)

The window size of the IPsec Phase-1 and Phase-2 Failure Tables. The IPsec Phase-1 and Phase-2 Failure Tables are implemented as a sliding window in which only the last n entries are maintained. This object is used specify the number of entries which will be maintained in the IPsec Phase-1 and Phase-2 Failure Tables. An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, a BAD VALUE may be returned.

cipSecTrapCntlIkeTunnelStart

1.3.6.1.4.1.9.9.171.1.6.1

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 Tunnel Start TRAP

cipSecTrapCntlIkeTunnelStop

1.3.6.1.4.1.9.9.171.1.6.2

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 Tunnel Stop TRAP

cipSecTrapCntlIkeSysFailure

1.3.6.1.4.1.9.9.171.1.6.3

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 System Failure TRAP

cipSecTrapCntlIkeCertCrlFailure

1.3.6.1.4.1.9.9.171.1.6.4

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 Certificate/CRL Failure TRAP

cipSecTrapCntlIkeProtocolFail

1.3.6.1.4.1.9.9.171.1.6.5

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 Protocol Failure TRAP

cipSecTrapCntlIkeNoSa

1.3.6.1.4.1.9.9.171.1.6.6

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec IKE Phase-1 No Security Association TRAP

cipSecTrapCntlIpSecTunnelStart

1.3.6.1.4.1.9.9.171.1.6.7

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Tunnel Start TRAP

cipSecTrapCntlIpSecTunnelStop

1.3.6.1.4.1.9.9.171.1.6.8

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Tunnel Stop TRAP

cipSecTrapCntlIpSecSysFailure

1.3.6.1.4.1.9.9.171.1.6.9

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 System Failure TRAP

cipSecTrapCntlIpSecSetUpFailure

1.3.6.1.4.1.9.9.171.1.6.10

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Set Up Failure TRAP

cipSecTrapCntlIpSecEarlyTunTerm

1.3.6.1.4.1.9.9.171.1.6.11

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Early Tunnel Termination TRAP

cipSecTrapCntlIpSecProtocolFail

1.3.6.1.4.1.9.9.171.1.6.12

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 Protocol Failure TRAP

cipSecTrapCntlIpSecNoSa

1.3.6.1.4.1.9.9.171.1.6.13

TrapStatus1 = enabled2 = disabledThe administrative status for sending a TRAP. · Integer32

This object defines the administrative state of sending the IPsec Phase-2 No Security Association TRAP

Table details

cikePeerTable

1.3.6.1.4.1.9.9.171.1.2.2

Index: cikePeerLocalType · cikePeerLocalValue · cikePeerRemoteType · cikePeerRemoteValue · cikePeerIntIndex

The IPsec Phase-1 Internet Key Exchange Peer Table. There is one entry in this table for each IPsec Phase-1 IKE peer association which is currently associated with an active IPsec Phase-1 Tunnel. The IPsec Phase-1 IKE Tunnel associated with this IPsec Phase-1 IKE peer association may or may not be currently active.

cikePeerLocalType

1.3.6.1.4.1.9.9.171.1.2.2.1.1

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.

cikePeerLocalValue

1.3.6.1.4.1.9.9.171.1.2.2.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.

cikePeerRemoteType

1.3.6.1.4.1.9.9.171.1.2.2.1.3

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.

cikePeerRemoteValue

1.3.6.1.4.1.9.9.171.1.2.2.1.4

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.

cikePeerIntIndex

1.3.6.1.4.1.9.9.171.1.2.2.1.5

Integer32 (1..2147483647)

The internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikePeerActiveTime

1.3.6.1.4.1.9.9.171.1.2.2.1.8

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time that the peer association has existed in hundredths of a second.

cikePeerActiveTunnelIndex

1.3.6.1.4.1.9.9.171.1.2.2.1.9

Integer32 (1..2147483647)

The index of the active IPsec Phase-1 IKE Tunnel (cikeTunIndex in the cikeTunnelTable) for this peer association. If an IPsec Phase-1 IKE Tunnel is not currently active, then the value of this object will be zero.

cikeTunnelTable

1.3.6.1.4.1.9.9.171.1.2.3

Index: cikeTunIndex

The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.

cikeTunIndex

1.3.6.1.4.1.9.9.171.1.2.3.1.1

Integer32 (1..2147483647)

The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.

cikeTunLocalType

1.3.6.1.4.1.9.9.171.1.2.3.1.2

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.

cikeTunLocalValue

1.3.6.1.4.1.9.9.171.1.2.3.1.3

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.

cikeTunLocalAddr

1.3.6.1.4.1.9.9.171.1.2.3.1.4

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-1 IKE Tunnel.

cikeTunLocalName

1.3.6.1.4.1.9.9.171.1.2.3.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the local IP address for the IPsec Phase-1 IKE Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a NULL string.

cikeTunRemoteType

1.3.6.1.4.1.9.9.171.1.2.3.1.6

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.

cikeTunRemoteValue

1.3.6.1.4.1.9.9.171.1.2.3.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.

cikeTunRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.3.1.8

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-1 IKE Tunnel.

cikeTunRemoteName

1.3.6.1.4.1.9.9.171.1.2.3.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the remote IP address of IPsec Phase-1 IKE Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a NULL string.

cikeTunNegoMode

1.3.6.1.4.1.9.9.171.1.2.3.1.10

IkeNegoMode1 = main2 = aggressiveThe IPsec Phase-1 IKE negotiation mode. · Integer32

The negotiation mode of the IPsec Phase-1 IKE Tunnel.

cikeTunDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.2.3.1.11

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.

cikeTunEncryptAlgo

1.3.6.1.4.1.9.9.171.1.2.3.1.12

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used in IPsec Phase-1 IKE negotiations.

cikeTunHashAlgo

1.3.6.1.4.1.9.9.171.1.2.3.1.13

IkeHashAlgo1 = none2 = md53 = shaThe hash algorithm used in IPsec Phase-1 IKE negotiations. · Integer32

The hash algorithm used in IPsec Phase-1 IKE negotiations.

cikeTunAuthMethod

1.3.6.1.4.1.9.9.171.1.2.3.1.14

IkeAuthMethod1 = none2 = preSharedKey3 = rsaSig4 = rsaEncrypt5 = revPublicKeyThe authentication method used in IPsec Phase-1 IKE negotiations. · Integer32

The authentication method used in IPsec Phase-1 IKE negotiations.

cikeTunLifeTime

1.3.6.1.4.1.9.9.171.1.2.3.1.15

Integer32 (1..2147483647) · seconds

The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.

cikeTunActiveTime

1.3.6.1.4.1.9.9.171.1.2.3.1.16

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.

cikeTunSaRefreshThreshold

1.3.6.1.4.1.9.9.171.1.2.3.1.17

Integer32 (1..2147483647) · seconds

The security association refresh threshold in seconds.

cikeTunTotalRefreshes

1.3.6.1.4.1.9.9.171.1.2.3.1.18

Counter32 · QM Exchanges

The total number of security associations refreshes performed.

cikeTunInOctets

1.3.6.1.4.1.9.9.171.1.2.3.1.19

Counter32 · Octets

The total number of octets received by this IPsec Phase-1 IKE Tunnel.

cikeTunInPkts

1.3.6.1.4.1.9.9.171.1.2.3.1.20

Counter32 · Packets

The total number of packets received by this IPsec Phase-1 IKE Tunnel.

cikeTunInDropPkts

1.3.6.1.4.1.9.9.171.1.2.3.1.21

Counter32 · Packets

The total number of packets dropped by this IPsec Phase-1 IKE Tunnel during receive processing.

cikeTunInNotifys

1.3.6.1.4.1.9.9.171.1.2.3.1.22

Counter32 · Notification Payloads

The total number of notifys received by this IPsec Phase-1 IKE Tunnel.

cikeTunInP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.3.1.23

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received by this IPsec Phase-1 IKE Tunnel.

cikeTunInP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.3.1.24

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received and found to be invalid by this IPsec Phase-1 IKE Tunnel.

cikeTunInP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.3.1.25

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received and rejected by this IPsec Phase-1 Tunnel.

cikeTunInP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.3.1.26

Counter32 · Notification Payloads

The total number of IPsec Phase-2 security association delete requests received by this IPsec Phase-1 IKE Tunnel.

cikeTunOutOctets

1.3.6.1.4.1.9.9.171.1.2.3.1.27

Counter32 · Octets

The total number of octets sent by this IPsec Phase-1 IKE Tunnel.

cikeTunOutPkts

1.3.6.1.4.1.9.9.171.1.2.3.1.28

Counter32 · Packets

The total number of packets sent by this IPsec Phase-1 IKE Tunnel.

cikeTunOutDropPkts

1.3.6.1.4.1.9.9.171.1.2.3.1.29

Counter32 · Packets

The total number of packets dropped by this IPsec Phase-1 IKE Tunnel during send processing.

cikeTunOutNotifys

1.3.6.1.4.1.9.9.171.1.2.3.1.30

Counter32 · Notification Payloads

The total number of notifys sent by this IPsec Phase-1 Tunnel.

cikeTunOutP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.3.1.31

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent by this IPsec Phase-1 IKE Tunnel.

cikeTunOutP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.3.1.32

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent and found to be invalid by this IPsec Phase-1 IKE Tunnel.

cikeTunOutP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.3.1.33

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent and rejected by this IPsec Phase-1 IKE Tunnel.

cikeTunOutP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.3.1.34

Counter32 · Notification Payloads

The total number of IPsec Phase-2 security association delete requests sent by this IPsec Phase-1 IKE Tunnel.

cikeTunStatus

1.3.6.1.4.1.9.9.171.1.2.3.1.35

TunnelStatus1 = active2 = destroyThe status of a Tunnel. Objects of this type may be used to bring the tunnel down by setting value of this object to destroy(2). Objects of this type cannot be used to create a Tunnel. · Integer32

The status of the MIB table row. This object can be used to bring the tunnel down by setting value of this object to destroy(2). This object cannot be used to create a MIB table row.

cikePeerCorrTable

1.3.6.1.4.1.9.9.171.1.2.4

Index: cikePeerCorrLocalType · cikePeerCorrLocalValue · cikePeerCorrRemoteType · cikePeerCorrRemoteValue · cikePeerCorrIntIndex · cikePeerCorrSeqNum

The IPsec Phase-1 Internet Key Exchange Peer Association to IPsec Phase-2 Tunnel Correlation Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.

cikePeerCorrLocalType

1.3.6.1.4.1.9.9.171.1.2.4.1.1

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.

cikePeerCorrLocalValue

1.3.6.1.4.1.9.9.171.1.2.4.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.

cikePeerCorrRemoteType

1.3.6.1.4.1.9.9.171.1.2.4.1.3

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.

cikePeerCorrRemoteValue

1.3.6.1.4.1.9.9.171.1.2.4.1.4

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.

cikePeerCorrIntIndex

1.3.6.1.4.1.9.9.171.1.2.4.1.5

Integer32 (1..2147483647)

The internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.

cikePeerCorrSeqNum

1.3.6.1.4.1.9.9.171.1.2.4.1.6

Integer32 (1..2147483647)

The sequence number of the local-remote peer association. This sequence number is used to uniquely identify multiple instances of an unique association between the local and remote peer.

cikePeerCorrIpSecTunIndex

1.3.6.1.4.1.9.9.171.1.2.4.1.7

Integer32 (1..2147483647)

The index of the active IPsec Phase-2 Tunnel (cipSecTunIndex in the cipSecTunnelTable) for this IPsec Phase-1 IKE Peer Association.

cikePhase1GWStatsTable

1.3.6.1.4.1.9.9.171.1.2.5

Index: cmgwIndex

Phase-1 IKE stats information is included in this table. Each entry is related to a specific gateway which is identified by 'cmgwIndex'.

from CISCO-MEDIA-GATEWAY-MIB

cmgwIndex

Integer32 (1..2147483647)

An index that uniquely identifies an entry in the cMediaGwTable.

cikePhase1GWActiveTunnels

1.3.6.1.4.1.9.9.171.1.2.5.1.1

Gauge32

The number of currently active IPsec Phase-1 IKE Tunnels.

cikePhase1GWPreviousTunnels

1.3.6.1.4.1.9.9.171.1.2.5.1.2

Counter32 · SAs

The total number of previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInOctets

1.3.6.1.4.1.9.9.171.1.2.5.1.3

Counter32 · Octets

The total number of octets received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInPkts

1.3.6.1.4.1.9.9.171.1.2.5.1.4

Counter32 · Packets

The total number of packets received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInDropPkts

1.3.6.1.4.1.9.9.171.1.2.5.1.5

Counter32 · Packets

The total number of packets which were dropped during receive processing by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInNotifys

1.3.6.1.4.1.9.9.171.1.2.5.1.6

Counter32 · Notification Payloads

The total number of notifys received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.5.1.7

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.5.1.8

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were received and found to be invalid by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.5.1.9

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were received and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.5.1.10

Counter32 · Notification Payloads

The total number of IPsec Phase-2 'Security Association' delete requests received by all currently and previously active and IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutOctets

1.3.6.1.4.1.9.9.171.1.2.5.1.11

Counter32 · Octets

The total number of octets sent by all currently and previously active and IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutPkts

1.3.6.1.4.1.9.9.171.1.2.5.1.12

Counter32 · Packets

The total number of packets sent by all currently and previously active and IPsec Phase-1 Tunnels.

cikePhase1GWOutDropPkts

1.3.6.1.4.1.9.9.171.1.2.5.1.13

Counter32 · Packets

The total number of packets which were dropped during send processing by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutNotifys

1.3.6.1.4.1.9.9.171.1.2.5.1.14

Counter32 · Notification Payloads

The total number of notifys sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutP2Exchgs

1.3.6.1.4.1.9.9.171.1.2.5.1.15

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.2.5.1.16

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent and found to be invalid by all currently and previously active IPsec Phase-1 Tunnels.

cikePhase1GWOutP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.2.5.1.17

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges which were sent and rejected by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWOutP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.2.5.1.18

Counter32 · Notification Payloads

The total number of IPsec Phase-2 SA delete requests sent by all currently and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWInitTunnels

1.3.6.1.4.1.9.9.171.1.2.5.1.19

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were locally initiated.

cikePhase1GWInitTunnelFails

1.3.6.1.4.1.9.9.171.1.2.5.1.20

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were locally initiated and failed to activate.

cikePhase1GWRespTunnelFails

1.3.6.1.4.1.9.9.171.1.2.5.1.21

Counter32 · SAs

The total number of IPsec Phase-1 IKE Tunnels which were remotely initiated and failed to activate.

cikePhase1GWSysCapFails

1.3.6.1.4.1.9.9.171.1.2.5.1.22

Counter32 · Failures

The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-1 IKE Tunnels.

cikePhase1GWAuthFails

1.3.6.1.4.1.9.9.171.1.2.5.1.23

Counter32 · Failures

The total number of authentications which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikePhase1GWDecryptFails

1.3.6.1.4.1.9.9.171.1.2.5.1.24

Counter32 · Failures

The total number of decryptions which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikePhase1GWHashValidFails

1.3.6.1.4.1.9.9.171.1.2.5.1.25

Counter32 · Failures

The total number of hash validations which ended in failure by all current and previous IPsec Phase-1 IKE Tunnels.

cikePhase1GWNoSaFails

1.3.6.1.4.1.9.9.171.1.2.5.1.26

Counter32 · Failures

The total number of non-existent 'Security Association' failures occurred during processing of current and previous IPsec Phase-1 IKE Tunnels.

cipSecTunnelTable

1.3.6.1.4.1.9.9.171.1.3.2

Index: cipSecTunIndex

The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.

cipSecTunIndex

1.3.6.1.4.1.9.9.171.1.3.2.1.1

Integer32 (1..2147483647)

The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.

cipSecTunIkeTunnelIndex

1.3.6.1.4.1.9.9.171.1.3.2.1.2

Integer32 (1..2147483647)

The index of the associated IPsec Phase-1 IKE Tunnel. (cikeTunIndex in the cikeTunnelTable)

cipSecTunIkeTunnelAlive

1.3.6.1.4.1.9.9.171.1.3.2.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

An indicator which specifies whether or not the IPsec Phase-1 IKE Tunnel currently exists.

cipSecTunLocalAddr

1.3.6.1.4.1.9.9.171.1.3.2.1.4

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-2 Tunnel.

cipSecTunRemoteAddr

1.3.6.1.4.1.9.9.171.1.3.2.1.5

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

cipSecTunKeyType

1.3.6.1.4.1.9.9.171.1.3.2.1.6

KeyType1 = ike2 = manualThe type of key used by an IPsec Phase-2 Tunnel. · Integer32

The type of key used by the IPsec Phase-2 Tunnel.

cipSecTunEncapMode

1.3.6.1.4.1.9.9.171.1.3.2.1.7

EncapMode1 = tunnel2 = transportThe encapsulation mode used by an IPsec Phase-2 Tunnel. · Integer32

The encapsulation mode used by the IPsec Phase-2 Tunnel.

cipSecTunLifeSize

1.3.6.1.4.1.9.9.171.1.3.2.1.8

Integer32 (1..2147483647) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

cipSecTunLifeTime

1.3.6.1.4.1.9.9.171.1.3.2.1.9

Integer32 (1..2147483647) · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.

cipSecTunActiveTime

1.3.6.1.4.1.9.9.171.1.3.2.1.10

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecTunSaLifeSizeThreshold

1.3.6.1.4.1.9.9.171.1.3.2.1.11

Integer32 (1..2147483647) · KBytes

The security association LifeSize refresh threshold in kilobytes.

cipSecTunSaLifeTimeThreshold

1.3.6.1.4.1.9.9.171.1.3.2.1.12

Integer32 (1..2147483647) · Seconds

The security association LifeTime refresh threshold in seconds.

cipSecTunTotalRefreshes

1.3.6.1.4.1.9.9.171.1.3.2.1.13

Counter32 · QM Exchanges

The total number of security association refreshes performed.

cipSecTunExpiredSaInstances

1.3.6.1.4.1.9.9.171.1.3.2.1.14

Counter32 · SAs

The total number of security associations which have expired.

cipSecTunCurrentSaInstances

1.3.6.1.4.1.9.9.171.1.3.2.1.15

Gauge32

The number of security associations which are currently active or expiring.

cipSecTunInSaDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.3.2.1.16

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunInSaEncryptAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.17

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunInSaAhAuthAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.18

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

cipSecTunInSaEspAuthAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.19

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

cipSecTunInSaDecompAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.20

CompAlgo1 = none2 = ldfThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunOutSaDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.3.2.1.21

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.

cipSecTunOutSaEncryptAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.22

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.

cipSecTunOutSaAhAuthAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.23

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

cipSecTunOutSaEspAuthAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.24

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

cipSecTunOutSaCompAlgo

1.3.6.1.4.1.9.9.171.1.3.2.1.25

CompAlgo1 = none2 = ldfThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunInOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.26

Counter32 · Octets

The total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecTunInOctWraps for the number of times this counter has wrapped.

cipSecTunHcInOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.27

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

cipSecTunInOctWraps

1.3.6.1.4.1.9.9.171.1.3.2.1.28

Counter32 · Integral units

The number of times the octets received counter (cipSecTunInOctets) has wrapped.

cipSecTunInDecompOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.29

Counter32 · Octets

The total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunInOctets. See also cipSecTunInDecompOctWraps for the number of times this counter has wrapped.

cipSecTunHcInDecompOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.30

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunHcInOctets.

cipSecTunInDecompOctWraps

1.3.6.1.4.1.9.9.171.1.3.2.1.31

Counter32 · Integral units

The number of times the decompressed octets received counter (cipSecTunInDecompOctets) has wrapped.

cipSecTunInPkts

1.3.6.1.4.1.9.9.171.1.3.2.1.32

Counter32 · Packets

The total number of packets received by this IPsec Phase-2 Tunnel.

cipSecTunInDropPkts

1.3.6.1.4.1.9.9.171.1.3.2.1.33

Counter32 · Packets

The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.

cipSecTunInReplayDropPkts

1.3.6.1.4.1.9.9.171.1.3.2.1.34

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.

cipSecTunInAuths

1.3.6.1.4.1.9.9.171.1.3.2.1.35

Counter32 · Events

The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.

cipSecTunInAuthFails

1.3.6.1.4.1.9.9.171.1.3.2.1.36

Counter32 · Failures

The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .

cipSecTunInDecrypts

1.3.6.1.4.1.9.9.171.1.3.2.1.37

Counter32 · Packets

The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.

cipSecTunInDecryptFails

1.3.6.1.4.1.9.9.171.1.3.2.1.38

Counter32 · Failures

The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecTunOutOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.39

Counter32 · Octets

The total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecTunOutOctWraps for the number of times this counter has wrapped.

cipSecTunHcOutOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.40

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.

cipSecTunOutOctWraps

1.3.6.1.4.1.9.9.171.1.3.2.1.41

Counter32 · Integral units

The number of times the out octets counter (cipSecTunOutOctets) has wrapped.

cipSecTunOutUncompOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.42

Counter32 · Octets

The total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunOutOctets. See also cipSecTunOutDecompOctWraps for the number of times this counter has wrapped.

cipSecTunHcOutUncompOctets

1.3.6.1.4.1.9.9.171.1.3.2.1.43

Counter64 (0..18446744073709551615)

A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunHcOutOctets.

cipSecTunOutUncompOctWraps

1.3.6.1.4.1.9.9.171.1.3.2.1.44

Counter32 · Integral units

The number of times the uncompressed octets sent counter (cipSecTunOutUncompOctets) has wrapped.

cipSecTunOutPkts

1.3.6.1.4.1.9.9.171.1.3.2.1.45

Counter32 · Packets

The total number of packets sent by this IPsec Phase-2 Tunnel.

cipSecTunOutDropPkts

1.3.6.1.4.1.9.9.171.1.3.2.1.46

Counter32 · Packets

The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.

cipSecTunOutAuths

1.3.6.1.4.1.9.9.171.1.3.2.1.47

Counter32 · Events

The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.

cipSecTunOutAuthFails

1.3.6.1.4.1.9.9.171.1.3.2.1.48

Counter32 · Failures

The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecTunOutEncrypts

1.3.6.1.4.1.9.9.171.1.3.2.1.49

Counter32 · Packets

The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.

cipSecTunOutEncryptFails

1.3.6.1.4.1.9.9.171.1.3.2.1.50

Counter32 · Failures

The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecTunStatus

1.3.6.1.4.1.9.9.171.1.3.2.1.51

TunnelStatus1 = active2 = destroyThe status of a Tunnel. Objects of this type may be used to bring the tunnel down by setting value of this object to destroy(2). Objects of this type cannot be used to create a Tunnel. · Integer32

The status of the MIB table row. This object can be used to bring the tunnel down by setting value of this object to destroy(2). When the value is set to destroy(2), the SA bundle is destroyed and this row is deleted from this table. When this MIB value is queried, the value of active(1) is always returned, if the instance exists. This object cannot be used to create a MIB table row.

cipSecEndPtTable

1.3.6.1.4.1.9.9.171.1.3.3

Index: cipSecTunIndex · cipSecEndPtIndex

The IPsec Phase-2 Tunnel Endpoint Table. This table contains an entry for each active endpoint associated with an IPsec Phase-2 Tunnel.

cipSecEndPtIndex

1.3.6.1.4.1.9.9.171.1.3.3.1.1

Integer32 (1..2147483647)

The number of the Endpoint associated with the IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.

cipSecEndPtLocalName

1.3.6.1.4.1.9.9.171.1.3.3.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the local Endpoint.

cipSecEndPtLocalType

1.3.6.1.4.1.9.9.171.1.3.3.1.3

EndPtType1 = singleIpAddr2 = ipAddrRange3 = ipSubnetThe type of identity use to specify an IPsec End Point. · Integer32

The type of identity for the local Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.

cipSecEndPtLocalAddr1

1.3.6.1.4.1.9.9.171.1.3.3.1.4

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range.

cipSecEndPtLocalAddr2

1.3.6.1.4.1.9.9.171.1.3.3.1.5

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range.

cipSecEndPtLocalProtocol

1.3.6.1.4.1.9.9.171.1.3.3.1.6

Integer32 (0..255)

The protocol number of the local Endpoint's traffic.

cipSecEndPtLocalPort

1.3.6.1.4.1.9.9.171.1.3.3.1.7

Integer32 (0..65535)

The port number of the local Endpoint's traffic.

cipSecEndPtRemoteName

1.3.6.1.4.1.9.9.171.1.3.3.1.8

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the remote Endpoint.

cipSecEndPtRemoteType

1.3.6.1.4.1.9.9.171.1.3.3.1.9

EndPtType1 = singleIpAddr2 = ipAddrRange3 = ipSubnetThe type of identity use to specify an IPsec End Point. · Integer32

The type of identity for the remote Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.

cipSecEndPtRemoteAddr1

1.3.6.1.4.1.9.9.171.1.3.3.1.10

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range.

cipSecEndPtRemoteAddr2

1.3.6.1.4.1.9.9.171.1.3.3.1.11

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range.

cipSecEndPtRemoteProtocol

1.3.6.1.4.1.9.9.171.1.3.3.1.12

Integer32 (0..255)

The protocol number of the remote Endpoint's traffic.

cipSecEndPtRemotePort

1.3.6.1.4.1.9.9.171.1.3.3.1.13

Integer32 (0..65535)

The port number of the remote Endpoint's traffic.

cipSecSpiTable

1.3.6.1.4.1.9.9.171.1.3.4

Index: cipSecTunIndex · cipSecSpiIndex

The IPsec Phase-2 Security Protection Index Table. This table contains an entry for each active and expiring security association.

cipSecSpiIndex

1.3.6.1.4.1.9.9.171.1.3.4.1.1

Integer32 (1..2147483647)

The number of the SPI associated with the Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.

cipSecSpiDirection

1.3.6.1.4.1.9.9.171.1.3.4.1.2

INTEGER1 = in2 = out · Integer32

The direction of the SPI.

cipSecSpiValue

1.3.6.1.4.1.9.9.171.1.3.4.1.3

Unsigned32 (1..4294967295)

The value of the SPI.

cipSecSpiProtocol

1.3.6.1.4.1.9.9.171.1.3.4.1.4

INTEGER1 = ah2 = esp3 = ipcomp · Integer32

The protocol of the SPI.

cipSecSpiStatus

1.3.6.1.4.1.9.9.171.1.3.4.1.5

INTEGER1 = active2 = expiring · Integer32

The status of the SPI.

cipSecPhase2GWStatsTable

1.3.6.1.4.1.9.9.171.1.3.5

Index: cmgwIndex

Phase-2 IPsec stats information is included in this table. Each entry is related to a specific gateway which is identified by 'cmgwIndex'

from CISCO-MEDIA-GATEWAY-MIB

cmgwIndex

Integer32 (1..2147483647)

An index that uniquely identifies an entry in the cMediaGwTable.

cipSecPhase2GWActiveTunnels

1.3.6.1.4.1.9.9.171.1.3.5.1.1

Gauge32

The total number of currently active IPsec Phase-2 Tunnels.

cipSecPhase2GWPreviousTunnels

1.3.6.1.4.1.9.9.171.1.3.5.1.2

Counter32 · Phase-2 Tunnels

The total number of previously active IPsec Phase-2 Tunnels.

cipSecPhase2GWInOctets

1.3.6.1.4.1.9.9.171.1.3.5.1.3

Counter32 · Octets

The total number of octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecGlobalInOctWraps for the number of times this counter has wrapped.

cipSecPhase2GWInOctWraps

1.3.6.1.4.1.9.9.171.1.3.5.1.4

Counter32 · Integral units

The number of times the global octets received counter (cipSecGlobalInOctets) has wrapped.

cipSecPhase2GWInDecompOctets

1.3.6.1.4.1.9.9.171.1.3.5.1.5

Counter32 · Octets

The total number of decompressed octets received by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecGlobalInOctets. See also cipSecGlobalInDecompOctWraps for the number of times this counter has wrapped.

cipSecPhase2GWInDecompOctWraps

1.3.6.1.4.1.9.9.171.1.3.5.1.6

Counter32 · Integral units

The number of times the global decompressed octets received counter (cipSecGlobalInDecompOctets) has wrapped.

cipSecPhase2GWInPkts

1.3.6.1.4.1.9.9.171.1.3.5.1.7

Counter32 · Packets

The total number of packets received by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWInDrops

1.3.6.1.4.1.9.9.171.1.3.5.1.8

Counter32 · Packets

The total number of packets dropped during receive processing by all current and previous IPsec Phase-2 Tunnels. This count does NOT include packets dropped due to Anti-Replay processing.

cipSecPhase2GWInReplayDrops

1.3.6.1.4.1.9.9.171.1.3.5.1.9

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWInAuths

1.3.6.1.4.1.9.9.171.1.3.5.1.10

Counter32 · Events

The total number of inbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWInAuthFails

1.3.6.1.4.1.9.9.171.1.3.5.1.11

Counter32 · Failures

The total number of inbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWInDecrypts

1.3.6.1.4.1.9.9.171.1.3.5.1.12

Counter32 · Packets

The total number of inbound decryption's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWInDecryptFails

1.3.6.1.4.1.9.9.171.1.3.5.1.13

Counter32 · Packets

The total number of inbound decryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutOctets

1.3.6.1.4.1.9.9.171.1.3.5.1.14

Counter32 · Octets

The total number of octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecGlobalOutOctWraps for the number of times this counter has wrapped.

cipSecPhase2GWOutOctWraps

1.3.6.1.4.1.9.9.171.1.3.5.1.15

Counter32 · Integral units

The number of times the global octets sent counter (cipSecGlobalOutOctets) has wrapped.

cipSecPhase2GWOutUncompOctets

1.3.6.1.4.1.9.9.171.1.3.5.1.16

Counter32 · Octets

The total number of uncompressed octets sent by all current and previous IPsec Phase-2 Tunnels. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecGlobalOutOctets. See also cipSecGlobalOutDecompOctWraps for the number of times this counter has wrapped.

cipSecPhase2GWOutUncompOctWraps

1.3.6.1.4.1.9.9.171.1.3.5.1.17

Counter32 · Integral units

The number of times the global uncompressed octets sent counter (cipSecGlobalOutUncompOctets) has wrapped.

cipSecPhase2GWOutPkts

1.3.6.1.4.1.9.9.171.1.3.5.1.18

Counter32 · Packets

The total number of packets sent by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutDrops

1.3.6.1.4.1.9.9.171.1.3.5.1.19

Counter32 · Packets

The total number of packets dropped during send processing by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutAuths

1.3.6.1.4.1.9.9.171.1.3.5.1.20

Counter32 · Events

The total number of outbound authentication's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutAuthFails

1.3.6.1.4.1.9.9.171.1.3.5.1.21

Counter32 · Failures

The total number of outbound authentication's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutEncrypts

1.3.6.1.4.1.9.9.171.1.3.5.1.22

Counter32 · Packets

The total number of outbound encryption's performed by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWOutEncryptFails

1.3.6.1.4.1.9.9.171.1.3.5.1.23

Counter32 · Failures

The total number of outbound encryption's which ended in failure by all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWProtocolUseFails

1.3.6.1.4.1.9.9.171.1.3.5.1.24

Counter32 · Failures

The total number of protocol use failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

cipSecPhase2GWNoSaFails

1.3.6.1.4.1.9.9.171.1.3.5.1.25

Counter32 · Failures

The total number of non-existent Security Association in failures which occurred during processing of all current and previous IPsec Phase-2 Tunnels.

cipSecPhase2GWSysCapFails

1.3.6.1.4.1.9.9.171.1.3.5.1.26

Counter32 · Failures

The total number of system capacity failures which occurred during processing of all current and previously active IPsec Phase-2 Tunnels.

cikeTunnelHistTable

1.3.6.1.4.1.9.9.171.1.4.2.1

Index: cikeTunHistIndex

The IPsec Phase-1 Internet Key Exchange Tunnel History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.

cikeTunHistIndex

1.3.6.1.4.1.9.9.171.1.4.2.1.1.1

Integer32 (1..2147483647)

The index of the IPsec Phase-1 IKE Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 2,147,483,647.

cikeTunHistTermReason

1.3.6.1.4.1.9.9.171.1.4.2.1.1.2

INTEGER1 = other2 = normal3 = operRequest4 = peerDelRequest5 = peerLost6 = localFailure7 = checkPointReg · Integer32

The reason the IPsec Phase-1 IKE Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = local failure occurred. 7 = operator initiated check point request

cikeTunHistActiveIndex

1.3.6.1.4.1.9.9.171.1.4.2.1.1.3

Integer32 (1..2147483647)

The index of the previously active IPsec Phase-1 IKE Tunnel.

cikeTunHistPeerLocalType

1.3.6.1.4.1.9.9.171.1.4.2.1.1.4

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.

cikeTunHistPeerLocalValue

1.3.6.1.4.1.9.9.171.1.4.2.1.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.

cikeTunHistPeerIntIndex

1.3.6.1.4.1.9.9.171.1.4.2.1.1.6

Integer32 (1..2147483647)

The internal index of the local-remote peer association. This internal index is used to uniquely identify multiple associations between the local and remote peer.

cikeTunHistPeerRemoteType

1.3.6.1.4.1.9.9.171.1.4.2.1.1.7

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.

cikeTunHistPeerRemoteValue

1.3.6.1.4.1.9.9.171.1.4.2.1.1.8

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.

cikeTunHistLocalAddr

1.3.6.1.4.1.9.9.171.1.4.2.1.1.9

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-1 IKE Tunnel.

cikeTunHistLocalName

1.3.6.1.4.1.9.9.171.1.4.2.1.1.10

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the local IP address for the IPsec Phase-1 IKE Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a NULL string.

cikeTunHistRemoteAddr

1.3.6.1.4.1.9.9.171.1.4.2.1.1.11

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-1 IKE Tunnel.

cikeTunHistRemoteName

1.3.6.1.4.1.9.9.171.1.4.2.1.1.12

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the remote IP address of IPsec Phase-1 IKE Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a NULL string.

cikeTunHistNegoMode

1.3.6.1.4.1.9.9.171.1.4.2.1.1.13

IkeNegoMode1 = main2 = aggressiveThe IPsec Phase-1 IKE negotiation mode. · Integer32

The negotiation mode of the IPsec Phase-1 IKE Tunnel.

cikeTunHistDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.4.2.1.1.14

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.

cikeTunHistEncryptAlgo

1.3.6.1.4.1.9.9.171.1.4.2.1.1.15

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used in IPsec Phase-1 IKE negotiations.

cikeTunHistHashAlgo

1.3.6.1.4.1.9.9.171.1.4.2.1.1.16

IkeHashAlgo1 = none2 = md53 = shaThe hash algorithm used in IPsec Phase-1 IKE negotiations. · Integer32

The hash algorithm used in IPsec Phase-1 IKE negotiations.

cikeTunHistAuthMethod

1.3.6.1.4.1.9.9.171.1.4.2.1.1.17

IkeAuthMethod1 = none2 = preSharedKey3 = rsaSig4 = rsaEncrypt5 = revPublicKeyThe authentication method used in IPsec Phase-1 IKE negotiations. · Integer32

The authentication method used in IPsec Phase-1 IKE negotiations.

cikeTunHistLifeTime

1.3.6.1.4.1.9.9.171.1.4.2.1.1.18

Integer32 (1..2147483647)

The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.

cikeTunHistStartTime

1.3.6.1.4.1.9.9.171.1.4.2.1.1.19

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds when the IPsec Phase-1 IKE tunnel was started.

cikeTunHistActiveTime

1.3.6.1.4.1.9.9.171.1.4.2.1.1.20

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-1 IKE tunnel was been active in hundredths of seconds.

cikeTunHistTotalRefreshes

1.3.6.1.4.1.9.9.171.1.4.2.1.1.21

Counter32 · QM Exchanges

The total number of security associations refreshes performed.

cikeTunHistTotalSas

1.3.6.1.4.1.9.9.171.1.4.2.1.1.22

Counter32 · SAs

The total number of security associations used during the life of the IPsec Phase-1 IKE Tunnel.

cikeTunHistInOctets

1.3.6.1.4.1.9.9.171.1.4.2.1.1.23

Counter32 · Octets

The total number of octets received by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInPkts

1.3.6.1.4.1.9.9.171.1.4.2.1.1.24

Counter32 · Packets

The total number of packets received by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInDropPkts

1.3.6.1.4.1.9.9.171.1.4.2.1.1.25

Counter32 · Packets

The total number of packets dropped by this IPsec Phase-1 IKE Tunnel during receive processing.

cikeTunHistInNotifys

1.3.6.1.4.1.9.9.171.1.4.2.1.1.26

Counter32 · Notification Payloads

The total number of notifys received by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInP2Exchgs

1.3.6.1.4.1.9.9.171.1.4.2.1.1.27

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.4.2.1.1.28

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received and found to be invalid by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.4.2.1.1.29

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges received and rejected by this IPsec Phase-1 IKE Tunnel.

cikeTunHistInP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.4.2.1.1.30

Counter32 · Notification Payloads

The total number of IPsec Phase-2 security association delete requests received by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutOctets

1.3.6.1.4.1.9.9.171.1.4.2.1.1.31

Counter32 · Octets

The total number of octets sent by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutPkts

1.3.6.1.4.1.9.9.171.1.4.2.1.1.32

Counter32 · Packets

The total number of packets sent by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutDropPkts

1.3.6.1.4.1.9.9.171.1.4.2.1.1.33

Counter32 · Packets

The total number of packets dropped by this IPsec Phase-1 IKE Tunnel during send processing.

cikeTunHistOutNotifys

1.3.6.1.4.1.9.9.171.1.4.2.1.1.34

Counter32 · Notification Payloads

The total number of notifys sent by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutP2Exchgs

1.3.6.1.4.1.9.9.171.1.4.2.1.1.35

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutP2ExchgInvalids

1.3.6.1.4.1.9.9.171.1.4.2.1.1.36

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent and found to be invalid by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutP2ExchgRejects

1.3.6.1.4.1.9.9.171.1.4.2.1.1.37

Counter32 · SA Payloads

The total number of IPsec Phase-2 exchanges sent and rejected by this IPsec Phase-1 IKE Tunnel.

cikeTunHistOutP2SaDelRequests

1.3.6.1.4.1.9.9.171.1.4.2.1.1.38

Counter32 · Notification Payloads

The total number of IPsec Phase-2 security association delete requests sent by this IPsec Phase-1 IKE Tunnel.

cipSecTunnelHistTable

1.3.6.1.4.1.9.9.171.1.4.3.1

Index: cipSecTunHistIndex

The IPsec Phase-2 Tunnel History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.

cipSecTunHistIndex

1.3.6.1.4.1.9.9.171.1.4.3.1.1.1

Integer32 (1..2147483647)

The index of the IPsec Phase-2 Tunnel History Table. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 2,147,483,647.

cipSecTunHistTermReason

1.3.6.1.4.1.9.9.171.1.4.3.1.1.2

INTEGER1 = other2 = normal3 = operRequest4 = peerDelRequest5 = peerLost6 = seqNumRollOver7 = checkPointReq · Integer32

The reason the IPsec Phase-2 Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = local failure occurred 7 = operator initiated check point request

cipSecTunHistActiveIndex

1.3.6.1.4.1.9.9.171.1.4.3.1.1.3

Integer32 (1..2147483647)

The index of the previously active IPsec Phase-2 Tunnel.

cipSecTunHistIkeTunnelIndex

1.3.6.1.4.1.9.9.171.1.4.3.1.1.4

Integer32 (1..2147483647)

The index of the associated IPsec Phase-1 Tunnel (cikeTunIndex in the cikeTunnelTable).

cipSecTunHistLocalAddr

1.3.6.1.4.1.9.9.171.1.4.3.1.1.5

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local endpoint for the IPsec Phase-2 Tunnel.

cipSecTunHistRemoteAddr

1.3.6.1.4.1.9.9.171.1.4.3.1.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote endpoint for the IPsec Phase-2 Tunnel.

cipSecTunHistKeyType

1.3.6.1.4.1.9.9.171.1.4.3.1.1.7

KeyType1 = ike2 = manualThe type of key used by an IPsec Phase-2 Tunnel. · Integer32

The type of key used by the IPsec Phase-2 Tunnel.

cipSecTunHistEncapMode

1.3.6.1.4.1.9.9.171.1.4.3.1.1.8

EncapMode1 = tunnel2 = transportThe encapsulation mode used by an IPsec Phase-2 Tunnel. · Integer32

The encapsulation mode used by the IPsec Phase-2 Tunnel.

cipSecTunHistLifeSize

1.3.6.1.4.1.9.9.171.1.4.3.1.1.9

Integer32 (1..2147483647) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

cipSecTunHistLifeTime

1.3.6.1.4.1.9.9.171.1.4.3.1.1.10

Integer32 (1..2147483647) · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.

cipSecTunHistStartTime

1.3.6.1.4.1.9.9.171.1.4.3.1.1.11

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds when the IPsec Phase-2 Tunnel was started.

cipSecTunHistActiveTime

1.3.6.1.4.1.9.9.171.1.4.3.1.1.12

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecTunHistTotalRefreshes

1.3.6.1.4.1.9.9.171.1.4.3.1.1.13

Counter32 · QM Exchanges

The total number of security association refreshes performed.

cipSecTunHistTotalSas

1.3.6.1.4.1.9.9.171.1.4.3.1.1.14

Counter32 · SAs

The total number of security associations used during the life of the IPsec Phase-2 Tunnel.

cipSecTunHistInSaDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.4.3.1.1.15

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistInSaEncryptAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.16

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistInSaAhAuthAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.17

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

cipSecTunHistInSaEspAuthAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.18

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

cipSecTunHistInSaDecompAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.19

CompAlgo1 = none2 = ldfThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The decompression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistOutSaDiffHellmanGrp

1.3.6.1.4.1.9.9.171.1.4.3.1.1.20

DiffHellmanGrp1 = none2 = dhGroup13 = dhGroup2The Diffie Hellman Group used in negotiations. · Integer32

The Diffie Hellman Group used by the outbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistOutSaEncryptAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.21

EncryptAlgo1 = none2 = des3 = des3The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used by the outbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistOutSaAhAuthAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.22

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the outbound authentication header (AH) security association of the IPsec Phase-2 Tunnel.

cipSecTunHistOutSaEspAuthAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.23

AuthAlgo1 = none2 = hmacMd53 = hmacShaThe authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The authentication algorithm used by the inbound encapsulation security protocol (ESP) security association of the IPsec Phase-2 Tunnel.

cipSecTunHistOutSaCompAlgo

1.3.6.1.4.1.9.9.171.1.4.3.1.1.24

CompAlgo1 = none2 = ldfThe compression algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The compression algorithm used by the inbound security association of the IPsec Phase-2 Tunnel.

cipSecTunHistInOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.25

Counter32 · Octets

The total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed. See also cipSecTunInOctWraps for the number of times this counter has wrapped.

cipSecTunHistHcInOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.26

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets received by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE determining whether or not the packet should be decompressed.

cipSecTunHistInOctWraps

1.3.6.1.4.1.9.9.171.1.4.3.1.1.27

Counter32 · Integral units

The number of times the octets received counter (cipSecTunInOctets) has wrapped.

cipSecTunHistInDecompOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.28

Counter32 · Octets

The total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunHistInOctets. See also cipSecTunInDecompOctWraps for the number of times this counter has wrapped.

cipSecTunHistHcInDecompOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.29

Counter64 (0..18446744073709551615)

A high capacity count of the total number of decompressed octets received by this IPsec Phase-2 Tunnel. This value is accumulated AFTER the packet is decompressed. If compression is not being used, this value will match the value of cipSecTunHistHcInOctets.

cipSecTunHistInDecompOctWraps

1.3.6.1.4.1.9.9.171.1.4.3.1.1.30

Counter32 · Integral units

The number of times the decompressed octets received counter (cipSecTunInDecompOctets) has wrapped.

cipSecTunHistInPkts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.31

Counter32 · Packets

The total number of packets received by this IPsec Phase-2 Tunnel.

cipSecTunHistInDropPkts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.32

Counter32 · Packets

The total number of packets dropped during receive processing by this IPsec Phase-2 Tunnel. This count does NOT include packets dropped due to Anti-Replay processing.

cipSecTunHistInReplayDropPkts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.33

Counter32 · Packets

The total number of packets dropped during receive processing due to Anti-Replay processing by this IPsec Phase-2 Tunnel.

cipSecTunHistInAuths

1.3.6.1.4.1.9.9.171.1.4.3.1.1.34

Counter32 · Events

The total number of inbound authentication's performed by this IPsec Phase-2 Tunnel.

cipSecTunHistInAuthFails

1.3.6.1.4.1.9.9.171.1.4.3.1.1.35

Counter32 · Failures

The total number of inbound authentication's which ended in failure by this IPsec Phase-2 Tunnel .

cipSecTunHistInDecrypts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.36

Counter32 · Packets

The total number of inbound decryption's performed by this IPsec Phase-2 Tunnel.

cipSecTunHistInDecryptFails

1.3.6.1.4.1.9.9.171.1.4.3.1.1.37

Counter32 · Failures

The total number of inbound decryption's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecTunHistOutOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.38

Counter32 · Octets

The total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed. See also cipSecTunOutOctWraps for the number of times this counter has wrapped.

cipSecTunHistHcOutOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.39

Counter64 (0..18446744073709551615)

A high capacity count of the total number of octets sent by this IPsec Phase-2 Tunnel. This value is accumulated AFTER determining whether or not the packet should be compressed.

cipSecTunHistOutOctWraps

1.3.6.1.4.1.9.9.171.1.4.3.1.1.40

Counter32 · Integral units

The number of times the octets sent counter (cipSecTunOutOctets) has wrapped.

cipSecTunHistOutUncompOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.41

Counter32 · Octets

The total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunHistOutOctets. See also cipSecTunOutDecompOctWraps for the number of times this counter has wrapped.

cipSecTunHistHcOutUncompOctets

1.3.6.1.4.1.9.9.171.1.4.3.1.1.42

Counter64 (0..18446744073709551615) · Octets

A high capacity count of the total number of uncompressed octets sent by this IPsec Phase-2 Tunnel. This value is accumulated BEFORE the packet is compressed. If compression is not being used, this value will match the value of cipSecTunHistHcOutOctets.

cipSecTunHistOutUncompOctWraps

1.3.6.1.4.1.9.9.171.1.4.3.1.1.43

Counter32 · Integral units

The number of times the uncompressed octets sent counter (cipSecTunOutUncompOctets) has wrapped.

cipSecTunHistOutPkts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.44

Counter32 · Packets

The total number of packets sent by this IPsec Phase-2 Tunnel.

cipSecTunHistOutDropPkts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.45

Counter32 · Packets

The total number of packets dropped during send processing by this IPsec Phase-2 Tunnel.

cipSecTunHistOutAuths

1.3.6.1.4.1.9.9.171.1.4.3.1.1.46

Counter32 · Events

The total number of outbound authentication's performed by this IPsec Phase-2 Tunnel.

cipSecTunHistOutAuthFails

1.3.6.1.4.1.9.9.171.1.4.3.1.1.47

Counter32 · Failures

The total number of outbound authentication's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecTunHistOutEncrypts

1.3.6.1.4.1.9.9.171.1.4.3.1.1.48

Counter32 · Packets

The total number of outbound encryption's performed by this IPsec Phase-2 Tunnel.

cipSecTunHistOutEncryptFails

1.3.6.1.4.1.9.9.171.1.4.3.1.1.49

Counter32 · Failures

The total number of outbound encryption's which ended in failure by this IPsec Phase-2 Tunnel.

cipSecEndPtHistTable

1.3.6.1.4.1.9.9.171.1.4.3.2

Index: cipSecEndPtHistIndex

The IPsec Phase-2 Tunnel Endpoint History Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecHistTableSize object.

cipSecEndPtHistIndex

1.3.6.1.4.1.9.9.171.1.4.3.2.1.1

Integer32 (1..2147483647)

The number of the previously active Endpoint associated with a IPsec Phase-2 Tunnel Table. The value of this index is a number which begins at one and is incremented with each Endpoint associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.

cipSecEndPtHistTunIndex

1.3.6.1.4.1.9.9.171.1.4.3.2.1.2

Integer32 (1..2147483647)

The index of the previously active IPsec Phase-2 Tunnel Table.

cipSecEndPtHistActiveIndex

1.3.6.1.4.1.9.9.171.1.4.3.2.1.3

Integer32 (1..2147483647)

The index of the previously active Endpoint.

cipSecEndPtHistLocalName

1.3.6.1.4.1.9.9.171.1.4.3.2.1.4

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the local Endpoint.

cipSecEndPtHistLocalType

1.3.6.1.4.1.9.9.171.1.4.3.2.1.5

EndPtType1 = singleIpAddr2 = ipAddrRange3 = ipSubnetThe type of identity use to specify an IPsec End Point. · Integer32

The type of identity for the local Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.

cipSecEndPtHistLocalAddr1

1.3.6.1.4.1.9.9.171.1.4.3.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The local Endpoint's first IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet. If the local Endpoint type is IP address range, then this is the value of beginning IP address of the range.

cipSecEndPtHistLocalAddr2

1.3.6.1.4.1.9.9.171.1.4.3.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The local Endpoint's second IP address specification. If the local Endpoint type is single IP address, then this is the value of the IP address. If the local Endpoint type is IP subnet, then this is the value of the subnet mask. If the local Endpoint type is IP address range, then this is the value of ending IP address of the range.

cipSecEndPtHistLocalProtocol

1.3.6.1.4.1.9.9.171.1.4.3.2.1.8

Integer32 (0..255)

The protocol number of the local Endpoint's traffic.

cipSecEndPtHistLocalPort

1.3.6.1.4.1.9.9.171.1.4.3.2.1.9

Integer32 (0..65535)

The port number of the local Endpoint's traffic.

cipSecEndPtHistRemoteName

1.3.6.1.4.1.9.9.171.1.4.3.2.1.10

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The DNS name of the remote Endpoint.

cipSecEndPtHistRemoteType

1.3.6.1.4.1.9.9.171.1.4.3.2.1.11

EndPtType1 = singleIpAddr2 = ipAddrRange3 = ipSubnetThe type of identity use to specify an IPsec End Point. · Integer32

The type of identity for the remote Endpoint. Possible values are: 1) a single IP address, or 2) an IP address range, or 3) an IP subnet.

cipSecEndPtHistRemoteAddr1

1.3.6.1.4.1.9.9.171.1.4.3.2.1.12

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The remote Endpoint's first IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet. If the remote Endpoint type is IP address range, then this is the value of beginning IP address of the range.

cipSecEndPtHistRemoteAddr2

1.3.6.1.4.1.9.9.171.1.4.3.2.1.13

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The remote Endpoint's second IP address specification. If the remote Endpoint type is single IP address, then this is the value of the IP address. If the remote Endpoint type is IP subnet, then this is the value of the subnet mask. If the remote Endpoint type is IP address range, then this is the value of ending IP address of the range.

cipSecEndPtHistRemoteProtocol

1.3.6.1.4.1.9.9.171.1.4.3.2.1.14

Integer32 (0..255)

The protocol number of the remote Endpoint's traffic.

cipSecEndPtHistRemotePort

1.3.6.1.4.1.9.9.171.1.4.3.2.1.15

Integer32 (0..65535)

The port number of the remote Endpoint's traffic.

cikeFailTable

1.3.6.1.4.1.9.9.171.1.5.2.1

Index: cikeFailIndex

The IPsec Phase-1 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecFailTableSize object.

cikeFailIndex

1.3.6.1.4.1.9.9.171.1.5.2.1.1.1

Integer32 (1..2147483647)

The IPsec Phase-1 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 2,147,483,647.

cikeFailReason

1.3.6.1.4.1.9.9.171.1.5.2.1.1.2

INTEGER1 = other2 = peerDelRequest3 = peerLost4 = localFailure5 = authFailure6 = hashValidation7 = encryptFailure8 = internalError9 = sysCapExceeded10 = proposalFailure11 = peerCertUnavailable12 = peerCertNotValid13 = localCertExpired14 = crlFailure15 = peerEncodingError16 = nonExistentSa17 = operRequest · Integer32

The reason for the failure. Possible reasons include: 1 = other 2 = peer delete request was received 3 = contact with peer was lost 4 = local failure occurred 5 = authentication failure 6 = hash validation failure 7 = encryption failure 8 = internal error occurred 9 = system capacity failure 10 = proposal failure 11 = peer's certificate is unavailable 12 = peer's certificate was found invalid 13 = local certificate expired 14 = certificate revoke list (crl) failure 15 = peer encoding error 16 = non-existent security association 17 = operator requested termination.

cikeFailTime

1.3.6.1.4.1.9.9.171.1.5.2.1.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds at the time of the failure.

cikeFailLocalType

1.3.6.1.4.1.9.9.171.1.5.2.1.1.4

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. a host name.

cikeFailLocalValue

1.3.6.1.4.1.9.9.171.1.5.2.1.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is a host name, then this is the host name used to identify the local peer.

cikeFailRemoteType

1.3.6.1.4.1.9.9.171.1.5.2.1.1.6

IkePeerType1 = ipAddrPeer2 = namePeerThe type of IPsec Phase-1 IKE peer identity. The IKE peer may be identified by: 1. an IP address, or 2. a host name. · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. a host name.

cikeFailRemoteValue

1.3.6.1.4.1.9.9.171.1.5.2.1.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is a host name, then this is the host name used to identify the remote peer.

cikeFailLocalAddr

1.3.6.1.4.1.9.9.171.1.5.2.1.1.8

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikeFailRemoteAddr

1.3.6.1.4.1.9.9.171.1.5.2.1.1.9

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cipSecFailTable

1.3.6.1.4.1.9.9.171.1.5.3.1

Index: cipSecFailIndex

The IPsec Phase-2 Failure Table. This table is implemented as a sliding window in which only the last n entries are maintained. The maximum number of entries is specified by the cipSecFailTableSize object.

cipSecFailIndex

1.3.6.1.4.1.9.9.171.1.5.3.1.1.1

Integer32 (1..2147483647)

The IPsec Phase-2 Failure Table index. The value of the index is a number which begins at one and is incremented with each IPsec Phase-1 failure. The value of this object will wrap at 2,147,483,647.

cipSecFailReason

1.3.6.1.4.1.9.9.171.1.5.3.1.1.2

INTEGER1 = other2 = internalError3 = peerEncodingError4 = proposalFailure5 = protocolUseFail6 = nonExistentSa7 = decryptFailure8 = encryptFailure9 = inAuthFailure10 = outAuthFailure11 = compression12 = sysCapExceeded13 = peerDelRequest14 = peerLost15 = seqNumRollOver16 = operRequest · Integer32

The reason for the failure. Possible reasons include: 1 = other 2 = internal error occurred 3 = peer encoding error 4 = proposal failure 5 = protocol use failure 6 = non-existent security association 7 = decryption failure 8 = encryption failure 9 = inbound authentication failure 10 = outbound authentication failure 11 = compression failure 12 = system capacity failure 13 = peer delete request was received 14 = contact with peer was lost 15 = sequence number rolled over 16 = operator requested termination.

cipSecFailTime

1.3.6.1.4.1.9.9.171.1.5.3.1.1.3

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The value of sysUpTime in hundredths of seconds at the time of the failure.

cipSecFailTunnelIndex

1.3.6.1.4.1.9.9.171.1.5.3.1.1.4

Integer32 (1..2147483647)

The Phase-2 Tunnel index (cipSecTunIndex).

cipSecFailSaSpi

1.3.6.1.4.1.9.9.171.1.5.3.1.1.5

Integer32 (0..2147483647)

The security association SPI value.

cipSecFailPktSrcAddr

1.3.6.1.4.1.9.9.171.1.5.3.1.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The packet's source IP address.

cipSecFailPktDstAddr

1.3.6.1.4.1.9.9.171.1.5.3.1.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The packet's destination IP address.

Trap details

cikeTunnelStart

1.3.6.1.4.1.9.9.171.2.0.1

This notification is generated when an IPsec Phase-1 IKE Tunnel becomes active.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikeTunLifeTime

1.3.6.1.4.1.9.9.171.1.2.3.1.15

Integer32 (1..2147483647) · seconds

The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.

cikeTunnelStop

1.3.6.1.4.1.9.9.171.2.0.2

This notification is generated when an IPsec Phase-1 IKE Tunnel becomes inactive.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikeTunActiveTime

1.3.6.1.4.1.9.9.171.1.2.3.1.16

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.

cikeSysFailure

1.3.6.1.4.1.9.9.171.2.0.3

This notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences an internal or system capacity error.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikeCertCrlFailure

1.3.6.1.4.1.9.9.171.2.0.4

This notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a Certificate or a Certificate Revoke List (CRL) related error.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikeProtocolFailure

1.3.6.1.4.1.9.9.171.2.0.5

This notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a protocol related error.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cikeNoSa

1.3.6.1.4.1.9.9.171.2.0.6

This notification is generated when the processing for an IPsec Phase-1 IKE Tunnel experiences a non-existent security association error.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cipSecTunnelStart

1.3.6.1.4.1.9.9.171.2.0.7

This notification is generated when an IPsec Phase-2 Tunnel becomes active.

cipSecTunLifeTime

1.3.6.1.4.1.9.9.171.1.3.2.1.9

Integer32 (1..2147483647) · Seconds

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.

cipSecTunLifeSize

1.3.6.1.4.1.9.9.171.1.3.2.1.8

Integer32 (1..2147483647) · KBytes

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

cipSecTunnelStop

1.3.6.1.4.1.9.9.171.2.0.8

This notification is generated when an IPsec Phase-2 Tunnel becomes inactive.

cipSecTunActiveTime

1.3.6.1.4.1.9.9.171.1.3.2.1.10

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecSysFailure

1.3.6.1.4.1.9.9.171.2.0.9

This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences an internal or system capacity error.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cipSecTunActiveTime

1.3.6.1.4.1.9.9.171.1.3.2.1.10

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecSpiProtocol

1.3.6.1.4.1.9.9.171.1.3.4.1.4

INTEGER1 = ah2 = esp3 = ipcomp · Integer32

The protocol of the SPI.

cipSecSetUpFailure

1.3.6.1.4.1.9.9.171.2.0.10

This notification is generated when the setup for an IPsec Phase-2 Tunnel fails.

cikePeerLocalAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.6

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the local peer.

cikePeerRemoteAddr

1.3.6.1.4.1.9.9.171.1.2.2.1.7

IPSIpAddressAn IP V4 or V6 Address. SIZE (4 | 16) · OCTET STRING

The IP address of the remote peer.

cipSecEarlyTunTerm

1.3.6.1.4.1.9.9.171.2.0.11

This notification is generated when an an IPsec Phase-2 Tunnel is terminated earily or before expected.

cipSecTunActiveTime

1.3.6.1.4.1.9.9.171.1.3.2.1.10

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecSpiProtocol

1.3.6.1.4.1.9.9.171.1.3.4.1.4

INTEGER1 = ah2 = esp3 = ipcomp · Integer32

The protocol of the SPI.

cipSecProtocolFailure

1.3.6.1.4.1.9.9.171.2.0.12

This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences a protocol related error.

cipSecTunActiveTime

1.3.6.1.4.1.9.9.171.1.3.2.1.10

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

cipSecSpiProtocol

1.3.6.1.4.1.9.9.171.1.3.4.1.4

INTEGER1 = ah2 = esp3 = ipcomp · Integer32

The protocol of the SPI.

cipSecNoSa

1.3.6.1.4.1.9.9.171.2.0.13

This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences a non-existent security association error.

↑ To TOC