This MIB Module models status, performance and failures of a protocol with the generic characteristics of signalling protocols used with IPsec and FC-SP protocols. Examples of such protocols include IKE, KINK, etc. This MIB views the common attributes of such protocols. Signaling protocols are also referred in this document as 'Control Protocols', since they perform session control.
This MIB is an attempt to capture the generic aspects of the signaling activity. The protocol-specific aspects of a signaling protocol still need to be captured in a protocol-specific MIB (e.g., CISCO-IKE-FLOW-MIB, etc.).
Acronyms The following acronyms are used in this document:
IPsec: Secure IP Protocol
VPN: Virtual Private Network
ISAKMP: Internet Security Association and Key Exchange
Protocol
IKE: Internet Key Exchange Protocol
SA: Security Association
(ref: rfc2408).
Phase 1 Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document.
Control Tunnel: Another term for a Phase 1 Tunnel.
Phase 2 Tunnel:
An instance of a non-ISAKMP SA bundle in which all
the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh).
History of the MIB A precursor to this MIB was the IPsec Flow Monitor MIB, which combined the objects pertaining to IKE and IPsec (Phase-2) into a single MIB module. Furthermore, the MIB supported only one signaling protocol, IKEv1, in addition to manual keying.
The MIB was written by Tivoli and implemented in IBM Nways routers in 1999. During late 1999, Cisco adopted the MIB and together with Tivoli publised the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms.
With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt.
With the emergence to multiple signaling protocols, it has further evolved to define separate set of MIB modules to instrument IPsec signaling alone. Thus, this MIB module is now the generic IPsec signaling MIB.
Overview of MIB The MIB contains major groups of objects which are used to manage the generic aspects of IPsec signaling. These groups include a global statistics, control tunnel table, Peer association group, control tunnel history group, signaling failure group and notification group.
The global statistics, tunnel table and peer association groups aid in the real-time monitoring of IPsec signaling activity.
The History group is to aid applications that do trending analysis.
The Failure group is to enable an operator to do troubleshooting and debugging. Further, counters are supported to aid detection of potential security violations.
The notifications are modeled as generic IPsec control notifications and are parameterized by the identity of the specific signaling protocol which caused the notification to be issued.
The window size of the control tunnel History Tables.
The control tunnel history table is implemented as a sliding window in which at most the last 'cisgIpsSgHistTableSize' entries are maintained. This object is, hence, used to control the size of the tunnel history table.
An implementation may choose suitable values for this element based on the available resources. If an SNMP SET request specifies a value outside this window for this element, in appropriate SNMP error code should be returned.
Setting this value to zero is equivalent to deleting all conceptual rows in the archiving table ('cisgIpsSgTunnelHistTable') and disabling the archiving of entries in the tables.
cisgIpsSgFailTableSize
1.3.6.1.4.1.9.9.438.1.4.1.1.1
Unsigned32 (0..2147483647)
The window size of the Internet Key Exchange Failure Tables.
The Failure Table is implemented as a sliding window in which only the last 'cisgIpsSgFailTableSize' entries are maintained. This object is used specify the number of entries which will be maintained in the control tunnel Failure Table.
An implementation may choose suitable minimum and maximum values for this element based on the local policy and available resources. If an SNMP SET request specifies a value outside this window for this element, an appropriate SNMP error code must be returned.
Setting this value to zero is equivalent to deleting all conceptual rows in the archiving tables ('cisgIpsSgFailTable') and disabling the archiving of entries in this table.
cisgIpsSgNotifCntlAllNotifs
1.3.6.1.4.1.9.9.438.1.5.1
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object acts as the knob that controls the the administrative state of sending any notification defined in this MIB module. That is, a particular notification 'foo' defined in this MIB module is enabled if and only if the expression
cisgIpsSgNotifCntlAllNotifs && cisgIpsSgNotifCntl<foo> evaluates to 'true'.
cisgIpsSgNotifCntlTunnelStart
1.3.6.1.4.1.9.9.438.1.5.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of sending the Control Tunnel Start notification.
If the value of this object is 'true', the issuing of the notification 'cisgIpsSgTunnelStart' is enabled.
cisgIpsSgNotifCntlTunnelStop
1.3.6.1.4.1.9.9.438.1.5.3
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of sending the Control Tunnel Stop notification.
If the value of this object is 'true', the issuing of the notification 'cisgIpsSgTunnelStop' is enabled.
cisgIpsSgNotifCntlSysFailure
1.3.6.1.4.1.9.9.438.1.5.4
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of sending the System Failure notification.
If the value of this object is 'true', the issuing of the notification 'ciscoIpsSgSysFailure' is enabled.
cisgIpsSgNotifCntlCertCrlFail
1.3.6.1.4.1.9.9.438.1.5.5
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
This object defines the administrative state of sending the Certificate/CRL Failure notification.
If the value of this object is 'true', the issuing of the notification 'ciscoIpsSgCertCrlFailure' is enabled.
Table details
cisgIpsSgGlobalStatsTable
1.3.6.1.4.1.9.9.438.1.1.1
Index: cisgIpsSgProtocol
This Signaling Protocol global statistics table. There is one row in the following table for each signaling protocol implemented by the managed entity.
There is no row corresponding to the instance 'cpNone'.
If the managed entity implements more than one signaling protocol, the aggregate statistics across all the supported signaling protocols must be computed by the network management station manually; in other words, there is no conceptual row in this table corresponding to 'all signaling protocols'.
cisgIpsSgProtocol
1.3.6.1.4.1.9.9.438.1.1.1.1.1
CIPsecControlProtocol1 = cpUnknown2 = cpAll3 = cpOther4 = cpManual5 = cpIkev16 = cpIkev27 = cpKink8 = cpPhoturisThe protocol used for keying and control in IPsec connections. The value of 'cpManual' indicates manual administration of IPsec tunnels. This enumeration will be expanded as new keying protocols are standardized.
The value 'cpAll' does not denote a specific keying protocol; it has been defined only as a convenience to facilitate aggregation of metrics across all control protocols.
Description of enum constants of this type: cpManual: Denotes manual keying (i.e., no signaling).
cpIkev1: Denotes keying signaling using IKEv1 protocol.
cpIkev2: Denotes keying signaling using IKEv2 protocol.
cpKink: Denotes keying signaling using KINK.
cpPhoturis: Denotes keying signaling using Photuris. · Integer32
The identity of the signaling protocol used by the control tunnel corresponding to this conceptual row.
cisgIpsSgGlobalActiveTunnels
1.3.6.1.4.1.9.9.438.1.1.1.1.2
Gauge32
The number of currently active Phase-1 control tunnels.
cisgIpsSgGlobalPreviousTunnels
1.3.6.1.4.1.9.9.438.1.1.1.1.3
Counter64 (0..18446744073709551615) · SAs
High capacity counter to accumulate the total number of Phase-1 control tunnels that are no longer active.
cisgIpsSgGlobalInOctets
1.3.6.1.4.1.9.9.438.1.1.1.1.4
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by all currently and previously active Phase-1 Control Tunnels.
cisgIpsSgGlobalInPkts
1.3.6.1.4.1.9.9.438.1.1.1.1.5
Counter64 (0..18446744073709551615) · Packets
The total number of packets received by all currently and previously active Phase-1 Control Tunnels.
cisgIpsSgGlobalInDropPkts
1.3.6.1.4.1.9.9.438.1.1.1.1.6
Counter64 (0..18446744073709551615) · Packets
The total number of packets which were dropped during receive processing by all currently and previously active Phase-1 Control Tunnels.
The total number of Phase-2 tunnel delete requests sent by all currently and previously active Phase-1 Control Tunnels.
cisgIpsSgGlobalInitTunnels
1.3.6.1.4.1.9.9.438.1.1.1.1.14
Counter64 (0..18446744073709551615) · SAs
The total number of Phase-1 currently and previously active Control Tunnels which were locally initiated.
cisgIpsSgGlobalInitTunnelFails
1.3.6.1.4.1.9.9.438.1.1.1.1.15
Counter64 (0..18446744073709551615) · SAs
The total number of Phase-1 currently and previously active Control Tunnels which were locally initiated and failed to activate.
cisgIpsSgGlobalRespTunnels
1.3.6.1.4.1.9.9.438.1.1.1.1.16
Counter64 (0..18446744073709551615) · SAs
The total number of Phase-1 currently and previously active Control Tunnels which were remotely initiated.
cisgIpsSgGlobalRespTunnelFails
1.3.6.1.4.1.9.9.438.1.1.1.1.17
Counter64 (0..18446744073709551615) · SAs
The total number of Phase-1 currently and previously active Control Tunnels which were remotely initiated and failed to activate.
cisgIpsSgGlobalSysCapFails
1.3.6.1.4.1.9.9.438.1.1.1.1.18
Counter64 (0..18446744073709551615) · Failures
The total number of system capacity failures which occurred during processing of all current and previously active Phase-1 Control Tunnels.
cisgIpsSgGlobalAuthFails
1.3.6.1.4.1.9.9.438.1.1.1.1.19
Counter64 (0..18446744073709551615) · Failures
The total number of authentications which ended in failure by all current and previous Phase-1 Control Tunnels.
cisgIpsSgGlobalDecryptFails
1.3.6.1.4.1.9.9.438.1.1.1.1.20
Counter64 (0..18446744073709551615) · Failures
The total number of decryption operations in all current and previous Phase-1 Control Tunnels which failed to yield the original payload.
cisgIpsSgGlobalHashValidFails
1.3.6.1.4.1.9.9.438.1.1.1.1.21
Counter64 (0..18446744073709551615) · Failures
The total number of hash validation operations in all current and previous Phase-1 Control Tunnels which resulted in failure.
cisgIpsSgGlobalBadTunnelRefs
1.3.6.1.4.1.9.9.438.1.1.1.1.22
Counter64 (0..18446744073709551615) · Failures
The total number of incoming packets that refer to non-existent Phase-1 control tunnels which occurred during processing of all current and previous Phase-1 Control Tunnels.
The total number of Phase-1 security association delete requests sent by all currently and previously active and Phase-1 Control Tunnels.
cisgIpsSgTunnelTable
1.3.6.1.4.1.9.9.438.1.1.2
Index: cisgIpsSgProtocol · cisgIpsSgTunIndex
This table lists active Phase-1 control tunnels. There is one entry in this table for each active Control Tunnel.
cisgIpsSgTunIndex
1.3.6.1.4.1.9.9.438.1.1.2.1.1
CIPsecPhase1TunnelIndexThe index of the IPsec Phase-1 (IKE) Tunnel Table. An index of this type is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32
The index of the Phase-1 Tunnel Table. The value of the index is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 4,294,967,296.
cisgIpsSgTunLocalType
1.3.6.1.4.1.9.9.438.1.1.2.1.2
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the identity used by the managed entity authenticating itself to the peer in the setup of the tunnel corresponding to this conceptual row.
cisgIpsSgTunLocalValue
1.3.6.1.4.1.9.9.438.1.1.2.1.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the local peer identity.
cisgIpsSgTunLocalAddressType
1.3.6.1.4.1.9.9.438.1.1.2.1.4
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the local endpoint of the Phase-1 Tunnel.
cisgIpsSgTunLocalAddress
1.3.6.1.4.1.9.9.438.1.1.2.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the local endpoint for the Phase-1 Tunnel.
cisgIpsSgTunLocalName
1.3.6.1.4.1.9.9.438.1.1.2.1.6
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The DNS name of the local IP address for the Phase-1 Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a zero-length string.
cisgIpsSgTunRemoteType
1.3.6.1.4.1.9.9.438.1.1.2.1.7
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the identity used by the remote peer in authenticating itself to the local peer in the setup of the tunnel corresponding to this conceptual row.
cisgIpsSgTunRemoteValue
1.3.6.1.4.1.9.9.438.1.1.2.1.8
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the remote peer identity.
cisgIpsSgTunRemoteAddressType
1.3.6.1.4.1.9.9.438.1.1.2.1.9
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the remote endpoint for the Phase-1 Tunnel.
cisgIpsSgTunRemoteAddress
1.3.6.1.4.1.9.9.438.1.1.2.1.10
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the remote endpoint of the Phase-1 Tunnel.
cisgIpsSgTunRemoteName
1.3.6.1.4.1.9.9.438.1.1.2.1.11
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The DNS name of the remote address of Phase-1 Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a zero-length string.
cisgIpsSgTunEncryptAlgo
1.3.6.1.4.1.9.9.438.1.1.2.1.12
CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'.
Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES.
esp3des: Payload encryption using 168-bit 3DES.
espRc5: Payload encryption using RC5.
espIdea: Payload encryption using International Data Encryption Algorithm.
espCast: Payload encryption using CAST.
espTwofish: Payload encryption using TwoFish.
espBlowfish: Payload encryption using BlowFish.
esp3idea: Payload encryption using International Data Encryption Algorithm.
espRc4: Payload encryption using RC4.
espNull: NULL Payload encryption.
espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys.
espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32
The encryption algorithm used in Phase-1 negotiations on the control tunnel corresponding to this conceptual row.
cisgIpsSgTunEncryptKeySize
1.3.6.1.4.1.9.9.438.1.1.2.1.13
CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform.
The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits
The size in bits of the key used for encrypting payloads by the tunnel corresponding to this conceptual row.
cisgIpsSgTunHashAlgo
1.3.6.1.4.1.9.9.438.1.1.2.1.14
CIPsecIkeHashAlgorithm1 = none2 = other3 = md54 = sha5 = tiger6 = sha2567 = sha3848 = sha5129 = aesMacThe hash algorithm used in IPsec Phase-1 IKE negotiations.
Description of enum constants of this type: md5: Hash payload using MD5 algorithm.
sha: Hash payload using 96-bit SHA-1 algorithm as defined in FIPS 180-1.
tiger: Hash payload using Tiger hash algorithm.
sha256: Hash payload using 256-bit key SHA-1 algorithm.
sha384: Hash payload using 384-bit key SHA-1 algorithm.
sha512: Hash payload using 512-bit key SHA-1 algorithm.
aesMac Hash payload using AES-XCBC-MAC-96 algorithm.Reference: rfc2408 and rfc2409 · Integer32
The hash algorithm used in Phase-1 negotiations on the control tunnel corresponding to this conceptual row.
cisgIpsSgTunAuthMethod
1.3.6.1.4.1.9.9.438.1.1.2.1.15
CIPsecIkeAuthMethod1 = other2 = preSharedKey3 = rsaSignature4 = rsaEncryption5 = revRsaEncryption6 = dssSignature7 = elGamalEncryption8 = revElGamalEncryption9 = ecsdaSignature10 = gssApiV111 = gssApiV2The authentication method used in IPsec Phase-1 IKE negotiations.
Description of enum constants of this type: preSharedKey: Peer authentication using pre-shared keys.
rsaSignature: Peer authentication using digital signatures.
rsaEncryption: Peer authentication using encrypted nonces.
revRsaEncryption: Peer authentication using revised RSA encryption.
dssSignature: Peer authentication using DSS signatures.
elGamalEncryption: Peer authentication using El Gamal.
revElGamalEncryption: Peer authentication using revised El Gamal.
ecdsaSignature: Peer authentication using Elliptic Curve Digital Signatures.
gssApiV1: Peer authentication using Generic Security Services API v1.
gssApiV2: Peer authentication using Generic Security Services API v2.Reference: rfc2408 and rfc2409 · Integer32
The authentication method used in Phase-1 negotiations on the control tunnel corresponding to this conceptual row.
cisgIpsSgTunLifeTime
1.3.6.1.4.1.9.9.438.1.1.2.1.16
Unsigned32 (1..2147483647) · seconds
The negotiated LifeTime of the Phase-1 Tunnel in seconds.
cisgIpsSgTunActiveTime
1.3.6.1.4.1.9.9.438.1.1.2.1.17
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the Phase-1 tunnel has been active in hundredths of seconds.
cisgIpsSgTunInOctets
1.3.6.1.4.1.9.9.438.1.1.2.1.18
Counter32 · Octets
The total number of octets received by this Phase-1 Tunnel.
cisgIpsSgTunInPkts
1.3.6.1.4.1.9.9.438.1.1.2.1.19
Counter32 · Packets
The total number of packets received by this Phase-1 Tunnel.
cisgIpsSgTunInDropPkts
1.3.6.1.4.1.9.9.438.1.1.2.1.20
Counter32 · Packets
The total number of packets dropped by this Phase-1 Tunnel during receive processing.
cisgIpsSgTunInNotifys
1.3.6.1.4.1.9.9.438.1.1.2.1.21
Counter32 · Notification Payloads
The total number of notification payloads received by this Phase-1 Tunnel.
cisgIpsSgTunOutOctets
1.3.6.1.4.1.9.9.438.1.1.2.1.22
Counter32 · Octets
The total number of octets sent by this Phase-1 Tunnel.
cisgIpsSgTunOutPkts
1.3.6.1.4.1.9.9.438.1.1.2.1.23
Counter32 · Packets
The total number of packets sent by this Phase-1 Tunnel.
cisgIpsSgTunOutDropPkts
1.3.6.1.4.1.9.9.438.1.1.2.1.24
Counter32 · Packets
The total number of packets dropped by this Phase-1 Tunnel during send processing.
cisgIpsSgTunOutNotifys
1.3.6.1.4.1.9.9.438.1.1.2.1.25
Counter32 · Notification Payloads
The total number of notification payloads sent by this Phase-1 Tunnel.
cisgIpsSgTunOutP2SaDelReqs
1.3.6.1.4.1.9.9.438.1.1.2.1.26
Counter32 · Notification Payloads
The total number of Phase-2 security association delete requests sent by this Phase-1 Tunnel.
cisgIpsSgTunStatus
1.3.6.1.4.1.9.9.438.1.1.2.1.27
CIPsecTunnelStatus1 = initializePhase12 = awaitXauth3 = awaitCommit4 = active5 = destroy6 = rekeyThis type represents the status of an IPsec Phase-1 or Phase-2 Tunnel. Objects of this type may be used to bring down the tunnel they represent by setting value of the object to destroy(5). Objects of this type cannot be used to create a tunnel.
Description of enum constants of this type: initializePhase1: The tunnel is initializing Phase 1 operations (applies only to IKE tunnels).
awaitXauth: The tunnel has concluded peer authentication successfully and is awaiting the completion of extended Authentication (applies only to IKE tunnels).
awaitCommit: The tunnel has concluded initialization and is awaiting a signal (commit bit) from the peer to start operations.
active: The tunnel is active.
destroy: This value is used in SNMP SET operations to tear down the specified tunnel.
rekey: This value is used in SNMP SET operations to force a rekeying. · Integer32
The status of the MIB table row.
cisgIpsSgTunAction
1.3.6.1.4.1.9.9.438.1.1.2.1.28
INTEGER1 = none2 = clear3 = rekey · Integer32
The action to be taken on this tunnel. If 'clear', then this tunnel is cleared. If 'rekey', then rekeying is forced on this tunnel. The value 'none' would be returned on doing read of this object.
cisgIpsSgTunnelHistTable
1.3.6.1.4.1.9.9.438.1.3.2
Index: cisgIpsSgProtocol · cisgIpsSgTunHistIndex
The control tunnel History Table. This table lists all instances of control tunnels that were successfully established but which are no longer in operation. An entry transitions to this table from the active tunnel table ('cisgIpsSgTunnelTable') into this table after it expires, is aborted or terminated.
This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'cisgIpsSgHistTableSize'.
If the value of 'cisgIpsSgHistTableSize' is 0, archiving of entries in this table is disabled.
cisgIpsSgTunHistIndex
1.3.6.1.4.1.9.9.438.1.3.2.1.1
Unsigned32
The index of the Phase-1 Control Tunnel History Table. This object has no relationship to the cisgIpsSgTunIndex of the tunnel when it was active. The value of the index is a number which begins at one and is incremented with each tunnel that ends. The value of this object will wrap at 4,294,967,296.
The reason the Phase-1 Control Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = applicationInitiated (eg: L2TP requesting the termination) 7 = failure of extended user authentication 8 = local failure occurred.
cisgIpsSgTunHistActiveIndex
1.3.6.1.4.1.9.9.438.1.3.2.1.3
CIPsecPhase1TunnelIndexThe index of the IPsec Phase-1 (IKE) Tunnel Table. An index of this type is a number which begins at 1 and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647. (1..2147483647) · Unsigned32
The index of the previously active Control Tunnel. This object must correspond to an expired IKE tunnel.
cisgIpsSgTunHistPeerLocalType
1.3.6.1.4.1.9.9.438.1.3.2.1.4
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of local peer identity.
cisgIpsSgTunHistPeerLocalValue
1.3.6.1.4.1.9.9.438.1.3.2.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the local peer identity.
cisgIpsSgTunHistPeerIntIndex
1.3.6.1.4.1.9.9.438.1.3.2.1.6
Unsigned32 (1..2147483647)
The arbitrary index to keep local-remote peer association. This index is used to uniquely identify multiple associations between the local and remote peer.
cisgIpsSgTunHistPeerRemoteType
1.3.6.1.4.1.9.9.438.1.3.2.1.7
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of remote peer identity.
cisgIpsSgTunHistPeerRemoteValue
1.3.6.1.4.1.9.9.438.1.3.2.1.8
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the remote peer identity.
cisgIpsSgTunHistLocalAddrType
1.3.6.1.4.1.9.9.438.1.3.2.1.9
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the local endpoint for the control tunnel.
cisgIpsSgTunHistLocalAddr
1.3.6.1.4.1.9.9.438.1.3.2.1.10
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the local endpoint for the control tunnel.
cisgIpsSgTunHistLocalName
1.3.6.1.4.1.9.9.438.1.3.2.1.11
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The DNS name of the local address for the control Tunnel. If the DNS name associated with the local tunnel endpoint is not known, then the value of this object will be a zero-length string.
cisgIpsSgTunHistRemoteAddrType
1.3.6.1.4.1.9.9.438.1.3.2.1.12
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the remote endpoint for the control Tunnel.
cisgIpsSgTunHistRemoteAddr
1.3.6.1.4.1.9.9.438.1.3.2.1.13
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the remote endpoint for the control Tunnel.
cisgIpsSgTunHistRemoteName
1.3.6.1.4.1.9.9.438.1.3.2.1.14
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The DNS name of the remote address of control Tunnel. If the DNS name associated with the remote tunnel endpoint is not known, then the value of this object will be a zero-length string.
cisgIpsSgTunHistEncryptAlgo
1.3.6.1.4.1.9.9.438.1.3.2.1.15
CIPsecEncryptAlgorithm1 = none2 = other3 = espDes4 = esp3des5 = espRc56 = espIdea7 = espCast8 = espTwofish9 = espBlowfish10 = esp3idea11 = espRc412 = espNull13 = espAes12814 = espAes19215 = espAes25616 = espAesCtr12817 = espAesCtr19218 = espAesCtr256The encryption algorithm used in negotiations. Since payload encryption is done by the ESP protocol, these enums are prefixed with 'esp'.
Description of enum constants of this type: espDes: Payload encryption using 56-bit key DES.
esp3des: Payload encryption using 168-bit 3DES.
espRc5: Payload encryption using RC5.
espIdea: Payload encryption using International Data Encryption Algorithm.
espCast: Payload encryption using CAST.
espTwofish: Payload encryption using TwoFish.
espBlowfish: Payload encryption using BlowFish.
esp3idea: Payload encryption using International Data Encryption Algorithm.
espRc4: Payload encryption using RC4.
espNull: NULL Payload encryption.
espAes128: espAes192: espAes256: Payload encryption using AES CBC mode and keysizes of 128, 192 and 256 bit keys.
espAesCtr128: espAesCtr192: espAesCtr256: Payload encryption using AES CTR mode and keysizes of 128, 192 and 256 bit keys. · Integer32
The encryption algorithm used in control tunnel.
cisgIpsSgTunHistEncryptKeySize
1.3.6.1.4.1.9.9.438.1.3.2.1.16
CIPsecEncryptionKeySizeThis type is used by objects that denote the size in bits of key of an encryption transform.
The value of 0 has been allowed to provide for 'NULL' encryption transforms. (0..65535) · Unsigned32 · Bits
The size in bits of the key which was negotiated for the control tunnel to be used with the algorithm denoted by the column 'cisgIpsSgTunEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.
cisgIpsSgTunHistHashAlgo
1.3.6.1.4.1.9.9.438.1.3.2.1.17
CIPsecIkeHashAlgorithm1 = none2 = other3 = md54 = sha5 = tiger6 = sha2567 = sha3848 = sha5129 = aesMacThe hash algorithm used in IPsec Phase-1 IKE negotiations.
Description of enum constants of this type: md5: Hash payload using MD5 algorithm.
sha: Hash payload using 96-bit SHA-1 algorithm as defined in FIPS 180-1.
tiger: Hash payload using Tiger hash algorithm.
sha256: Hash payload using 256-bit key SHA-1 algorithm.
sha384: Hash payload using 384-bit key SHA-1 algorithm.
sha512: Hash payload using 512-bit key SHA-1 algorithm.
aesMac Hash payload using AES-XCBC-MAC-96 algorithm.Reference: rfc2408 and rfc2409 · Integer32
The hash algorithm used in control tunnel negotiations.
cisgIpsSgTunHistAuthMethod
1.3.6.1.4.1.9.9.438.1.3.2.1.18
CIPsecIkeAuthMethod1 = other2 = preSharedKey3 = rsaSignature4 = rsaEncryption5 = revRsaEncryption6 = dssSignature7 = elGamalEncryption8 = revElGamalEncryption9 = ecsdaSignature10 = gssApiV111 = gssApiV2The authentication method used in IPsec Phase-1 IKE negotiations.
Description of enum constants of this type: preSharedKey: Peer authentication using pre-shared keys.
rsaSignature: Peer authentication using digital signatures.
rsaEncryption: Peer authentication using encrypted nonces.
revRsaEncryption: Peer authentication using revised RSA encryption.
dssSignature: Peer authentication using DSS signatures.
elGamalEncryption: Peer authentication using El Gamal.
revElGamalEncryption: Peer authentication using revised El Gamal.
ecdsaSignature: Peer authentication using Elliptic Curve Digital Signatures.
gssApiV1: Peer authentication using Generic Security Services API v1.
gssApiV2: Peer authentication using Generic Security Services API v2.Reference: rfc2408 and rfc2409 · Integer32
The authentication method used in control tunnel negotiations.
cisgIpsSgTunHistLifeTime
1.3.6.1.4.1.9.9.438.1.3.2.1.19
Unsigned32 (1..2147483647)
The negotiated LifeTime of the control tunnel in seconds.
cisgIpsSgTunHistStartTime
1.3.6.1.4.1.9.9.438.1.3.2.1.20
TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be
defined in the description of any object defined using this type.
If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks
The value of sysUpTime in hundredths of seconds when the control tunnel was started.
cisgIpsSgTunHistActiveTime
1.3.6.1.4.1.9.9.438.1.3.2.1.21
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the control tunnel has been active in hundredths of seconds.
cisgIpsSgTunHistInOctets
1.3.6.1.4.1.9.9.438.1.3.2.1.22
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by this control tunnel.
cisgIpsSgTunHistInPkts
1.3.6.1.4.1.9.9.438.1.3.2.1.23
Counter64 (0..18446744073709551615) · Packets
The total number of packets received by this Phase-1 control tunnel.
cisgIpsSgTunHistInDropPkts
1.3.6.1.4.1.9.9.438.1.3.2.1.24
Counter64 (0..18446744073709551615) · Packets
The total number of packets dropped by this control Tunnel during receive processing.
The total number of Phase-2 tunnel delete requests sent by this control tunnel.
cisgIpsSgFailTable
1.3.6.1.4.1.9.9.438.1.4.2
Index: cisgIpsSgProtocol · cisgIpsSgFailIndex
This is the control tunnel Table and is implemented as a sliding window in which only the last 'N' entries are maintained. The maximum number of entries is specified by the object 'cisgIpsSgFailTableSize'.
The failure records are catalogued under each signaling protocol type; that is, the first index of this table is the signaling protocol identifier ('cisgIpsSgProtocol'). The second index ('cisgIpsSgFailIndex') identifies the failure record uniquely in the subcategory.
Should a failure be identified before the signaling protocol itself has been identified by the managed entity, the failure record will be classified under 'cpUnknown'.
cisgIpsSgFailIndex
1.3.6.1.4.1.9.9.438.1.4.2.1.1
Unsigned32
The Phase-1 Failure Table index. This object has no relationship to the cisgIpsSgTunIndex of the tunnel when it was active. The value of the index is a number which begins at one and is incremented with each Phase-1 failure. The value of this object will wrap at 4,294,967,296.
The reason for the failure. Possible reasons include: 1 = other 2 = peer delete request was received 3 = contact with peer was lost 4 = local failure occurred 5 = authentication failure 6 = hash validation failure 7 = encryption failure 8 = internal error occurred 9 = system capacity failure 10 = proposal failure 11 = peer's certificate is unavailable 12 = peer's certificate was found invalid 13 = local certificate expired 14 = certificate revoke list (crl) failure 15 = peer encoding error 16 = Reference to a non-existent control tunnel 17 = Extended User authentication failed 18 = operator requested termination. 19 = An attempt to establish a tunnel was aborted by the admission control policy (this could include a simple policy that limits the maximum active tunnels) 20 = A protocol specific reason (look in the protocol-specific MIB for more info).
cisgIpsSgFailTime
1.3.6.1.4.1.9.9.438.1.4.2.1.3
TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be
defined in the description of any object defined using this type.
If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks
The value of sysUpTime in hundredths of seconds at the time of the failure.
cisgIpsSgFailLocalType
1.3.6.1.4.1.9.9.438.1.4.2.1.4
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of local peer identity.
cisgIpsSgFailLocalValue
1.3.6.1.4.1.9.9.438.1.4.2.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the local peer identity.
cisgIpsSgFailRemoteType
1.3.6.1.4.1.9.9.438.1.4.2.1.6
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of remote peer identity.
cisgIpsSgFailRemoteValue
1.3.6.1.4.1.9.9.438.1.4.2.1.7
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The value of the remote peer identity.
cisgIpsSgFailLocalAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.8
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the local peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.
cisgIpsSgFailRemoteAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.9
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the remote peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.
Trap details
ciscoIpsSgTunnelStart
1.3.6.1.4.1.9.9.438.0.1
This notification is generated when an control tunnel becomes active.
cisgIpsSgTunLocalAddressType
1.3.6.1.4.1.9.9.438.1.1.2.1.4
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the local endpoint of the Phase-1 Tunnel.
cisgIpsSgTunLocalAddress
1.3.6.1.4.1.9.9.438.1.1.2.1.5
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the local endpoint for the Phase-1 Tunnel.
cisgIpsSgTunRemoteAddressType
1.3.6.1.4.1.9.9.438.1.1.2.1.9
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the remote endpoint for the Phase-1 Tunnel.
cisgIpsSgTunRemoteAddress
1.3.6.1.4.1.9.9.438.1.1.2.1.10
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the remote endpoint of the Phase-1 Tunnel.
cisgIpsSgTunLifeTime
1.3.6.1.4.1.9.9.438.1.1.2.1.16
Unsigned32 (1..2147483647) · seconds
The negotiated LifeTime of the Phase-1 Tunnel in seconds.
ciscoIpsSgTunnelStop
1.3.6.1.4.1.9.9.438.0.2
This notification is generated when an control tunnel becomes inactive.
cisgIpsSgTunHistLocalAddrType
1.3.6.1.4.1.9.9.438.1.3.2.1.9
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the local endpoint for the control tunnel.
cisgIpsSgTunHistLocalAddr
1.3.6.1.4.1.9.9.438.1.3.2.1.10
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the local endpoint for the control tunnel.
cisgIpsSgTunHistRemoteAddrType
1.3.6.1.4.1.9.9.438.1.3.2.1.12
CIPsecPhase1PeerIdentityType1 = idOther2 = idIpv4Addr3 = idFqdn4 = idDn5 = idIpv6Addr6 = idUserFqdn7 = idIpv4AddrSubnet8 = idIpv6AddrSubnet9 = idIpv4AddrRange10 = idIpv6AddrRange11 = idDerAsn1Gn12 = idKeyId13 = idWwnThe type of IPsec Phase-1 peer identity. The peer may be identified by one of the ID types defined in IPSEC DOI.
Description of enum constants of this type: idIpv4Addr: IPv4 address
idFqdn: Fully QUalified Domain Name
idDn: Represents the binary DER encoding of the identity.
idIpv6Addr: IPv6 address
idUserFqdn: User FQDN (such as an email address).
idIpv4AddrSubnet: IPv4 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv6AddrSubnet: IPv6 subnet specification (comprising a subnet identifier and a subnet mask).
idIpv4AddrRange: A range of IPv4 addresses (comprising a starting address and an ending address)
idIpv6AddrRange: A range of IPv6 addresses (comprising a starting address and an ending address)
idDerAsn1Gn: The ASN.1 encoded general number.
idKeyId: This is the symbolic name (key identifier).
idWwn: World Wide Number or the encoding of the layer-2 address used by MDS switches.Reference: rfc2408 and rfc2409 · Integer32
The type of the address of the remote endpoint for the control Tunnel.
cisgIpsSgTunHistRemoteAddr
1.3.6.1.4.1.9.9.438.1.3.2.1.13
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t
The address of the remote endpoint for the control Tunnel.
The reason the Phase-1 Control Tunnel was terminated. Possible reasons include: 1 = other 2 = normal termination 3 = operator request 4 = peer delete request was received 5 = contact with peer was lost 6 = applicationInitiated (eg: L2TP requesting the termination) 7 = failure of extended user authentication 8 = local failure occurred.
cisgIpsSgTunHistActiveTime
1.3.6.1.4.1.9.9.438.1.3.2.1.21
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the control tunnel has been active in hundredths of seconds.
ciscoIpsSgSysFailure
1.3.6.1.4.1.9.9.438.0.3
This notification is generated when the processing for an control Tunnel experiences an system capacity error.
cisgIpsSgFailLocalAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.8
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the local peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.
cisgIpsSgFailRemoteAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.9
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the remote peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.
ciscoIpsSgCertCrlFailure
1.3.6.1.4.1.9.9.438.0.4
This notification is generated when the processing for an control Tunnel experiences a Certificate or a Certificate validation (CRL or OCSP) related error.
cisgIpsSgFailLocalAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.8
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the local peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.
cisgIpsSgFailRemoteAddress
1.3.6.1.4.1.9.9.438.1.4.2.1.9
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..255) · OCTET STRING · hint 255t
The address of the remote peer.
The value of cisgIpsSgFailLocalType identifies the type of the address contained in this object.