EZ5 MIB Catalog

CISCO-SSLVPN-MIB

2015-11-17

This MIB module defines management objects for configuration and monitoring of the Cisco secure gateway that implements SSLVPN. Glossary: AnyConnect - Cisco AnyConnect a unified agent that delivers multiple security services to help enable and protect the enterprise. SSL - Secure Sockets Layer URL - Uniform Resource Locator VPN - Virtual Private Network

Download CISCO-SSLVPN-MIB.txt Open CISCO-SSLVPN-MIB.txt in a new tab

SCALARS (18) · TABLES (1) · TRAPS (3)

Scalars (18)

NameOID
csslvpnMaxSessionAllowed1.3.6.1.4.1.9.9.829.1.1.1
csslvpnActiveSessions1.3.6.1.4.1.9.9.829.1.1.2
csslvpnPeakSessions1.3.6.1.4.1.9.9.829.1.1.3
csslvpnInControlPackets1.3.6.1.4.1.9.9.829.1.1.4
csslvpnInDataPackets1.3.6.1.4.1.9.9.829.1.1.5
csslvpnOutControlPackets1.3.6.1.4.1.9.9.829.1.1.6
csslvpnOutDataPackets1.3.6.1.4.1.9.9.829.1.1.7
csslvpnAuthFailures1.3.6.1.4.1.9.9.829.1.1.8
csslvpnConnectFailures1.3.6.1.4.1.9.9.829.1.1.9
csslvpnReconnectFailures1.3.6.1.4.1.9.9.829.1.1.10
csslvpnDpdTimeouts1.3.6.1.4.1.9.9.829.1.1.11
csslvpnAuthRequests1.3.6.1.4.1.9.9.829.1.1.12
csslvpnAuthResponses1.3.6.1.4.1.9.9.829.1.1.13
csslvpnInDpdRequests1.3.6.1.4.1.9.9.829.1.1.14
csslvpnOutDpdRequests1.3.6.1.4.1.9.9.829.1.1.15
csslvpnInDpdResponses1.3.6.1.4.1.9.9.829.1.1.16
csslvpnOutDpdResponses1.3.6.1.4.1.9.9.829.1.1.17
csslvpnNotificationEnable1.3.6.1.4.1.9.9.829.1.3.1

Tables (1)

NameOID
csslvpnSessionTable1.3.6.1.4.1.9.9.829.1.2.1

Traps (3)

NameOID
csslvpnSessionLimitNotif1.3.6.1.4.1.9.9.829.0.1
csslvpnTunnelUpNotif1.3.6.1.4.1.9.9.829.0.2
csslvpnTunnelDownNotif1.3.6.1.4.1.9.9.829.0.3

END OF TOC

Scalar details

csslvpnMaxSessionAllowed

1.3.6.1.4.1.9.9.829.1.1.1

Unsigned32

This object indicates the maximum number of active SSLVPN sessions that are supported by the device.

csslvpnActiveSessions

1.3.6.1.4.1.9.9.829.1.1.2

Unsigned32 · sessions

This object indicates the total number of active SSLVPN sessions.

csslvpnPeakSessions

1.3.6.1.4.1.9.9.829.1.1.3

Unsigned32 · sessions

This object indicates the total number of sessions during peak time.

csslvpnInControlPackets

1.3.6.1.4.1.9.9.829.1.1.4

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of control packets received by the Secure Gateway.

csslvpnInDataPackets

1.3.6.1.4.1.9.9.829.1.1.5

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of data packets received by the Secure Gateway.

csslvpnOutControlPackets

1.3.6.1.4.1.9.9.829.1.1.6

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of control packets sent by the Secure Gateway.

csslvpnOutDataPackets

1.3.6.1.4.1.9.9.829.1.1.7

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of data packets sent by the Secure Gateway.

csslvpnAuthFailures

1.3.6.1.4.1.9.9.829.1.1.8

Unsigned32

This object indicates the total number of authentication failures.

csslvpnConnectFailures

1.3.6.1.4.1.9.9.829.1.1.9

Unsigned32

This object indicates the total number of connect failures.

csslvpnReconnectFailures

1.3.6.1.4.1.9.9.829.1.1.10

Unsigned32

This object indicates the total number of reconnect failures.

csslvpnDpdTimeouts

1.3.6.1.4.1.9.9.829.1.1.11

Counter64 (0..18446744073709551615)

This object indicates the total number of Dead Peer Detection timeouts.

csslvpnAuthRequests

1.3.6.1.4.1.9.9.829.1.1.12

Counter64 (0..18446744073709551615) · requests

This object indicates the total number of authentication requests.

csslvpnAuthResponses

1.3.6.1.4.1.9.9.829.1.1.13

Counter64 (0..18446744073709551615) · responses

This object indicates the total number of authentication responses.

csslvpnInDpdRequests

1.3.6.1.4.1.9.9.829.1.1.14

Counter64 (0..18446744073709551615) · requests

This object indicates the total number of Dead Peer Detection requests received by Secure Gateway.

csslvpnOutDpdRequests

1.3.6.1.4.1.9.9.829.1.1.15

Counter64 (0..18446744073709551615) · requests

This object indicates the total number of Dead Peer Detection requests sent by Secure Gateway.

csslvpnInDpdResponses

1.3.6.1.4.1.9.9.829.1.1.16

Counter64 (0..18446744073709551615) · responses

This object indicates the total number of Dead Peer Detection responses received by Secure Gateway.

csslvpnOutDpdResponses

1.3.6.1.4.1.9.9.829.1.1.17

Counter64 (0..18446744073709551615) · responses

This object indicates the total number of Dead Peer Detection responses sent by Secure Gateway.

csslvpnNotificationEnable

1.3.6.1.4.1.9.9.829.1.3.1

BITS

This object specifies whether a specified notification is enabled or not. If a bit corresponding to a notification is set to 1, then the specified notification can be generated. sessionLimit -- the csslvpnSessionLimitNotif notification. tunnelUp -- the csslvpnTunnelUpNotif notification. tunnelDown -- the csslvpnTunnelDownNotif notification.

Table details

csslvpnSessionTable

1.3.6.1.4.1.9.9.829.1.2.1

Index: csslvpnSessionID

A list of SSLVPN sessions which has been successfully created by the secure gateway.

csslvpnSessionID

1.3.6.1.4.1.9.9.829.1.2.1.1.1

Unsigned32 (1..4294967295)

This object indicates the index of a SSLVPN session. The value of csslvpnSessionID is assigned uniquely during session creation.

csslvpnSessionUser

1.3.6.1.4.1.9.9.829.1.2.1.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object indicates the username with which session is authenticated.

csslvpnSessionProfile

1.3.6.1.4.1.9.9.829.1.2.1.1.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object indicates the SSL profile to which session is connected. The SSL profile defines authentication and accounting lists. Profile selection will be based on policy and URL values. Profile may also optionally associate with default authorization policy

csslvpnSessionPolicy

1.3.6.1.4.1.9.9.829.1.2.1.1.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object indicates the SSL policy to which session is connected. SSL policy defines the cipher suites to be supported and the trust point to be used during SSL negotiation. SSL policy is a container of all the parameters used in the SSL negotiation. The policy selection would be done by matching the session parameters against the parameters configured under the policy

csslvpnSessionClientIpAddrType

1.3.6.1.4.1.9.9.829.1.2.1.1.5

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the type of public IP Address of the client that initiated the session.

csslvpnSessionClientIpAddr

1.3.6.1.4.1.9.9.829.1.2.1.1.6

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the public IP Address of the client that initiated the session. The type of this address is determined by the value of csslvpnSessionClientIpAddrType object.

csslvpnSessionTunnelIpAddrType

1.3.6.1.4.1.9.9.829.1.2.1.1.7

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the type of IP address assigned to AnyConnect client during tunnel bring up.

csslvpnSessionTunnelIpAddr

1.3.6.1.4.1.9.9.829.1.2.1.1.8

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the IP address assigned to AnyConnect client during tunnel bring up. The type of this address is determined by the value of csslvpnSessionTunnelIpAddrType object.

csslvpnSessionTunnelNetmask

1.3.6.1.4.1.9.9.829.1.2.1.1.9

InetAddressPrefixLengthDenotes the length of a generic Internet network address prefix. A value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB), with all other bits set to 0. An InetAddressPrefixLength value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddressPrefixLength textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddressPrefixLength textual convention, if they appear in the same logical row. InetAddressPrefixLength values larger than the maximum length of an IP address for a specific InetAddressType are treated as the maximum significant value applicable for the InetAddressType. The maximum significant value is 32 for the InetAddressType 'ipv4(1)' and 'ipv4z(3)' and 128 for the InetAddressType 'ipv6(2)' and 'ipv6z(4)'. The maximum significant value for the InetAddressType 'dns(16)' is 0. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where the Internet network address prefix is unknown or does not apply. The upper bound of the prefix length has been chosen to be consistent with the maximum size of an InetAddress. (0..2040) · Unsigned32 · hint d

This object indicates the netmask assigned to the client during the session bring up. This object is always interpreted with the value of csslvpnSessionTunnelIpAddrType object.

csslvpnSessionNumConnections

1.3.6.1.4.1.9.9.829.1.2.1.1.10

Unsigned32

This object indicates the total number of connections associated with a particular session.

csslvpnSessionRxPackets

1.3.6.1.4.1.9.9.829.1.2.1.1.11

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of packets received during the session.

csslvpnSessionTxPackets

1.3.6.1.4.1.9.9.829.1.2.1.1.12

Counter64 (0..18446744073709551615) · packets

This object indicates the total number of packets transmitted during the session.

csslvpnSessionRxBytes

1.3.6.1.4.1.9.9.829.1.2.1.1.13

Counter64 (0..18446744073709551615) · bytes

This object indicates the total number of bytes received during the session.

csslvpnSessionTxBytes

1.3.6.1.4.1.9.9.829.1.2.1.1.14

Counter64 (0..18446744073709551615) · bytes

This object indicates the total number of bytes transmitted during the session.

csslvpnSessionLastUsed

1.3.6.1.4.1.9.9.829.1.2.1.1.15

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

This object indicates the time, when the session was last used.

csslvpnSessionCreated

1.3.6.1.4.1.9.9.829.1.2.1.1.16

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

This object indicates the time, when the session was created.

Trap details

csslvpnSessionLimitNotif

1.3.6.1.4.1.9.9.829.0.1

This notification would be sent when the attempt of creating a new active sessions may exceed the maximum number of sessions supported by the device.

csslvpnMaxSessionAllowed

1.3.6.1.4.1.9.9.829.1.1.1

Unsigned32

This object indicates the maximum number of active SSLVPN sessions that are supported by the device.

csslvpnTunnelUpNotif

1.3.6.1.4.1.9.9.829.0.2

This notification would be sent when SSLVPN tunnel gets created.

csslvpnSessionUser

1.3.6.1.4.1.9.9.829.1.2.1.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object indicates the username with which session is authenticated.

csslvpnSessionTunnelIpAddrType

1.3.6.1.4.1.9.9.829.1.2.1.1.7

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the type of IP address assigned to AnyConnect client during tunnel bring up.

csslvpnSessionTunnelIpAddr

1.3.6.1.4.1.9.9.829.1.2.1.1.8

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the IP address assigned to AnyConnect client during tunnel bring up. The type of this address is determined by the value of csslvpnSessionTunnelIpAddrType object.

csslvpnSessionTunnelNetmask

1.3.6.1.4.1.9.9.829.1.2.1.1.9

InetAddressPrefixLengthDenotes the length of a generic Internet network address prefix. A value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB), with all other bits set to 0. An InetAddressPrefixLength value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddressPrefixLength textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddressPrefixLength textual convention, if they appear in the same logical row. InetAddressPrefixLength values larger than the maximum length of an IP address for a specific InetAddressType are treated as the maximum significant value applicable for the InetAddressType. The maximum significant value is 32 for the InetAddressType 'ipv4(1)' and 'ipv4z(3)' and 128 for the InetAddressType 'ipv6(2)' and 'ipv6z(4)'. The maximum significant value for the InetAddressType 'dns(16)' is 0. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where the Internet network address prefix is unknown or does not apply. The upper bound of the prefix length has been chosen to be consistent with the maximum size of an InetAddress. (0..2040) · Unsigned32 · hint d

This object indicates the netmask assigned to the client during the session bring up. This object is always interpreted with the value of csslvpnSessionTunnelIpAddrType object.

csslvpnTunnelDownNotif

1.3.6.1.4.1.9.9.829.0.3

This notification would be sent when SSLVPN tunnel tears down.

csslvpnSessionUser

1.3.6.1.4.1.9.9.829.1.2.1.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object indicates the username with which session is authenticated.

csslvpnSessionTunnelIpAddrType

1.3.6.1.4.1.9.9.829.1.2.1.1.7

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the type of IP address assigned to AnyConnect client during tunnel bring up.

csslvpnSessionTunnelIpAddr

1.3.6.1.4.1.9.9.829.1.2.1.1.8

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the IP address assigned to AnyConnect client during tunnel bring up. The type of this address is determined by the value of csslvpnSessionTunnelIpAddrType object.

csslvpnSessionTunnelNetmask

1.3.6.1.4.1.9.9.829.1.2.1.1.9

InetAddressPrefixLengthDenotes the length of a generic Internet network address prefix. A value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB), with all other bits set to 0. An InetAddressPrefixLength value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddressPrefixLength textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddressPrefixLength textual convention, if they appear in the same logical row. InetAddressPrefixLength values larger than the maximum length of an IP address for a specific InetAddressType are treated as the maximum significant value applicable for the InetAddressType. The maximum significant value is 32 for the InetAddressType 'ipv4(1)' and 'ipv4z(3)' and 128 for the InetAddressType 'ipv6(2)' and 'ipv6z(4)'. The maximum significant value for the InetAddressType 'dns(16)' is 0. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where the Internet network address prefix is unknown or does not apply. The upper bound of the prefix length has been chosen to be consistent with the maximum size of an InetAddress. (0..2040) · Unsigned32 · hint d

This object indicates the netmask assigned to the client during the session bring up. This object is always interpreted with the value of csslvpnSessionTunnelIpAddrType object.

↑ To TOC