Acronyms and Definitions The following acronyms and terms are used in this document:
IPSec: Secure IP Protocol
VPN: Virtual Private Network
LAN: Local Area Network
Group: A collection of VPN license usage users grouped and managed together as a single entity for administrative convenience.
SVC: SSL VPN Client
LicServer: Multi-site shared License server.
LicBkpServer: Multi-site shared License Backup server.
LicClient: Multi-site shared License client.
Overview of the MIB
This is a MIB Module for monitoring licenses in Virtual Private Networks. The MIB seeks to create a common model of VPN License Usage across different VPN implementations. The MIB defines counters and objects of interest to usage/message monitoring in a way which is independent of which VPN technology is requested.
MIB contains four major groups of objects which are used to get VPN License Usage information a) VPN Lic device type This section defines if the device is acting as a server, backupserver, client(participant) in a shared license system.
b) VPN License Server Usage group This section defines total network license usage information and also server information as well along with backup server address. service.
c) VPN License Backup server Usage group This section defines backup license server information in detail, along with statistics of hello, sync and update messages from server.
d) VPN License client Usage group This section defines license usage information by this client. along with statistics about registration, get request,release request and transfer request.
VPNLicDeviceRole1 = server2 = bkpserver3 = clientRole the device is playing in shared license system. If it's acting as server/backup server, it also acts as license client.
server - License server acting as both server and client.
bkpserver - backup license server acting as both backup
server and client.
client - Client. · Integer32
ASA Device Role in a shared License System as server/backup/client.
cvpnLicServerAddrType
1.3.6.1.4.1.9.9.816.0.2.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
IP address type of Shared License Server.
cvpnLicServerAddr
1.3.6.1.4.1.9.9.816.0.2.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
IP address of Shared License Server.
cvpnLicBkpSerAddrType
1.3.6.1.4.1.9.9.816.0.2.3
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
IP address Type of Shared License Backup Server.
cvpnLicBkpSerAddr
1.3.6.1.4.1.9.9.816.0.2.4
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
IP address of Shared License Backup Server.
cvpnLicServerVer
1.3.6.1.4.1.9.9.816.0.2.5
Integer32 (1..2147483647)
Shared License Server version.
cvpnLicServerStatus
1.3.6.1.4.1.9.9.816.0.2.6
LicServerStatus1 = active2 = inactive3 = expiredStatus of a license server, indicating if the server is currently active or backup (inactive). *Note* : backup will still be acting as a client.
active - Server is active.
inactive - Server is inactive.
expired - Server expired. · Integer32
Shared License Server Status.
cvpnLicBkpServerAddrType
1.3.6.1.4.1.9.9.816.0.3.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
IP address type of Shared License Backup Server
cvpnLicBkpServerAddr
1.3.6.1.4.1.9.9.816.0.3.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
IP address of Shared License Backup Server
cvpnLicBkpServerDevID
1.3.6.1.4.1.9.9.816.0.3.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..64) · OCTET STRING · hint 255t
Device ID of the shared license backup server.
cvpnLicBkpServerVer
1.3.6.1.4.1.9.9.816.0.3.4
Unsigned32 · license
Shared License Backup Server version.
cvpnLicBkpServerRegd
1.3.6.1.4.1.9.9.816.0.3.5
LicServerRegistered1 = no2 = yes3 = invalidState of the Backup License server registered as a participant.
no - ASA is not registered.
yes - ASA is registered.
invalid - Unknown value. · Integer32
Shared License Backup Server Registered information.
cvpnLicBkpServerHAPeerDevID
1.3.6.1.4.1.9.9.816.0.3.6
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..64) · OCTET STRING · hint 255t
Device ID of the shared license backup server HA Peer.
cvpnLicBkpServerHAPeerRegd
1.3.6.1.4.1.9.9.816.0.3.7
LicServerRegistered1 = no2 = yes3 = invalidState of the Backup License server registered as a participant.
no - ASA is not registered.
yes - ASA is registered.
invalid - Unknown value. · Integer32
Shared License Backup Server HA Peer registered information
cvpnLicBkpServerStatus
1.3.6.1.4.1.9.9.816.0.3.8
LicServerStatus1 = active2 = inactive3 = expiredStatus of a license server, indicating if the server is currently active or backup (inactive). *Note* : backup will still be acting as a client.
active - Server is active.
inactive - Server is inactive.
expired - Server expired. · Integer32
Shared License Backup Server Status.
cvpnLicServerHelloTx
1.3.6.1.4.1.9.9.816.0.3.9
Counter32 · packets
The total number of Hello packets transmitted from this license server.
cvpnLicServerHelloRx
1.3.6.1.4.1.9.9.816.0.3.10
Counter32 · packets
The total number of Hello packets received by the license server.
cvpnLicServerHelloError
1.3.6.1.4.1.9.9.816.0.3.11
Counter32 · packets
The total number of erroneous Hello packet received. e.g. request received with no Rx data.
cvpnLicServerSyncTx
1.3.6.1.4.1.9.9.816.0.3.12
Counter32 · packets
The total number of Sync packets transmitted from this license server.
cvpnLicServerSyncRx
1.3.6.1.4.1.9.9.816.0.3.13
Counter32 · packets
The total number of Sync packets received by the license server.
cvpnLicServerSyncError
1.3.6.1.4.1.9.9.816.0.3.14
Counter32 · packets
The total number of erroneous Sync packet received e.g. request received with no Rx data.
cvpnLicServerUpdateTx
1.3.6.1.4.1.9.9.816.0.3.15
Counter32 · packets
The total number of Update packets transmitted from this license server.
cvpnLicServerUpdateRx
1.3.6.1.4.1.9.9.816.0.3.16
Counter32 · packets
The total number of Update packets received by the license server.
cvpnLicServerUpdateError
1.3.6.1.4.1.9.9.816.0.3.17
Counter32 · packets
The total number of erroneous Update packet received. e.g. request received with no Rx data.
Table details
cvpnLicServerTable
1.3.6.1.4.1.9.9.816.0.2.7
Index: cvpnLicServerVPNLicType
This table lists the Shared License Usage Information per VPN type. For each VPN type, it lists Total capacity, current usage, total available
cvpnLicServerVPNLicType
1.3.6.1.4.1.9.9.816.0.2.7.1.1
VPNLicType1 = other2 = anyconnectpremiumType of VPN supporting shared license
other - other VPN type
anyconnectpremium - anyconnect VPN type. · Integer32
Statistics for a particular VPN type.
cvpnLicServerNumLicCapacity
1.3.6.1.4.1.9.9.816.0.2.7.1.2
Unsigned32 · license
Total number of shared license capacity for network for this VPN type.
cvpnLicServerNumLicAvail
1.3.6.1.4.1.9.9.816.0.2.7.1.3
Unsigned32 · license
Available License in network for this VPN type.
cvpnLicServerUtilized
1.3.6.1.4.1.9.9.816.0.2.7.1.4
Unsigned32 · license
Number of Licenses utilised by the entire network for this License type.
This table lists all the License LicClnt Information. For each LicClnt, it lists the attributes (Hostname,Device ID,Current usage, High,Registration Tx/Rx/Error,Get Tx/Rx/Error Release Tx/Rx/Error, Transfer Tx/Rx/Error
cvpnLicClntVPNLicType
1.3.6.1.4.1.9.9.816.0.4.1.1.1
VPNLicType1 = other2 = anyconnectpremiumType of VPN supporting shared license
other - other VPN type
anyconnectpremium - anyconnect VPN type. · Integer32
VPN Type of Shared License client
cvpnLicClntInfoDeviceID
1.3.6.1.4.1.9.9.816.0.4.1.1.2
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (1..64) · OCTET STRING · hint 255t
Device ID of the shared license client.
cvpnLicClntInfoHostName
1.3.6.1.4.1.9.9.816.0.4.1.1.3
SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form.
To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279].
Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited.
The use of control codes should be avoided.
When it is necessary to represent a newline, the control code sequence CR LF should be used.
The use of leading or trailing white space should be avoided.
For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided.
For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding.
UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding.
Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416].
Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..64) · OCTET STRING · hint 255t
The Hostname of the shared license Client.
cvpnLicClntInfoPlatLmt
1.3.6.1.4.1.9.9.816.0.4.1.1.4
Unsigned32 · license
Platform limit for max License on this client.
cvpnLicClntInfoCurUsage
1.3.6.1.4.1.9.9.816.0.4.1.1.5
Unsigned32 · license
Current Usage of Shared License by this device.
cvpnLicClntInfoHigh
1.3.6.1.4.1.9.9.816.0.4.1.1.6
Unsigned32 · license
The maximum number of licenses provided by the license server to the client.
cvpnLicClntInfoRegReqTx
1.3.6.1.4.1.9.9.816.0.4.1.1.7
Counter32 · packets
The total number of Registration Request packets transmitted on this client for this VPN type.
cvpnLicClntInfoRegReqRx
1.3.6.1.4.1.9.9.816.0.4.1.1.8
Counter32 · packets
The total number of Registration Request packets received on this client for this VPN type.
cvpnLicClntInfoRegReqError
1.3.6.1.4.1.9.9.816.0.4.1.1.9
Counter32 · packets
The total number of Registration Request packet errors on this client for this VPN type.
cvpnLicClntInfoGetReqTx
1.3.6.1.4.1.9.9.816.0.4.1.1.10
Counter32 · packets
The total number of Get Request packets transmitted on this client for this VPN type.
cvpnLicClntInfoGetReqRx
1.3.6.1.4.1.9.9.816.0.4.1.1.11
Counter32 · packets
The total number of Get Request packets Received on this client for this VPN type.
cvpnLicClntInfoGetReqError
1.3.6.1.4.1.9.9.816.0.4.1.1.12
Counter32 · packets
The total number of Get Request packet errors on this client for this VPN type.
cvpnLicClntInfoRelReqTx
1.3.6.1.4.1.9.9.816.0.4.1.1.13
Counter32 · packets
The total number of Release Request packets transmitted on this client for this VPN type.
cvpnLicClntInfoRelReqRx
1.3.6.1.4.1.9.9.816.0.4.1.1.14
Counter32 · packets
The total number of Release Request packets received on this client for this VPN type.
cvpnLicClntInfoRelReqError
1.3.6.1.4.1.9.9.816.0.4.1.1.15
Counter32 · packets
The total number of Release Request packet errors on this client for this VPN type.
cvpnLicClntInfoTransferReqTx
1.3.6.1.4.1.9.9.816.0.4.1.1.16
Counter32 · packets
The total number of Transfer Request packets transmitted on this client for this VPN type.
cvpnLicClntInfoTransferReqRx
1.3.6.1.4.1.9.9.816.0.4.1.1.17
Counter32 · packets
The total number of Transfer Request packets received on this client for this VPN type.
cvpnLicClntInfoTransferReqError
1.3.6.1.4.1.9.9.816.0.4.1.1.18
Counter32 · packets
The total number of Transfer Request packet errros on this client for this VPN type.