This module defines the configuration and operational state for managing the IP Traffic Flow Security functionality (RFC 9349).
Copyright (c) 2023 IETF Trust and the persons identified as authors of the code. All rights reserved.
Redistribution and use in source and binary forms, with or without modification, is permitted pursuant to, and subject to the license terms contained in, the Simplified BSD License set forth in Section 4.c of the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info).
This version of this SNMP MIB module is part of RFC 9349; see the RFC itself for full legal notices.
The table containing configuration information for IP-TFS.
iptfsConfigSaIndex
1.3.6.1.2.1.246.1.1.1.1.1
Integer32 (1..16777215)
A unique value, greater than zero, for each SA. It is recommended that values are assigned contiguously, starting from 1.
The value for each entry must remain constant at least from one re-initialization of an entity's network management system to the next re-initialization.
congestionControl
1.3.6.1.2.1.246.1.1.1.1.2
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
When set to true, the default, this enables the congestion control on-the-wire exchange of data that is required by congestion control algorithms, as defined by RFC 5348. When set to false, IP-TFS sends fixed-sized packets over an IP-TFS tunnel at a constant rate.
usePathMtuDiscovery
1.3.6.1.2.1.246.1.1.1.1.3
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
Packet size is either auto-discovered or manually configured. If usePathMtuDiscovery is true, the system utilizes path-mtu to determine the maximum IP-TFS packet size. If the packet size is explicitly configured, then it will only be adjusted downward if use-path-mtu is set.
outerPacketSize
1.3.6.1.2.1.246.1.1.1.1.4
UnsignedShortxs:unsignedShort (0..65535) · Unsigned32 · hint d
On transmission, the size of the outer encapsulating tunnel packet (i.e., the IP packet containing Encapsulating Security Payload).
l2FixedRate
1.3.6.1.2.1.246.1.1.1.1.5
CounterBasedGauge64The CounterBasedGauge64 type represents a non-negative integer, which may increase or decrease, but shall never exceed a maximum value, nor fall below a minimum value. The maximum value can not be greater than 2^64-1 (18446744073709551615 decimal), and the minimum value can not be smaller than 0. The value of a CounterBasedGauge64 has its maximum value whenever the information being modeled is greater than or equal to its maximum value, and has its minimum value whenever the information being modeled is smaller than or equal to its minimum value. If the information being modeled subsequently decreases below (increases above) the maximum (minimum) value, the CounterBasedGauge64 also decreases (increases).
Note that this TC is not strictly supported in SMIv2, because the 'always increasing' and 'counter wrap' semantics associated with the Counter64 base type are not preserved. It is possible that management applications which rely solely upon the (Counter64) ASN.1 tag to determine object semantics will mistakenly operate upon objects of this type as they would for Counter64 objects.
This textual convention represents a limited and short-term solution, and may be deprecated as a long term solution is defined and deployed to replace it. (0..18446744073709551615) · Counter64
The IP-TFS bit rate may be specified as a layer 2 wire rate. On transmission, the target bandwidth/bit rate in bits per second (bps) for the IP-TFS tunnel. This rate is the nominal timing for the fixed-size packet. If congestion control is enabled, the rate may be adjusted down.
l3FixedRate
1.3.6.1.2.1.246.1.1.1.1.6
CounterBasedGauge64The CounterBasedGauge64 type represents a non-negative integer, which may increase or decrease, but shall never exceed a maximum value, nor fall below a minimum value. The maximum value can not be greater than 2^64-1 (18446744073709551615 decimal), and the minimum value can not be smaller than 0. The value of a CounterBasedGauge64 has its maximum value whenever the information being modeled is greater than or equal to its maximum value, and has its minimum value whenever the information being modeled is smaller than or equal to its minimum value. If the information being modeled subsequently decreases below (increases above) the maximum (minimum) value, the CounterBasedGauge64 also decreases (increases).
Note that this TC is not strictly supported in SMIv2, because the 'always increasing' and 'counter wrap' semantics associated with the Counter64 base type are not preserved. It is possible that management applications which rely solely upon the (Counter64) ASN.1 tag to determine object semantics will mistakenly operate upon objects of this type as they would for Counter64 objects.
This textual convention represents a limited and short-term solution, and may be deprecated as a long term solution is defined and deployed to replace it. (0..18446744073709551615) · Counter64
The IP-TFS bit rate may be specified as a layer 3 packet rate. On transmission, the target bandwidth/bit rate in bps for the IP-TFS tunnel. This rate is the nominal timing for the fixed-size packet. If congestion control is enabled, the rate may be adjusted down.
dontFragment
1.3.6.1.2.1.246.1.1.1.1.7
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
On transmission, disable packet fragmentation across consecutive IP-TFS tunnel packets; inner packets larger than what can be transmitted in outer packets will be dropped.
maxAggregationTime
1.3.6.1.2.1.246.1.1.1.1.8
NanoSecondsRepresents the time unit value in nanoseconds. · Integer32 · hint d-6
On transmission, the maximum aggregation time is the maximum length of time a received inner packet can be held prior to transmission in the IP-TFS tunnel. Inner packets that would be held longer than this time, based on the current tunnel configuration, will be dropped rather than be queued for transmission.
windowSize
1.3.6.1.2.1.246.1.1.1.1.9
UnsignedShortxs:unsignedShort (0..65535) · Unsigned32 · hint d
On reception, the maximum number of out-of-order packets that will be reordered by an IP-TFS receiver while performing the reordering operation. The value 0 disables any reordering.
sendImmediately
1.3.6.1.2.1.246.1.1.1.1.10
TruthValue1 = true2 = falseRepresents a boolean value. · Integer32
On reception, send inner packets as soon as possible; do not wait for lost or misordered outer packets. Selecting this option reduces the inner (user) packet delay but can amplify out-of-order delivery of the inner packet stream in the presence of packet aggregation and any reordering.
lostPacketTimerInterval
1.3.6.1.2.1.246.1.1.1.1.11
NanoSecondsRepresents the time unit value in nanoseconds. · Integer32 · hint d-6
On reception, this interval defines the length of time an IP-TFS receiver will wait for a missing packet before considering it lost. If not using send-immediately, then each lost packet will delay inner (user) packets until this timer expires. Setting this value too low can impact reordering and reassembly.
ipsecStatsTable
1.3.6.1.2.1.246.1.2.1
Index: ipsecSaIndex
The table containing basic statistics on IPsec.
ipsecSaIndex
1.3.6.1.2.1.246.1.2.1.1.1
Integer32 (1..16777215)
A unique value, greater than zero, for each SA. It is recommended that values are assigned contiguously, starting from 1.
The value for each entry must remain constant at least from one re-initialization of an entity's network management system to the next re-initialization.
txPkts
1.3.6.1.2.1.246.1.2.1.1.2
Counter64 (0..18446744073709551615)
Outbound Packet count.
txOctets
1.3.6.1.2.1.246.1.2.1.1.3
Counter64 (0..18446744073709551615)
Outbound Packet bytes.
txDropPkts
1.3.6.1.2.1.246.1.2.1.1.4
Counter64 (0..18446744073709551615)
Outbound dropped packets count.
rxPkts
1.3.6.1.2.1.246.1.2.1.1.5
Counter64 (0..18446744073709551615)
Inbound Packet count.
rxOctets
1.3.6.1.2.1.246.1.2.1.1.6
Counter64 (0..18446744073709551615)
Inbound Packet bytes.
rxDropPkts
1.3.6.1.2.1.246.1.2.1.1.7
Counter64 (0..18446744073709551615)
Inbound dropped packets.
iptfsInnerStatsTable
1.3.6.1.2.1.246.1.3.1
Index: iptfsInnerSaIndex
The table containing information on IP-TFS inner packets.
iptfsInnerSaIndex
1.3.6.1.2.1.246.1.3.1.1.1
Integer32 (1..16777215)
A unique value, greater than zero, for each SA. It is recommended that values are assigned contiguously, starting from 1.
The value for each entry must remain constant at least from one re-initialization of an entity's network management system to the next re-initialization.
txInnerPkts
1.3.6.1.2.1.246.1.3.1.1.2
Counter64 (0..18446744073709551615)
Total number of IP-TFS inner packets sent. This count is whole packets only. A fragmented packet counts as one packet.
txInnerOctets
1.3.6.1.2.1.246.1.3.1.1.3
Counter64 (0..18446744073709551615)
Total number of IP-TFS inner octets sent. This is inner packet octets only. This does not count padding.
rxInnerPkts
1.3.6.1.2.1.246.1.3.1.1.4
Counter64 (0..18446744073709551615)
Total number of IP-TFS inner packets received.
rxInnerOctets
1.3.6.1.2.1.246.1.3.1.1.5
Counter64 (0..18446744073709551615)
Total number of IP-TFS inner octets received. This does not include padding or overhead.
rxIncompleteInnerPkts
1.3.6.1.2.1.246.1.3.1.1.6
Counter64 (0..18446744073709551615)
Total number of IP-TFS inner packets that were incomplete. Usually, this is due to fragments not received. Also, this may be due to misordering or errors in received outer packets.
iptfsOuterStatsTable
1.3.6.1.2.1.246.1.4.1
Index: iptfsOuterSaIndex
The table containing information on IP-TFS.
iptfsOuterSaIndex
1.3.6.1.2.1.246.1.4.1.1.1
Integer32 (1..16777215)
A unique value, greater than zero, for each SA. It is recommended that values are assigned contiguously, starting from 1.
The value for each entry must remain constant at least from one re-initialization of an entity's network management system to the next re-initialization.
txExtraPadPkts
1.3.6.1.2.1.246.1.4.1.1.2
Counter64 (0..18446744073709551615)
Total number of transmitted outer IP-TFS packets that included some padding.
txExtraPadOctets
1.3.6.1.2.1.246.1.4.1.1.3
Counter64 (0..18446744073709551615)
Total number of transmitted octets of padding added to outer IP-TFS packets with data.
txAllPadPkts
1.3.6.1.2.1.246.1.4.1.1.4
Counter64 (0..18446744073709551615)
Total number of transmitted IP-TFS packets that were all padding with no inner packet data.
txAllPadOctets
1.3.6.1.2.1.246.1.4.1.1.5
Counter64 (0..18446744073709551615)
Total number transmitted octets of padding added to IP-TFS packets with no inner packet data.
rxExtraPadPkts
1.3.6.1.2.1.246.1.4.1.1.6
Counter64 (0..18446744073709551615)
Total number of received outer IP-TFS packets that included some padding.
rxExtraPadOctets
1.3.6.1.2.1.246.1.4.1.1.7
Counter64 (0..18446744073709551615)
Total number of received octets of padding added to outer IP-TFS packets with data.
rxAllPadPkts
1.3.6.1.2.1.246.1.4.1.1.8
Counter64 (0..18446744073709551615)
Total number of received IP-TFS packets that were all padding with no inner packet data.
rxAllPadOctets
1.3.6.1.2.1.246.1.4.1.1.9
Counter64 (0..18446744073709551615)
Total number received octets of padding added to IP-TFS packets with no inner packet data.
rxErroredPkts
1.3.6.1.2.1.246.1.4.1.1.10
Counter64 (0..18446744073709551615)
Total number of IP-TFS outer packets dropped due to errors.
rxMissedPkts
1.3.6.1.2.1.246.1.4.1.1.11
Counter64 (0..18446744073709551615)
Total number of IP-TFS outer packets missing indicated by a missing sequence number.