jnxIpSecMibLevel
1.3.6.1.4.1.2636.3.22.1.1.1
Integer32 (1..4096)
The version of the IPsec MIB.
2016-05-31
Download JNX-IPSEC-MONITOR-MIB.txt Open JNX-IPSEC-MONITOR-MIB.txt in a new tab
| Name | OID |
|---|---|
| jnxIpSecMibLevel | 1.3.6.1.4.1.2636.3.22.1.1.1 |
| Name | OID |
|---|---|
| jnxIkeTunnelTable | 1.3.6.1.4.1.2636.3.22.1.2.1 |
| jnxIpSecTunnelTable | 1.3.6.1.4.1.2636.3.22.1.3.1 |
| jnxIpSecSaTable | 1.3.6.1.4.1.2636.3.22.1.3.2 |
END OF TOC
1.3.6.1.4.1.2636.3.22.1.1.1
Integer32 (1..4096)
The version of the IPsec MIB.
1.3.6.1.4.1.2636.3.22.1.2.1
Index: jnxSpSvcSetName · jnxIkeTunRemoteGwAddrType · jnxIkeTunRemoteGwAddr · jnxIkeTunIndex
The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
from JUNIPER-SP-MIB
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..96) · OCTET STRING · hint 255a
The Service Set name.
1.3.6.1.4.1.2636.3.22.1.2.1.1.1
Integer32 (1..2147483647)
The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.2.1.1.2
JnxIkePeerRole1 = initiator2 = responderRole of the local endpoint in negotiating the IPsec Phase-1 IKE security association. It can be either Initiator or Responder. · Integer32
The role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder.
1.3.6.1.4.1.2636.3.22.1.2.1.1.3
JnxIkeNegState1 = matured2 = notmaturedState of the Phase-1 IKE negotiation. · Integer32
The state of the current negotiation , It can be 1. matured 2. not matured
1.3.6.1.4.1.2636.3.22.1.2.1.1.4
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Cookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header.
1.3.6.1.4.1.2636.3.22.1.2.1.1.5
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Cookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header.
1.3.6.1.4.1.2636.3.22.1.2.1.1.6
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.7
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
1.3.6.1.4.1.2636.3.22.1.2.1.1.8
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.9
InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.10
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.11
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
1.3.6.1.4.1.2636.3.22.1.2.1.1.12
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
1.3.6.1.4.1.2636.3.22.1.2.1.1.13
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.14
InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.15
JnxIkeNegoMode1 = main2 = aggressive3 = ikev2The IPsec Phase-1 IKE negotiation mode. Main Mode: A six-message Phase 1 exchange that provides identity protection. Aggressive mode: a three-message phase 1 exchange that does not provide identity protection · Integer32
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
1.3.6.1.4.1.2636.3.22.1.2.1.1.16
JnxDiffHellmanGrp0 = unknown1 = modp7682 = modp10245 = modp153614 = modp204815 = modp307216 = modp409619 = ecmodp25620 = ecmodp38421 = ecmodp52124 = modp2048s256The Diffie Hellman Group used in negotiations. modp768 -- 768-bit MODP modp1024 -- 1024-bit MODP modp1536 -- 1536-bit MODP modp2048 -- 2048-bit MODP modp3072 -- 3072-bit MODP modp4096 -- 4096-bit MODP ec-modp256 -- 256-bit EC-MODP ec-modp384 -- 384-bit EC-MODP ec-modp521 -- 521-bit EC-MODP modp2048s256 -- 2048-bit MODP group with 256 bit subgroup · Integer32
The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.17
JnxEncryptAlgo1 = espDes2 = esp3des3 = espNull4 = espAes1285 = espAes1926 = espAes2567 = espAesGcm1288 = espAesGcm1929 = espAesGcm25610 = espChaCha20Poly1305The encryption algorithm used in negotiations. · Integer32
The encryption algorithm used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.18
JnxIkeHashAlgo1 = md52 = sha3 = sha2564 = sha3845 = sha512The hash algorithm used in IPsec Phase-1 IKE negotiations. · Integer32
The hash algorithm used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.19
JnxIkeAuthMethod1 = preSharedKey2 = dssSignature3 = rsaSignature4 = rsaEncryption5 = revRsaEncryption6 = xauthPreSharedKey7 = xauthDssSignature8 = xauthRsaSignature9 = xauthRsaEncryption10 = xauthRevRsaEncryption11 = ecdsa256Signature12 = ecdsa384Signature13 = ecdsa521Signature14 = digitalSignatureThe authentication method used in IPsec Phase-1 IKE negotiations. · Integer32
The authentication method used in IPsec Phase-1 IKE negotiations.
1.3.6.1.4.1.2636.3.22.1.2.1.1.20
Integer32 (1..2147483647) · seconds
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.
1.3.6.1.4.1.2636.3.22.1.2.1.1.21
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.
1.3.6.1.4.1.2636.3.22.1.2.1.1.22
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.23
Counter32 · Packets
The total number of packets received by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.24
Counter64 (0..18446744073709551615) · Octets
The total number of octets sent by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.2.1.1.25
Counter32 · Packets
The total number of packets sent by this IPsec Phase-1 IKE security association.
1.3.6.1.4.1.2636.3.22.1.3.1
Index: jnxSpSvcSetName · jnxIpSecTunRemoteGwAddrType · jnxIpSecTunRemoteGwAddr · jnxIpSecTunIndex
The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel.
from JUNIPER-SP-MIB
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..96) · OCTET STRING · hint 255a
The Service Set name.
1.3.6.1.4.1.2636.3.22.1.3.1.1.1
Integer32 (1..2147483647)
The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.3.1.1.2
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the rule configured in IPSec configuration.
1.3.6.1.4.1.2636.3.22.1.3.1.1.3
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the term configured under IPSec rule.
1.3.6.1.4.1.2636.3.22.1.3.1.1.4
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.5
InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.6
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.7
InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.8
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the local end.
1.3.6.1.4.1.2636.3.22.1.3.1.1.9
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the remote end.
1.3.6.1.4.1.2636.3.22.1.3.1.1.10
JnxKeyType0 = unknown1 = keyIke2 = keyManualThe type of key used by an IPsec Phase-2 Tunnel. · Integer32
The type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installed
1.3.6.1.4.1.2636.3.22.1.3.1.1.11
JnxRemotePeerType0 = unknown1 = static2 = dynamicThe type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand). · Integer32
The type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand)
1.3.6.1.4.1.2636.3.22.1.3.1.1.12
Integer32
MTU value of this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.13
Counter64 (0..18446744073709551615)
Number of bytes encrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.14
Counter64 (0..18446744073709551615)
Number of packets encrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.15
Counter64 (0..18446744073709551615)
Number of bytes decrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.16
Counter64 (0..18446744073709551615)
Number of packets decrypted by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.17
Counter64 (0..18446744073709551615)
Number of incoming bytes authenticated using AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.18
Counter64 (0..18446744073709551615)
Number of incoming packets authenticated using AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.19
Counter64 (0..18446744073709551615)
Number of outgoing bytes applied AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.20
Counter64 (0..18446744073709551615)
Number of outgoing packets applied AH by this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.1.1.21
Counter64 (0..18446744073709551615)
Number of packets dropped by this Phase-2 tunnel due to anti replay check failure.
1.3.6.1.4.1.2636.3.22.1.3.1.1.22
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed AH authentication.
1.3.6.1.4.1.2636.3.22.1.3.1.1.23
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed ESP authentication.
1.3.6.1.4.1.2636.3.22.1.3.1.1.24
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed decryption.
1.3.6.1.4.1.2636.3.22.1.3.1.1.25
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed due to bad headers.
1.3.6.1.4.1.2636.3.22.1.3.1.1.26
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed due to bad ESP trailers.
1.3.6.1.4.1.2636.3.22.1.3.1.1.27
Counter64 (0..18446744073709551615)
Total number of dropped packets for this Phase-2 tunnel.
1.3.6.1.4.1.2636.3.22.1.3.2
Index: jnxSpSvcSetName · jnxIpSecTunRemoteGwAddrType · jnxIpSecTunRemoteGwAddr · jnxIpSecTunIndex · jnxIpSecSaIndex
The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table. The index of this table reflects the <destination-address, protocol, spi> rule for identifying Security Associations.
from JUNIPER-SP-MIB
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..96) · OCTET STRING · hint 255a
The Service Set name.
1.3.6.1.4.1.2636.3.22.1.3.2.1.1
INTEGER1 = ah2 = esp · Integer32
The index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
1.3.6.1.4.1.2636.3.22.1.3.2.1.2
Integer32 (1..2147483647)
The index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 2,147,483,647.
1.3.6.1.4.1.2636.3.22.1.3.2.1.3
JnxSpiThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the incoming SPI.
1.3.6.1.4.1.2636.3.22.1.3.2.1.4
JnxSpiThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the outgoing SPI.
1.3.6.1.4.1.2636.3.22.1.3.2.1.5
JnxSpiThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the incoming auxiliary SPI. This is valid for AH and ESP bundles.
1.3.6.1.4.1.2636.3.22.1.3.2.1.6
JnxSpiThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the outgoing auxiliary SPI. This is valid for AH and ESP bundles.
1.3.6.1.4.1.2636.3.22.1.3.2.1.7
JnxSAType0 = unknown1 = manual2 = dynamicSA Type manual or dynamic · Integer32
This field represents the type of security associations which can be either manual or dynamic
1.3.6.1.4.1.2636.3.22.1.3.2.1.8
JnxEncapMode0 = unknown1 = tunnel2 = transportThe encapsulation mode used by an IPsec Phase-2 Tunnel. · Integer32
The encapsulation mode used by an IPsec Phase-2 Tunnel.
1.3.6.1.4.1.2636.3.22.1.3.2.1.9
Integer32
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
1.3.6.1.4.1.2636.3.22.1.3.2.1.10
Integer32
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.11
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the IPsec Phase-2 Tunnel has been active in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.12
Integer32
The security association LifeSize refresh threshold in kilobytes.
1.3.6.1.4.1.2636.3.22.1.3.2.1.13
Integer32
The security association LifeTime refresh threshold in seconds.
1.3.6.1.4.1.2636.3.22.1.3.2.1.14
JnxEncryptAlgo1 = espDes2 = esp3des3 = espNull4 = espAes1285 = espAes1926 = espAes2567 = espAesGcm1288 = espAesGcm1929 = espAesGcm25610 = espChaCha20Poly1305The encryption algorithm used in negotiations. · Integer32
The Encryption algorithm used to encrypt the packets which can be either es-cbc or 3des-cbc.
1.3.6.1.4.1.2636.3.22.1.3.2.1.15
JnxAuthAlgo0 = unknown1 = hmacMd52 = hmacSha3 = hmacSha2564 = hmacSha3845 = hmacSha5126 = aesGcm1287 = aesGcm1928 = aesGcm2569 = chacha20Poly1305The authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32
The algorithm used for authentication of packets which can be hmac-md5-96 or hmac-sha1-96
1.3.6.1.4.1.2636.3.22.1.3.2.1.16
INTEGER0 = unknown1 = active2 = expiring · Integer32
This column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.