This module defines the object used to monitor the entries pertaining to IPSec objects and the management of the IPSEC VPN functionalities. tables: - IKE tunnel table - IPSec tunnel table - IPSec security associations table.
This mib module is based on JNX-IPSEC-MONITOR-MIB. Building on the existing IKE infrastruature, the security IKE implementation integrates the value-added features for the security products
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.
jnxIkeTrapPeerRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IKE SA negotiation.
jnxIkeTrapPeerRemotePort
1.3.6.1.4.1.2636.3.52.1.0.1.3
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.0.1.4
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.5
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalPort
1.3.6.1.4.1.2636.3.52.1.0.1.6
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerRoutingInstance
1.3.6.1.4.1.2636.3.52.1.0.1.7
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the routing instance.
jnxIkeTrapPeerLocalIdType
1.3.6.1.4.1.2636.3.52.1.0.1.8
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerLocalIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.9
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity.
If the local peer type is an IP Address, then this is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is the FQDN of the remote peer.
If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkeTrapPeerRemoteIdType
1.3.6.1.4.1.2636.3.52.1.0.1.10
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.11
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity.
If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is the FQDN of the remote peer.
If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkeTrapPeerAAAUserName
1.3.6.1.4.1.2636.3.52.1.0.1.12
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.
jnxIkeTrapPeerGwName
1.3.6.1.4.1.2636.3.52.1.0.1.13
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the IKE gateway.
jnxIkeTrapIpSecTunVpnName
1.3.6.1.4.1.2636.3.52.1.0.1.14
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
IPsec tunnel VPN name.
jnxIkeTrapIpSecTunTsName
1.3.6.1.4.1.2636.3.52.1.0.1.15
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
IPsec tunnel Traffic Selector name.
jnxIkeTrapIpSecTunLocalTS
1.3.6.1.4.1.2636.3.52.1.0.1.16
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the local end of IPsec tunnel.
jnxIkeTrapIpSecTunRemoteTS
1.3.6.1.4.1.2636.3.52.1.0.1.17
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the remote end of IPsec tunnel.
jnxIkeNumOfTunnels
1.3.6.1.4.1.2636.3.52.1.1.1
INTEGER · Integer32
Number of IKE Tunnels (phase-1) actively negotiating between peers. The SA can be in either the up or down state. This attribute should detail the number of IKE tunnels in jnxIkeTunnelMonTable.
jnxIkeGlobalInitiatorIkev2SaInitRequestOut
1.3.6.1.4.1.2636.3.52.1.1.3.1.1
Counter64 (0..18446744073709551615)
Number of IKE_SA_INIT request message sent by Initiator.
jnxIkeGlobalInitiatorIkev2SaInitResponseIn
1.3.6.1.4.1.2636.3.52.1.1.3.1.2
Counter64 (0..18446744073709551615)
Number of IKE_SA_INIT response message received by Initiator.
jnxIkeGlobalInitiatorIkev2SaInitResInvalidIkeSpi
1.3.6.1.4.1.2636.3.52.1.1.3.1.3
Counter64 (0..18446744073709551615)
Number of IKE_SA_INIT response message containing invalid SPI received by Initiator.
Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Responder.
jnxIkeGlobalIkev2TotalDiscarded
1.3.6.1.4.1.2636.3.52.1.1.3.9.1
Counter64 (0..18446744073709551615)
Total number of discarded messages. Includes the failures encountered during decode of IKEv2 packets that is failures before the IKEv2 exchange payload processing. Also this counter encompasses all the other message failure counters.
jnxIkeGlobalIkev2TotalIdError
1.3.6.1.4.1.2636.3.52.1.1.3.9.2
Counter64 (0..18446744073709551615)
Total number of messages with ID error. Message ID is not compliant with what is expected. For ex. IKE_SA_INIT message with message ID larger than zero is encountered.
jnxIkeGlobalIkev2TotalIntegrityFail
1.3.6.1.4.1.2636.3.52.1.1.3.9.3
Counter64 (0..18446744073709551615)
Total number of messages with Integrity check failure.
jnxIkeGlobalIkev2TotalInvalidSPI
1.3.6.1.4.1.2636.3.52.1.1.3.9.4
Counter64 (0..18446744073709551615)
Total number of messages with Invalid SPI failure. Used one of the SPIs to find the SA, but the other SPI is not matching. Invalid IKE SPIs in IKE_SA_INIT response message at Initiator.
jnxIkeGlobalIkev2TotalInvalidExchgType
1.3.6.1.4.1.2636.3.52.1.1.3.9.5
Counter64 (0..18446744073709551615)
Total number of messages with unknown / unexpected exchange type encountered during message exchange.
jnxIkeGlobalIkev2TotalInvalidLength
1.3.6.1.4.1.2636.3.52.1.1.3.9.6
Counter64 (0..18446744073709551615)
Total number of messages with Invalid length failure. During decode a malformed message where length is inconsistent with that indicated in header is encountered.
jnxIkeGlobalIkev2TotalDisorder
1.3.6.1.4.1.2636.3.52.1.1.3.9.7
Counter64 (0..18446744073709551615)
Total number of messages failure due to disorder. Packet message ID is out of window. For a response packet the corresponding request with given message ID is not found.
jnxIkeHaLinkGlobalInitiatorIkev2SaInitRequestOut
1.3.6.1.4.1.2636.3.52.1.1.9.1.1
Counter64 (0..18446744073709551615)
Number of IKE_SA_INIT request message sent by Initiator.
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResponseIn
1.3.6.1.4.1.2636.3.52.1.1.9.1.2
Counter64 (0..18446744073709551615)
Number of IKE_SA_INIT response message received by Initiator.
Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Responder.
jnxIkeHaLinkGlobalIkev2TotalDiscarded
1.3.6.1.4.1.2636.3.52.1.1.9.9.1
Counter64 (0..18446744073709551615)
Total number of discarded messages. Includes the failures encountered during decode of IKEv2 packets that is failures before the IKEv2 exchange payload processing. Also this counter encompasses all the other message failure counters.
jnxIkeHaLinkGlobalIkev2TotalIdError
1.3.6.1.4.1.2636.3.52.1.1.9.9.2
Counter64 (0..18446744073709551615)
Total number of messages with ID error. Message ID is not compliant with what is expected. For ex. IKE_SA_INIT message with message ID larger than zero is encountered.
jnxIkeHaLinkGlobalIkev2TotalIntegrityFail
1.3.6.1.4.1.2636.3.52.1.1.9.9.3
Counter64 (0..18446744073709551615)
Total number of messages with Integrity check failure.
jnxIkeHaLinkGlobalIkev2TotalInvalidSPI
1.3.6.1.4.1.2636.3.52.1.1.9.9.4
Counter64 (0..18446744073709551615)
Total number of messages with Invalid SPI failure. Used one of the SPIs to find the SA, but the other SPI is not matching. Invalid IKE SPIs in IKE_SA_INIT response message at Initiator.
jnxIkeHaLinkGlobalIkev2TotalInvalidExchgType
1.3.6.1.4.1.2636.3.52.1.1.9.9.5
Counter64 (0..18446744073709551615)
Total number of messages with unknown / unexpected exchange type encountered during message exchange.
jnxIkeHaLinkGlobalIkev2TotalInvalidLength
1.3.6.1.4.1.2636.3.52.1.1.9.9.6
Counter64 (0..18446744073709551615)
Total number of messages with Invalid length failure. During decode a malformed message where length is inconsistent with that indicated in header is encountered.
jnxIkeHaLinkGlobalIkev2TotalDisorder
1.3.6.1.4.1.2636.3.52.1.1.9.9.7
Counter64 (0..18446744073709551615)
Total number of messages failure due to disorder. Packet message ID is out of window. For a response packet the corresponding request with given message ID is not found.
jnxIpSecNumOfTunnels
1.3.6.1.4.1.2636.3.52.1.2.1
INTEGER · Integer32
Number of IPSEC VPN Tunnels. This attribute should detail the number of IPSEC VPN tunnel in jnxIpSecTunnelTable.
jnxIpSecGlobalOutEncryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.4.1
Counter64 (0..18446744073709551615)
Number of bytes encrypted by all Phase-2 tunnel.
jnxIpSecGlobalOutEncryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.4.2
Counter64 (0..18446744073709551615)
Number of packets encrypted by all Phase-2 tunnel.
jnxIpSecGlobalInDecryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.4.3
Counter64 (0..18446744073709551615)
Number of bytes decrypted by all Phase-2 tunnel.
jnxIpSecGlobalInDecryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.4.4
Counter64 (0..18446744073709551615)
Number of packets decrypted by all Phase-2 tunnel.
jnxIpSecGlobalAHInBytes
1.3.6.1.4.1.2636.3.52.1.2.4.5
Counter64 (0..18446744073709551615)
Number of incoming bytes authenticated using AH by all Phase-2 tunnel.
jnxIpSecGlobalAHInPkts
1.3.6.1.4.1.2636.3.52.1.2.4.6
Counter64 (0..18446744073709551615)
Number of incoming packets authenticated using AH by all Phase-2 tunnel.
jnxIpSecGlobalAHOutBytes
1.3.6.1.4.1.2636.3.52.1.2.4.7
Counter64 (0..18446744073709551615)
Number of outgoing bytes applied AH by all Phase-2 tunnel.
jnxIpSecGlobalAHOutPkts
1.3.6.1.4.1.2636.3.52.1.2.4.8
Counter64 (0..18446744073709551615)
Number of outgoing packets applied AH by all Phase-2 tunnel.
jnxIpSecGlobalReplayDropPkts
1.3.6.1.4.1.2636.3.52.1.2.4.9
Counter64 (0..18446744073709551615)
Number of packets dropped by all Phase-2 tunnel due to anti-replay check failure.
jnxIpSecGlobalAhAuthFails
1.3.6.1.4.1.2636.3.52.1.2.4.10
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed AH authentication.
jnxIpSecGlobalEspAuthFails
1.3.6.1.4.1.2636.3.52.1.2.4.11
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed ESP authentication.
jnxIpSecGlobalDecryptFails
1.3.6.1.4.1.2636.3.52.1.2.4.12
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed decryption.
jnxIpSecGlobalBadHeaders
1.3.6.1.4.1.2636.3.52.1.2.4.13
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed due to bad headers.
jnxIpSecGlobalBadTrailers
1.3.6.1.4.1.2636.3.52.1.2.4.14
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed due to bad ESP trailers.
jnxIpSecGlobalInvalidSpi
1.3.6.1.4.1.2636.3.52.1.2.4.15
Counter64 (0..18446744073709551615) · Packets
Total number of Invalid SPI.
jnxIpSecGlobalTsCheckFail
1.3.6.1.4.1.2636.3.52.1.2.4.16
Counter64 (0..18446744073709551615) · Packets
Total number of TS check fail.
jnxIpSecGlobalDiscarded
1.3.6.1.4.1.2636.3.52.1.2.4.17
Counter64 (0..18446744073709551615) · Packets
Total number of discarded packets.
jnxIpSecGlobalExceedsTunMtu
1.3.6.1.4.1.2636.3.52.1.2.4.18
Counter64 (0..18446744073709551615) · Packets
Number of packets received by all Phase-2 tunnel that failed due to Exceeding Tunnel MTU.
jnxIpSecHaLinkGlobalOutEncryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.5.1
Counter64 (0..18446744073709551615)
Number of bytes encrypted by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalOutEncryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.5.2
Counter64 (0..18446744073709551615)
Number of packets encrypted by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalInDecryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.5.3
Counter64 (0..18446744073709551615)
Number of bytes decrypted by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalInDecryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.5.4
Counter64 (0..18446744073709551615)
Number of packets decrypted by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalAHInBytes
1.3.6.1.4.1.2636.3.52.1.2.5.5
Counter64 (0..18446744073709551615)
Number of incoming bytes authenticated using AH by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalAHInPkts
1.3.6.1.4.1.2636.3.52.1.2.5.6
Counter64 (0..18446744073709551615)
Number of incoming packets authenticated using AH by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalAHOutBytes
1.3.6.1.4.1.2636.3.52.1.2.5.7
Counter64 (0..18446744073709551615)
Number of outgoing bytes applied AH by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalAHOutPkts
1.3.6.1.4.1.2636.3.52.1.2.5.8
Counter64 (0..18446744073709551615)
Number of outgoing packets applied AH by all Phase-2 tunnel.
jnxIpSecHaLinkGlobalReplayDropPkts
1.3.6.1.4.1.2636.3.52.1.2.5.9
Counter64 (0..18446744073709551615)
Number of packets dropped by all Phase-2 tunnel due to anti-replay check failure.
jnxIpSecHaLinkGlobalAhAuthFails
1.3.6.1.4.1.2636.3.52.1.2.5.10
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed AH authentication.
jnxIpSecHaLinkGlobalEspAuthFails
1.3.6.1.4.1.2636.3.52.1.2.5.11
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed ESP authentication.
jnxIpSecHaLinkGlobalDecryptFails
1.3.6.1.4.1.2636.3.52.1.2.5.12
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed decryption.
jnxIpSecHaLinkGlobalBadHeaders
1.3.6.1.4.1.2636.3.52.1.2.5.13
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed due to bad headers.
jnxIpSecHaLinkGlobalBadTrailers
1.3.6.1.4.1.2636.3.52.1.2.5.14
Counter64 (0..18446744073709551615)
Number of packets received by all Phase-2 tunnel that failed due to bad ESP trailers.
jnxIpSecHaLinkGlobalInvalidSpi
1.3.6.1.4.1.2636.3.52.1.2.5.15
Counter64 (0..18446744073709551615) · Packets
Total number of Invalid SPI.
jnxIpSecHaLinkGlobalTsCheckFail
1.3.6.1.4.1.2636.3.52.1.2.5.16
Counter64 (0..18446744073709551615) · Packets
Total number of TS check fail.
jnxIpSecHaLinkGlobalDiscarded
1.3.6.1.4.1.2636.3.52.1.2.5.17
Counter64 (0..18446744073709551615) · Packets
Total number of discarded packets.
jnxIpSecHaLinkGlobalExceedsTunMtu
1.3.6.1.4.1.2636.3.52.1.2.5.18
Counter64 (0..18446744073709551615) · Packets
Number of packets received by all Phase-2 tunnel that failed due to Exceeding Tunnel MTU.
The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
jnxIkeTunMonRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.2.1.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
jnxIkeTunMonRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.1.2.1.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.
jnxIkeTunMonIndex
1.3.6.1.4.1.2636.3.52.1.1.2.1.3
Integer32 (1..2147483647)
The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
jnxIkeTunMonLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.1.2.1.4
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
jnxIkeTunMonLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.2.1.5
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.
jnxIkeTunMonState
1.3.6.1.4.1.2636.3.52.1.1.2.1.6
JnxIkeTunStateType1 = up2 = downState of the Phase-1 IKE negotiation. · Integer32
The state of the IKE tunnel, It can be: 1. up - negotiation completed 2. down- being negotiated
jnxIkeTunMonInitiatorCookie
1.3.6.1.4.1.2636.3.52.1.1.2.1.7
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Cookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header.
jnxIkeTunMonResponderCookie
1.3.6.1.4.1.2636.3.52.1.1.2.1.8
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Cookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header.
jnxIkeTunMonLocalRole
1.3.6.1.4.1.2636.3.52.1.1.2.1.9
JnxIkePeerRole1 = initiator2 = responderRole of the local endpoint in negotiating the IPsec Phase-1 IKE security association. It can be either Initiator or Responder. · Integer32
The role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder.
jnxIkeTunMonLocalIdType
1.3.6.1.4.1.2636.3.52.1.1.2.1.10
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTunMonLocalIdValue
1.3.6.1.4.1.2636.3.52.1.1.2.1.11
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity.
If the local peer type is an IP Address, then this is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is the FQDN of the remote peer.
If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkeTunMonLocalCertName
1.3.6.1.4.1.2636.3.52.1.1.2.1.12
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string.
jnxIkeTunMonRemoteIdType
1.3.6.1.4.1.2636.3.52.1.1.2.1.13
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTunMonRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.1.2.1.14
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity.
If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is the FQDN of the remote peer.
If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkeTunMonNegoMode
1.3.6.1.4.1.2636.3.52.1.1.2.1.15
JnxIkeNegoMode1 = main2 = aggressive3 = ikev2The IPsec Phase-1 IKE negotiation mode. Main Mode: A six-message Phase 1 exchange that provides identity protection. Aggressive mode: a three-message phase 1 exchange that does not provide identity protection · Integer32
The negotiation mode of the IPsec Phase-1 IKE Tunnel.
The authentication method used in IPsec Phase-1 IKE negotiations.
jnxIkeTunMonLifeTime
1.3.6.1.4.1.2636.3.52.1.1.2.1.20
Integer32 (1..2147483647) · seconds
The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.
jnxIkeTunMonActiveTime
1.3.6.1.4.1.2636.3.52.1.1.2.1.21
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.
jnxIkeTunMonInOctets
1.3.6.1.4.1.2636.3.52.1.1.2.1.22
Counter64 (0..18446744073709551615) · Octets
The total number of octets received by this IPsec Phase-1 IKE security association.
jnxIkeTunMonInPkts
1.3.6.1.4.1.2636.3.52.1.1.2.1.23
Counter32 · Packets
The total number of packets received by this IPsec Phase-1 IKE security association.
jnxIkeTunMonOutOctets
1.3.6.1.4.1.2636.3.52.1.1.2.1.24
Counter64 (0..18446744073709551615) · Octets
The total number of octets sent by this IPsec Phase-1 IKE security association.
jnxIkeTunMonOutPkts
1.3.6.1.4.1.2636.3.52.1.1.2.1.25
Counter32 · Packets
The total number of packets sent by this IPsec Phase-1 IKE security association.
jnxIkeTunMonXAuthUserId
1.3.6.1.4.1.2636.3.52.1.1.2.1.26
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The extended Authentication (XAuth) User Identifier, identifies the user associated with this IPSec Phase negotiation.
jnxIkeTunMonDPDDownCount
1.3.6.1.4.1.2636.3.52.1.1.2.1.27
Counter32 · Packets
The number of times that the remote peer is detected in a dead (or down) state. This attribute is obsolete
jnxIkeTunMonInitiatorIkev2IPSecSaRekeyRequestOut
1.3.6.1.4.1.2636.3.52.1.1.2.1.28
Counter64 (0..18446744073709551615) · Messages
The number of IPSec SA rekey CREATE_CHILD_SA request message sent by Initiator.
jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResponseIn
1.3.6.1.4.1.2636.3.52.1.1.2.1.29
Counter64 (0..18446744073709551615) · Messages
The number of IPSec SA rekey CREATE_CHILD_SA response message received by Initiator.
The number of IPSec SA rekey CREATE_CHILD_SA response message Diffie-Hellman compute key failed at Responder.
jnxIkeTunMonGwName
1.3.6.1.4.1.2636.3.52.1.1.2.1.43
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The gateway name
jnxIkeTunMonTunType
1.3.6.1.4.1.2636.3.52.1.1.2.1.44
JnxIkeTunType1 = regular2 = halinkType of the tunnel. · Integer32
The Tunnel type. It can be regular (1) or ha-link (2)
jnxIkeTunMonLocalSignatureHashAlgo
1.3.6.1.4.1.2636.3.52.1.1.2.1.45
JnxIkeLocalSignatureHashAlgo1 = sha12 = sha2563 = sha3844 = sha512The signature hash algorithm used locally in IPsec Phase-1 IKE negotiations. · Integer32
The signature hash algorithm used locally in IPsec Phase-1 IKE negotiations.
jnxIkeTunMonRemoteSignatureHashAlgo
1.3.6.1.4.1.2636.3.52.1.1.2.1.46
JnxIkeRemoteSignatureHashAlgo1 = sha12 = sha2563 = sha3844 = sha512The signature hash algorithm used by remote peer in IPsec Phase-1 IKE negotiations. · Integer32
The signature hash algorithm used by remote peer in IPsec Phase-1 IKE negotiations.
jnxIkeTunMonDigitalSignAuthKey
1.3.6.1.4.1.2636.3.52.1.1.2.1.47
JnxIkeDigitalSignAuthKey1 = signAuthRsa2 = signAuthDsa3 = signAuthEcdsaSignature key RSA/DSA/ECDSA used for digital-signature auth method. · Integer32
Signature key RSA/DSA/ECDSA used for digital-signature auth method.
The IKE Key Exchange Peer Address Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated.
jnxIkePeerAddrState
1.3.6.1.4.1.2636.3.52.1.1.4.1.1
JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32
The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.
jnxIkePeerAddrRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.4.1.2
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerAddrRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.1.4.1.3
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerAddrRemotePort
1.3.6.1.4.1.2636.3.52.1.1.4.1.4
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkePeerAddrLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.4.1.5
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerAddrLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.1.4.1.6
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerAddrLocalPort
1.3.6.1.4.1.2636.3.52.1.1.4.1.7
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkePeerAddrRoutingInstance
1.3.6.1.4.1.2636.3.52.1.1.4.1.8
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The VR ID.
jnxIkePeerAddrIndex
1.3.6.1.4.1.2636.3.52.1.1.4.1.9
Unsigned32 (1..4294967295)
The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.
The IKE Key Exchange Peer ID Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated. In the index truncated value for Remote ID value, Local ID value and AAA username is used to restrict the length of the SNMP index to a legal size. In the index, for jnxIkePeerIdRemoteId and jnxIkePeerIdLocalId, any string longer than 41 bytes will be truncated and only 41 bytes would be considered. Similarly in the index, for jnxIkePeerIdAAAUserName, any string longer than 25 bytes will be truncated and only 25 bytes would be considered. Because of the truncation, the index may become same for different peers, to keep the index unique, jnxIkePeerInternalIndex is used to uniquely identify each peer.
jnxIkePeerIdState
1.3.6.1.4.1.2636.3.52.1.1.5.1.1
JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32
The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.
jnxIkePeerIdRemoteIdType
1.3.6.1.4.1.2636.3.52.1.1.5.1.2
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkePeerIdRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.1.5.1.3
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity.
If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is the FQDN of the remote peer.
If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkePeerIdLocalIdType
1.3.6.1.4.1.2636.3.52.1.1.5.1.4
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkePeerIdLocalIdValue
1.3.6.1.4.1.2636.3.52.1.1.5.1.5
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity.
If the local peer type is an IP Address, then this is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is the FQDN of the remote peer.
If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkePeerIdAAAUserName
1.3.6.1.4.1.2636.3.52.1.1.5.1.6
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.
jnxIkePeerInternalIndex
1.3.6.1.4.1.2636.3.52.1.1.5.1.7
Integer32 (1..2147483647)
The internal index of the Peer Id table. This index is used to uniquely identify multiple entry for the same truncated ids.
jnxIkePeerIdIndex
1.3.6.1.4.1.2636.3.52.1.1.5.1.8
Unsigned32 (1..4294967295)
The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.
The IKE Key Exchange Peer Stats Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated.
jnxIkePeerStatsState
1.3.6.1.4.1.2636.3.52.1.1.6.1.1
JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32
The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.
jnxIkePeerStatsIndex
1.3.6.1.4.1.2636.3.52.1.1.6.1.2
Unsigned32 (1..4294967295)
The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.
jnxIkePeerStatsRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.6.1.3
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerStatsRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.1.6.1.4
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerStatsRemotePort
1.3.6.1.4.1.2636.3.52.1.1.6.1.5
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The value specifying a port associated with the remote gateway (endpoint) for the IKE Tunnel. A value of zero means that the port should be ignored.
jnxIkePeerStatsLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.1.6.1.6
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerStatsLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.1.6.1.7
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.
jnxIkePeerStatsLocalPort
1.3.6.1.4.1.2636.3.52.1.1.6.1.8
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The value specifying a port associated with the local endpoint (gateway) for the IKE Tunnel. A value of zero means that the port should be ignored.
jnxIkePeerStatsRoutingInstance
1.3.6.1.4.1.2636.3.52.1.1.6.1.9
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The VR ID.
jnxIkePeerStatsRemoteIdType
1.3.6.1.4.1.2636.3.52.1.1.6.1.10
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkePeerStatsRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.1.6.1.11
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkePeerStatsLocalIdType
1.3.6.1.4.1.2636.3.52.1.1.6.1.12
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkePeerStatsLocalIdValue
1.3.6.1.4.1.2636.3.52.1.1.6.1.13
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkePeerStatsAAAUserName
1.3.6.1.4.1.2636.3.52.1.1.6.1.14
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The extended authentication User Name, identifies the user associated with the IKE SA negotiation.
jnxIkePeerStatsGwName
1.3.6.1.4.1.2636.3.52.1.1.6.1.15
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The Peer Association to active IKE SA - Correlation Table. There is one entry in this table for each active IKE SA.
jnxPeerIkeSaCorrPeerIndex
1.3.6.1.4.1.2636.3.52.1.1.7.1.1
Integer32 (1..2147483647)
The index of the Peer (jnxPeerIndex in the jnxIkePeerTable).
jnxPeerIkeSaCorrIntIndex
1.3.6.1.4.1.2636.3.52.1.1.7.1.2
Integer32 (1..2147483647)
The internal index of the Peer and IKE SA association. This internal index is used to uniquely identify multiple Instances of a unique association between the peer and IKE SA.
jnxPeerIkeSaCorrIkeTunMonIndex
1.3.6.1.4.1.2636.3.52.1.1.7.1.3
Unsigned32 (1..4294967295)
The index of the active IKE SA (jnxIkeTunMonIndex in the jnxIkeTunnelMonTable) for this Peer association.
The Peer Association to IPSec Tunnel Correlation Table. There is one entry in this table for each active IPSec Tunnel.
jnxPeerIPSecTunnelCorrPeerIndex
1.3.6.1.4.1.2636.3.52.1.1.8.1.1
Integer32 (1..2147483647)
The index of the Peer (jnxPeerIndex in the jnxIkePeerTable).
jnxPeerIPSecTunnelCorrIntIndex
1.3.6.1.4.1.2636.3.52.1.1.8.1.2
Integer32 (1..2147483647)
The internal index of the Peer and IPSec Tunnel association. This index is used to uniquely identify multiple association between the peer and IPSec Tunnel.
jnxPeerIPSecTunnelCorrIPSecTunMonIndex
1.3.6.1.4.1.2636.3.52.1.1.8.1.3
Integer32 (1..2147483647)
The index of the active IPSec Tunnel (jnxIpSecTunMonIndex in the jnxIpSecTunnelMonTable) for this association between Peer and IPSec Tunnel.
The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel. If the tunnel is terminated, then the entry is no longer available after the table has been refreshed.
jnxIpSecTunMonRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.2.2.1.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
jnxIpSecTunMonRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.2.2.1.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.
jnxIpSecTunMonIndex
1.3.6.1.4.1.2636.3.52.1.2.2.1.3
Integer32 (1..2147483647)
The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.
jnxIpSecTunMonLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.2.2.1.4
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
jnxIpSecTunMonLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.2.2.1.5
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.
jnxIpSecTunMonLocalProxyId
1.3.6.1.4.1.2636.3.52.1.2.2.1.6
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the local end.
jnxIpSecTunMonRemoteProxyId
1.3.6.1.4.1.2636.3.52.1.2.2.1.7
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the remote end.
jnxIpSecTunMonKeyType
1.3.6.1.4.1.2636.3.52.1.2.2.1.8
JnxKeyType0 = unknown1 = keyIke2 = keyManualThe type of key used by an IPsec Phase-2 Tunnel. · Integer32
The type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installed
jnxIpSecTunMonRemotePeerType
1.3.6.1.4.1.2636.3.52.1.2.2.1.9
JnxRemotePeerType0 = unknown1 = static2 = dynamicThe type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand). · Integer32
The type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand)
jnxIpSecTunMonOutEncryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.2.1.10
Counter64 (0..18446744073709551615)
Number of bytes encrypted by this Phase-2 tunnel.
jnxIpSecTunMonOutEncryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.11
Counter64 (0..18446744073709551615)
Number of packets encrypted by this Phase-2 tunnel.
jnxIpSecTunMonInDecryptedBytes
1.3.6.1.4.1.2636.3.52.1.2.2.1.12
Counter64 (0..18446744073709551615)
Number of bytes decrypted by this Phase-2 tunnel.
jnxIpSecTunMonInDecryptedPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.13
Counter64 (0..18446744073709551615)
Number of packets decrypted by this Phase-2 tunnel.
jnxIpSecTunMonAHInBytes
1.3.6.1.4.1.2636.3.52.1.2.2.1.14
Counter64 (0..18446744073709551615)
Number of incoming bytes authenticated using AH by this Phase-2 tunnel.
jnxIpSecTunMonAHInPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.15
Counter64 (0..18446744073709551615)
Number of incoming packets authenticated using AH by this Phase-2 tunnel.
jnxIpSecTunMonAHOutBytes
1.3.6.1.4.1.2636.3.52.1.2.2.1.16
Counter64 (0..18446744073709551615)
Number of outgoing bytes applied AH by this Phase-2 tunnel.
jnxIpSecTunMonAHOutPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.17
Counter64 (0..18446744073709551615)
Number of outgoing packets applied AH by this Phase-2 tunnel.
jnxIpSecTunMonReplayDropPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.18
Counter64 (0..18446744073709551615)
Number of packets dropped by this Phase-2 tunnel due to anti replay check failure.
jnxIpSecTunMonAhAuthFails
1.3.6.1.4.1.2636.3.52.1.2.2.1.19
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed AH authentication.
jnxIpSecTunMonEspAuthFails
1.3.6.1.4.1.2636.3.52.1.2.2.1.20
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed ESP authentication.
jnxIpSecTunMonDecryptFails
1.3.6.1.4.1.2636.3.52.1.2.2.1.21
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed decryption.
jnxIpSecTunMonBadHeaders
1.3.6.1.4.1.2636.3.52.1.2.2.1.22
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed due to bad headers.
jnxIpSecTunMonBadTrailers
1.3.6.1.4.1.2636.3.52.1.2.2.1.23
Counter64 (0..18446744073709551615)
Number of packets received by this Phase-2 tunnel that failed due to bad ESP trailers.
jnxIpSecTunMonDroppedPkts
1.3.6.1.4.1.2636.3.52.1.2.2.1.26
Counter64 (0..18446744073709551615)
Total number of dropped packets for this Phase-2 tunnel. This attribute is obsolete.
jnxIpSecTunMonVpnName
1.3.6.1.4.1.2636.3.52.1.2.2.1.27
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
VPN tunnel name.
jnxIpSecTunMonTsName
1.3.6.1.4.1.2636.3.52.1.2.2.1.28
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Traffic selector name.
jnxIpSecTunMonMultiSa
1.3.6.1.4.1.2636.3.52.1.2.2.1.29
INTEGER0 = disable1 = enable · Integer32
Multi-SA Configuration Status.
jnxIpSecTunMonInvalidSpi
1.3.6.1.4.1.2636.3.52.1.2.2.1.30
Counter64 (0..18446744073709551615) · Packets
Total number of Invalid SPI for this IPSec tunnel.
jnxIpSecTunMonTsCheckFail
1.3.6.1.4.1.2636.3.52.1.2.2.1.31
Counter64 (0..18446744073709551615) · Packets
Total number of TS check fail for this IPSec tunnel.
jnxIpSecTunMonDiscarded
1.3.6.1.4.1.2636.3.52.1.2.2.1.32
Counter64 (0..18446744073709551615) · Packets
Total number of discarded packets for this IPSec tunnel.
jnxIpSecTunMonTunType
1.3.6.1.4.1.2636.3.52.1.2.2.1.33
JnxIkeTunType1 = regular2 = halinkType of the tunnel. · Integer32
The Tunnel type. It can be regular (1) or ha-link (2).
jnxIpSecTunMonTsType
1.3.6.1.4.1.2636.3.52.1.2.2.1.34
JnxIpSecTsType1 = proxyId2 = trafficSelectorType of the TS. · Integer32
The TS type. It can be proxyId (1) or trafficSelector (2).
jnxIpSecTunMonTSi
1.3.6.1.4.1.2636.3.52.1.2.2.1.35
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Negotiated Traffic Selector or Proxy ID for the local end.
jnxIpSecTunMonTSr
1.3.6.1.4.1.2636.3.52.1.2.2.1.36
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Negotiated Traffic Selector or Proxy ID for the remote end.
jnxIpSecTunMonTunMtu
1.3.6.1.4.1.2636.3.52.1.2.2.1.37
Integer32 (0..9192)
The maximum transmit packet size (256..9192) for IPSec tunnels. The value of this object will be 0, if tunnel MTU is not configured.
jnxIpSecTunMonExceedsTunMtu
1.3.6.1.4.1.2636.3.52.1.2.2.1.38
Counter64 (0..18446744073709551615) · Packets
Number of packets received by this Phase-2 tunnel that failed due to Exceeding Tunnel MTU.
The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table.
SA contains the information negotiated by IKE. The SA is like a contract laying out the rules of the VPN connection for the duration of the SA. An SA is assigned a 32-bit number that, when used in conjunction with the destination IP address, uniquely identifies the SA. This number is called the Security Parameters Index or SPI.
IPSec SAs area unidirectional and they are unique in each security protocol. A set of SAs are needed for a protected data pipe, one per direction per protocol.
jnxIpSecSaMonIndex
1.3.6.1.4.1.2636.3.52.1.2.3.1.1
Integer32 (1..65535)
The index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 65535.
jnxIpSecSaMonProtocol
1.3.6.1.4.1.2636.3.52.1.2.3.1.2
INTEGER1 = ah2 = esp · Integer32
The index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup.
jnxIpSecSaMonInSpi
1.3.6.1.4.1.2636.3.52.1.2.3.1.3
JnxSpiTypeThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the incoming SPI.
jnxIpSecSaMonOutSpi
1.3.6.1.4.1.2636.3.52.1.2.3.1.4
JnxSpiTypeThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32
The value of the outgoing SPI.
jnxIpSecSaMonType
1.3.6.1.4.1.2636.3.52.1.2.3.1.5
JnxSAType0 = unknown1 = manual2 = dynamicSA Type manual or dynamic · Integer32
This field represents the type of security associations which can be either manual or dynamic
jnxIpSecSaMonEncapMode
1.3.6.1.4.1.2636.3.52.1.2.3.1.6
JnxEncapMode0 = unknown1 = tunnel2 = transportThe encapsulation mode used by an IPsec Phase-2 Tunnel. · Integer32
The encapsulation mode used by an IPsec Phase-2 Tunnel.
jnxIpSecSaMonLifeSize
1.3.6.1.4.1.2636.3.52.1.2.3.1.7
Integer32
The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.
jnxIpSecSaMonLifeTime
1.3.6.1.4.1.2636.3.52.1.2.3.1.8
Integer32
The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.
jnxIpSecSaMonActiveTime
1.3.6.1.4.1.2636.3.52.1.2.3.1.9
TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32
The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.
jnxIpSecSaMonLifeSizeThreshold
1.3.6.1.4.1.2636.3.52.1.2.3.1.10
Integer32
The security association LifeSize refresh threshold in kilobytes.
jnxIpSecSaMonLifeTimeThreshold
1.3.6.1.4.1.2636.3.52.1.2.3.1.11
Integer32
The security association LifeTime refresh threshold in seconds.
This column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.
jnxIpSecSaMonFcName
1.3.6.1.4.1.2636.3.52.1.2.3.1.15
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
This field represents whether IPSec extended sequence number support is enabled or disabled
Trap details
jnxIkePeerDown
1.3.6.1.4.1.2636.3.52.1.0.0.1
To provide notification for the event when Peer goes down.
jnxIkeTrapPeerRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.0.1.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.
jnxIkeTrapPeerRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IKE SA negotiation.
jnxIkeTrapPeerRemotePort
1.3.6.1.4.1.2636.3.52.1.0.1.3
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.0.1.4
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.5
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalPort
1.3.6.1.4.1.2636.3.52.1.0.1.6
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerRoutingInstance
1.3.6.1.4.1.2636.3.52.1.0.1.7
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the routing instance.
jnxIkeTrapPeerLocalIdType
1.3.6.1.4.1.2636.3.52.1.0.1.8
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerLocalIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.9
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity.
If the local peer type is an IP Address, then this is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is the FQDN of the remote peer.
If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkeTrapPeerRemoteIdType
1.3.6.1.4.1.2636.3.52.1.0.1.10
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.11
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity.
If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is the FQDN of the remote peer.
If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkeTrapPeerAAAUserName
1.3.6.1.4.1.2636.3.52.1.0.1.12
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.
jnxIkeTrapPeerGwName
1.3.6.1.4.1.2636.3.52.1.0.1.13
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the IKE gateway.
jnxIkePeerIPSecTunnelDown
1.3.6.1.4.1.2636.3.52.1.0.0.2
To provide notification for the event of IPSec Tunnels going down for a peer. These traps are not generated if the corresponding peer has gone down.
jnxIkeTrapPeerRemoteGwAddrType
1.3.6.1.4.1.2636.3.52.1.0.1.1
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.
jnxIkeTrapPeerRemoteGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.2
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the remote gateway (endpoint) for the IKE SA negotiation.
jnxIkeTrapPeerRemotePort
1.3.6.1.4.1.2636.3.52.1.0.1.3
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerLocalGwAddrType
1.3.6.1.4.1.2636.3.52.1.0.1.4
InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address.
unknown(0) An unknown address type. This value MUST
be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below.
ipv4(1) An IPv4 address as defined by the
InetAddressIPv4 textual convention.
ipv6(2) An IPv6 address as defined by the
InetAddressIPv6 textual convention.
ipv4z(3) A non-global IPv4 address including a zone
index as defined by the InetAddressIPv4z textual convention.
ipv6z(4) A non-global IPv6 address including a zone
index as defined by the InetAddressIPv6z textual convention.
dns(16) A DNS domain name as defined by the
InetAddressDNS textual convention.
Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType.
To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation.
Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32
The IP address type of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalGwAddr
1.3.6.1.4.1.2636.3.52.1.0.1.5
InetAddressDenotes a generic Internet address.
An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row.
The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error.
When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING
The IP address of the local endpoint (gateway) for the IKE SA negotiation.
jnxIkeTrapPeerLocalPort
1.3.6.1.4.1.2636.3.52.1.0.1.6
InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>.
The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d
The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.
jnxIkeTrapPeerRoutingInstance
1.3.6.1.4.1.2636.3.52.1.0.1.7
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the routing instance.
jnxIkeTrapPeerLocalIdType
1.3.6.1.4.1.2636.3.52.1.0.1.8
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerLocalIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.9
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the local peer identity.
If the local peer type is an IP Address, then this is the IP Address used to identify the local peer.
If the local peer type is id_fqdn, then this is the FQDN of the remote peer.
If the local peer type is a id_dn, then this is the distinguished name string of the local peer.
jnxIkeTrapPeerRemoteIdType
1.3.6.1.4.1.2636.3.52.1.0.1.10
JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address.
idUfqdn - user fully qualified domain name (user@hostname).
idFqdn - full qualified domain name
idDn - distinquished name · Integer32
The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.
jnxIkeTrapPeerRemoteIdValue
1.3.6.1.4.1.2636.3.52.1.0.1.11
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
The value of the remote peer identity.
If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer.
If the remote peer type is id_fqdn, then this is the FQDN of the remote peer.
If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.
jnxIkeTrapPeerAAAUserName
1.3.6.1.4.1.2636.3.52.1.0.1.12
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.
jnxIkeTrapPeerGwName
1.3.6.1.4.1.2636.3.52.1.0.1.13
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Name of the IKE gateway.
jnxIkeTrapIpSecTunVpnName
1.3.6.1.4.1.2636.3.52.1.0.1.14
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
IPsec tunnel VPN name.
jnxIkeTrapIpSecTunTsName
1.3.6.1.4.1.2636.3.52.1.0.1.15
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
IPsec tunnel Traffic Selector name.
jnxIkeTrapIpSecTunLocalTS
1.3.6.1.4.1.2636.3.52.1.0.1.16
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a
Identifier for the local end of IPsec tunnel.
jnxIkeTrapIpSecTunRemoteTS
1.3.6.1.4.1.2636.3.52.1.0.1.17
DisplayStringRepresents textual information taken from the NVT ASCII
character set, as defined in pages 4, 10-11 of RFC 854.
To summarize RFC 854, the NVT ASCII repertoire specifies:
- the use of character codes 0-127 (decimal)
- the graphics characters (32-126) are interpreted as US ASCII
- NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854
- the other 25 codes have no standard interpretation
- the sequence 'CR LF' means newline
- the sequence 'CR NUL' means carriage-return
- an 'LF' not preceded by a 'CR' means moving to the same column on the next line.
- the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.)
Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a