EZ5 MIB Catalog

JUNIPER-IPSEC-FLOW-MON-MIB

2021-03-15

This module defines the object used to monitor the entries pertaining to IPSec objects and the management of the IPSEC VPN functionalities. tables: - IKE tunnel table - IPSec tunnel table - IPSec security associations table. This mib module is based on JNX-IPSEC-MONITOR-MIB. Building on the existing IKE infrastruature, the security IKE implementation integrates the value-added features for the security products

Download JUNIPER-IPSEC-FLOW-MON-MIB.txt Open JUNIPER-IPSEC-FLOW-MON-MIB.txt in a new tab

SCALARS (188) · TABLES (8) · TRAPS (2)

Scalars (188)

NameOID
jnxIkeTrapPeerRemoteGwAddrType1.3.6.1.4.1.2636.3.52.1.0.1.1
jnxIkeTrapPeerRemoteGwAddr1.3.6.1.4.1.2636.3.52.1.0.1.2
jnxIkeTrapPeerRemotePort1.3.6.1.4.1.2636.3.52.1.0.1.3
jnxIkeTrapPeerLocalGwAddrType1.3.6.1.4.1.2636.3.52.1.0.1.4
jnxIkeTrapPeerLocalGwAddr1.3.6.1.4.1.2636.3.52.1.0.1.5
jnxIkeTrapPeerLocalPort1.3.6.1.4.1.2636.3.52.1.0.1.6
jnxIkeTrapPeerRoutingInstance1.3.6.1.4.1.2636.3.52.1.0.1.7
jnxIkeTrapPeerLocalIdType1.3.6.1.4.1.2636.3.52.1.0.1.8
jnxIkeTrapPeerLocalIdValue1.3.6.1.4.1.2636.3.52.1.0.1.9
jnxIkeTrapPeerRemoteIdType1.3.6.1.4.1.2636.3.52.1.0.1.10
jnxIkeTrapPeerRemoteIdValue1.3.6.1.4.1.2636.3.52.1.0.1.11
jnxIkeTrapPeerAAAUserName1.3.6.1.4.1.2636.3.52.1.0.1.12
jnxIkeTrapPeerGwName1.3.6.1.4.1.2636.3.52.1.0.1.13
jnxIkeTrapIpSecTunVpnName1.3.6.1.4.1.2636.3.52.1.0.1.14
jnxIkeTrapIpSecTunTsName1.3.6.1.4.1.2636.3.52.1.0.1.15
jnxIkeTrapIpSecTunLocalTS1.3.6.1.4.1.2636.3.52.1.0.1.16
jnxIkeTrapIpSecTunRemoteTS1.3.6.1.4.1.2636.3.52.1.0.1.17
jnxIkeNumOfTunnels1.3.6.1.4.1.2636.3.52.1.1.1
jnxIkeGlobalInitiatorIkev2SaInitRequestOut1.3.6.1.4.1.2636.3.52.1.1.3.1.1
jnxIkeGlobalInitiatorIkev2SaInitResponseIn1.3.6.1.4.1.2636.3.52.1.1.3.1.2
jnxIkeGlobalInitiatorIkev2SaInitResInvalidIkeSpi1.3.6.1.4.1.2636.3.52.1.1.3.1.3
jnxIkeGlobalInitiatorIkev2SaInitInvalidKePayloadIn1.3.6.1.4.1.2636.3.52.1.1.3.1.4
jnxIkeGlobalInitiatorIkev2SaInitNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.3.1.5
jnxIkeGlobalInitiatorIkev2SaInitResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.3.1.6
jnxIkeGlobalInitiatorIkev2SaInitResIkeSaFillFail1.3.6.1.4.1.2636.3.52.1.1.3.1.7
jnxIkeGlobalInitiatorIkev2SaInitResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.3.1.8
jnxIkeGlobalInitiatorIkev2SaInitCookieRequestIn1.3.6.1.4.1.2636.3.52.1.1.3.1.9
jnxIkeGlobalInitiatorIkev2SaInitCookieResponseOut1.3.6.1.4.1.2636.3.52.1.1.3.1.10
jnxIkeGlobalInitiatorIkev2SaInitResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.1.11
jnxIkeGlobalResponderIkev2SaInitRequestIn1.3.6.1.4.1.2636.3.52.1.1.3.2.1
jnxIkeGlobalResponderIkev2SaInitResponseOut1.3.6.1.4.1.2636.3.52.1.1.3.2.2
jnxIkeGlobalResponderIkev2SaInitNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.3.2.3
jnxIkeGlobalResponderIkev2SaInitInvalidKePayloadOut1.3.6.1.4.1.2636.3.52.1.1.3.2.4
jnxIkeGlobalResponderIkev2SaInitResInvalidDhGroupConf1.3.6.1.4.1.2636.3.52.1.1.3.2.5
jnxIkeGlobalResponderIkev2SaInitResDhGenKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.2.6
jnxIkeGlobalResponderIkev2SaInitResGetCAsFail1.3.6.1.4.1.2636.3.52.1.1.3.2.7
jnxIkeGlobalResponderIkev2SaInitResGetVidFail1.3.6.1.4.1.2636.3.52.1.1.3.2.8
jnxIkeGlobalResponderIkev2SaInitResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.2.9
jnxIkeGlobalResponderIkev2SaInitCookieRequestOut1.3.6.1.4.1.2636.3.52.1.1.3.2.10
jnxIkeGlobalResponderIkev2SaInitCookieResponseIn1.3.6.1.4.1.2636.3.52.1.1.3.2.11
jnxIkeGlobalInitiatorIkev2AuthRequestOut1.3.6.1.4.1.2636.3.52.1.1.3.3.1
jnxIkeGlobalInitiatorIkev2AuthResponseIn1.3.6.1.4.1.2636.3.52.1.1.3.3.2
jnxIkeGlobalInitiatorIkev2AuthNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.3.3.3
jnxIkeGlobalInitiatorIkev2AuthTsUnacceptableIn1.3.6.1.4.1.2636.3.52.1.1.3.3.4
jnxIkeGlobalInitiatorIkev2AuthAuthenticationFailedIn1.3.6.1.4.1.2636.3.52.1.1.3.3.5
jnxIkeGlobalResponderIkev2AuthRequestIn1.3.6.1.4.1.2636.3.52.1.1.3.4.1
jnxIkeGlobalResponderIkev2AuthResponseOut1.3.6.1.4.1.2636.3.52.1.1.3.4.2
jnxIkeGlobalResponderIkev2AuthNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.3.4.3
jnxIkeGlobalResponderIkev2AuthTsUnacceptableOut1.3.6.1.4.1.2636.3.52.1.1.3.4.4
jnxIkeGlobalResponderIkev2AuthAuthenticationFailedOut1.3.6.1.4.1.2636.3.52.1.1.3.4.5
jnxIkeGlobalInitiatorIkev2IkeSaRekeyRequestOut1.3.6.1.4.1.2636.3.52.1.1.3.5.1
jnxIkeGlobalInitiatorIkev2IkeSaRekeyResponseIn1.3.6.1.4.1.2636.3.52.1.1.3.5.2
jnxIkeGlobalInitiatorIkev2IkeSaRekeyNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.3.5.3
jnxIkeGlobalInitiatorIkev2IkeSaRekeyInvalidKeIn1.3.6.1.4.1.2636.3.52.1.1.3.5.4
jnxIkeGlobalInitiatorIkev2IkeSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.5.5
jnxIkeGlobalInitiatorIkev2IkeSaRekeyResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.3.5.6
jnxIkeGlobalInitiatorIkev2IkeSaRekeyResFillIkeSaFail1.3.6.1.4.1.2636.3.52.1.1.3.5.7
jnxIkeGlobalInitiatorIkev2IkeSaRekeyResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.3.5.8
jnxIkeGlobalResponderIkev2IkeSaRekeyRequestIn1.3.6.1.4.1.2636.3.52.1.1.3.6.1
jnxIkeGlobalResponderIkev2IkeSaRekeyResponseOut1.3.6.1.4.1.2636.3.52.1.1.3.6.2
jnxIkeGlobalResponderIkev2IkeSaRekeyNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.3.6.3
jnxIkeGlobalResponderIkev2IkeSaRekeyInvalidKeOut1.3.6.1.4.1.2636.3.52.1.1.3.6.4
jnxIkeGlobalResponderIkev2IkeSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.6.5
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyRequestOut1.3.6.1.4.1.2636.3.52.1.1.3.7.1
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResponseIn1.3.6.1.4.1.2636.3.52.1.1.3.7.2
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.3.7.3
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyInvalidKeIn1.3.6.1.4.1.2636.3.52.1.1.3.7.4
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyTsUnacceptableIn1.3.6.1.4.1.2636.3.52.1.1.3.7.5
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.3.7.6
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.7.7
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.3.7.8
jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifyTsFail1.3.6.1.4.1.2636.3.52.1.1.3.7.9
jnxIkeGlobalResponderIkev2IpsecSaRekeyRequestIn1.3.6.1.4.1.2636.3.52.1.1.3.8.1
jnxIkeGlobalResponderIkev2IpsecSaRekeyResponseOut1.3.6.1.4.1.2636.3.52.1.1.3.8.2
jnxIkeGlobalResponderIkev2IpsecSaRekeyNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.3.8.3
jnxIkeGlobalResponderIkev2IpsecSaRekeyInvalidKeOut1.3.6.1.4.1.2636.3.52.1.1.3.8.4
jnxIkeGlobalResponderIkev2IpsecSaRekeyTsUnacceptableOut1.3.6.1.4.1.2636.3.52.1.1.3.8.5
jnxIkeGlobalResponderIkev2IpsecSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.3.8.6
jnxIkeGlobalIkev2TotalDiscarded1.3.6.1.4.1.2636.3.52.1.1.3.9.1
jnxIkeGlobalIkev2TotalIdError1.3.6.1.4.1.2636.3.52.1.1.3.9.2
jnxIkeGlobalIkev2TotalIntegrityFail1.3.6.1.4.1.2636.3.52.1.1.3.9.3
jnxIkeGlobalIkev2TotalInvalidSPI1.3.6.1.4.1.2636.3.52.1.1.3.9.4
jnxIkeGlobalIkev2TotalInvalidExchgType1.3.6.1.4.1.2636.3.52.1.1.3.9.5
jnxIkeGlobalIkev2TotalInvalidLength1.3.6.1.4.1.2636.3.52.1.1.3.9.6
jnxIkeGlobalIkev2TotalDisorder1.3.6.1.4.1.2636.3.52.1.1.3.9.7
jnxIkeHaLinkGlobalInitiatorIkev2SaInitRequestOut1.3.6.1.4.1.2636.3.52.1.1.9.1.1
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResponseIn1.3.6.1.4.1.2636.3.52.1.1.9.1.2
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResInvalidIkeSpi1.3.6.1.4.1.2636.3.52.1.1.9.1.3
jnxIkeHaLinkGlobalInitiatorIkev2SaInitInvalidKePayloadIn1.3.6.1.4.1.2636.3.52.1.1.9.1.4
jnxIkeHaLinkGlobalInitiatorIkev2SaInitNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.9.1.5
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.9.1.6
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResIkeSaFillFail1.3.6.1.4.1.2636.3.52.1.1.9.1.7
jnxIkeHaLinkGlobalInitiatorIkev2SaInitResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.9.1.8
jnxIkeHaLinkGlobalInitiatorIkev2SaInitCookieRequestIn1.3.6.1.4.1.2636.3.52.1.1.9.1.9
jnxIkeHaLinkGlobalInitiatorIkev2SaInitCookieResponseOut1.3.6.1.4.1.2636.3.52.1.1.9.1.10
jnxIkeHaLinkGlobalResponderIkev2SaInitRequestIn1.3.6.1.4.1.2636.3.52.1.1.9.2.1
jnxIkeHaLinkGlobalResponderIkev2SaInitResponseOut1.3.6.1.4.1.2636.3.52.1.1.9.2.2
jnxIkeHaLinkGlobalResponderIkev2SaInitNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.9.2.3
jnxIkeHaLinkGlobalResponderIkev2SaInitInvalidKePayloadOut1.3.6.1.4.1.2636.3.52.1.1.9.2.4
jnxIkeHaLinkGlobalResponderIkev2SaInitResInvalidDhGroupConf1.3.6.1.4.1.2636.3.52.1.1.9.2.5
jnxIkeHaLinkGlobalResponderIkev2SaInitResDhGenKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.2.6
jnxIkeHaLinkGlobalResponderIkev2SaInitResGetCAsFail1.3.6.1.4.1.2636.3.52.1.1.9.2.7
jnxIkeHaLinkGlobalResponderIkev2SaInitResGetVidFail1.3.6.1.4.1.2636.3.52.1.1.9.2.8
jnxIkeHaLinkGlobalResponderIkev2SaInitResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.2.9
jnxIkeHaLinkGlobalResponderIkev2SaInitCookieRequestOut1.3.6.1.4.1.2636.3.52.1.1.9.2.10
jnxIkeHaLinkGlobalResponderIkev2SaInitCookieResponseIn1.3.6.1.4.1.2636.3.52.1.1.9.2.11
jnxIkeHaLinkGlobalInitiatorIkev2AuthRequestOut1.3.6.1.4.1.2636.3.52.1.1.9.3.1
jnxIkeHaLinkGlobalInitiatorIkev2AuthResponseIn1.3.6.1.4.1.2636.3.52.1.1.9.3.2
jnxIkeHaLinkGlobalInitiatorIkev2AuthNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.9.3.3
jnxIkeHaLinkGlobalInitiatorIkev2AuthTsUnacceptableIn1.3.6.1.4.1.2636.3.52.1.1.9.3.4
jnxIkeHaLinkGlobalInitiatorIkev2AuthAuthenticationFailedIn1.3.6.1.4.1.2636.3.52.1.1.9.3.5
jnxIkeHaLinkGlobalResponderIkev2AuthRequestIn1.3.6.1.4.1.2636.3.52.1.1.9.4.1
jnxIkeHaLinkGlobalResponderIkev2AuthResponseOut1.3.6.1.4.1.2636.3.52.1.1.9.4.2
jnxIkeHaLinkGlobalResponderIkev2AuthNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.9.4.3
jnxIkeHaLinkGlobalResponderIkev2AuthTsUnacceptableOut1.3.6.1.4.1.2636.3.52.1.1.9.4.4
jnxIkeHaLinkGlobalResponderIkev2AuthAuthenticationFailedOut1.3.6.1.4.1.2636.3.52.1.1.9.4.5
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyRequestOut1.3.6.1.4.1.2636.3.52.1.1.9.5.1
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResponseIn1.3.6.1.4.1.2636.3.52.1.1.9.5.2
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.9.5.3
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyInvalidKeIn1.3.6.1.4.1.2636.3.52.1.1.9.5.4
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.5.5
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.9.5.6
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResFillIkeSaFail1.3.6.1.4.1.2636.3.52.1.1.9.5.7
jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.9.5.8
jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyRequestIn1.3.6.1.4.1.2636.3.52.1.1.9.6.1
jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyResponseOut1.3.6.1.4.1.2636.3.52.1.1.9.6.2
jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.9.6.3
jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyInvalidKeOut1.3.6.1.4.1.2636.3.52.1.1.9.6.4
jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.6.5
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyRequestOut1.3.6.1.4.1.2636.3.52.1.1.9.7.1
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResponseIn1.3.6.1.4.1.2636.3.52.1.1.9.7.2
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyNoProposalChosenIn1.3.6.1.4.1.2636.3.52.1.1.9.7.3
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyInvalidKeIn1.3.6.1.4.1.2636.3.52.1.1.9.7.4
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyTsUnacceptableIn1.3.6.1.4.1.2636.3.52.1.1.9.7.5
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifySaFail1.3.6.1.4.1.2636.3.52.1.1.9.7.6
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.7.7
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifyDhGroupFail1.3.6.1.4.1.2636.3.52.1.1.9.7.8
jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifyTsFail1.3.6.1.4.1.2636.3.52.1.1.9.7.9
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyRequestIn1.3.6.1.4.1.2636.3.52.1.1.9.8.1
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyResponseOut1.3.6.1.4.1.2636.3.52.1.1.9.8.2
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyNoProposalChosenOut1.3.6.1.4.1.2636.3.52.1.1.9.8.3
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyInvalidKeOut1.3.6.1.4.1.2636.3.52.1.1.9.8.4
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyTsUnacceptableOut1.3.6.1.4.1.2636.3.52.1.1.9.8.5
jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyResDhComputeKeyFail1.3.6.1.4.1.2636.3.52.1.1.9.8.6
jnxIkeHaLinkGlobalIkev2TotalDiscarded1.3.6.1.4.1.2636.3.52.1.1.9.9.1
jnxIkeHaLinkGlobalIkev2TotalIdError1.3.6.1.4.1.2636.3.52.1.1.9.9.2
jnxIkeHaLinkGlobalIkev2TotalIntegrityFail1.3.6.1.4.1.2636.3.52.1.1.9.9.3
jnxIkeHaLinkGlobalIkev2TotalInvalidSPI1.3.6.1.4.1.2636.3.52.1.1.9.9.4
jnxIkeHaLinkGlobalIkev2TotalInvalidExchgType1.3.6.1.4.1.2636.3.52.1.1.9.9.5
jnxIkeHaLinkGlobalIkev2TotalInvalidLength1.3.6.1.4.1.2636.3.52.1.1.9.9.6
jnxIkeHaLinkGlobalIkev2TotalDisorder1.3.6.1.4.1.2636.3.52.1.1.9.9.7
jnxIpSecNumOfTunnels1.3.6.1.4.1.2636.3.52.1.2.1
jnxIpSecGlobalOutEncryptedBytes1.3.6.1.4.1.2636.3.52.1.2.4.1
jnxIpSecGlobalOutEncryptedPkts1.3.6.1.4.1.2636.3.52.1.2.4.2
jnxIpSecGlobalInDecryptedBytes1.3.6.1.4.1.2636.3.52.1.2.4.3
jnxIpSecGlobalInDecryptedPkts1.3.6.1.4.1.2636.3.52.1.2.4.4
jnxIpSecGlobalAHInBytes1.3.6.1.4.1.2636.3.52.1.2.4.5
jnxIpSecGlobalAHInPkts1.3.6.1.4.1.2636.3.52.1.2.4.6
jnxIpSecGlobalAHOutBytes1.3.6.1.4.1.2636.3.52.1.2.4.7
jnxIpSecGlobalAHOutPkts1.3.6.1.4.1.2636.3.52.1.2.4.8
jnxIpSecGlobalReplayDropPkts1.3.6.1.4.1.2636.3.52.1.2.4.9
jnxIpSecGlobalAhAuthFails1.3.6.1.4.1.2636.3.52.1.2.4.10
jnxIpSecGlobalEspAuthFails1.3.6.1.4.1.2636.3.52.1.2.4.11
jnxIpSecGlobalDecryptFails1.3.6.1.4.1.2636.3.52.1.2.4.12
jnxIpSecGlobalBadHeaders1.3.6.1.4.1.2636.3.52.1.2.4.13
jnxIpSecGlobalBadTrailers1.3.6.1.4.1.2636.3.52.1.2.4.14
jnxIpSecGlobalInvalidSpi1.3.6.1.4.1.2636.3.52.1.2.4.15
jnxIpSecGlobalTsCheckFail1.3.6.1.4.1.2636.3.52.1.2.4.16
jnxIpSecGlobalDiscarded1.3.6.1.4.1.2636.3.52.1.2.4.17
jnxIpSecGlobalExceedsTunMtu1.3.6.1.4.1.2636.3.52.1.2.4.18
jnxIpSecHaLinkGlobalOutEncryptedBytes1.3.6.1.4.1.2636.3.52.1.2.5.1
jnxIpSecHaLinkGlobalOutEncryptedPkts1.3.6.1.4.1.2636.3.52.1.2.5.2
jnxIpSecHaLinkGlobalInDecryptedBytes1.3.6.1.4.1.2636.3.52.1.2.5.3
jnxIpSecHaLinkGlobalInDecryptedPkts1.3.6.1.4.1.2636.3.52.1.2.5.4
jnxIpSecHaLinkGlobalAHInBytes1.3.6.1.4.1.2636.3.52.1.2.5.5
jnxIpSecHaLinkGlobalAHInPkts1.3.6.1.4.1.2636.3.52.1.2.5.6
jnxIpSecHaLinkGlobalAHOutBytes1.3.6.1.4.1.2636.3.52.1.2.5.7
jnxIpSecHaLinkGlobalAHOutPkts1.3.6.1.4.1.2636.3.52.1.2.5.8
jnxIpSecHaLinkGlobalReplayDropPkts1.3.6.1.4.1.2636.3.52.1.2.5.9
jnxIpSecHaLinkGlobalAhAuthFails1.3.6.1.4.1.2636.3.52.1.2.5.10
jnxIpSecHaLinkGlobalEspAuthFails1.3.6.1.4.1.2636.3.52.1.2.5.11
jnxIpSecHaLinkGlobalDecryptFails1.3.6.1.4.1.2636.3.52.1.2.5.12
jnxIpSecHaLinkGlobalBadHeaders1.3.6.1.4.1.2636.3.52.1.2.5.13
jnxIpSecHaLinkGlobalBadTrailers1.3.6.1.4.1.2636.3.52.1.2.5.14
jnxIpSecHaLinkGlobalInvalidSpi1.3.6.1.4.1.2636.3.52.1.2.5.15
jnxIpSecHaLinkGlobalTsCheckFail1.3.6.1.4.1.2636.3.52.1.2.5.16
jnxIpSecHaLinkGlobalDiscarded1.3.6.1.4.1.2636.3.52.1.2.5.17
jnxIpSecHaLinkGlobalExceedsTunMtu1.3.6.1.4.1.2636.3.52.1.2.5.18

Tables (8)

NameOID
jnxIkeTunnelMonTable1.3.6.1.4.1.2636.3.52.1.1.2
jnxIkePeerAddrTable1.3.6.1.4.1.2636.3.52.1.1.4
jnxIkePeerIdTable1.3.6.1.4.1.2636.3.52.1.1.5
jnxIkePeerStatsTable1.3.6.1.4.1.2636.3.52.1.1.6
jnxPeerIkeSaCorrTable1.3.6.1.4.1.2636.3.52.1.1.7
jnxPeerIPSecTunnelCorrTable1.3.6.1.4.1.2636.3.52.1.1.8
jnxIpSecTunnelMonTable1.3.6.1.4.1.2636.3.52.1.2.2
jnxIpSecSaMonTable1.3.6.1.4.1.2636.3.52.1.2.3

Traps (2)

NameOID
jnxIkePeerDown1.3.6.1.4.1.2636.3.52.1.0.0.1
jnxIkePeerIPSecTunnelDown1.3.6.1.4.1.2636.3.52.1.0.0.2

END OF TOC

Scalar details

jnxIkeTrapPeerRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.

jnxIkeTrapPeerRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IKE SA negotiation.

jnxIkeTrapPeerRemotePort

1.3.6.1.4.1.2636.3.52.1.0.1.3

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalPort

1.3.6.1.4.1.2636.3.52.1.0.1.6

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerRoutingInstance

1.3.6.1.4.1.2636.3.52.1.0.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the routing instance.

jnxIkeTrapPeerLocalIdType

1.3.6.1.4.1.2636.3.52.1.0.1.8

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerLocalIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkeTrapPeerRemoteIdType

1.3.6.1.4.1.2636.3.52.1.0.1.10

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.11

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkeTrapPeerAAAUserName

1.3.6.1.4.1.2636.3.52.1.0.1.12

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.

jnxIkeTrapPeerGwName

1.3.6.1.4.1.2636.3.52.1.0.1.13

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the IKE gateway.

jnxIkeTrapIpSecTunVpnName

1.3.6.1.4.1.2636.3.52.1.0.1.14

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

IPsec tunnel VPN name.

jnxIkeTrapIpSecTunTsName

1.3.6.1.4.1.2636.3.52.1.0.1.15

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

IPsec tunnel Traffic Selector name.

jnxIkeTrapIpSecTunLocalTS

1.3.6.1.4.1.2636.3.52.1.0.1.16

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the local end of IPsec tunnel.

jnxIkeTrapIpSecTunRemoteTS

1.3.6.1.4.1.2636.3.52.1.0.1.17

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the remote end of IPsec tunnel.

jnxIkeNumOfTunnels

1.3.6.1.4.1.2636.3.52.1.1.1

INTEGER · Integer32

Number of IKE Tunnels (phase-1) actively negotiating between peers. The SA can be in either the up or down state. This attribute should detail the number of IKE tunnels in jnxIkeTunnelMonTable.

jnxIkeGlobalInitiatorIkev2SaInitRequestOut

1.3.6.1.4.1.2636.3.52.1.1.3.1.1

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT request message sent by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitResponseIn

1.3.6.1.4.1.2636.3.52.1.1.3.1.2

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message received by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitResInvalidIkeSpi

1.3.6.1.4.1.2636.3.52.1.1.3.1.3

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message containing invalid SPI received by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitInvalidKePayloadIn

1.3.6.1.4.1.2636.3.52.1.1.3.1.4

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT INVALID_KE_PAYLOAD received by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.3.1.5

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT NO_PROPSAL_CHOSEN received by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.3.1.6

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message verification of peer SA failed at Initiator.

jnxIkeGlobalInitiatorIkev2SaInitResIkeSaFillFail

1.3.6.1.4.1.2636.3.52.1.1.3.1.7

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message IKE SA fill operation failed at Initiator.

jnxIkeGlobalInitiatorIkev2SaInitResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.3.1.8

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message verification of DH group failed at Initiator.

jnxIkeGlobalInitiatorIkev2SaInitCookieRequestIn

1.3.6.1.4.1.2636.3.52.1.1.3.1.9

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification request message received by Initiator.

jnxIkeGlobalInitiatorIkev2SaInitCookieResponseOut

1.3.6.1.4.1.2636.3.52.1.1.3.1.10

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification response message sent by Responder.

jnxIkeGlobalInitiatorIkev2SaInitResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.1.11

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message Diffie-Hellman compute key failed at Initiator.

jnxIkeGlobalResponderIkev2SaInitRequestIn

1.3.6.1.4.1.2636.3.52.1.1.3.2.1

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT request message received by Responder.

jnxIkeGlobalResponderIkev2SaInitResponseOut

1.3.6.1.4.1.2636.3.52.1.1.3.2.2

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message sent by Responder.

jnxIkeGlobalResponderIkev2SaInitNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.3.2.3

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeGlobalResponderIkev2SaInitInvalidKePayloadOut

1.3.6.1.4.1.2636.3.52.1.1.3.2.4

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeGlobalResponderIkev2SaInitResInvalidDhGroupConf

1.3.6.1.4.1.2636.3.52.1.1.3.2.5

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message invalid DH group configured at Responder.

jnxIkeGlobalResponderIkev2SaInitResDhGenKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.2.6

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message Diffie-Hellman generate key failed at Responder

jnxIkeGlobalResponderIkev2SaInitResGetCAsFail

1.3.6.1.4.1.2636.3.52.1.1.3.2.7

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message get CAs failed at Responder.

jnxIkeGlobalResponderIkev2SaInitResGetVidFail

1.3.6.1.4.1.2636.3.52.1.1.3.2.8

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message get vendor ID request failed at Responder.

jnxIkeGlobalResponderIkev2SaInitResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.2.9

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message Diffie-Hellman compute key failed at Responder

jnxIkeGlobalResponderIkev2SaInitCookieRequestOut

1.3.6.1.4.1.2636.3.52.1.1.3.2.10

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification request message sent by Responder.

jnxIkeGlobalResponderIkev2SaInitCookieResponseIn

1.3.6.1.4.1.2636.3.52.1.1.3.2.11

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification response message received by Responder.

jnxIkeGlobalInitiatorIkev2AuthRequestOut

1.3.6.1.4.1.2636.3.52.1.1.3.3.1

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message sent by Initiator.

jnxIkeGlobalInitiatorIkev2AuthResponseIn

1.3.6.1.4.1.2636.3.52.1.1.3.3.2

Counter64 (0..18446744073709551615)

Number of IKE_AUTH response message received by Initiator.

jnxIkeGlobalInitiatorIkev2AuthNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.3.3.3

Counter64 (0..18446744073709551615)

Number of IKE_AUTH NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeGlobalInitiatorIkev2AuthTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.3.3.4

Counter64 (0..18446744073709551615)

Number of IKE_AUTH TS_UNACCEPTABLE notification received by Initiator.

jnxIkeGlobalInitiatorIkev2AuthAuthenticationFailedIn

1.3.6.1.4.1.2636.3.52.1.1.3.3.5

Counter64 (0..18446744073709551615)

Number of IKE_AUTH AUTHENTICATION_FAILED notification received by Initiator.

jnxIkeGlobalResponderIkev2AuthRequestIn

1.3.6.1.4.1.2636.3.52.1.1.3.4.1

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message received by Responder.

jnxIkeGlobalResponderIkev2AuthResponseOut

1.3.6.1.4.1.2636.3.52.1.1.3.4.2

Counter64 (0..18446744073709551615)

Number of IKE_AUTH response message sent by Responder.

jnxIkeGlobalResponderIkev2AuthNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.3.4.3

Counter64 (0..18446744073709551615)

Number of IKE_AUTH NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeGlobalResponderIkev2AuthTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.3.4.4

Counter64 (0..18446744073709551615)

Number of IKE_AUTH TS_UNACCEPTABLE notification sent by Responder.

jnxIkeGlobalResponderIkev2AuthAuthenticationFailedOut

1.3.6.1.4.1.2636.3.52.1.1.3.4.5

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message AUTHENTICATION_FAILED notification sent by Responder.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.3.5.1

Counter64 (0..18446744073709551615)

Number of IKE SA rekey CREATE_CHILD_SA request message sent by Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.3.5.2

Counter64 (0..18446744073709551615)

Number of IKE SA rekey CREATE_CHILD_SA response message received by Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.3.5.3

Counter64 (0..18446744073709551615)

Number of IKE SA rekey NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.3.5.4

Counter64 (0..18446744073709551615)

Number of IKE SA rekey INVALID_KE_PAYLOAD notification received by Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.5.5

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.3.5.6

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message verification of peer SA failed at Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyResFillIkeSaFail

1.3.6.1.4.1.2636.3.52.1.1.3.5.7

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message fill IKE SA failed at Initiator.

jnxIkeGlobalInitiatorIkev2IkeSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.3.5.8

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message verification of DH group failed at Initiator.

jnxIkeGlobalResponderIkev2IkeSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.3.6.1

Counter64 (0..18446744073709551615)

Number of IKE SA rekey request message received by Responder.

jnxIkeGlobalResponderIkev2IkeSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.3.6.2

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message sent by Responder.

jnxIkeGlobalResponderIkev2IkeSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.3.6.3

Counter64 (0..18446744073709551615)

Number of IKE SA rekey NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeGlobalResponderIkev2IkeSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.3.6.4

Counter64 (0..18446744073709551615)

Number of IKE SA rekey INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeGlobalResponderIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.6.5

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message Diffie-Hellman compute key failed at Responder.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.3.7.1

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey request message sent by Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.3.7.2

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message received by Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.3.7.3

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.3.7.4

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey INVALID_KE_PAYLOAD notification received by Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.3.7.5

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey TS_UNACCEPTABLE notification received by Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.3.7.6

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of peer SA failed at Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.7.7

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.3.7.8

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of DH group failed at Initiator.

jnxIkeGlobalInitiatorIkev2IpsecSaRekeyResVerifyTsFail

1.3.6.1.4.1.2636.3.52.1.1.3.7.9

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of TS failed at Initiator.

jnxIkeGlobalResponderIkev2IpsecSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.3.8.1

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey request message received by Responder.

jnxIkeGlobalResponderIkev2IpsecSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.3.8.2

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message sent by Responder.

jnxIkeGlobalResponderIkev2IpsecSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.3.8.3

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeGlobalResponderIkev2IpsecSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.3.8.4

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeGlobalResponderIkev2IpsecSaRekeyTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.3.8.5

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey TS_UNACCEPTABLE notification sent by Responder.

jnxIkeGlobalResponderIkev2IpsecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.3.8.6

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Responder.

jnxIkeGlobalIkev2TotalDiscarded

1.3.6.1.4.1.2636.3.52.1.1.3.9.1

Counter64 (0..18446744073709551615)

Total number of discarded messages. Includes the failures encountered during decode of IKEv2 packets that is failures before the IKEv2 exchange payload processing. Also this counter encompasses all the other message failure counters.

jnxIkeGlobalIkev2TotalIdError

1.3.6.1.4.1.2636.3.52.1.1.3.9.2

Counter64 (0..18446744073709551615)

Total number of messages with ID error. Message ID is not compliant with what is expected. For ex. IKE_SA_INIT message with message ID larger than zero is encountered.

jnxIkeGlobalIkev2TotalIntegrityFail

1.3.6.1.4.1.2636.3.52.1.1.3.9.3

Counter64 (0..18446744073709551615)

Total number of messages with Integrity check failure.

jnxIkeGlobalIkev2TotalInvalidSPI

1.3.6.1.4.1.2636.3.52.1.1.3.9.4

Counter64 (0..18446744073709551615)

Total number of messages with Invalid SPI failure. Used one of the SPIs to find the SA, but the other SPI is not matching. Invalid IKE SPIs in IKE_SA_INIT response message at Initiator.

jnxIkeGlobalIkev2TotalInvalidExchgType

1.3.6.1.4.1.2636.3.52.1.1.3.9.5

Counter64 (0..18446744073709551615)

Total number of messages with unknown / unexpected exchange type encountered during message exchange.

jnxIkeGlobalIkev2TotalInvalidLength

1.3.6.1.4.1.2636.3.52.1.1.3.9.6

Counter64 (0..18446744073709551615)

Total number of messages with Invalid length failure. During decode a malformed message where length is inconsistent with that indicated in header is encountered.

jnxIkeGlobalIkev2TotalDisorder

1.3.6.1.4.1.2636.3.52.1.1.3.9.7

Counter64 (0..18446744073709551615)

Total number of messages failure due to disorder. Packet message ID is out of window. For a response packet the corresponding request with given message ID is not found.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitRequestOut

1.3.6.1.4.1.2636.3.52.1.1.9.1.1

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT request message sent by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitResponseIn

1.3.6.1.4.1.2636.3.52.1.1.9.1.2

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitResInvalidIkeSpi

1.3.6.1.4.1.2636.3.52.1.1.9.1.3

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message containing invalid SPI received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitInvalidKePayloadIn

1.3.6.1.4.1.2636.3.52.1.1.9.1.4

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT INVALID_KE_PAYLOAD received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.9.1.5

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT NO_PROPSAL_CHOSEN received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.9.1.6

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message verification of peer SA failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitResIkeSaFillFail

1.3.6.1.4.1.2636.3.52.1.1.9.1.7

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message IKE SA fill operation failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.9.1.8

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message verification of DH group failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitCookieRequestIn

1.3.6.1.4.1.2636.3.52.1.1.9.1.9

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification request message received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2SaInitCookieResponseOut

1.3.6.1.4.1.2636.3.52.1.1.9.1.10

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification response message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitRequestIn

1.3.6.1.4.1.2636.3.52.1.1.9.2.1

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT request message received by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitResponseOut

1.3.6.1.4.1.2636.3.52.1.1.9.2.2

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.9.2.3

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitInvalidKePayloadOut

1.3.6.1.4.1.2636.3.52.1.1.9.2.4

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitResInvalidDhGroupConf

1.3.6.1.4.1.2636.3.52.1.1.9.2.5

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message invalid DH group configured at Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitResDhGenKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.2.6

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message Diffie-Hellman generate key failed at Responder

jnxIkeHaLinkGlobalResponderIkev2SaInitResGetCAsFail

1.3.6.1.4.1.2636.3.52.1.1.9.2.7

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message get CAs failed at Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitResGetVidFail

1.3.6.1.4.1.2636.3.52.1.1.9.2.8

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message get vendor ID request failed at Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.2.9

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT response message Diffie-Hellman compute key failed at Responder

jnxIkeHaLinkGlobalResponderIkev2SaInitCookieRequestOut

1.3.6.1.4.1.2636.3.52.1.1.9.2.10

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification request message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2SaInitCookieResponseIn

1.3.6.1.4.1.2636.3.52.1.1.9.2.11

Counter64 (0..18446744073709551615)

Number of IKE_SA_INIT COOKIE notification response message received by Responder.

jnxIkeHaLinkGlobalInitiatorIkev2AuthRequestOut

1.3.6.1.4.1.2636.3.52.1.1.9.3.1

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message sent by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2AuthResponseIn

1.3.6.1.4.1.2636.3.52.1.1.9.3.2

Counter64 (0..18446744073709551615)

Number of IKE_AUTH response message received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2AuthNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.9.3.3

Counter64 (0..18446744073709551615)

Number of IKE_AUTH NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2AuthTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.9.3.4

Counter64 (0..18446744073709551615)

Number of IKE_AUTH TS_UNACCEPTABLE notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2AuthAuthenticationFailedIn

1.3.6.1.4.1.2636.3.52.1.1.9.3.5

Counter64 (0..18446744073709551615)

Number of IKE_AUTH AUTHENTICATION_FAILED notification received by Initiator.

jnxIkeHaLinkGlobalResponderIkev2AuthRequestIn

1.3.6.1.4.1.2636.3.52.1.1.9.4.1

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message received by Responder.

jnxIkeHaLinkGlobalResponderIkev2AuthResponseOut

1.3.6.1.4.1.2636.3.52.1.1.9.4.2

Counter64 (0..18446744073709551615)

Number of IKE_AUTH response message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2AuthNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.9.4.3

Counter64 (0..18446744073709551615)

Number of IKE_AUTH NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2AuthTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.9.4.4

Counter64 (0..18446744073709551615)

Number of IKE_AUTH TS_UNACCEPTABLE notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2AuthAuthenticationFailedOut

1.3.6.1.4.1.2636.3.52.1.1.9.4.5

Counter64 (0..18446744073709551615)

Number of IKE_AUTH request message AUTHENTICATION_FAILED notification sent by Responder.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.9.5.1

Counter64 (0..18446744073709551615)

Number of IKE SA rekey CREATE_CHILD_SA request message sent by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.9.5.2

Counter64 (0..18446744073709551615)

Number of IKE SA rekey CREATE_CHILD_SA response message received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.9.5.3

Counter64 (0..18446744073709551615)

Number of IKE SA rekey NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.9.5.4

Counter64 (0..18446744073709551615)

Number of IKE SA rekey INVALID_KE_PAYLOAD notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.5.5

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.9.5.6

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message verification of peer SA failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResFillIkeSaFail

1.3.6.1.4.1.2636.3.52.1.1.9.5.7

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message fill IKE SA failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IkeSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.9.5.8

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message verification of DH group failed at Initiator.

jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.9.6.1

Counter64 (0..18446744073709551615)

Number of IKE SA rekey request message received by Responder.

jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.9.6.2

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.9.6.3

Counter64 (0..18446744073709551615)

Number of IKE SA rekey NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.9.6.4

Counter64 (0..18446744073709551615)

Number of IKE SA rekey INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.6.5

Counter64 (0..18446744073709551615)

Number of IKE SA rekey response message Diffie-Hellman compute key failed at Responder.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.9.7.1

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey request message sent by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.9.7.2

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.9.7.3

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.9.7.4

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey INVALID_KE_PAYLOAD notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.9.7.5

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey TS_UNACCEPTABLE notification received by Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.9.7.6

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of peer SA failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.7.7

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.9.7.8

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of DH group failed at Initiator.

jnxIkeHaLinkGlobalInitiatorIkev2IpsecSaRekeyResVerifyTsFail

1.3.6.1.4.1.2636.3.52.1.1.9.7.9

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message verification of TS failed at Initiator.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.9.8.1

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey request message received by Responder.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.9.8.2

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.9.8.3

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.9.8.4

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.9.8.5

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey TS_UNACCEPTABLE notification sent by Responder.

jnxIkeHaLinkGlobalResponderIkev2IpsecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.9.8.6

Counter64 (0..18446744073709551615)

Number of IPSec SA rekey response message Diffie-Hellman compute key failed at Responder.

jnxIkeHaLinkGlobalIkev2TotalDiscarded

1.3.6.1.4.1.2636.3.52.1.1.9.9.1

Counter64 (0..18446744073709551615)

Total number of discarded messages. Includes the failures encountered during decode of IKEv2 packets that is failures before the IKEv2 exchange payload processing. Also this counter encompasses all the other message failure counters.

jnxIkeHaLinkGlobalIkev2TotalIdError

1.3.6.1.4.1.2636.3.52.1.1.9.9.2

Counter64 (0..18446744073709551615)

Total number of messages with ID error. Message ID is not compliant with what is expected. For ex. IKE_SA_INIT message with message ID larger than zero is encountered.

jnxIkeHaLinkGlobalIkev2TotalIntegrityFail

1.3.6.1.4.1.2636.3.52.1.1.9.9.3

Counter64 (0..18446744073709551615)

Total number of messages with Integrity check failure.

jnxIkeHaLinkGlobalIkev2TotalInvalidSPI

1.3.6.1.4.1.2636.3.52.1.1.9.9.4

Counter64 (0..18446744073709551615)

Total number of messages with Invalid SPI failure. Used one of the SPIs to find the SA, but the other SPI is not matching. Invalid IKE SPIs in IKE_SA_INIT response message at Initiator.

jnxIkeHaLinkGlobalIkev2TotalInvalidExchgType

1.3.6.1.4.1.2636.3.52.1.1.9.9.5

Counter64 (0..18446744073709551615)

Total number of messages with unknown / unexpected exchange type encountered during message exchange.

jnxIkeHaLinkGlobalIkev2TotalInvalidLength

1.3.6.1.4.1.2636.3.52.1.1.9.9.6

Counter64 (0..18446744073709551615)

Total number of messages with Invalid length failure. During decode a malformed message where length is inconsistent with that indicated in header is encountered.

jnxIkeHaLinkGlobalIkev2TotalDisorder

1.3.6.1.4.1.2636.3.52.1.1.9.9.7

Counter64 (0..18446744073709551615)

Total number of messages failure due to disorder. Packet message ID is out of window. For a response packet the corresponding request with given message ID is not found.

jnxIpSecNumOfTunnels

1.3.6.1.4.1.2636.3.52.1.2.1

INTEGER · Integer32

Number of IPSEC VPN Tunnels. This attribute should detail the number of IPSEC VPN tunnel in jnxIpSecTunnelTable.

jnxIpSecGlobalOutEncryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.4.1

Counter64 (0..18446744073709551615)

Number of bytes encrypted by all Phase-2 tunnel.

jnxIpSecGlobalOutEncryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.4.2

Counter64 (0..18446744073709551615)

Number of packets encrypted by all Phase-2 tunnel.

jnxIpSecGlobalInDecryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.4.3

Counter64 (0..18446744073709551615)

Number of bytes decrypted by all Phase-2 tunnel.

jnxIpSecGlobalInDecryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.4.4

Counter64 (0..18446744073709551615)

Number of packets decrypted by all Phase-2 tunnel.

jnxIpSecGlobalAHInBytes

1.3.6.1.4.1.2636.3.52.1.2.4.5

Counter64 (0..18446744073709551615)

Number of incoming bytes authenticated using AH by all Phase-2 tunnel.

jnxIpSecGlobalAHInPkts

1.3.6.1.4.1.2636.3.52.1.2.4.6

Counter64 (0..18446744073709551615)

Number of incoming packets authenticated using AH by all Phase-2 tunnel.

jnxIpSecGlobalAHOutBytes

1.3.6.1.4.1.2636.3.52.1.2.4.7

Counter64 (0..18446744073709551615)

Number of outgoing bytes applied AH by all Phase-2 tunnel.

jnxIpSecGlobalAHOutPkts

1.3.6.1.4.1.2636.3.52.1.2.4.8

Counter64 (0..18446744073709551615)

Number of outgoing packets applied AH by all Phase-2 tunnel.

jnxIpSecGlobalReplayDropPkts

1.3.6.1.4.1.2636.3.52.1.2.4.9

Counter64 (0..18446744073709551615)

Number of packets dropped by all Phase-2 tunnel due to anti-replay check failure.

jnxIpSecGlobalAhAuthFails

1.3.6.1.4.1.2636.3.52.1.2.4.10

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed AH authentication.

jnxIpSecGlobalEspAuthFails

1.3.6.1.4.1.2636.3.52.1.2.4.11

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed ESP authentication.

jnxIpSecGlobalDecryptFails

1.3.6.1.4.1.2636.3.52.1.2.4.12

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed decryption.

jnxIpSecGlobalBadHeaders

1.3.6.1.4.1.2636.3.52.1.2.4.13

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed due to bad headers.

jnxIpSecGlobalBadTrailers

1.3.6.1.4.1.2636.3.52.1.2.4.14

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed due to bad ESP trailers.

jnxIpSecGlobalInvalidSpi

1.3.6.1.4.1.2636.3.52.1.2.4.15

Counter64 (0..18446744073709551615) · Packets

Total number of Invalid SPI.

jnxIpSecGlobalTsCheckFail

1.3.6.1.4.1.2636.3.52.1.2.4.16

Counter64 (0..18446744073709551615) · Packets

Total number of TS check fail.

jnxIpSecGlobalDiscarded

1.3.6.1.4.1.2636.3.52.1.2.4.17

Counter64 (0..18446744073709551615) · Packets

Total number of discarded packets.

jnxIpSecGlobalExceedsTunMtu

1.3.6.1.4.1.2636.3.52.1.2.4.18

Counter64 (0..18446744073709551615) · Packets

Number of packets received by all Phase-2 tunnel that failed due to Exceeding Tunnel MTU.

jnxIpSecHaLinkGlobalOutEncryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.5.1

Counter64 (0..18446744073709551615)

Number of bytes encrypted by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalOutEncryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.5.2

Counter64 (0..18446744073709551615)

Number of packets encrypted by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalInDecryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.5.3

Counter64 (0..18446744073709551615)

Number of bytes decrypted by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalInDecryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.5.4

Counter64 (0..18446744073709551615)

Number of packets decrypted by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalAHInBytes

1.3.6.1.4.1.2636.3.52.1.2.5.5

Counter64 (0..18446744073709551615)

Number of incoming bytes authenticated using AH by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalAHInPkts

1.3.6.1.4.1.2636.3.52.1.2.5.6

Counter64 (0..18446744073709551615)

Number of incoming packets authenticated using AH by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalAHOutBytes

1.3.6.1.4.1.2636.3.52.1.2.5.7

Counter64 (0..18446744073709551615)

Number of outgoing bytes applied AH by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalAHOutPkts

1.3.6.1.4.1.2636.3.52.1.2.5.8

Counter64 (0..18446744073709551615)

Number of outgoing packets applied AH by all Phase-2 tunnel.

jnxIpSecHaLinkGlobalReplayDropPkts

1.3.6.1.4.1.2636.3.52.1.2.5.9

Counter64 (0..18446744073709551615)

Number of packets dropped by all Phase-2 tunnel due to anti-replay check failure.

jnxIpSecHaLinkGlobalAhAuthFails

1.3.6.1.4.1.2636.3.52.1.2.5.10

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed AH authentication.

jnxIpSecHaLinkGlobalEspAuthFails

1.3.6.1.4.1.2636.3.52.1.2.5.11

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed ESP authentication.

jnxIpSecHaLinkGlobalDecryptFails

1.3.6.1.4.1.2636.3.52.1.2.5.12

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed decryption.

jnxIpSecHaLinkGlobalBadHeaders

1.3.6.1.4.1.2636.3.52.1.2.5.13

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed due to bad headers.

jnxIpSecHaLinkGlobalBadTrailers

1.3.6.1.4.1.2636.3.52.1.2.5.14

Counter64 (0..18446744073709551615)

Number of packets received by all Phase-2 tunnel that failed due to bad ESP trailers.

jnxIpSecHaLinkGlobalInvalidSpi

1.3.6.1.4.1.2636.3.52.1.2.5.15

Counter64 (0..18446744073709551615) · Packets

Total number of Invalid SPI.

jnxIpSecHaLinkGlobalTsCheckFail

1.3.6.1.4.1.2636.3.52.1.2.5.16

Counter64 (0..18446744073709551615) · Packets

Total number of TS check fail.

jnxIpSecHaLinkGlobalDiscarded

1.3.6.1.4.1.2636.3.52.1.2.5.17

Counter64 (0..18446744073709551615) · Packets

Total number of discarded packets.

jnxIpSecHaLinkGlobalExceedsTunMtu

1.3.6.1.4.1.2636.3.52.1.2.5.18

Counter64 (0..18446744073709551615) · Packets

Number of packets received by all Phase-2 tunnel that failed due to Exceeding Tunnel MTU.

Table details

jnxIkeTunnelMonTable

1.3.6.1.4.1.2636.3.52.1.1.2

Index: jnxIkeTunMonRemoteGwAddrType · jnxIkeTunMonRemoteGwAddr · jnxIkeTunMonIndex

The IPsec Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.2.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.1.2.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonIndex

1.3.6.1.4.1.2636.3.52.1.1.2.1.3

Integer32 (1..2147483647)

The index of the IPsec Phase-1 IKE Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.

jnxIkeTunMonLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.1.2.1.4

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.2.1.5

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonState

1.3.6.1.4.1.2636.3.52.1.1.2.1.6

JnxIkeTunStateType1 = up2 = downState of the Phase-1 IKE negotiation. · Integer32

The state of the IKE tunnel, It can be: 1. up - negotiation completed 2. down- being negotiated

jnxIkeTunMonInitiatorCookie

1.3.6.1.4.1.2636.3.52.1.1.2.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Cookie as generated by the peer that initiated the IKE Phase-1 negotiation. This cookie is carried in the ISAKMP header.

jnxIkeTunMonResponderCookie

1.3.6.1.4.1.2636.3.52.1.1.2.1.8

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Cookie as generated by the peer responding to the IKE Phase-1 negotiation initiated by the remote peer. This cookie is carried in the ISAKMP header.

jnxIkeTunMonLocalRole

1.3.6.1.4.1.2636.3.52.1.1.2.1.9

JnxIkePeerRole1 = initiator2 = responderRole of the local endpoint in negotiating the IPsec Phase-1 IKE security association. It can be either Initiator or Responder. · Integer32

The role of local peer identity. The Role of the local peer can be: 1. initiator. 2. or responder.

jnxIkeTunMonLocalIdType

1.3.6.1.4.1.2636.3.52.1.1.2.1.10

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTunMonLocalIdValue

1.3.6.1.4.1.2636.3.52.1.1.2.1.11

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkeTunMonLocalCertName

1.3.6.1.4.1.2636.3.52.1.1.2.1.12

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the certificate used for authentication of the local tunnel endpoint. This object will have some valid value only if negotiated IKE authentication method is other than pre-saherd key. If the IKE negotiation do not use certificate based authentication method, then the value of this object will be a NULL string.

jnxIkeTunMonRemoteIdType

1.3.6.1.4.1.2636.3.52.1.1.2.1.13

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTunMonRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.1.2.1.14

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkeTunMonNegoMode

1.3.6.1.4.1.2636.3.52.1.1.2.1.15

JnxIkeNegoMode1 = main2 = aggressive3 = ikev2The IPsec Phase-1 IKE negotiation mode. Main Mode: A six-message Phase 1 exchange that provides identity protection. Aggressive mode: a three-message phase 1 exchange that does not provide identity protection · Integer32

The negotiation mode of the IPsec Phase-1 IKE Tunnel.

jnxIkeTunMonDiffHellmanGrp

1.3.6.1.4.1.2636.3.52.1.1.2.1.16

JnxDiffHellmanGrp0 = unknown1 = modp7682 = modp10245 = modp153614 = modp204815 = modp307216 = modp409619 = ecmodp25620 = ecmodp38421 = ecmodp52124 = modp2048s256The Diffie Hellman Group used in negotiations. modp768 -- 768-bit MODP modp1024 -- 1024-bit MODP modp1536 -- 1536-bit MODP modp2048 -- 2048-bit MODP modp3072 -- 3072-bit MODP modp4096 -- 4096-bit MODP ec-modp256 -- 256-bit EC-MODP ec-modp384 -- 384-bit EC-MODP ec-modp521 -- 521-bit EC-MODP modp2048s256 -- 2048-bit MODP group with 256 bit subgroup · Integer32

The Diffie Hellman Group used in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonEncryptAlgo

1.3.6.1.4.1.2636.3.52.1.1.2.1.17

JnxEncryptAlgo1 = espDes2 = esp3des3 = espNull4 = espAes1285 = espAes1926 = espAes2567 = espAesGcm1288 = espAesGcm1929 = espAesGcm25610 = espChaCha20Poly1305The encryption algorithm used in negotiations. · Integer32

The encryption algorithm used in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonHashAlgo

1.3.6.1.4.1.2636.3.52.1.1.2.1.18

JnxIkeHashAlgo1 = md52 = sha3 = sha2564 = sha3845 = sha512The hash algorithm used in IPsec Phase-1 IKE negotiations. · Integer32

The hash algorithm used in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonAuthMethod

1.3.6.1.4.1.2636.3.52.1.1.2.1.19

JnxIkeAuthMethod1 = preSharedKey2 = dssSignature3 = rsaSignature4 = rsaEncryption5 = revRsaEncryption6 = xauthPreSharedKey7 = xauthDssSignature8 = xauthRsaSignature9 = xauthRsaEncryption10 = xauthRevRsaEncryption11 = ecdsa256Signature12 = ecdsa384Signature13 = ecdsa521Signature14 = digitalSignatureThe authentication method used in IPsec Phase-1 IKE negotiations. · Integer32

The authentication method used in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonLifeTime

1.3.6.1.4.1.2636.3.52.1.1.2.1.20

Integer32 (1..2147483647) · seconds

The negotiated LifeTime of the IPsec Phase-1 IKE Tunnel in seconds.

jnxIkeTunMonActiveTime

1.3.6.1.4.1.2636.3.52.1.1.2.1.21

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-1 IKE tunnel has been active in hundredths of seconds.

jnxIkeTunMonInOctets

1.3.6.1.4.1.2636.3.52.1.1.2.1.22

Counter64 (0..18446744073709551615) · Octets

The total number of octets received by this IPsec Phase-1 IKE security association.

jnxIkeTunMonInPkts

1.3.6.1.4.1.2636.3.52.1.1.2.1.23

Counter32 · Packets

The total number of packets received by this IPsec Phase-1 IKE security association.

jnxIkeTunMonOutOctets

1.3.6.1.4.1.2636.3.52.1.1.2.1.24

Counter64 (0..18446744073709551615) · Octets

The total number of octets sent by this IPsec Phase-1 IKE security association.

jnxIkeTunMonOutPkts

1.3.6.1.4.1.2636.3.52.1.1.2.1.25

Counter32 · Packets

The total number of packets sent by this IPsec Phase-1 IKE security association.

jnxIkeTunMonXAuthUserId

1.3.6.1.4.1.2636.3.52.1.1.2.1.26

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The extended Authentication (XAuth) User Identifier, identifies the user associated with this IPSec Phase negotiation.

jnxIkeTunMonDPDDownCount

1.3.6.1.4.1.2636.3.52.1.1.2.1.27

Counter32 · Packets

The number of times that the remote peer is detected in a dead (or down) state. This attribute is obsolete

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.2.1.28

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA request message sent by Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.2.1.29

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message received by Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.2.1.30

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN Notification received by Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.2.1.31

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD received by Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.2.1.32

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE notification received by Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.2.1.33

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of peer SA failed at Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.2.1.34

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of DH group failed at Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResVerifyTsFail

1.3.6.1.4.1.2636.3.52.1.1.2.1.35

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of TS failed at Initiator.

jnxIkeTunMonInitiatorIkev2IPSecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.2.1.36

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message Diffie-Hellman compute key failed at Initiator.

jnxIkeTunMonResponderIkev2IPSecSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.2.1.37

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA request message received by Responder.

jnxIkeTunMonResponderIkev2IPSecSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.2.1.38

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message sent by Responder.

jnxIkeTunMonResponderIkev2IPSecSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.2.1.39

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN Notification sent by Responder.

jnxIkeTunMonResponderIkev2IPSecSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.2.1.40

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD Notification sent by Responder.

jnxIkeTunMonResponderIkev2IPSecSaRekeyTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.2.1.41

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE notification sent by Responder.

jnxIkeTunMonResponderIkev2IPSecSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.2.1.42

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message Diffie-Hellman compute key failed at Responder.

jnxIkeTunMonGwName

1.3.6.1.4.1.2636.3.52.1.1.2.1.43

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The gateway name

jnxIkeTunMonTunType

1.3.6.1.4.1.2636.3.52.1.1.2.1.44

JnxIkeTunType1 = regular2 = halinkType of the tunnel. · Integer32

The Tunnel type. It can be regular (1) or ha-link (2)

jnxIkeTunMonLocalSignatureHashAlgo

1.3.6.1.4.1.2636.3.52.1.1.2.1.45

JnxIkeLocalSignatureHashAlgo1 = sha12 = sha2563 = sha3844 = sha512The signature hash algorithm used locally in IPsec Phase-1 IKE negotiations. · Integer32

The signature hash algorithm used locally in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonRemoteSignatureHashAlgo

1.3.6.1.4.1.2636.3.52.1.1.2.1.46

JnxIkeRemoteSignatureHashAlgo1 = sha12 = sha2563 = sha3844 = sha512The signature hash algorithm used by remote peer in IPsec Phase-1 IKE negotiations. · Integer32

The signature hash algorithm used by remote peer in IPsec Phase-1 IKE negotiations.

jnxIkeTunMonDigitalSignAuthKey

1.3.6.1.4.1.2636.3.52.1.1.2.1.47

JnxIkeDigitalSignAuthKey1 = signAuthRsa2 = signAuthDsa3 = signAuthEcdsaSignature key RSA/DSA/ECDSA used for digital-signature auth method. · Integer32

Signature key RSA/DSA/ECDSA used for digital-signature auth method.

jnxIkePeerAddrTable

1.3.6.1.4.1.2636.3.52.1.1.4

Index: jnxIkePeerAddrState · jnxIkePeerAddrRemoteGwAddrType · jnxIkePeerAddrRemoteGwAddr · jnxIkePeerAddrRemotePort · jnxIkePeerAddrLocalGwAddrType · jnxIkePeerAddrLocalGwAddr · jnxIkePeerAddrLocalPort · jnxIkePeerAddrRoutingInstance

The IKE Key Exchange Peer Address Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated.

jnxIkePeerAddrState

1.3.6.1.4.1.2636.3.52.1.1.4.1.1

JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32

The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.

jnxIkePeerAddrRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.4.1.2

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerAddrRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.1.4.1.3

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerAddrRemotePort

1.3.6.1.4.1.2636.3.52.1.1.4.1.4

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkePeerAddrLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.4.1.5

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerAddrLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.1.4.1.6

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerAddrLocalPort

1.3.6.1.4.1.2636.3.52.1.1.4.1.7

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkePeerAddrRoutingInstance

1.3.6.1.4.1.2636.3.52.1.1.4.1.8

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The VR ID.

jnxIkePeerAddrIndex

1.3.6.1.4.1.2636.3.52.1.1.4.1.9

Unsigned32 (1..4294967295)

The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.

jnxIkePeerIdTable

1.3.6.1.4.1.2636.3.52.1.1.5

Index: jnxIkePeerIdState · jnxIkePeerIdRemoteIdType · jnxIkePeerIdRemoteIdValue · jnxIkePeerIdLocalIdType · jnxIkePeerIdLocalIdValue · jnxIkePeerIdAAAUserName · jnxIkePeerInternalIndex

The IKE Key Exchange Peer ID Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated. In the index truncated value for Remote ID value, Local ID value and AAA username is used to restrict the length of the SNMP index to a legal size. In the index, for jnxIkePeerIdRemoteId and jnxIkePeerIdLocalId, any string longer than 41 bytes will be truncated and only 41 bytes would be considered. Similarly in the index, for jnxIkePeerIdAAAUserName, any string longer than 25 bytes will be truncated and only 25 bytes would be considered. Because of the truncation, the index may become same for different peers, to keep the index unique, jnxIkePeerInternalIndex is used to uniquely identify each peer.

jnxIkePeerIdState

1.3.6.1.4.1.2636.3.52.1.1.5.1.1

JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32

The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.

jnxIkePeerIdRemoteIdType

1.3.6.1.4.1.2636.3.52.1.1.5.1.2

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkePeerIdRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.1.5.1.3

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkePeerIdLocalIdType

1.3.6.1.4.1.2636.3.52.1.1.5.1.4

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkePeerIdLocalIdValue

1.3.6.1.4.1.2636.3.52.1.1.5.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkePeerIdAAAUserName

1.3.6.1.4.1.2636.3.52.1.1.5.1.6

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.

jnxIkePeerInternalIndex

1.3.6.1.4.1.2636.3.52.1.1.5.1.7

Integer32 (1..2147483647)

The internal index of the Peer Id table. This index is used to uniquely identify multiple entry for the same truncated ids.

jnxIkePeerIdIndex

1.3.6.1.4.1.2636.3.52.1.1.5.1.8

Unsigned32 (1..4294967295)

The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.

jnxIkePeerStatsTable

1.3.6.1.4.1.2636.3.52.1.1.6

Index: jnxIkePeerStatsState · jnxIkePeerStatsIndex

The IKE Key Exchange Peer Stats Table. There is one entry in this table for each IKE peer with which the managed entity is currently associated.

jnxIkePeerStatsState

1.3.6.1.4.1.2636.3.52.1.1.6.1.1

JnxPeerStateType1 = active2 = inactiveState of the IKE peer with which the managed entity is currently associated. · Integer32

The state of the peer, it can be: 1. active - The IKE peer is currently associated by an active IKE SA. There is at least one active IKE SA or Tunnel termination on the managed entity from the peer. 2. down - The IKE peer was associated with a previously active IKE SA.

jnxIkePeerStatsIndex

1.3.6.1.4.1.2636.3.52.1.1.6.1.2

Unsigned32 (1..4294967295)

The index of the IPSec Phase-1 key exchange Peer Table. The value of the index is a number which begins at one and is incremented with each peer that is created due to an association. The value of this object will wrap at 2,147,483,647.

jnxIkePeerStatsRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.6.1.3

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerStatsRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.1.6.1.4

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerStatsRemotePort

1.3.6.1.4.1.2636.3.52.1.1.6.1.5

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The value specifying a port associated with the remote gateway (endpoint) for the IKE Tunnel. A value of zero means that the port should be ignored.

jnxIkePeerStatsLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.1.6.1.6

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerStatsLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.1.6.1.7

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IPSec Phase-1 IKE Tunnel.

jnxIkePeerStatsLocalPort

1.3.6.1.4.1.2636.3.52.1.1.6.1.8

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The value specifying a port associated with the local endpoint (gateway) for the IKE Tunnel. A value of zero means that the port should be ignored.

jnxIkePeerStatsRoutingInstance

1.3.6.1.4.1.2636.3.52.1.1.6.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The VR ID.

jnxIkePeerStatsRemoteIdType

1.3.6.1.4.1.2636.3.52.1.1.6.1.10

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkePeerStatsRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.1.6.1.11

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkePeerStatsLocalIdType

1.3.6.1.4.1.2636.3.52.1.1.6.1.12

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkePeerStatsLocalIdValue

1.3.6.1.4.1.2636.3.52.1.1.6.1.13

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkePeerStatsAAAUserName

1.3.6.1.4.1.2636.3.52.1.1.6.1.14

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The extended authentication User Name, identifies the user associated with the IKE SA negotiation.

jnxIkePeerStatsGwName

1.3.6.1.4.1.2636.3.52.1.1.6.1.15

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The gateway name

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitRequestOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.16

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT request message sent by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResponseIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.17

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResInvalidIkeSpi

1.3.6.1.4.1.2636.3.52.1.1.6.1.18

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message containing invalid SPI received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitInvalidKePayloadIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.19

Counter64 (0..18446744073709551615) · Messages

The total number of IKE_SA_INIT INVALID_KE_PAYLOAD received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.20

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT NO_PROPSAL_CHOSEN received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.21

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message verification of peer SA failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResIkeSaFillFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.22

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message IKE_SA fill operation failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.23

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message verification of DH group failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitCookieRequestIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.24

Counter64 (0..18446744073709551615) · Messages

The total number of IKE_SA_INIT COOKIE notification request message received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitCookieResponseOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.25

Counter64 (0..18446744073709551615) · Messages

The total number of IKE_SA_INIT COOKIE notification response message sent by Responder.

jnxIkePeerStatsIkeSaInitiatorIkev2SaInitResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.26

Counter64 (0..18446744073709551615) · Messages

Number of IKE SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkePeerStatsIkeSaResponderIkev2SaInitRequestIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.27

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT request message received by Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitResponseOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.28

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.29

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT NO_PROPSAL_CHOSEN notification sent by Responder

jnxIkePeerStatsIkeSaResponderIkev2SaInitInvalidKePayloadOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.30

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT INVALID_KE_PAYLOAD notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitResInvalidDhGroupConf

1.3.6.1.4.1.2636.3.52.1.1.6.1.31

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message invalid DH group configured at Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitResDhGenKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.32

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message Diffie-Hellman generate key failed at Responder

jnxIkePeerStatsIkeSaResponderIkev2SaInitResGetCAsFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.33

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message get CAs failed at Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitResGetVidFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.34

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message get vendor ID request failed at Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.35

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT response message Diffie-Hellman compute key failed at Responder

jnxIkePeerStatsIkeSaResponderIkev2SaInitCookieRequestOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.36

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT COOKIE notification request sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2SaInitCookieResponseIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.37

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA_INIT COOKIE notification response message received by Responder.

jnxIkePeerStatsIkeSaInitiatorIkev2AuthRequestOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.38

Counter64 (0..18446744073709551615) · Messages

The total number of IKE_AUTH request message sent by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2AuthResponseIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.39

Counter64 (0..18446744073709551615) · Messages

The total number of IKE_AUTH response message received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2AuthNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.40

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2AuthTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.41

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH TS_UNACCEPTABLE notification received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2AuthAuthenticationFailedIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.42

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH AUTHENTICATION_FAILED notification received by Initiator.

jnxIkePeerStatsIkeSaResponderIkev2AuthRequestIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.43

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH request message received by Responder.

jnxIkePeerStatsIkeSaResponderIkev2AuthResponseOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.44

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH response message sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2AuthAuthenticationFailedOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.45

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH request message AUTHENTICATION_FAILED notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2AuthNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.46

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH NO_PROPSAL_CHOSEN notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2AuthTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.47

Counter64 (0..18446744073709551615) · Messages

The number of IKE_AUTH TS_UNACCEPTABLE notification sent by Responder.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.48

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA request message sent by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.49

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA response message received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.50

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE SA rekey NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.51

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE SA rekey INVALID_KE_PAYLOAD received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.52

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE SA rekey response message verification of peer SA failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyResFillIkeSaFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.53

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA response message fill IKE_SA failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyResVerifyDhGroupFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.54

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE SA rekey response message verification of DH group failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.55

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE SA rekey response message Diffie-Hellman compute key failed at Initiator.

jnxIkePeerStatsIkeSaResponderIkev2IkeSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.56

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA request message received by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IkeSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.57

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA response message sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IkeSaRekeyNoProposalChosenOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.58

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE rekey NO_PROPSAL_CHOSEN notification sent by Responder

jnxIkePeerStatsIkeSaResponderIkev2IkeSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.59

Counter64 (0..18446744073709551615) · Messages

The number of IKE_SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IkeSaRekeyResDhComputeKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.60

Counter64 (0..18446744073709551615) · Messages

The number of CREATE_CHILD_SA IKE rekey response message Diffie-Hellman compute key failed at Responder.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyRequestOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.61

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA request message sent by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyResponseIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.62

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyNoProposalChosenIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.63

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN notification received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyInvalidKeIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.64

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyTsUnacceptableIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.65

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE notification received by Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyResVerifySaFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.66

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of peer SA failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyResVerifyDhGrpFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.67

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of DH group failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyResVerifyTsFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.68

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message verification of TS failed at Initiator.

jnxIkePeerStatsIkeSaInitiatorIkev2IPSecSaRekeyResDhCompKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.69

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message Diffie-Hellman compute key failed at Initiator.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyRequestIn

1.3.6.1.4.1.2636.3.52.1.1.6.1.70

Counter64 (0..18446744073709551615) · Messages

The total number of IPSec SA rekey CREATE_CHILD_SA request message received by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyResponseOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.71

Counter64 (0..18446744073709551615) · Messages

The total number of IPSec SA rekey CREATE_CHILD_SA response message sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyNoPropChosenOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.72

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA NO_PROPSAL_CHOSEN Notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyInvalidKeOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.73

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA INVALID_KE_PAYLOAD Notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyTsUnacceptableOut

1.3.6.1.4.1.2636.3.52.1.1.6.1.74

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA TS_UNACCEPTABLE notification sent by Responder.

jnxIkePeerStatsIkeSaResponderIkev2IPSecSaRekeyResDhCompKeyFail

1.3.6.1.4.1.2636.3.52.1.1.6.1.75

Counter64 (0..18446744073709551615) · Messages

The number of IPSec SA rekey CREATE_CHILD_SA response message Diffie-Hellman compute key failed at Responder.

jnxIkePeerStatsTunType

1.3.6.1.4.1.2636.3.52.1.1.6.1.76

JnxIkeTunType1 = regular2 = halinkType of the tunnel. · Integer32

The Tunnel type. It can be regular (1) or ha-link (2).

jnxPeerIkeSaCorrTable

1.3.6.1.4.1.2636.3.52.1.1.7

Index: jnxPeerIkeSaCorrPeerIndex · jnxPeerIkeSaCorrIntIndex

The Peer Association to active IKE SA - Correlation Table. There is one entry in this table for each active IKE SA.

jnxPeerIkeSaCorrPeerIndex

1.3.6.1.4.1.2636.3.52.1.1.7.1.1

Integer32 (1..2147483647)

The index of the Peer (jnxPeerIndex in the jnxIkePeerTable).

jnxPeerIkeSaCorrIntIndex

1.3.6.1.4.1.2636.3.52.1.1.7.1.2

Integer32 (1..2147483647)

The internal index of the Peer and IKE SA association. This internal index is used to uniquely identify multiple Instances of a unique association between the peer and IKE SA.

jnxPeerIkeSaCorrIkeTunMonIndex

1.3.6.1.4.1.2636.3.52.1.1.7.1.3

Unsigned32 (1..4294967295)

The index of the active IKE SA (jnxIkeTunMonIndex in the jnxIkeTunnelMonTable) for this Peer association.

jnxPeerIPSecTunnelCorrTable

1.3.6.1.4.1.2636.3.52.1.1.8

Index: jnxPeerIPSecTunnelCorrPeerIndex · jnxPeerIPSecTunnelCorrIntIndex

The Peer Association to IPSec Tunnel Correlation Table. There is one entry in this table for each active IPSec Tunnel.

jnxPeerIPSecTunnelCorrPeerIndex

1.3.6.1.4.1.2636.3.52.1.1.8.1.1

Integer32 (1..2147483647)

The index of the Peer (jnxPeerIndex in the jnxIkePeerTable).

jnxPeerIPSecTunnelCorrIntIndex

1.3.6.1.4.1.2636.3.52.1.1.8.1.2

Integer32 (1..2147483647)

The internal index of the Peer and IPSec Tunnel association. This index is used to uniquely identify multiple association between the peer and IPSec Tunnel.

jnxPeerIPSecTunnelCorrIPSecTunMonIndex

1.3.6.1.4.1.2636.3.52.1.1.8.1.3

Integer32 (1..2147483647)

The index of the active IPSec Tunnel (jnxIpSecTunMonIndex in the jnxIpSecTunnelMonTable) for this association between Peer and IPSec Tunnel.

jnxIpSecTunnelMonTable

1.3.6.1.4.1.2636.3.52.1.2.2

Index: jnxIpSecTunMonRemoteGwAddrType · jnxIpSecTunMonRemoteGwAddr · jnxIpSecTunMonIndex

The IPsec Phase-2 Tunnel Table. There is one entry in this table for each active IPsec Phase-2 Tunnel. If the tunnel is terminated, then the entry is no longer available after the table has been refreshed.

jnxIpSecTunMonRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.2.2.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.

jnxIpSecTunMonRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.2.2.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IPsec Phase-2 Tunnel.

jnxIpSecTunMonIndex

1.3.6.1.4.1.2636.3.52.1.2.2.1.3

Integer32 (1..2147483647)

The index of the IPsec Phase-2 Tunnel Table. The value of the index is a number which begins at one and is incremented with each tunnel that is created. The value of this object will wrap at 2,147,483,647.

jnxIpSecTunMonLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.2.2.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.

jnxIpSecTunMonLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.2.2.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local gateway (endpoint) for the IPsec Phase-2 Tunnel.

jnxIpSecTunMonLocalProxyId

1.3.6.1.4.1.2636.3.52.1.2.2.1.6

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the local end.

jnxIpSecTunMonRemoteProxyId

1.3.6.1.4.1.2636.3.52.1.2.2.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the remote end.

jnxIpSecTunMonKeyType

1.3.6.1.4.1.2636.3.52.1.2.2.1.8

JnxKeyType0 = unknown1 = keyIke2 = keyManualThe type of key used by an IPsec Phase-2 Tunnel. · Integer32

The type of key used by the IPsec Phase-2 Tunnel. It can be one of the following two types: - IKE negotiated - Manually installed

jnxIpSecTunMonRemotePeerType

1.3.6.1.4.1.2636.3.52.1.2.2.1.9

JnxRemotePeerType0 = unknown1 = static2 = dynamicThe type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand). · Integer32

The type of the remote peer gateway (endpoint). It can be one of the following two types: - static (Remote peer whose IP address is known beforehand) - dynamic (Remote peer whose IP address is not known beforehand)

jnxIpSecTunMonOutEncryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.2.1.10

Counter64 (0..18446744073709551615)

Number of bytes encrypted by this Phase-2 tunnel.

jnxIpSecTunMonOutEncryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.11

Counter64 (0..18446744073709551615)

Number of packets encrypted by this Phase-2 tunnel.

jnxIpSecTunMonInDecryptedBytes

1.3.6.1.4.1.2636.3.52.1.2.2.1.12

Counter64 (0..18446744073709551615)

Number of bytes decrypted by this Phase-2 tunnel.

jnxIpSecTunMonInDecryptedPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.13

Counter64 (0..18446744073709551615)

Number of packets decrypted by this Phase-2 tunnel.

jnxIpSecTunMonAHInBytes

1.3.6.1.4.1.2636.3.52.1.2.2.1.14

Counter64 (0..18446744073709551615)

Number of incoming bytes authenticated using AH by this Phase-2 tunnel.

jnxIpSecTunMonAHInPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.15

Counter64 (0..18446744073709551615)

Number of incoming packets authenticated using AH by this Phase-2 tunnel.

jnxIpSecTunMonAHOutBytes

1.3.6.1.4.1.2636.3.52.1.2.2.1.16

Counter64 (0..18446744073709551615)

Number of outgoing bytes applied AH by this Phase-2 tunnel.

jnxIpSecTunMonAHOutPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.17

Counter64 (0..18446744073709551615)

Number of outgoing packets applied AH by this Phase-2 tunnel.

jnxIpSecTunMonReplayDropPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.18

Counter64 (0..18446744073709551615)

Number of packets dropped by this Phase-2 tunnel due to anti replay check failure.

jnxIpSecTunMonAhAuthFails

1.3.6.1.4.1.2636.3.52.1.2.2.1.19

Counter64 (0..18446744073709551615)

Number of packets received by this Phase-2 tunnel that failed AH authentication.

jnxIpSecTunMonEspAuthFails

1.3.6.1.4.1.2636.3.52.1.2.2.1.20

Counter64 (0..18446744073709551615)

Number of packets received by this Phase-2 tunnel that failed ESP authentication.

jnxIpSecTunMonDecryptFails

1.3.6.1.4.1.2636.3.52.1.2.2.1.21

Counter64 (0..18446744073709551615)

Number of packets received by this Phase-2 tunnel that failed decryption.

jnxIpSecTunMonBadHeaders

1.3.6.1.4.1.2636.3.52.1.2.2.1.22

Counter64 (0..18446744073709551615)

Number of packets received by this Phase-2 tunnel that failed due to bad headers.

jnxIpSecTunMonBadTrailers

1.3.6.1.4.1.2636.3.52.1.2.2.1.23

Counter64 (0..18446744073709551615)

Number of packets received by this Phase-2 tunnel that failed due to bad ESP trailers.

jnxIpSecTunMonDroppedPkts

1.3.6.1.4.1.2636.3.52.1.2.2.1.26

Counter64 (0..18446744073709551615)

Total number of dropped packets for this Phase-2 tunnel. This attribute is obsolete.

jnxIpSecTunMonVpnName

1.3.6.1.4.1.2636.3.52.1.2.2.1.27

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

VPN tunnel name.

jnxIpSecTunMonTsName

1.3.6.1.4.1.2636.3.52.1.2.2.1.28

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Traffic selector name.

jnxIpSecTunMonMultiSa

1.3.6.1.4.1.2636.3.52.1.2.2.1.29

INTEGER0 = disable1 = enable · Integer32

Multi-SA Configuration Status.

jnxIpSecTunMonInvalidSpi

1.3.6.1.4.1.2636.3.52.1.2.2.1.30

Counter64 (0..18446744073709551615) · Packets

Total number of Invalid SPI for this IPSec tunnel.

jnxIpSecTunMonTsCheckFail

1.3.6.1.4.1.2636.3.52.1.2.2.1.31

Counter64 (0..18446744073709551615) · Packets

Total number of TS check fail for this IPSec tunnel.

jnxIpSecTunMonDiscarded

1.3.6.1.4.1.2636.3.52.1.2.2.1.32

Counter64 (0..18446744073709551615) · Packets

Total number of discarded packets for this IPSec tunnel.

jnxIpSecTunMonTunType

1.3.6.1.4.1.2636.3.52.1.2.2.1.33

JnxIkeTunType1 = regular2 = halinkType of the tunnel. · Integer32

The Tunnel type. It can be regular (1) or ha-link (2).

jnxIpSecTunMonTsType

1.3.6.1.4.1.2636.3.52.1.2.2.1.34

JnxIpSecTsType1 = proxyId2 = trafficSelectorType of the TS. · Integer32

The TS type. It can be proxyId (1) or trafficSelector (2).

jnxIpSecTunMonTSi

1.3.6.1.4.1.2636.3.52.1.2.2.1.35

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Negotiated Traffic Selector or Proxy ID for the local end.

jnxIpSecTunMonTSr

1.3.6.1.4.1.2636.3.52.1.2.2.1.36

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Negotiated Traffic Selector or Proxy ID for the remote end.

jnxIpSecTunMonTunMtu

1.3.6.1.4.1.2636.3.52.1.2.2.1.37

Integer32 (0..9192)

The maximum transmit packet size (256..9192) for IPSec tunnels. The value of this object will be 0, if tunnel MTU is not configured.

jnxIpSecTunMonExceedsTunMtu

1.3.6.1.4.1.2636.3.52.1.2.2.1.38

Counter64 (0..18446744073709551615) · Packets

Number of packets received by this Phase-2 tunnel that failed due to Exceeding Tunnel MTU.

jnxIpSecSaMonTable

1.3.6.1.4.1.2636.3.52.1.2.3

Index: jnxIpSecTunMonRemoteGwAddrType · jnxIpSecTunMonRemoteGwAddr · jnxIpSecTunMonIndex · jnxIpSecSaMonIndex

The IPsec Phase-2 Security Association Table. This table identifies the structure (in terms of component SAs) of each active Phase-2 IPsec tunnel. This table contains an entry for each active and expiring security association and maps each entry in the active Phase-2 tunnel table (ipSecTunTable) into a number of entries in this table. SA contains the information negotiated by IKE. The SA is like a contract laying out the rules of the VPN connection for the duration of the SA. An SA is assigned a 32-bit number that, when used in conjunction with the destination IP address, uniquely identifies the SA. This number is called the Security Parameters Index or SPI. IPSec SAs area unidirectional and they are unique in each security protocol. A set of SAs are needed for a protected data pipe, one per direction per protocol.

jnxIpSecSaMonIndex

1.3.6.1.4.1.2636.3.52.1.2.3.1.1

Integer32 (1..65535)

The index, in the context of the IPsec tunnel ipSecTunIndex, of the security association represented by this table entry. The value of this index is a number which begins at one and is incremented with each SPI associated with an IPsec Phase-2 Tunnel. The value of this object will wrap at 65535.

jnxIpSecSaMonProtocol

1.3.6.1.4.1.2636.3.52.1.2.3.1.2

INTEGER1 = ah2 = esp · Integer32

The index, represents the security protocol (AH, ESP or IPComp) for which this security association was setup.

jnxIpSecSaMonInSpi

1.3.6.1.4.1.2636.3.52.1.2.3.1.3

JnxSpiTypeThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32

The value of the incoming SPI.

jnxIpSecSaMonOutSpi

1.3.6.1.4.1.2636.3.52.1.2.3.1.4

JnxSpiTypeThe type of the SPI associated with IPsec Phase-2 security associations. (256..4294967295) · Unsigned32

The value of the outgoing SPI.

jnxIpSecSaMonType

1.3.6.1.4.1.2636.3.52.1.2.3.1.5

JnxSAType0 = unknown1 = manual2 = dynamicSA Type manual or dynamic · Integer32

This field represents the type of security associations which can be either manual or dynamic

jnxIpSecSaMonEncapMode

1.3.6.1.4.1.2636.3.52.1.2.3.1.6

JnxEncapMode0 = unknown1 = tunnel2 = transportThe encapsulation mode used by an IPsec Phase-2 Tunnel. · Integer32

The encapsulation mode used by an IPsec Phase-2 Tunnel.

jnxIpSecSaMonLifeSize

1.3.6.1.4.1.2636.3.52.1.2.3.1.7

Integer32

The negotiated LifeSize of the IPsec Phase-2 Tunnel in kilobytes.

jnxIpSecSaMonLifeTime

1.3.6.1.4.1.2636.3.52.1.2.3.1.8

Integer32

The negotiated LifeTime of the IPsec Phase-2 Tunnel in seconds.

jnxIpSecSaMonActiveTime

1.3.6.1.4.1.2636.3.52.1.2.3.1.9

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

The length of time the IPsec Phase-2 Tunnel has been active in hundredths of seconds.

jnxIpSecSaMonLifeSizeThreshold

1.3.6.1.4.1.2636.3.52.1.2.3.1.10

Integer32

The security association LifeSize refresh threshold in kilobytes.

jnxIpSecSaMonLifeTimeThreshold

1.3.6.1.4.1.2636.3.52.1.2.3.1.11

Integer32

The security association LifeTime refresh threshold in seconds.

jnxIpSecSaMonEncryptAlgo

1.3.6.1.4.1.2636.3.52.1.2.3.1.12

JnxEncryptAlgo1 = espDes2 = esp3des3 = espNull4 = espAes1285 = espAes1926 = espAes2567 = espAesGcm1288 = espAesGcm1929 = espAesGcm25610 = espChaCha20Poly1305The encryption algorithm used in negotiations. · Integer32

The Encryption algorithm used to encrypt the packets.

jnxIpSecSaMonAuthAlgo

1.3.6.1.4.1.2636.3.52.1.2.3.1.13

JnxAuthAlgo0 = unknown1 = hmacMd52 = hmacSha3 = hmacSha2564 = hmacSha3845 = hmacSha5126 = aesGcm1287 = aesGcm1928 = aesGcm2569 = chacha20Poly1305The authentication algorithm used by a security association of an IPsec Phase-2 Tunnel. · Integer32

The algorithm used for authentication of packets which can be hmac-md5-96 or hmac-sha1-96 or hmac-sha-256-128

jnxIpSecSaMonState

1.3.6.1.4.1.2636.3.52.1.2.3.1.14

INTEGER0 = unknown1 = active2 = expiring · Integer32

This column represents the status of the security association represented by this table entry. If the status of the SA is 'active', the SA is ready for active use. The status 'expiring' represents any of the various states that the security association transitions through before being purged.

jnxIpSecSaMonFcName

1.3.6.1.4.1.2636.3.52.1.2.3.1.15

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Class-Of-Service Forwarding Class name.

jnxIpSecSaMonEsnMode

1.3.6.1.4.1.2636.3.52.1.2.3.1.16

JnxEsnMode0 = none1 = enable2 = disableESN mode Enable or Disable · Integer32

This field represents whether IPSec extended sequence number support is enabled or disabled

Trap details

jnxIkePeerDown

1.3.6.1.4.1.2636.3.52.1.0.0.1

To provide notification for the event when Peer goes down.

jnxIkeTrapPeerRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.

jnxIkeTrapPeerRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IKE SA negotiation.

jnxIkeTrapPeerRemotePort

1.3.6.1.4.1.2636.3.52.1.0.1.3

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalPort

1.3.6.1.4.1.2636.3.52.1.0.1.6

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerRoutingInstance

1.3.6.1.4.1.2636.3.52.1.0.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the routing instance.

jnxIkeTrapPeerLocalIdType

1.3.6.1.4.1.2636.3.52.1.0.1.8

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerLocalIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkeTrapPeerRemoteIdType

1.3.6.1.4.1.2636.3.52.1.0.1.10

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.11

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkeTrapPeerAAAUserName

1.3.6.1.4.1.2636.3.52.1.0.1.12

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.

jnxIkeTrapPeerGwName

1.3.6.1.4.1.2636.3.52.1.0.1.13

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the IKE gateway.

jnxIkePeerIPSecTunnelDown

1.3.6.1.4.1.2636.3.52.1.0.0.2

To provide notification for the event of IPSec Tunnels going down for a peer. These traps are not generated if the corresponding peer has gone down.

jnxIkeTrapPeerRemoteGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the remote gateway (endpoint) for the IKE SA negotiaton.

jnxIkeTrapPeerRemoteGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the remote gateway (endpoint) for the IKE SA negotiation.

jnxIkeTrapPeerRemotePort

1.3.6.1.4.1.2636.3.52.1.0.1.3

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the remote gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerLocalGwAddrType

1.3.6.1.4.1.2636.3.52.1.0.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The IP address type of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalGwAddr

1.3.6.1.4.1.2636.3.52.1.0.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The IP address of the local endpoint (gateway) for the IKE SA negotiation.

jnxIkeTrapPeerLocalPort

1.3.6.1.4.1.2636.3.52.1.0.1.6

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The port number of the local gateway (endpoint) for the IKE SA negotiation. The port number zero means the input value is ignored for this object and the default port is considered.

jnxIkeTrapPeerRoutingInstance

1.3.6.1.4.1.2636.3.52.1.0.1.7

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the routing instance.

jnxIkeTrapPeerLocalIdType

1.3.6.1.4.1.2636.3.52.1.0.1.8

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of local peer identity. The local peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerLocalIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.9

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer type is id_fqdn, then this is the FQDN of the remote peer. If the local peer type is a id_dn, then this is the distinguished name string of the local peer.

jnxIkeTrapPeerRemoteIdType

1.3.6.1.4.1.2636.3.52.1.0.1.10

JnxIkePeerType0 = unknown1 = idIpv4Addr2 = idFqdn3 = idDn4 = idUfqdn5 = idIpv6AddrThe type of IPsec Phase-1 IKE peer identity. It is the local IKE identify to send in the exchange. The IKE peer may be identified by one of the ID types defined in IPSEC DOI. idIpv4Addr - IPv4 Address. idIpv6Addr - IPv6 Address. idUfqdn - user fully qualified domain name (user@hostname). idFqdn - full qualified domain name idDn - distinquished name · Integer32

The type of remote peer identity. The remote peer may be identified by: 1. an IP address, or 2. or a fully qualified domain name string. 3. or a distinguished name string.

jnxIkeTrapPeerRemoteIdValue

1.3.6.1.4.1.2636.3.52.1.0.1.11

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote peer type is id_fqdn, then this is the FQDN of the remote peer. If the remote peer type is a id_dn, then this is the distinguished named string of the remote peer.

jnxIkeTrapPeerAAAUserName

1.3.6.1.4.1.2636.3.52.1.0.1.12

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifies the user with the specified authentication, authorization and accounting (AAA) username, associated with the IKE SA negotiation.

jnxIkeTrapPeerGwName

1.3.6.1.4.1.2636.3.52.1.0.1.13

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Name of the IKE gateway.

jnxIkeTrapIpSecTunVpnName

1.3.6.1.4.1.2636.3.52.1.0.1.14

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

IPsec tunnel VPN name.

jnxIkeTrapIpSecTunTsName

1.3.6.1.4.1.2636.3.52.1.0.1.15

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

IPsec tunnel Traffic Selector name.

jnxIkeTrapIpSecTunLocalTS

1.3.6.1.4.1.2636.3.52.1.0.1.16

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the local end of IPsec tunnel.

jnxIkeTrapIpSecTunRemoteTS

1.3.6.1.4.1.2636.3.52.1.0.1.17

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

Identifier for the remote end of IPsec tunnel.

↑ To TOC