AVAYA-IPSEC-MIB
170 objects
The MIB module for configuring IPSec functionality in Avaya converged Gateways.
Imported Objects
| AVAYAGEN-MIB | avGatewayMibs |
| SNMPv2-CONF | MODULE-COMPLIANCE OBJECT-GROUP |
| SNMPv2-SMI | Counter32 Gauge32 Integer32 IpAddress MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | DisplayString RowStatus TEXTUAL-CONVENTION TimeStamp TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.6889.2.6.1 | IdentityavayaIpsecMib | The MIB module for configuring IPSec functionality in Avaya converged Gateways. | ||
| 1.3.6.1.4.1.6889.2.6.1.1 | NodeavipsMIBObjects | |||
| 1.3.6.1.4.1.6889.2.6.1.1.1 | NodeavipsGlobals | |||
| 1.3.6.1.4.1.6889.2.6.1.1.1.1 | ScalaravipsGlobalsInvalidSpiRecovery | read-write | current | This object determines whether invalid-spi-recovery is enabled (true) or disabled (false). When enabled, the device shall open an IKE SA, if it does not alread… |
| 1.3.6.1.4.1.6889.2.6.1.1.1.2 | ScalaravipsNatTEnabled | read-write | current | This object specifies whether IPSec NAT-T is invoked in the device. If this object is True then NAT-T is enabled. |
| 1.3.6.1.4.1.6889.2.6.1.1.1.3 | ScalaravipsNatTKeepaliveInterval | read-write | current | This object determines the NAT-T keepalive interval in seconds. If this object is set to 0 then NAT-T keepalives are disabled. |
| 1.3.6.1.4.1.6889.2.6.1.1.1.4 | ScalaravipsCryptoEngineAccelEnabled | read-write | current | The value of this object determines whether IPSec HW acceleration is enabled or disabled. In case the HW does not support acceleration the value of this object… |
| 1.3.6.1.4.1.6889.2.6.1.1.2 | NodeavipsIsakmpGroup | |||
| 1.3.6.1.4.1.6889.2.6.1.1.2.1 | TableavipsIsakmpPeerTable | not-accessible | current | This table contains a list of all the remote peers and peer-groups we are willing to establish an IPSec VPN connection with. Each entry represents a peer or a … |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1 | RowavipsIsakmpPeerEntry | not-accessible | current | A specific entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.1 | ColumnavipsIsakmpPeerIdType | not-accessible | current | This object is an enumeration identifying the type of the Identity value. Note that value can also be peerGroup, in that case avipsIsakmpPeerId contains the pe… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.2 | ColumnavipsIsakmpPeerId | not-accessible | current | This object contains an Identity filter to be used to match against the identity payload in an IKE request. This is also the second index component of this tab… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.3 | ColumnavipsIsakmpPeerDescription | read-write | current | Free text describing this row. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.4 | ColumnavipsIsakmpPeerIsaPlcyId1 | read-write | current | This object contains the ID of the ISAKMP policy to be used in IKE Phase I negotiation with this peer. A value of 0 indicates that this object is empty. This o… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.5 | ColumnavipsIsakmpPeerInitiateMode | read-write | current | This object specifies how to initiate IKE when communicating with this peer: none(1) - Never initiate IKE with this peer (i.e. respond only) main(2) - Initiate… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.6 | ColumnavipsIsakmpPeerSelfIdType | read-write | current | This object is an enumeration identifying the type of the Identity value which the local peer shall use in the its identity payload during Phase-1 negotiation.… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.7 | ColumnavipsIsakmpPeerSelfId | read-write | current | If not empty, this object specifies the identity value which the local peer will send in the identification payload during IKE Phase-1 negotiation. If this obj… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.8 | ColumnavipsIsakmpPeerKeepaliveMetric | read-write | current | The worry-metric to be used for deciding when to send R-U-THERE message to the remote peer. This object is N/A if avipsIsakmpPeerIdType is peerGroup. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.9 | ColumnavipsIsakmpPeerKeepaliveInterval | read-write | current | The minimal interval, in seconds, between two consecutive R-U-THERE sent by the local peer, when the previous R-U-THERE message has been answered. The actual i… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.10 | ColumnavipsIsakmpPeerKeepaliveRetryInterval | read-write | current | The actual interval, in seconds, between R-U-THERE retries sent by the local peer, when the previous R-U-THERE message has not been answered. This object is N/… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.11 | ColumnavipsIsakmpPeerKeepaliveTrackId | read-write | current | Bind the status of this peer to an object-tracker by specifying the ID of the object-tracker (avstrTrackerId in AVAYA-SAA-TRACK-MIB). A value of 0 means that p… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.12 | ColumnavipsIsakmpPeerContChannel | read-write | current | This object determines whether continuous channel IKE mode is used for contacting the peer. Continuous channel IKE means that local peer tries to establish an … |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.13 | ColumnavipsIsakmpPeerRowStatus | read-write | current | This object indicates the conceptual status of this row. The value of this object has no effect on whether other objects in this conceptual row can be modified… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.1.1.14 | ColumnavipsIsakmpPeerGroupFailbacktoPrimaryInterval | read-write | current | The amount of time in seconds that secondary peer shall be up (after primary peer went down) before there will be failback to primary peer (in case it is up ag… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2 | TableavipsPeerGroupPeersTable | not-accessible | current | This table contains all the associations between peer-groups and isakmp peers. The relation between peer-group and isakmp peer is many-to-many. A valid peer-gr… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1 | RowavipsPeerGroupPeersEntry | not-accessible | current | A specific entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1.1 | ColumnavipsPeerGroupPeersPGrpName | not-accessible | current | The name of the peer-group associated with this isakmp peer. Note that there must exist a matching active entry in avipsIsakmpPeerTable which avipsIsakmpPeerId… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1.2 | ColumnavipsPeerGroupPeersPeerIndex | not-accessible | current | The ordered index of the peer within the peer-group. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1.3 | ColumnavipsPeerGroupPeersPIdType | read-write | current | This object is an enumeration identifying the type of the Identity value of the peer associated with this IPSec connection. Note that value cannot be peerGroup… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1.4 | ColumnavipsPeerGroupPeersPIdValue | read-write | current | This object contains value of the peer ID. The contents of this object object is interpreted along with avipsPeerGroupPeersPIdType. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.2.1.5 | ColumnavipsPeerGroupPeersRowStatus | read-write | current | This object indicates the conceptual status of this row. The value of this object has no effect on whether other objects in this conceptual row can be modified… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3 | TableavipsIsakmpPlcyTable | not-accessible | current | The table containing the list of all ISAKMP policy entries configured by the operator. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1 | RowavipsIsakmpPlcyEntry | not-accessible | current | Each entry contains the attributes associated with a single ISAKMP Policy entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.1 | ColumnavipsIsakmpPlcyId | not-accessible | current | The ID of this ISAKMP Policy entry. This is also the index of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.2 | ColumnavipsIsakmpPlcyDescription | read-write | current | Free text describing this object. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.3 | ColumnavipsIsakmpPlcyDhGroup | read-write | current | This object specifies the Oakley group used for Diffie Hellman exchange in the Main Mode. If this policy item is selected to negotiate Main Mode with an IKE pe… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.4 | ColumnavipsIsakmpPlcyEncrAlgo | read-write | current | The encryption transform specified by this ISAKMP policy specification. The Internet Key Exchange (IKE) tunnels setup using this policy item would use the spec… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.5 | ColumnavipsIsakmpPlcyHashAlgo | read-write | current | The hash transform specified by this ISAKMP policy specification. The IKE tunnels setup using this policy item would use the specified hash transform to protec… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.6 | ColumnavipsIsakmpPlcyLifetime | read-write | current | This object specifies the lifetime, in seconds, of the IKE tunnels generated using this policy specification. |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.7 | ColumnavipsIsakmpPlcyAuth | read-write | current | The peer authentication method specified by this ISAKMP policy specification. If this policy entity is selected for negotiation with a peer, the local entity w… |
| 1.3.6.1.4.1.6889.2.6.1.1.2.3.1.8 | ColumnavipsIsakmpPlcyRowStatus | read-write | current | This object indicates the conceptual status of this row. The value of this object has no effect on whether other objects in this conceptual row can be modified… |
| 1.3.6.1.4.1.6889.2.6.1.1.3 | NodeavipsIpsecGroup | |||
| 1.3.6.1.4.1.6889.2.6.1.1.3.1 | TableavipsCryptoMapTable | not-accessible | current | This table contains all the crypto maps configured by the user. A crypto map essentially concentrates all the IPSec protection policy required for establishing… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1 | RowavipsCryptoMapEntry | not-accessible | current | A specific crypto map entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.1 | ColumnavipsCryptoMapId | not-accessible | current | The ID of the crypto map entry. This is also the index of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.2 | ColumnavipsCryptoMapDescription | read-write | current | Free text describing this object. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.3 | ColumnavipsCryptoMapPeerIdType | read-write | current | This object is an enumeration identifying the type of the Identity value of the peer associated with this IPSec connection. The contents of this object object … |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.4 | ColumnavipsCryptoMapPeerIdValue | read-write | current | This object contains an Identity filter to be used to select the remote peer or peer-group when initiating IKE, and to match against the identity payload in an… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.5 | ColumnavipsCryptoMapTranSetName1 | read-write | current | The name of the transforms-set for this crypto map. This object is the index into the avipsTranSetTable. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.6 | ColumnavipsCryptoMapIsReady | read-only | current | This field is true if and only if this crypto map entry and all the descendent configuration objects pointed by it are in the ready state. Note that crypto lis… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.7 | ColumnavipsCryptoMapTunnelDscp | read-write | current | The method used to set the high 6 bits of the TOS in the outer IP header. A value of -1 indicates that the bits are copied from the payload's header. A value b… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.8 | ColumnavipsCryptoMapContChannel | read-write | current | This object determines whether continuous channel IPSec mode is used for the rule pointing to this crypto map. Continuous channel IPSec means that local peer t… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.1.1.9 | ColumnavipsCryptoMapRowStatus | read-write | current | This object indicates the conceptual status of this row. The value of this object has no effect on whether other objects in this conceptual row can be modified… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2 | TableavipsTranSetTable | not-accessible | current | This table lists all the transform-sets which can be used to build or accept IPsec proposals. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1 | RowavipsTranSetEntry | not-accessible | current | An entry containing the information on an IPsec transform-set. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.1 | ColumnavipsTranSetName | not-accessible | current | The name of this particular transform-set be referred to by an avipsCryptoMapEntry. This is the index of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.2 | ColumnavipsTranSetEspEncrTran | read-write | current | This object specifies the transform ID of the ESP encryption algorithm. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.3 | ColumnavipsTranSetEspHashTran | read-write | current | This object specifies the ESP hash algorithm ID. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.4 | ColumnavipsTranSetLifetime | read-write | current | This object specifies how long, in seconds, the security association (SA) derived from this transform should be used. The value 0 is reserved for future use. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.5 | ColumnavipsTranSetLifesize | read-write | current | This object specifies how long, in Kilobytes, the security association (SA) derived from this transform should be used. The value -1 means that no size based l… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.6 | ColumnavipsTranSetPfsGroup | read-write | current | This object specifies the DH group that shall be used for PFS in quick mode exchange, when creating the security association (SA) derived from this transform. … |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.7 | ColumnavipsTranSetEncapMode | read-write | current | This object determines the ESP encapsulation mode that will be used. Possible values are 'tunnel' and 'transport'. In case transport mode is configured, it sha… |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.8 | ColumnavipsTranSetEspCompTran | read-write | current | This object specifies the ESP compression algorithm: none(1) - no compression algorithm. ippcpLzs(2) - IPPCP with LZS compression. |
| 1.3.6.1.4.1.6889.2.6.1.1.3.2.1.9 | ColumnavipsTranRowStatus | read-write | current | This object indicates the conceptual status of this row. The value of this object has no effect on whether other objects in this conceptual row can be modified… |
| 1.3.6.1.4.1.6889.2.6.1.1.4 | NodeavipsMonitoringGroup | |||
| 1.3.6.1.4.1.6889.2.6.1.1.4.1 | NodeavipsMonitoringTables | |||
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.1 | NodeavipsMonitoringTablesGlobals | |||
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.1.1 | ScalaravipsMonitorRstCntrs | read-write | current | Use this object to reset all the IPSec counters. Set this object to reset(2) in order to do that. This operation is equivalent to issuing the 'clear crypto sa … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.1.2 | ScalaravipsMonitorRstCntrsLastChange | read-only | current | sysUpTime when last IPSec counters reset by avipsMonitorRstCntrs or 'clear crypto sa counters' in CLI, in hundredths of a second. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2 | TableavipsPeerTable | not-accessible | current | This table contains entries for every active isakmp peer in the system. The word 'active' suggests that in case the peer is part of a redundant list of peers w… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1 | RowavipsPeerEntry | not-accessible | current | A specific peer entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.1 | ColumnavipsPeerLocalId | not-accessible | current | A synthetic ID that uniquely identifies the local peer for monitoring purpose. Note that this ID is persistent for this peer. This is also the first index comp… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.2 | ColumnavipsPeerRemoteId | not-accessible | current | A synthetic ID that uniquely identifies the remote peer for monitoring purpose. Note that this ID is persistent for this peer. This is also the second index co… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.3 | ColumnavipsPeerLocalType | read-only | current | The type of the local peer identity, as it was configured. If the local peer ID was configured as an interface name, the value of this object shall be ifName. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.4 | ColumnavipsPeerLocalValue | read-only | current | The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer t… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.5 | ColumnavipsPeerRemoteType | read-only | current | The type of the remote peer identity. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.6 | ColumnavipsPeerRemoteValue | read-only | current | The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote pe… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.7 | ColumnavipsPeerRemoteDescription | read-only | current | Free text describing the remote peer or peer-group. The value of this field is taken from avipsIsakmpPeerDescription. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.8 | ColumnavipsPeerLocalAddress | read-only | current | The IP address of the local peer. This is derived from the local-address specified in the crypto-list that creates this connection. If the local peer type is a… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.9 | ColumnavipsPeerRemoteAddress | read-only | current | The IP address of the remote peer. If the remote peer type is an IP Address, then this is identical to avipsPeerRemoteValue. If the remote peer type is a fqdn,… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.10 | ColumnavipsPeerRemotePeerGrpActiveIndex | read-only | current | In case the remote is a peer-group, i.e. avipsPeerRemoteType is peerGroup, this object specifies the index within the peer-group of the currently active peer. … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.11 | ColumnavipsPeerRemotePeerGrpActiveIdType | read-only | current | In case the remote is a peer-group, i.e. avipsPeerRemoteType is peerGroup, this object specifies the id-type of the currently active peer. This value is taken … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.12 | ColumnavipsPeerRemotePeerGrpActiveIdValue | read-only | current | In case the remote is a peer-group, i.e. avipsPeerRemoteType is peerGroup, this object specifies the id-value of the currently active peer. This value is taken… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.13 | ColumnavipsPeerIsakmpState | read-only | current | This object specifies the state of the IKE connection between the peers. 1. closed - No IKE SA exists between peers because it was not negotiated yet, or becau… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.14 | ColumnavipsPeerIsakmpStateLastChange | read-only | current | sysUpTime when the last change in avipsPeerIsakmpState occured, in hundredths of a second. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.15 | ColumnavipsPeerTunnelsClosed | read-only | current | The number of IPSec tunnels associated with these peers, which are in the 'closed' state. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.16 | ColumnavipsPeerTunnelsInProgress | read-only | current | The number of IPSec tunnels associated with these peers, which are in the 'inProgress' state. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.17 | ColumnavipsPeerTunnelsEstablished | read-only | current | The number of IPSec tunnels associated with these peers, which are in the 'established' state. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.18 | ColumnavipsPeerTunnelsFailed | read-only | current | The number of IPSec tunnels associated with these peers, which are in the 'failed' state. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.19 | ColumnavipsPeerInOctets | read-only | current | The aggregate number of octets (bytes) successfully received through all the tunnels between the peers. This value is accumulated BEFORE determining whether or… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.20 | ColumnavipsPeerInOctetsWraps | read-only | current | The number of times avipsPeerInOctets has wrapped. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.21 | ColumnavipsPeerInDecompOctets | read-only | current | The aggregate number of decompressed octets (bytes) successfully received through all the tunnels between the peers. This value is accumulated AFTER the packet… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.22 | ColumnavipsPeerInDecompOctetsWraps | read-only | current | The number of times avipsPeerInDecompOctets has wrapped. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.23 | ColumnavipsPeerInDecompRatio | read-only | current | The overall decompression ratio * 100. This is the ratio between the number of octets received after decompression and the number of octets received before dec… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.24 | ColumnavipsPeerInPkts | read-only | current | The aggregate number of packets successfully received through all the tunnels between the peers. This number is the sum of avipsTunnelInPkts for all the tunnel… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.25 | ColumnavipsPeerInDropPkts | read-only | current | The aggregate number of packets dropped after being received through any of the tunnels between the peers. This number is the sum of avipsTunnelInDropTotalPkts… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.26 | ColumnavipsPeerOutOctets | read-only | current | The aggregate number of octets (bytes) successfully transmitted through all the tunnels between the peers. This value is accumulated AFTER determining whether … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.27 | ColumnavipsPeerOutOctetsWraps | read-only | current | The number of times avipsPeerOutOctets has wrapped. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.28 | ColumnavipsPeerOutUncompOctets | read-only | current | The aggregate number of uncompressed octets (bytes) successfully transmitted through this IPsec Tunnel. This value is accumulated BEFORE the packet is compress… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.29 | ColumnavipsPeerOutUncompOctetsWraps | read-only | current | The number of times avipsPeerInDecompOctets has wrapped. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.30 | ColumnavipsPeerOutCompRatio | read-only | current | The overall compression ratio * 100. This is the ratio between the number of outbound octets before compression and the number of outbound octets after compres… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.31 | ColumnavipsPeerOutPkts | read-only | current | The aggregate number of packets successfully transmitted through all the tunnels between the peers. This number is the sum of avipsTunnelOutPkts for all the tu… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.2.1.32 | ColumnavipsPeerOutDropPkts | read-only | current | The aggregate number of packets dropped before being transmitted through any of the tunnels between the peers. This number is the sum of avipsTunnelOutDropTota… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3 | TableavipsTunnelTable | not-accessible | current | This table contains a entries for all the tunnels in the system. A 'tunnel' is a rule within an active crypto-list. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1 | RowavipsTunnelEntry | not-accessible | current | A specific tunnel entry. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.1 | ColumnavipsTunnelPeerLocalId | not-accessible | current | A synthetic ID that uniquely identifies the local peer for monitoring purpose. Note that this ID is persistent for this peer. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.2 | ColumnavipsTunnelPeerRemoteId | not-accessible | current | A synthetic ID that uniquely identifies the remote peer for monitoring purpose. Note that this ID is persistent for this peer. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.3 | ColumnavipsTunnelIndex | not-accessible | current | The ID of the crypto-list containing the rule that creates this tunnel. This is also the fifth index component of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.4 | ColumnavipsTunnelSubIndex | not-accessible | current | The index of the crypto-list rule that creates this tunnel. This is also the sixth index component of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.5 | ColumnavipsTunnelPeerLocalType | read-only | current | The type of the local peer identity, as it was configured. If the local peer ID was configured as an interface name, the value of this object shall be ifName. … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.6 | ColumnavipsTunnelPeerLocalValue | read-only | current | The value of the local peer identity. If the local peer type is an IP Address, then this is the IP Address used to identify the local peer. If the local peer t… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.7 | ColumnavipsTunnelPeerRemoteType | read-only | current | The type of the remote peer identity. This is also the third index component of this table. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.8 | ColumnavipsTunnelPeerRemoteValue | read-only | current | The value of the remote peer identity. If the remote peer type is an IP Address, then this is the IP Address used to identify the remote peer. If the remote pe… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.9 | ColumnavipsTunnelDescription | read-only | current | Free text describing this tunnel. The value of this field is taken from the description specified for the crypto-list rule that creates this tunnel. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.10 | ColumnavipsTunnelLocalAddress | read-only | current | The IP address of the local peer. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.11 | ColumnavipsTunnelRemoteAddress | read-only | current | The IP address of the remote peer. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.12 | ColumnavipsTunnelProxyLocalSubnet | read-only | current | The local subnet address this tunnel protects. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.13 | ColumnavipsTunnelProxyLocalMask | read-only | current | The local subnet mask this tunnel protects. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.14 | ColumnavipsTunnelProxyRemoteSubnet | read-only | current | The remote subnet address this tunnel protects. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.15 | ColumnavipsTunnelProxyRemoteMask | read-only | current | The remote subnet mask this tunnel protects. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.16 | ColumnavipsTunnelState | read-only | current | This object specifies the state of this tunnel. 1. closed - The tunnel does not exist between the peers because it was not negotiated yet, or because last tunn… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.17 | ColumnavipsTunnelStateLastChange | read-only | current | sysUpTime when the last change in avipsTunnelState occured, in hundredths of a second. |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.18 | ColumnavipsTunnelLastCntrsReset | read-only | current | sysUpTime when last counter reset for this tunnel occured, in hundredths of a second. Counters are zeroized when: o Issuing 'clear crypto sa counters' in CLI. … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.19 | ColumnavipsTunnelInOctets | read-only | current | The total number of octets (bytes) successfully received through this IPSec tunnel. This value is accumulated BEFORE determining whether or not the packet shou… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.20 | ColumnavipsTunnelInOctetsWraps | read-only | current | The number of times avipsTunnelInOctets has wrapped. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsMonitorRstCntrs… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.21 | ColumnavipsTunnelInDecompOctets | read-only | current | The total number of decompressed octets (bytes) successfully received through this IPsec Tunnel. This value is accumulated AFTER the packet is decompressed. If… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.22 | ColumnavipsTunnelInDecompOctetsWraps | read-only | current | The number of times avipsTunnelInDecompOctets has wrapped. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsMonitorRs… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.23 | ColumnavipsTunnelInDecompRatio | read-only | current | The overall decompression ratio * 100. This is the ratio between the number of octets received after decompression and the number of octets received before dec… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.24 | ColumnavipsTunnelInPkts | read-only | current | The number of packets succesfully received through this tunnel. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsMoni… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.25 | ColumnavipsTunnelInDropTotalPkts | read-only | current | The total number of packets discarded after being received through this tunnel. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o S… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.26 | ColumnavipsTunnelInDropAntiReplayPkts | read-only | current | The number of packets discarded after being received through this tunnel due to anti-replay verification failure. This counter is zeroized when: o Issuing 'cle… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.27 | ColumnavipsTunnelInDropHmacFailPkts | read-only | current | The number of packets discarded after being received through this tunnel due to HMAC verification failure. This counter is zeroized when: o Issuing 'clear cryp… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.28 | ColumnavipsTunnelInDropBadTrailerPkts | read-only | current | The number of packets discarded after being received through this tunnel due to bad ESP trailer format received failure. This counter is zeroized when: o Issui… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.29 | ColumnavipsTunnelInDropInvalidIdPkts | read-only | current | The number of packets discarded after being received through this tunnel due to invalid identity: inner (original) IP header address doesn't match the configur… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.30 | ColumnavipsTunnelInDropUnprotectPkts | read-only | current | The number of packets discarded after being received in the clear (unprotected) although they were expected to arrive protected by this tunnel (i.e. unprotecte… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.31 | ColumnavipsTunnelInDropInvalidLenPkts | read-only | current | The number of packets discarded after being received through this tunnel due to length being not aligned to cipher block. This counter is zeroized when: o Issu… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.32 | ColumnavipsTunnelInDropSaExpiredPkts | read-only | current | The number of packets discarded after being received through this tunnel due to SA KB lifetime being smaller then the external IP packet total length. This cou… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.33 | ColumnavipsTunnelOutOctets | read-only | current | The total number of octets (bytes) successfully transmitted through this IPSec tunnel. This value is accumulated AFTER determining whether or not the packet sh… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.34 | ColumnavipsTunnelOutOctetsWraps | read-only | current | The number of times avipsTunnelOutOctets has wrapped. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsMonitorRstCntr… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.35 | ColumnavipsTunnelOutUncompOctets | read-only | current | The total number of uncompressed octets (bytes) successfully transmitted through this IPsec Tunnel. This value is accumulated BEFORE the packet is compressed. … |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.36 | ColumnavipsTunnelOutUncompOctetsWraps | read-only | current | The number of times avipsTunnelInDecompOctets has wrapped. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsMonitorRs… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.37 | ColumnavipsTunnelOutCompRatio | read-only | current | The overall compression ratio * 100. This is the ratio between the number of outbound octets before compression and the number of outbound octets after compres… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.38 | ColumnavipsTunnelOutPkts | read-only | current | The number of packets succesfully transmitted through this tunnel. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o Setting avipsM… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.39 | ColumnavipsTunnelOutDropTotalPkts | read-only | current | The total number of packets dropped before being transmitted through this tunnel. This counter is zeroized when: o Issuing 'clear crypto sa counters' in CLI. o… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.40 | ColumnavipsTunnelOutDropNoSaPkts | read-only | current | The number of packets dropped before being transmitted through this tunnel due to no IPSec SA existed when the packet arrived. This counter is zeroized when: o… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.41 | ColumnavipsTunnelOutDropSeqRolPkts | read-only | current | The number of packets dropped before being transmitted through this tunnel due to sequence number rollover: the sequence number of the IPSec SA reached its cap… |
| 1.3.6.1.4.1.6889.2.6.1.1.4.1.3.1.42 | ColumnavipsTunnelOutDropSaExpiredPkts | read-only | current | The number of packets dropped before being transmitted through this tunnel due to SA expired: SA KB lifetime is smaller then the external IP packet total lengt… |
| 1.3.6.1.4.1.6889.2.6.1.2 | NodeavipsMIBNotificationPrefix | |||
| 1.3.6.1.4.1.6889.2.6.1.2.0 | NodeavipsMIBNotifications | |||
| 1.3.6.1.4.1.6889.2.6.1.2.0.1 | NotificationavipsIskampEstablished | current | This notification is sent whenever avipsPeerIsakmpState moves into the 'established' state. | |
| 1.3.6.1.4.1.6889.2.6.1.2.0.2 | NotificationavipsIskampClosed | current | This notification is sent whenever avipsPeerIsakmpState moves into the 'closed' state, excluding during row creation. | |
| 1.3.6.1.4.1.6889.2.6.1.2.0.3 | NotificationavipsIskampFailed | current | This notification is sent whenever avipsPeerIsakmpState moves into the 'failed' state. | |
| 1.3.6.1.4.1.6889.2.6.1.2.0.4 | NotificationavipsIpsecTunnelEstablished | current | This notification is sent whenever avipsTunnelState moves into the 'established' state. | |
| 1.3.6.1.4.1.6889.2.6.1.2.0.5 | NotificationavipsIpsecTunnelClosed | current | This notification is sent whenever avipsTunnelState moves into the 'closed' state, excluding during row creation. | |
| 1.3.6.1.4.1.6889.2.6.1.2.0.6 | NotificationavipsIpsecTunnelFailed | current | This notification is sent whenever avipsTunnelState moves into the 'failed' state. | |
| 1.3.6.1.4.1.6889.2.6.1.3 | NodeavipsMIBConformance | |||
| 1.3.6.1.4.1.6889.2.6.1.3.1 | NodeavipsMIBGroups | |||
| 1.3.6.1.4.1.6889.2.6.1.3.1.1 | GroupavipsConfigurationGroup | current | This group consists of: 1) Global configuration objects. 2) Isakmp configuration objects. 3) IPsec configuration objects. | |
| 1.3.6.1.4.1.6889.2.6.1.3.1.2 | GroupavipsMonitorGroup | current | This group consists of: 1) Global monitoring objects. 2) Peer monitoring objects. 3) IPSec tunnels monitoring objects. | |
| 1.3.6.1.4.1.6889.2.6.1.3.2 | NodeavipsMIBCompliances | |||
| 1.3.6.1.4.1.6889.2.6.1.3.2.1 | ComplianceavipsMIBCompliance | current | The compliance statement for SNMP entities the IP Security Protocol. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| DiffHellmanGrp | INTEGER { dhGroup1(1), dhGroup2(2), dhGroup5(5), dhGroup14(14), dhGroup15(15), dhGroup16(16), dhGroup17(17), dhGroup18(18), none(255) } | current | The Diffie Hellman Group used in negotiations. |
| EspEncrTransform | INTEGER { null(1), des(2), des3(3), aes(4), aes192(5), aes256(6), none(255) } | current | The values of the IPsec DOI ESP Transform Identifier which identify a particular algorithm to be used to provide secrecy protection for ESP. It is used in the Transform-ID field of a ISAKMP Transform Payload for the IPs… |
| EspHashTransform | INTEGER { none(1), md5(2), sha(3) } | current | The ESP Authentication Algorithm used in the IPsec DOI as a SA Attributes definition in the Transform Payload of Phase II of an IKE negotiation. This set of values defines the AH authentication algorithm, when the assoc… |
| IkeEncryptAlgo | INTEGER { des(2), des3(3), aes(4), aes192(5), aes256(6), none(255) } | current | Values for encryption algorithms negotiated for the ISAKMP SA by IKE in Phase I. These are values for SA Attribute type Encryption Algorithm (1). |
| IkeHashAlgo | INTEGER { none(1), md5(2), sha(3) } | current | Values for hash algorithms negotiated for the ISAKMP SA by IKE in Phase I. These are values for SA Attribute type Hash Algorithm (2). |
| IpsecEncapMode | INTEGER { tunnel(1), transport(2) } | current | IPSec encapsulation mode. |
| IsakmpDpdKeepaliveMetric | INTEGER { disabled(1), onDemand(2), periodic(3) } | current | Specifies the type of worry-metric to be used for DPD. |
| IsakmpIdentityType | INTEGER { ipv4Address(1), fqdn(2), userFqdn(3), none(256), peerGroup(257), ifName(270) } | current | This TC provides the semantics for a column with IsakmpIdentityValue TC. Wherever this TC is used, there should be an accompanying column which uses the IsakmpIdentityValue TC to specify the data for which the semantics… |
| IsakmpIdentityValue | OCTET STRING (SIZE (1..110)) | current | IsakmpIdentityValue contains a string encoded Identity Type value to be used in comparisons against an IKE Identity payload. Wherever this TC is used, there should be an accompanying column which uses the IsakmpIdentity… |