CISCO-IKE-CONFIGURATION-MIB
88 objects
This is a MIB Module for configuring and viewing IKE parameters and policies. Acronyms The following acronyms are used in this document: IPsec: Secure IP Protocol VPN: Virtual Private Network ISAKMP: Internet Security Association and Key Exchange Protocol IKE: Internet Key Exchange Protocol DOI: Domain of Interpretation (of the attributes of IKE protocol in the context of a specific Phase-2 protocol). SA: Security Association (ref: rfc2408). SPI: Security Parameter Index is the pointer or identifier used in accessing SA attributes (ref: rfc2408). MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs Phase 1 Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document. Phase 2 Tunnel: A Phase 2 Tunnel is an instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) and protect the same stream of application traffic. Note that a Phase 2 tunnel may comprise one SA bundle at any given point of time, but the SA bundle changes with time due to key refresh. History of the MIB This MIB was originally written as CISCO-IPSEC-MIB which combined the configuration of IKE and IPsec protocols into a single MIB.
Imported Objects
| CISCO-IPSEC-TC | CIKEIsakmpDoi CIKELifesize CIKELifetime CIPsecControlProtocol CIPsecDiffHellmanGrp CIPsecEncryptAlgorithm CIPsecIkeAuthMethod CIPsecIkeHashAlgorithm CIPsecIkePRFAlgorithm CIPsecPhase1PeerIdentityType |
| CISCO-SMI | ciscoMgmt |
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType |
| SNMPv2-CONF | MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP |
| SNMPv2-SMI | MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | RowStatus TEXTUAL-CONVENTION TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.9.9.423 | IdentityciscoIkeConfigMIB | This is a MIB Module for configuring and viewing IKE parameters and policies. Acronyms The following acronyms are used in this document: IPsec: Secure IP Proto… | ||
| 1.3.6.1.4.1.9.9.423.0 | NodecicIkeConfigMIBNotifs | |||
| 1.3.6.1.4.1.9.9.423.0.1 | NotificationciscoIkeConfigOperStateChanged | current | The notification is generated when the operational state of IKE entity on the managed device has been changed. | |
| 1.3.6.1.4.1.9.9.423.0.2 | NotificationciscoIkeConfigPskAdded | current | This notification is generated when a new preshared key is configured on the managed device. | |
| 1.3.6.1.4.1.9.9.423.0.3 | NotificationciscoIkeConfigPskDeleted | current | This notification is generated when an existing preshared key is configured on the managed device is about to be deleted. | |
| 1.3.6.1.4.1.9.9.423.0.4 | NotificationciscoIkeConfigPolicyAdded | current | This notification is generated when a new ISAKMP policy is configured on the managed device. | |
| 1.3.6.1.4.1.9.9.423.0.5 | NotificationciscoIkeConfigPolicyDeleted | current | This notification is issued when an existing ISAKMP policy configured on the managed device is about to be deleted. | |
| 1.3.6.1.4.1.9.9.423.1 | NodecicIkeConfigMIBObjects | |||
| 1.3.6.1.4.1.9.9.423.1.1 | NodecicIkeCfgOperations | |||
| 1.3.6.1.4.1.9.9.423.1.1.1 | ScalarcicIkeEnabled | read-write | current | This object reflects the operational status (enabled/ disabled) of the IKE entity on the managed device. 'true' - IKE is enabled. 'false' - IKE is disabled. |
| 1.3.6.1.4.1.9.9.423.1.1.2 | ScalarcicIkeAggressModeEnabled | read-write | current | This object reflects if the IKE entity on the managed device performs aggressive mode negotiations. 'true' - IKE entity performs aggressive mode negotiations. … |
| 1.3.6.1.4.1.9.9.423.1.2 | NodecicIkeCfgIdentities | |||
| 1.3.6.1.4.1.9.9.423.1.2.1 | TablecicIkeCfgIdentityTable | not-accessible | current | The table containing the list of Phase-1 identities used by the IKE protocol for the different Phase-2 DOIs it operates in. |
| 1.3.6.1.4.1.9.9.423.1.2.1.1 | RowcicIkeCfgIdentityEntry | not-accessible | current | Each entry represents a Phase-1 identity used by IKE for a specific Phase-2 DOI. |
| 1.3.6.1.4.1.9.9.423.1.2.1.1.1 | ColumncicIkeCfgIdentityDoi | not-accessible | current | This is the DOI type that is supported by this IKE entity on the managed device and for which the Phase-1 identity corresponding to this conceptual row is bein… |
| 1.3.6.1.4.1.9.9.423.1.2.1.1.2 | ColumncicIkeCfgIdentityType | read-write | current | The Phase I identity type used by the Phase-2 DOI corresponding to this conceptual row. |
| 1.3.6.1.4.1.9.9.423.1.2.2 | TablecicIkeCfgInitiatorNextAvailTable | not-accessible | current | The table providing the next available index for the cicIkeCfgInitiatorTable, in a domain of interpretation(DOI), identified by cicIkeCfgIdentityDoi. This valu… |
| 1.3.6.1.4.1.9.9.423.1.2.2.1 | RowcicIkeCfgInitiatorNextAvailEntry | not-accessible | current | Each entry represents a next available index for the cicIkeCfgInitiatorTable. |
| 1.3.6.1.4.1.9.9.423.1.2.2.1.1 | ColumncicIkeCfgInitiatorNextAvailIndex | read-only | current | The object specifies the next available index for object cicIkeCfgInitiatorIndex which can be used for creating an entry in cicIkeCfgInitiatorTable. |
| 1.3.6.1.4.1.9.9.423.1.2.3 | TablecicIkeCfgInitiatorTable | not-accessible | current | The table containing the IKE version initiators for peers. |
| 1.3.6.1.4.1.9.9.423.1.2.3.1 | RowcicIkeCfgInitiatorEntry | not-accessible | current | Each entry represents the IKE protocol version initiated when connecting to a remote peer. |
| 1.3.6.1.4.1.9.9.423.1.2.3.1.1 | ColumncicIkeCfgInitiatorIndex | not-accessible | current | An arbitrary value identifying the configured IKE version initiated for a peer in this domain of interpretation, identified by cicIkeCfgIdentityDoi, on a manag… |
| 1.3.6.1.4.1.9.9.423.1.2.3.1.2 | ColumncicIkeCfgInitiatorPAddrType | read-create | current | The Phase 1 ID type of the remote peer for which this IKE protocol initiator is configured. This object cannot be modified while the corresponding value of cic… |
| 1.3.6.1.4.1.9.9.423.1.2.3.1.3 | ColumncicIkeCfgInitiatorPAddr | read-create | current | This object represents the address of the remote peer corresponding to this conceptual row. This object cannot be modified while the corresponding value of cic… |
| 1.3.6.1.4.1.9.9.423.1.2.3.1.4 | ColumncicIkeCfgInitiatorVer | read-create | current | This object represents the IKE protocol version used when connecting to a remote peer specified in cicIkeCfgInitiatorPAddr. This object cannot be modified whil… |
| 1.3.6.1.4.1.9.9.423.1.2.3.1.5 | ColumncicIkeCfgInitiatorStatus | read-create | current | The status of this conceptual row. To configure an IKE version initiator entry, the NMS must do a multivarbind set containing cicIkeCfgInitiatorPAddrType, cicI… |
| 1.3.6.1.4.1.9.9.423.1.3 | NodecicIkeCfgFailureRecovery | |||
| 1.3.6.1.4.1.9.9.423.1.3.1 | TablecicIkeCfgFailureRecovConfigTable | not-accessible | current | The table containing the failure recovery configuration for IKE per supported DOI in the managed entity. |
| 1.3.6.1.4.1.9.9.423.1.3.1.1 | RowcicIkeCfgFailureRecovConfigEntry | not-accessible | current | Each entry represents a Phase I failure recovery configuration for the Phase 2 DOI corresponding to the conceptual row. |
| 1.3.6.1.4.1.9.9.423.1.3.1.1.1 | ColumncicIkeKeepAliveEnabled | read-write | current | This object reflects if the IKE entity in the managed device performs keepalives with all the peers for the DOI corresponding to this conceptual row. 'true' - … |
| 1.3.6.1.4.1.9.9.423.1.3.1.1.2 | ColumncicIkeKeepAliveType | read-write | current | This object reflects the type of keepalives to be used by the IKE entity on the managed device with all the peers for the DOI corresponding to this conceptual … |
| 1.3.6.1.4.1.9.9.423.1.3.1.1.3 | ColumncicIkeKeepAliveInterval | read-write | current | This object reflects the keepalive interval in seconds used by the IKE entity on the managed device with all the peers for the DOI corresponding to this concep… |
| 1.3.6.1.4.1.9.9.423.1.3.1.1.4 | ColumncicIkeKeepAliveRetryInterval | read-write | current | This object reflects the keepalive retry interval in seconds used by the IKE entity on the managed device with all the peers for the DOI corresponding to this … |
| 1.3.6.1.4.1.9.9.423.1.3.1.1.5 | ColumncicIkeInvalidSpiNotify | read-write | current | This object reflects if the IKE entity on the managed device notifies any peer when an IPsec Phase-1 or Phase-2 packet with an invalid SPI is received from tha… |
| 1.3.6.1.4.1.9.9.423.1.4 | NodecicIkeCfgPeerAuth | |||
| 1.3.6.1.4.1.9.9.423.1.4.1 | NodecicIkeCfgPskAuthConfig | |||
| 1.3.6.1.4.1.9.9.423.1.4.1.1 | TablecicIkeCfgPskNextAvailTable | not-accessible | current | The table providing the next available index for the cicIkeCfgPskTable, in a domain of interpretation(DOI), identified by cicIkeCfgIdentityDoi. This value is o… |
| 1.3.6.1.4.1.9.9.423.1.4.1.1.1 | RowcicIkeCfgPskNextAvailEntry | not-accessible | current | Each entry represents a next available index for the cicIkeCfgPskTable. |
| 1.3.6.1.4.1.9.9.423.1.4.1.1.1.1 | ColumncicIkeCfgPskNextAvailIndex | read-only | current | The object specifies the next available index for object cicIkeCfgPskIndex which can be used for creating an entry in cicIkeCfgPskTable. |
| 1.3.6.1.4.1.9.9.423.1.4.1.2 | TablecicIkeCfgPskTable | not-accessible | current | The table containing the list of pre shared authentication keys configured to be used by IKE protocol catalogued by the DOI and the peer identity. It is possib… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1 | RowcicIkeCfgPskEntry | not-accessible | current | Each entry represents a configured pre-shared authentication key for a specific peer. |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.1 | ColumncicIkeCfgPskIndex | not-accessible | current | An arbitrary value identifying the configured pre-shared keys for IKE entity in this domain of interpretation, identified by cicIkeCfgIdentityDoi, on a managed… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.2 | ColumncicIkeCfgPskKey | read-create | current | The pre-shared authorization key used in authenticating the peer corresponding to this conceptual row. This object cannot be modified while the corresponding v… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.3 | ColumncicIkeCfgPskRemIdentType | read-create | current | The Phase 1 ID type of the remote peer identity for which this preshared key is configured. This object cannot be modified while the corresponding value of cic… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.4 | ColumncicIkeCfgPskRemIdentTypeStand | read-only | current | If the object 'cicIkeCfgPskRemIdentType' is one of idIpv4Addr idIpv6Addr idIpv4AddrRange idIpv6AddrRange idIpv4AddrSubnet idIpv6AddrSubnet then this object con… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.5 | ColumncicIkeCfgPskRemIdentity | read-create | current | The Phase 1 ID identity of the peer for which this preshared key is configured on the local entity. This object cannot be modified while the corresponding valu… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.6 | ColumncicIkeCfgPskRemIdAddrOrRg1OrSn | read-create | current | If the object cicIkeCfgPskRemIdentType is one of idIpv4Addr idIpv6Addr idIpv4AddrRange idIpv6AddrRange idIpv4AddrSubnet idIpv6AddrSubnet then this object conta… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.7 | ColumncicIkeCfgPskRemIdAddrRange2 | read-create | current | If the object cicIkeCfgPskRemIdentType is one of idIpv4AddrRange idIpv6AddrRange then this object contains the second component of the Phase 1 identity. Otherw… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.8 | ColumncicIkeCfgPskRemIdSubnetMask | read-create | current | If the object 'cicIkeCfgPskRemIdentType' is one of idIpv4AddrSubnet idIpv6AddrSubnet then this object contains the second component of the Phase 1 identity. Ot… |
| 1.3.6.1.4.1.9.9.423.1.4.1.2.1.9 | ColumncicIkeCfgPskStatus | read-create | current | The status of this conceptual row. To configure an pre shared authentication key entry, the NMS must do a multivarbind set containing cicIkeCfgPskKey, cicIkeCf… |
| 1.3.6.1.4.1.9.9.423.1.4.2 | NodecicIkeCfgNonceAuthConfig | |||
| 1.3.6.1.4.1.9.9.423.1.4.3 | NodecicIkeCfgPkiAuthConfig | |||
| 1.3.6.1.4.1.9.9.423.1.5 | NodecicIkeCfgPolicies | |||
| 1.3.6.1.4.1.9.9.423.1.5.1 | TablecicIkeCfgPolicyTable | not-accessible | current | The table containing the list of all ISAKMP policy entries configured by the operator. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1 | RowcicIkeCfgPolicyEntry | not-accessible | current | Each entry contains the attributes associated with a single ISAKMP Policy entry. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.1 | ColumncicIkeCfgPolicyPriority | not-accessible | current | The priority of this ISAKMP Policy entry. The policy with lower value would take precedence over the policy with higher value in the same DOI. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.2 | ColumncicIkeCfgPolicyEncr | read-create | current | The encryption transform specified by this ISAKMP policy specification. The Internet Key Exchange (IKE) tunnels setup using this policy item would use the spec… |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.3 | ColumncicIkeCfgPolicyHash | read-create | current | The hash transform specified by this ISAKMP policy specification. The IKE tunnels setup using this policy item would use the specified hash transform to protec… |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.4 | ColumncicIkeCfgPolicyPRF | read-create | current | The Pseudo Random Function algorithm specified by this ISAKMP policy specification. The value of this object would only be used for IKEv2. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.5 | ColumncicIkeCfgPolicyAuth | read-create | current | The peer authentication method specified by this ISAKMP policy specification. If this policy entity is selected for negotiation with a peer, the local entity w… |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.6 | ColumncicIkeCfgPolicyDHGroup | read-create | current | This object specifies the Oakley group used for Diffie Hellman exchange in the Main Mode. If this policy item is selected to negotiate Main Mode with an IKE pe… |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.7 | ColumncicIkeCfgPolicyLifetime | read-create | current | This object specifies the lifetime in seconds of the IKE tunnels generated using this policy specification. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.8 | ColumncicIkeCfgPolicyLifesize | read-create | current | This object specifies the life size in Kbytes of the IKE tunnels generated using this policy specification. |
| 1.3.6.1.4.1.9.9.423.1.5.1.1.9 | ColumncicIkeCfgPolicyStatus | read-create | current | This object specifies the status of the ISAKMP policy corresponding to this conceptual row. Creation of row can only be done via 'createAndGo'. To remove a row… |
| 1.3.6.1.4.1.9.9.423.1.6 | NodecicIkeCfgServiceControl | |||
| 1.3.6.1.4.1.9.9.423.1.6.1 | NodecicIkeCfgCallAdmssionnCtrl | |||
| 1.3.6.1.4.1.9.9.423.1.6.2 | NodecicIkeCfgQoSControl | |||
| 1.3.6.1.4.1.9.9.423.1.7 | NodecicIkeConfigMibNotifCntl | |||
| 1.3.6.1.4.1.9.9.423.1.7.1 | ScalarcicNotifCntlIkeAllNotifs | read-write | current | This value of this object must be 'true' to enable any notification in addition to the notification-specific control variables defined below. A notification <f… |
| 1.3.6.1.4.1.9.9.423.1.7.2 | ScalarcicNotifCntlIkeOperStateChanged | read-write | current | When cicNotifCntlIkeAllNotifs has the value 'true', this variable controls the generation of the ciscoIkeConfigOperStateChanged notification. When this variabl… |
| 1.3.6.1.4.1.9.9.423.1.7.3 | ScalarcicNotifCntlIkePskAdded | read-write | current | When cicNotifCntlIkeAllNotifs has the value 'true', this variable controls the generation of cicNotifCntlIkePskAdded notification. When this variable is set to… |
| 1.3.6.1.4.1.9.9.423.1.7.4 | ScalarcicNotifCntlIkePskDeleted | read-write | current | When cicNotifCntlIkeAllNotifs has the value 'true', this variable controls the generation of cicNotifCntlIkePskDeleted notification. When this variable is set … |
| 1.3.6.1.4.1.9.9.423.1.7.5 | ScalarcicNotifCntlIkePolicyAdded | read-write | current | When cicNotifCntlIkeAllNotifs has the value 'true', this variable controls the generation of cicNotifCntlIkePolicyAdded notification. When this variable is set… |
| 1.3.6.1.4.1.9.9.423.1.7.6 | ScalarcicNotifCntlIkePolicyDeleted | read-write | current | When cicNotifCntlIkeAllNotifs has the value 'true', this variable controls the generation of cicNotifCntlIkePolicyDeleted notification. When this variable is s… |
| 1.3.6.1.4.1.9.9.423.2 | NodecicIkeConfigMIBConform | |||
| 1.3.6.1.4.1.9.9.423.2.1 | NodecicIkeCfgMIBGroups | |||
| 1.3.6.1.4.1.9.9.423.2.1.1 | GroupcicIkeCfgOperGroup | current | This group consists of objects that reflect the operational state of the IKE entity on the managed device. | |
| 1.3.6.1.4.1.9.9.423.2.1.2 | GroupcicIkeCfgIdentitiesGroup | current | This group consists of objects that reflect the Phase 1 ID used by the IKE entity on the managed device. | |
| 1.3.6.1.4.1.9.9.423.2.1.3 | GroupcicIkeCfgFailureRecoveryGroup | current | This group consists of objects that define how the local IKE entity is configured to respond to common failures. | |
| 1.3.6.1.4.1.9.9.423.2.1.4 | GroupcicIkeCfgPskAuthGroup | current | This group consists of objects that are used to view and configure the preshared keys configured on the managed entity. | |
| 1.3.6.1.4.1.9.9.423.2.1.5 | GroupcicIkeCfgPolicyGroup | current | This group consists of objects that are used to view and configure the ISAKMP policies configured on the managed device. | |
| 1.3.6.1.4.1.9.9.423.2.1.6 | GroupcicIkeCfgOptionalPolicyGroup | current | This group consists of objects pertaining to ISAKMP policy management which are optional and may not be supported by every implementation of IKE. | |
| 1.3.6.1.4.1.9.9.423.2.1.7 | GroupcicIkeCfgNotifCntlGroup | current | This group of objects controls the sending of notifications to signal the state of Phase-1 IKE configuration on the managed device. | |
| 1.3.6.1.4.1.9.9.423.2.1.8 | GroupcicIkeCfgNotificationGroup | current | This group contains the notifications to signal the changes to IKE on the managed device. | |
| 1.3.6.1.4.1.9.9.423.2.2 | NodecicIkeCfgMIBCompliances | |||
| 1.3.6.1.4.1.9.9.423.2.2.1 | CompliancecicIkeCfgMIBCompliance | read-only | current | The compliance statement for SNMP entities the Internet Key Exchange Protocol configuration MIB. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| CicIkeConfigInitiatorIndex | Unsigned32(1..65535) | current | An arbitrary unique value identifying the configured IKE version initiator. |
| CicIkeConfigPskIndex | Unsigned32(1..65535) | current | An arbitrary unique value identifying the configured pre-shared keys. |