MIB Viewer

CISCO-IPSEC-MIB

101 objects
The MIB module for modeling Cisco-specific IPsec attributes Overview of Cisco IPsec MIB MIB description This MIB models the Cisco implementation-specific attributes of a Cisco entity that implements IPsec. This MIB is complementary to the standard IPsec MIB proposed jointly by Tivoli and Cisco. The ciscoIPsec MIB provides the operational information on Cisco's IPsec tunnelling implementation. The following entities are managed: 1) ISAKMP Group: a) ISAKMP global parameters b) ISAKMP Policy Table 2) IPSec Group: a) IPSec Global Parameters b) IPSec Global Traffic Parameters c) Cryptomap Group - Cryptomap Set Table - Cryptomap Table - CryptomapSet Binding Table 3) System Capacity & Capability Group: a) Capacity Parameters b) Capability Parameters 4) Trap Control Group 5) Notifications Group
Imported Objects
CISCO-SMIciscoExperiment
IF-MIBifIndex
RFC1213-MIB--
SNMPv2-CONFMODULE-COMPLIANCE OBJECT-GROUP
SNMPv2-SMICounter32 Gauge32 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE
SNMPv2-TCDisplayString TEXTUAL-CONVENTION TruthValue
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.10.62IdentityciscoIPsecMIBThe MIB module for modeling Cisco-specific IPsec attributes Overview of Cisco IPsec MIB MIB description This MIB models the Cisco implementation-specific attri…
1.3.6.1.4.1.9.10.62.1NodeciscoIPsecMIBObjects
1.3.6.1.4.1.9.10.62.1.1NodecipsIsakmpGroup
1.3.6.1.4.1.9.10.62.1.1.1ScalarcipsIsakmpEnabledread-onlycurrentThe value of this object is TRUE if ISAKMP has been enabled on the managed entity. Otherise the value of this object is FALSE.
1.3.6.1.4.1.9.10.62.1.1.2ScalarcipsIsakmpIdentityread-onlycurrentThe value of this object is shows the type of identity used by the managed entity in ISAKMP negotiations with another peer.
1.3.6.1.4.1.9.10.62.1.1.3ScalarcipsIsakmpKeepaliveIntervalread-onlycurrentThe value of this object is time interval in seconds between successive ISAKMP keepalive heartbeats issued to the peers to which IKE tunnels have been setup.
1.3.6.1.4.1.9.10.62.1.1.4ScalarcipsNumIsakmpPoliciesread-onlycurrentThe value of this object is the number of ISAKMP policies that have been configured on the managed entity.
1.3.6.1.4.1.9.10.62.1.1.5TablecipsIsakmpPolicyTablenot-accessiblecurrentThe table containing the list of all ISAKMP policy entries configured by the operator.
1.3.6.1.4.1.9.10.62.1.1.5.1RowcipsIsakmpPolicyEntrynot-accessiblecurrentEach entry contains the attributes associated with a single ISAKMP Policy entry.
1.3.6.1.4.1.9.10.62.1.1.5.1.1ColumncipsIsakmpPolPrioritynot-accessiblecurrentThe priotity of this ISAKMP Policy entry. This is also the index of this table.
1.3.6.1.4.1.9.10.62.1.1.5.1.2ColumncipsIsakmpPolEncrread-onlycurrentThe encryption transform specified by this ISAKMP policy specification. The Internet Key Exchange (IKE) tunnels setup using this policy item would use the spec…
1.3.6.1.4.1.9.10.62.1.1.5.1.3ColumncipsIsakmpPolHashread-onlycurrentThe hash transform specified by this ISAKMP policy specification. The IKE tunnels setup using this policy item would use the specified hash transform to protec…
1.3.6.1.4.1.9.10.62.1.1.5.1.4ColumncipsIsakmpPolAuthread-onlycurrentThe peer authentication mthod specified by this ISAKMP policy specification. If this policy entity is selected for negotiation with a peer, the local entity wo…
1.3.6.1.4.1.9.10.62.1.1.5.1.5ColumncipsIsakmpPolGroupread-onlycurrentThis object specifies the Oakley group used for Diffie Hellman exchange in the Main Mode. If this policy item is selected to negotiate Main Mode with an IKE pe…
1.3.6.1.4.1.9.10.62.1.1.5.1.6ColumncipsIsakmpPolLifetimeread-onlycurrentThis object specifies the lifetime in seconds of the IKE tunnels generated using this policy specification.
1.3.6.1.4.1.9.10.62.1.2NodecipsIPsecGroup
1.3.6.1.4.1.9.10.62.1.2.1NodecipsIPsecGlobals
1.3.6.1.4.1.9.10.62.1.2.1.1ScalarcipsSALifetimeread-onlycurrentThe default lifetime (in seconds) assigned to an SA as a global policy (maybe overridden in specific cryptomap definitions).
1.3.6.1.4.1.9.10.62.1.2.1.2ScalarcipsSALifesizeread-onlycurrentThe default lifesize in KBytes assigned to an SA as a global policy (unless overridden in cryptomap definition)
1.3.6.1.4.1.9.10.62.1.2.1.3ScalarcipsNumStaticCryptomapSetsread-onlycurrentThe number of Cryptomap Sets that are are fully configured. Statically defined cryptomap sets are ones where the operator has fully specified all the parameter…
1.3.6.1.4.1.9.10.62.1.2.1.4ScalarcipsNumCETCryptomapSetsread-onlycurrentThe number of static Cryptomap Sets that have at least one CET cryptomap element as a member of the set.
1.3.6.1.4.1.9.10.62.1.2.1.5ScalarcipsNumDynamicCryptomapSetsread-onlycurrentThe number of dynamic IPSec Policy templates (called 'dynamic cryptomap templates') configured on the managed entity.
1.3.6.1.4.1.9.10.62.1.2.1.6ScalarcipsNumTEDCryptomapSetsread-onlycurrentThe number of static Cryptomap Sets that have at least one dynamic cryptomap template bound to them which has the Tunnel Endpoint Discovery (TED) enabled.
1.3.6.1.4.1.9.10.62.1.2.2NodecipsIPsecStatistics
1.3.6.1.4.1.9.10.62.1.2.2.1ScalarcipsNumTEDProbesReceivedread-onlycurrentThe number of TED probes that were received by this managed entity since bootup. Not affected by any CLI operation.
1.3.6.1.4.1.9.10.62.1.2.2.2ScalarcipsNumTEDProbesSentread-onlycurrentThe number of TED probes that were dispatched by all the dynamic cryptomaps in this managed entity since bootup. Not affected by any CLI operation.
1.3.6.1.4.1.9.10.62.1.2.2.3ScalarcipsNumTEDFailuresread-onlycurrentThe number of TED probes that were dispatched by the local entity and that failed to locate crypto endpoint. Not affected by any CLI operation.
1.3.6.1.4.1.9.10.62.1.2.3NodecipsCryptomapGroup
1.3.6.1.4.1.9.10.62.1.2.3.1TablecipsStaticCryptomapSetTablenot-accessiblecurrentThe table containing the list of all cryptomap sets that are fully specified and are not wild-carded. The operator may include different types of cryptomaps in…
1.3.6.1.4.1.9.10.62.1.2.3.1.1RowcipsStaticCryptomapSetEntrynot-accessiblecurrentEach entry contains the attributes associated with a single static cryptomap set.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.1ColumncipsStaticCryptomapSetNamenot-accessiblecurrentThe index of the static cryptomap table. The value of the string is the name string assigned by the operator in defining the cryptomap set.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.2ColumncipsStaticCryptomapSetSizeread-onlycurrentThe total number of cryptomap entries contained in this cryptomap set.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.3ColumncipsStaticCryptomapSetNumIsakmpread-onlycurrentThe number of cryptomaps associated with this cryptomap set that use ISAKMP protocol to do key exchange.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.4ColumncipsStaticCryptomapSetNumManualread-onlycurrentThe number of cryptomaps associated with this cryptomap set that require the operator to manually setup the keys and SPIs.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.5ColumncipsStaticCryptomapSetNumCETread-onlycurrentThe number of cryptomaps of type 'ipsec-cisco' associated with this cryptomap set. Such cryptomap elements implement Cisco Encryption Technology based Virtual …
1.3.6.1.4.1.9.10.62.1.2.3.1.1.6ColumncipsStaticCryptomapSetNumDynamicread-onlycurrentThe number of dynamic cryptomap templates linked to this cryptomap set.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.7ColumncipsStaticCryptomapSetNumDiscread-onlycurrentThe number of dynamic cryptomap templates linked to this cryptomap set that have Tunnel Endpoint Discovery (TED) enabled.
1.3.6.1.4.1.9.10.62.1.2.3.1.1.8ColumncipsStaticCryptomapSetNumSAsread-onlycurrentThe number of and IPsec Security Associations that are active and were setup using this cryptomap.
1.3.6.1.4.1.9.10.62.1.2.3.2TablecipsDynamicCryptomapSetTablenot-accessiblecurrentThe table containing the list of all dynamic cryptomaps that use IKE, defined on the managed entity.
1.3.6.1.4.1.9.10.62.1.2.3.2.1RowcipsDynamicCryptomapSetEntrynot-accessiblecurrentEach entry contains the attributes associated with a single dynamic cryptomap template.
1.3.6.1.4.1.9.10.62.1.2.3.2.1.1ColumncipsDynamicCryptomapSetNamenot-accessiblecurrentThe index of the dynamic cryptomap table. The value of the string is the one assigned by the operator in defining the cryptomap set.
1.3.6.1.4.1.9.10.62.1.2.3.2.1.2ColumncipsDynamicCryptomapSetSizeread-onlycurrentThe number of cryptomap entries in this cryptomap.
1.3.6.1.4.1.9.10.62.1.2.3.2.1.3ColumncipsDynamicCryptomapSetNumAssocread-onlycurrentThe number of static cryptomap sets with which this dynamic cryptomap is associated.
1.3.6.1.4.1.9.10.62.1.2.3.3TablecipsStaticCryptomapTablenot-accessiblecurrentThe table ilisting the member cryptomaps of the cryptomap sets that are configured on the managed entity.
1.3.6.1.4.1.9.10.62.1.2.3.3.1RowcipsStaticCryptomapEntrynot-accessiblecurrentEach entry contains the attributes associated with a single static (fully specified) cryptomap entry. This table does not include the members of dynamic crypto…
1.3.6.1.4.1.9.10.62.1.2.3.3.1.1ColumncipsStaticCryptomapPrioritynot-accessiblecurrentThe priority of the cryptomap entry in the cryptomap set. This is the second index component of this table.
1.3.6.1.4.1.9.10.62.1.2.3.3.1.2ColumncipsStaticCryptomapTyperead-onlycurrentThe type of the cryptomap entry. This can be an ISAKMP cryptomap, CET or manual. Dynamic cryptomaps are not counted in this table.
1.3.6.1.4.1.9.10.62.1.2.3.3.1.3ColumncipsStaticCryptomapDescrread-onlycurrentThe description string entered by the operatoir while creating this cryptomap. The string generally identifies a description and the purpose of this policy.
1.3.6.1.4.1.9.10.62.1.2.3.3.1.4ColumncipsStaticCryptomapPeerread-onlycurrentThe IP address of the current peer associated with this IPSec policy item. Traffic that is protected by this cryptomap is protected by a tunnel that terminates…
1.3.6.1.4.1.9.10.62.1.2.3.3.1.5ColumncipsStaticCryptomapNumPeersread-onlycurrentThe number of peers associated with this cryptomap entry. The peers other than the one identified by 'cipsStaticCryptomapPeer' are backup peers. Manual cryptom…
1.3.6.1.4.1.9.10.62.1.2.3.3.1.6ColumncipsStaticCryptomapPfsread-onlycurrentThis object identifies if the tunnels instantiated due to this policy item should use Perfect Forward Secrecy (PFS) and if so, what group of Oakley they should…
1.3.6.1.4.1.9.10.62.1.2.3.3.1.7ColumncipsStaticCryptomapLifetimeread-onlycurrentThis object identifies the lifetime of the IPSec Security Associations (SA) created using this IPSec policy entry. If this value is zero, the lifetime assumes …
1.3.6.1.4.1.9.10.62.1.2.3.3.1.8ColumncipsStaticCryptomapLifesizeread-onlycurrentThis object identifies the lifesize (maximum traffic in bytes that may be carried) of the IPSec SAs created using this IPSec policy entry. If this value is zer…
1.3.6.1.4.1.9.10.62.1.2.3.3.1.9ColumncipsStaticCryptomapLevelHostread-onlycurrentThis object identifies the granularity of the IPSec SAs created using this IPSec policy entry. If this value is TRUE, distinct SA bundles are created for disti…
1.3.6.1.4.1.9.10.62.1.2.3.4TablecipsCryptomapSetIfTablenot-accessiblecurrentThe table lists the binding of cryptomap sets to the interfaces of the managed entity.
1.3.6.1.4.1.9.10.62.1.2.3.4.1RowcipsCryptomapSetIfEntrynot-accessiblecurrentEach entry contains the record of the association between an interface and a cryptomap set (static) that is defined on the managed entity. Note that the crypto…
1.3.6.1.4.1.9.10.62.1.2.3.4.1.1ColumncipsCryptomapSetIfVirtualread-onlycurrentThe value of this object identifies if the interface to which the cryptomap set is attached is a tunnel (such as a GRE or PPTP tunnel).
1.3.6.1.4.1.9.10.62.1.2.3.4.1.2ColumncipsCryptomapSetIfStatusread-writecurrentThis object identifies the status of the binding of the specified cryptomap set with the specified interface. The value when queried is always 'attached'. When…
1.3.6.1.4.1.9.10.62.1.3NodecipsSysCapacityGroup
1.3.6.1.4.1.9.10.62.1.3.1ScalarcipsMaxSAsread-onlycurrentThe maximum number of IPsec Security Associations that can be established on this managed entity. If no theoretical limit exists, this returns value 0. Not aff…
1.3.6.1.4.1.9.10.62.1.3.2Scalarcips3DesCapableread-onlycurrentThe value of this object is TRUE if the managed entity has the hardware nad software features to support 3DES encryption algorithm. Not affected by any CLI ope…
1.3.6.1.4.1.9.10.62.1.4NodecipsTrapCntlGroup
1.3.6.1.4.1.9.10.62.1.4.1ScalarcipsCntlIsakmpPolicyAddedread-writecurrentThis object defines the administrative state of sending the IOS IPsec ISAKMP Policy Add trap.
1.3.6.1.4.1.9.10.62.1.4.2ScalarcipsCntlIsakmpPolicyDeletedread-writecurrentThis object defines the administrative state of sending the IOS IPsec ISAKMP Policy Delete trap.
1.3.6.1.4.1.9.10.62.1.4.3ScalarcipsCntlCryptomapAddedread-writecurrentThis object defines the administrative state of sending the IOS IPsec Cryptomap Add trap.
1.3.6.1.4.1.9.10.62.1.4.4ScalarcipsCntlCryptomapDeletedread-writecurrentThis object defines the administrative state of sending the IOS IPsec Cryptomap Delete trap.
1.3.6.1.4.1.9.10.62.1.4.5ScalarcipsCntlCryptomapSetAttachedread-writecurrentThis object defines the administrative state of sending the IOS IPsec trap that is issued when a cryptomap set is attached to an interface.
1.3.6.1.4.1.9.10.62.1.4.6ScalarcipsCntlCryptomapSetDetachedread-writecurrentThis object defines the administrative state of sending the IOS IPsec trap that is issued when a cryptomap set is detached from an interface. to which it was e…
1.3.6.1.4.1.9.10.62.1.4.7ScalarcipsCntlTooManySAsread-writecurrentThis object defines the administrative state of sending the IOS IPsec trap that is issued when the number of SAs crosses the maximum number of SAs that may be …
1.3.6.1.4.1.9.10.62.2NodeciscoIPsecMIBNotificationPrefix
1.3.6.1.4.1.9.10.62.2.0NodecipsMIBNotifications
1.3.6.1.4.1.9.10.62.2.0.1NotificationcipsIsakmpPolicyAddedcurrentThis trap is generated when a new ISAKMP policy element is defined on the managed entity. The context of the event includes the updated number of ISAKMP policy…
1.3.6.1.4.1.9.10.62.2.0.2NotificationcipsIsakmpPolicyDeletedcurrentThis trap is generated when an existing ISAKMP policy element is deleted on the managed entity. The context of the event includes the updated number of ISAKMP …
1.3.6.1.4.1.9.10.62.2.0.3NotificationcipsCryptomapAddedcurrentThis trap is generated when a new cryptomap is added to the specified cryptomap set.
1.3.6.1.4.1.9.10.62.2.0.4NotificationcipsCryptomapDeletedcurrentThis trap is generated when a cryptomap is removed from the specified cryptomap set.
1.3.6.1.4.1.9.10.62.2.0.5NotificationcipsCryptomapSetAttachedcurrentA cryptomap set must be attached to an interface of the device in order for it to be operational. This trap is generated when the cryptomap set attached to an …
1.3.6.1.4.1.9.10.62.2.0.6NotificationcipsCryptomapSetDetachedcurrentThis trap is generated when a cryptomap set is detached from an interafce to which it was bound earlier. The context of the event identifies the size of the cr…
1.3.6.1.4.1.9.10.62.2.0.7NotificationcipsTooManySAscurrentThis trap is generated when a new SA is attempted to be setup while the number of currently active SAs equals the maximum configurable. The variables are: cips…
1.3.6.1.4.1.9.10.62.3NodeciscoIPsecMIBConformance
1.3.6.1.4.1.9.10.62.3.1NodecipsMIBConformances
1.3.6.1.4.1.9.10.62.3.1.1CompliancecipsMIBComplianceread-onlycurrentThe compliance statement for entities which implement the Cisco IPsec MIB
1.3.6.1.4.1.9.10.62.3.2NodecipsMIBGroups
1.3.6.1.4.1.9.10.62.3.2.1GroupcipsMIBConfIsakmpGroupcurrentA collection of objects providing Global ISAKMP policy monitoring capability to a Cisco IPsec capable VPN router.
1.3.6.1.4.1.9.10.62.3.2.2GroupcipsMIBConfIPSecGlobalsGroupcurrentA collection of objects providing Global IPSec policy monitoring capability to a Cisco IPsec capable VPN router.
1.3.6.1.4.1.9.10.62.3.2.3GroupcipsMIBConfCapacityGroupcurrentA collection of objects providing IPsec System Capacity monitoring capability to a Cisco IPsec capable VPN router.
1.3.6.1.4.1.9.10.62.3.2.4GroupcipsMIBStaticCryptomapGroupcurrentA collection of objects instrumenting the properties of the Static (fully specified) Cryptomap Sets on an IPsec-capable IOS router.
1.3.6.1.4.1.9.10.62.3.2.5GroupcipsMIBManualCryptomapGroupcurrentA collection of objects instrumenting the properties of the Manual Cryptomap entries on a Cisco IPsec capable IOS router.
1.3.6.1.4.1.9.10.62.3.2.6GroupcipsMIBDynamicCryptomapGroupcurrentA collection of objects instrumenting the properties of the Dynamic Cryptomap group on a Cisco IPsec capable IOS router.
1.3.6.1.4.1.9.10.62.3.2.7GroupcipsMIBMandatoryNotifCntlGroupcurrentA collection of objects providing IPsec Notification capability to a IPsec-capable IOS router. It is mandatory to implement this set of objects pertaining to I…
Type Definitions
NameSyntaxStatusDescription
CIPsecLifesizeGauge32(2560..536870912)currentValue in units of kilobytes
CIPsecLifetimeGauge32(120..86400)currentValue in units of seconds
CIPsecNumCryptoMapsGauge32(0..2147483647)currentIntegral units representing count of cryptomaps
CryptomapSetBindStatusINTEGER { unknown(0), attached(1), detached(2) }currentThe status of the binding of a cryptomap set to the specified interface. The value qhen queried is always 'attached'. When set to 'detached', the cryptomap set if detached from the specified interface. Setting the value…
CryptomapTypeINTEGER { cryptomapTypeNONE(0), cryptomapTypeMANUAL(1), cryptomapTypeISAKMP(2), cryptomapTypeCET(3), cryptomapTypeDYNAMIC(4), cryptomapTypeDYNAMICDISCOVERY(5) }currentThe type of a cryptomap entry. Cryptomap is a unit of IOS IPSec policy specification.
DiffHellmanGrpINTEGER { none(1), dhGroup1(2), dhGroup2(3) }currentThe Diffie Hellman Group used in negotiations.
EncryptAlgoINTEGER { none(1), des(2), des3(3) }currentThe encryption algorithm used in negotiations.
IkeAuthMethodINTEGER { none(1), preSharedKey(2), rsaSig(3), rsaEncrypt(4), revPublicKey(5) }currentThe authentication method used in IPsec Phase-1 IKE negotiations.
IkeHashAlgoINTEGER { none(1), md5(2), sha(3) }currentThe hash algorithm used in IPsec Phase-1 IKE negotiations.
IkeIdentityTypeINTEGER { isakmpIdTypeUNKNOWN(0), isakmpIdTypeADDRESS(1), isakmpIdTypeHOSTNAME(2) }currentThe type of identity used by the local entity to identity itself to the peer with which it performs IPSec Main Mode negotiations. This type decides the content of the Identification payload in the Main Mode of IPSec tun…
IPSIpAddressOCTET STRING(SIZE(4 | 16))currentAn IP V4 or V6 Address.
TrapStatusINTEGER { enabled(1), disabled(2) }currentThe administrative status for sending a TRAP.