MIB Viewer

FEC-IPSEC-MIB

475 objects
Vendor specific Management Information for the IPSec Subsystem
Imported Objects
BINTEC-MIB MISSINGBitValue Date HexValue ipsec
INET-ADDRESS-MIBInetAddressIPv6
SNMPv2-CONFMODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP
SNMPv2-SMICounter32 Counter64 enterprises IpAddress mib-2 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE snmpModules TimeTicks Unsigned32
SNMPv2-TCDisplayString TestAndIncr TimeStamp
OIDNameAccessStatusDescription
1.3.6.1.4.1.272.4.26.1NodeipsecGlobals
1.3.6.1.4.1.272.4.26.1.1ScalaripsecGlobPeerIndexread-onlycurrentIndex of first IPsec peer in ipsecPeerTable. If this object is set to a Value <= 0, IPSec is switched explicitly off. If the peer referenced by this object doe…
1.3.6.1.4.1.272.4.26.1.2ScalaripsecGlobDefaultAuthMethodread-onlycurrent
1.3.6.1.4.1.272.4.26.1.3ScalaripsecGlobDefaultCertificateread-onlycurrentThe index of the default certificate in the certTable used for local authentication for ike keyed rules with non pre-shared-key authentication. This may be ove…
1.3.6.1.4.1.272.4.26.1.4ScalaripsecGlobDefaultLocalIdread-onlycurrentThe default ID used for local authentication for ike keyed rules. If this is an empty or invaid id string one of the subject alternative names or the subject n…
1.3.6.1.4.1.272.4.26.1.5ScalaripsecGlobDefaultIpsecProposalread-onlycurrentIndex of default ipsec proposal used for traffic entries with empty ipsec proposal, defined for peers with empty default ipsec proposal.
1.3.6.1.4.1.272.4.26.1.6ScalaripsecGlobDefaultIkeProposalread-onlycurrentIndex of default ike proposal used for peers with empty default ike proposal.
1.3.6.1.4.1.272.4.26.1.7ScalaripsecGlobDefaultIpsecLifeTimeread-onlycurrentIndex of default lifetime for ike SA's in ipsecLifeTimeTable. This lifetime is used, when there is no valid lifetime entry specified for an IPsec peer entry.
1.3.6.1.4.1.272.4.26.1.8ScalaripsecGlobDefaultIkeLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable with the default lifetime settings used for IKE SA's. This lifetime is used whenever there is no valid…
1.3.6.1.4.1.272.4.26.1.9ScalaripsecGlobDefaultIkeGroupread-onlycurrentIndex of default IKE group used if no IKE group is defined for a peer. Possible values: 1 (768 bit MODP), 2 (1024 bit MODP), 5 (1536 bit MODP).
1.3.6.1.4.1.272.4.26.1.10ScalaripsecGlobMaxSysLogLevelread-writecurrentMaximum level for syslog messages issued by IPSec. All messages with a level higher than this value are suppressed, independently from other global syslog leve…
1.3.6.1.4.1.272.4.26.1.11ScalaripsecGlobDefaultGranularityread-onlycurrent
1.3.6.1.4.1.272.4.26.1.12ScalaripsecGlobDefaultPh1Moderead-onlycurrent
1.3.6.1.4.1.272.4.26.1.13ScalaripsecGlobDefaultPfsGroupread-onlycurrentThis object specifies the PFS group to use. PFS is done only for phase 2, i.e. the Phase 1 SAs are not deleted after phase 2 negotiation is completed. Note how…
1.3.6.1.4.1.272.4.26.1.20ScalaripsecGlobIkePortread-writecurrentThis object specifies the port the IKE key management service listens to.
1.3.6.1.4.1.272.4.26.1.21ScalaripsecGlobMaxRetriesread-writecurrentThis object specifies the maximum number of retries sent by IKE for one message.
1.3.6.1.4.1.272.4.26.1.22ScalaripsecGlobRetryTimeout0milliread-writecurrentThis object specifies the period of time in milliseconds before an IKE message is repeated for the first time if the answer is missing. After each retry, this …
1.3.6.1.4.1.272.4.26.1.23ScalaripsecGlobRetryTimeoutMaxsecread-writecurrentThis object specifies the maximum period of time in seconds before an IKE message is repeated if the answer is missing. The retry timeout is not increased beyo…
1.3.6.1.4.1.272.4.26.1.24ScalaripsecGlobMaxNegotiationTimeoutsecread-writecurrentThis object specifies the maximum number of seconds after which a negotiation is canceled if it is not finished.
1.3.6.1.4.1.272.4.26.1.25ScalaripsecGlobMaxIkeSasread-writecurrentThis object specifies the maximum number of simultaneous ISAKMP Security associations allowed. If this limit is reached, the entries are removed from the datab…
1.3.6.1.4.1.272.4.26.1.29ScalaripsecGlobIgnoreCrPayloadsread-writecurrent
1.3.6.1.4.1.272.4.26.1.30ScalaripsecGlobNoCrPayloadsread-writecurrent
1.3.6.1.4.1.272.4.26.1.31ScalaripsecGlobNoKeyHashPayloadsread-writecurrent
1.3.6.1.4.1.272.4.26.1.32ScalaripsecGlobNoCrlsread-writecurrent
1.3.6.1.4.1.272.4.26.1.33ScalaripsecGlobSendFullCertChainsread-writecurrent
1.3.6.1.4.1.272.4.26.1.34ScalaripsecGlobTrustIcmpMsgread-writecurrent
1.3.6.1.4.1.272.4.26.1.35ScalaripsecGlobSpiSizeread-writecurrentA compatibility flag that specifies the length of the SPI in bytes, which is used when an ISAKMP SA SPI (Cookie) is sent to the remote peer. This field takes e…
1.3.6.1.4.1.272.4.26.1.36ScalaripsecGlobZeroIsakmpCookiesread-writecurrent
1.3.6.1.4.1.272.4.26.1.37ScalaripsecGlobMaxKeyLengthread-writecurrentThis object specifies the maximum length of an encryption key (in bits) that is accepted from the remote end. This limit prevents denial of service attacks whe…
1.3.6.1.4.1.272.4.26.1.38ScalaripsecGlobNoInitialContactread-writecurrent
1.3.6.1.4.1.272.4.26.1.39ScalaripsecGlobIkeProfileread-writecurrentThis object specifies the default IKE (phase 1) profile to use.
1.3.6.1.4.1.272.4.26.1.40ScalaripsecGlobIpsecProfileread-writecurrentThis object specifies the default IPSec (phase 2) profile to use.
1.3.6.1.4.1.272.4.26.1.41ScalaripsecGlobEnabledread-writecurrentEnables/disables IPSec globally.
1.3.6.1.4.1.272.4.26.1.42ScalaripsecGlobBlockTimeoutread-writecurrentFor peers with nonzero block time, the value of this object is used instead of ipsecGlobMaxNegotiationTimeoutSec.
1.3.6.1.4.1.272.4.26.1.43ScalaripsecGlobDPDIdleThresholdread-writecurrentThe minimum idle time period after which a dpd request is sent.
1.3.6.1.4.1.272.4.26.1.44ScalaripsecGlobDPDMaxRetriesread-writecurrentThe number of DPD retries sent before a peer is considered dead.
1.3.6.1.4.1.272.4.26.1.45ScalaripsecGlobDPDRetryTimeoutread-writecurrentThe number of seconds between retries.
1.3.6.1.4.1.272.4.26.1.46ScalaripsecGlobIkev2Enabledread-writecurrentEnables/disables IKEv2 globally.
1.3.6.1.4.1.272.4.26.3TableipsecSaTablenot-accessiblecurrentThis table contains the list of currently active IPSec security associations.
1.3.6.1.4.1.272.4.26.3.1RowipsecSaEntrynot-accessiblecurrentThis object contains an IPSec security association.
1.3.6.1.4.1.272.4.26.3.1.1ColumnipsecSaIndexread-onlycurrentA unique index for this entry.
1.3.6.1.4.1.272.4.26.3.1.3ColumnipsecSaStateread-onlycurrentThe current state of the security association Possible values: alive(1), expired(2), negotiating(4), established(5) rekeyed.
1.3.6.1.4.1.272.4.26.3.1.5ColumnipsecSaDirread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.6ColumnipsecSaModeread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.7ColumnipsecSaSecProtoread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.17ColumnipsecSaSpiread-onlycurrentThe Security Parameters Index of this SA.
1.3.6.1.4.1.272.4.26.3.1.18ColumnipsecSaAuthAlgread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.19ColumnipsecSaEncAlgread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.20ColumnipsecSaCompAlgread-onlycurrent
1.3.6.1.4.1.272.4.26.3.1.21ColumnipsecSaAuthKeyLenread-onlycurrentThe length in bytes of the key used for authentication, if any.
1.3.6.1.4.1.272.4.26.3.1.22ColumnipsecSaEncKeyLenread-onlycurrentThe length in bytes of the key used for encryption, if any.
1.3.6.1.4.1.272.4.26.3.1.33ColumnipsecSaReplayErrorsread-onlycurrentThe number of replayed packets detected for this SA.
1.3.6.1.4.1.272.4.26.3.1.34ColumnipsecSaRecvErrorsread-onlycurrentThe number of receive errors (replayed packets not counted) detected for this SA.
1.3.6.1.4.1.272.4.26.3.1.35ColumnipsecSaDecryptErrorsread-onlycurrentThe number of decryption errors (ESP only) detected for this SA.
1.3.6.1.4.1.272.4.26.3.1.39ColumnipsecSaBundleread-onlycurrentunique id of SA-bundle within this SA is used.
1.3.6.1.4.1.272.4.26.3.1.40ColumnipsecSaBundleNestingread-onlycurrentplace of SA within SA-Bundle.
1.3.6.1.4.1.272.4.26.3.1.45ColumnipsecSaSpiSizeread-onlycurrentThe size of the SPI in bytes.
1.3.6.1.4.1.272.4.26.3.1.64ColumnipsecSaEncKeynot-accessiblecurrent
1.3.6.1.4.1.272.4.26.3.1.65ColumnipsecSaAuthKeynot-accessiblecurrent
1.3.6.1.4.1.272.4.26.3.1.66ColumnipsecSaIkeMajVersionread-onlycurrentThe IKE major version number.
1.3.6.1.4.1.272.4.26.3.1.67ColumnipsecSaIkeMinVersionread-onlycurrentThe IKE minor version number.
1.3.6.1.4.1.272.4.26.4TableikeSaTablenot-accessiblecurrentThis table contains the list of currently active IKE security associations.
1.3.6.1.4.1.272.4.26.4.1RowikeSaEntrynot-accessiblecurrentThis object contains an IKE security association.
1.3.6.1.4.1.272.4.26.4.1.1ColumnikeSaIndexread-onlycurrentA unique index for this entry.
1.3.6.1.4.1.272.4.26.4.1.3ColumnikeSaStateread-writecurrent
1.3.6.1.4.1.272.4.26.4.1.4ColumnikeSaXchTyperead-onlycurrent
1.3.6.1.4.1.272.4.26.4.1.5ColumnikeSaAuthMethodread-onlycurrent
1.3.6.1.4.1.272.4.26.4.1.7ColumnikeSaRoleread-onlycurrent
1.3.6.1.4.1.272.4.26.4.1.8ColumnikeSaLocalIdread-onlycurrentThe local ID used for authentication.
1.3.6.1.4.1.272.4.26.4.1.9ColumnikeSaRemoteIdread-onlycurrentThe remote ID used for authentication.
1.3.6.1.4.1.272.4.26.4.1.10ColumnikeSaLocalIpread-onlycurrentThe local IP address used in the IKE communication.
1.3.6.1.4.1.272.4.26.4.1.11ColumnikeSaRemoteIpread-onlycurrentThe remote IP address used in the IKE communication.
1.3.6.1.4.1.272.4.26.4.1.12ColumnikeSaCookieIread-onlycurrentThe cookie of the initiator.
1.3.6.1.4.1.272.4.26.4.1.13ColumnikeSaCookieRread-onlycurrentThe cookie of the responder.
1.3.6.1.4.1.272.4.26.4.1.15ColumnikeSaNumCertsread-onlycurrentThe number of certificates received from the remote side when negotiating this SA.
1.3.6.1.4.1.272.4.26.4.1.16ColumnikeSaNumNegotiationsread-onlycurrentThis object specifies the number of currently active negotiations for this SA.
1.3.6.1.4.1.272.4.26.4.1.17ColumnikeSaBytesread-onlycurrentNumber of bytes transmitted using this SA.
1.3.6.1.4.1.272.4.26.4.1.18ColumnikeSaMajVersionread-onlycurrentThe IKE major version number.
1.3.6.1.4.1.272.4.26.4.1.19ColumnikeSaMinVersionread-onlycurrentThe IKE minor version number.
1.3.6.1.4.1.272.4.26.4.1.20ColumnikeSaPeerIndexread-onlycurrentThe index of the peer for which this SA was created.
1.3.6.1.4.1.272.4.26.4.1.21ColumnikeSaHeartbeatsEnabledread-onlycurrent
1.3.6.1.4.1.272.4.26.4.1.22ColumnikeSaHeartbeatsSentread-onlycurrentNumber of Heartbeats sent over this SA.
1.3.6.1.4.1.272.4.26.4.1.23ColumnikeSaHeartbeatsReceivedread-onlycurrentNumber of Heartbeats received over this SA.
1.3.6.1.4.1.272.4.26.4.1.24ColumnikeSaCreatedread-onlycurrentTime the SA was created.
1.3.6.1.4.1.272.4.26.4.1.25ColumnikeSaLastUsedread-onlycurrentTime the SA was used last.
1.3.6.1.4.1.272.4.26.4.1.26ColumnikeSaEncAlgread-onlycurrentThe encryption algorithm used.
1.3.6.1.4.1.272.4.26.4.1.27ColumnikeSaHashAlgread-onlycurrentThe hash algorithm used.
1.3.6.1.4.1.272.4.26.4.1.28ColumnikeSaPrfAlgread-onlycurrentThe hash algorithm used for the pseudo random function.
1.3.6.1.4.1.272.4.26.4.1.29ColumnikeSaExpiresread-onlycurrentTime the SA will expire.
1.3.6.1.4.1.272.4.26.4.1.30ColumnikeSaLocalPortread-onlycurrentLocal port currently used for the SA.
1.3.6.1.4.1.272.4.26.4.1.31ColumnikeSaRemotePortread-onlycurrentRemote port currently used for the SA.
1.3.6.1.4.1.272.4.26.4.1.32ColumnikeSaXauthTyperead-onlycurrentThis object displayes whether XAUTH is used or not after complete establishment of the SA. If XAUTH is used then the type of the extended authentication is dis…
1.3.6.1.4.1.272.4.26.4.1.33ColumnikeSaXauthUserread-onlycurrentUser name used for Extended Authentication.
1.3.6.1.4.1.272.4.26.5TableipsecPeerTablenot-accessiblecurrentThis table contains the list of IPSec peers.
1.3.6.1.4.1.272.4.26.5.1RowipsecPeerEntrynot-accessiblecurrentThis object contains the description of an IPSec peer.
1.3.6.1.4.1.272.4.26.5.1.1ColumnipsecPeerIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.5.1.3ColumnipsecPeerDescriptionread-writecurrentAn optional description for this peer.
1.3.6.1.4.1.272.4.26.5.1.5ColumnipsecPeerPeerIdsread-writecurrentThe IDs of the peer which are accepted for authentication. Syntax: - X500 distinguished name: <obj-name=obj-value, obj-ID=obj-value, ...> - IPV4-Address: |123.…
1.3.6.1.4.1.272.4.26.5.1.8ColumnipsecPeerLocalAddressread-writecurrentThe local address used for IPSec encrypted packets.
1.3.6.1.4.1.272.4.26.5.1.11ColumnipsecPeerTrafficListread-writecurrentThis object specifies the first entry of possibly a chain of traffic entries from the ipsecTrafficTable which should be protected with IPSec using this peer.
1.3.6.1.4.1.272.4.26.5.1.14ColumnipsecPeerDynamicAddressread-writecurrentThe IP-address of the peer. This object may contain either an IP address or a domain name.
1.3.6.1.4.1.272.4.26.5.1.15ColumnipsecPeerVirtualInterfaceread-writecurrentThis object specifies if a virtual interface should be created for this peer. If set to enabled, all traffic routed towards this peer will be protected. The tr…
1.3.6.1.4.1.272.4.26.5.1.16ColumnipsecPeerStartModeread-writecurrent
1.3.6.1.4.1.272.4.26.5.1.21ColumnipsecPeerPreSharedKeyread-writecurrentThe pre-shared-key used with this peer, if pre-shared-keys are used for authentication. This field serves only as an input field and its contents are replaced …
1.3.6.1.4.1.272.4.26.5.1.45ColumnipsecPeerIsdnCBread-writecurrentSwitch for turning ISDN call back feature on and off specifically for peer. Default value is disabled.
1.3.6.1.4.1.272.4.26.5.1.47ColumnipsecPeerPriorityread-writecurrentDefines the matching priority.
1.3.6.1.4.1.272.4.26.5.1.48ColumnipsecPeerIkeProfileread-writecurrentWhen ipsecPeerIkeVersion is set to ikev1 this is an index from the ikeProfileTable containing a special phase 1 profile to use for this peer. When ipsecPeerIke…
1.3.6.1.4.1.272.4.26.5.1.49ColumnipsecPeerIpsecProfileread-writecurrentThe index from the ipsecProfileTable containing a special phase 2 profile to use for this peer.
1.3.6.1.4.1.272.4.26.5.1.50ColumnipsecPeerAdminStatusread-writecurrentPeer administrative state.
1.3.6.1.4.1.272.4.26.5.1.63ColumnipsecPeerPreSharedKeyDatanot-accessiblecurrentField used for storing the pre-shared-key permanently.
1.3.6.1.4.1.272.4.26.5.1.66ColumnipsecPeerIsdnCBModeread-writecurrentDefine callback mode. The following modes are defined: compat(1) auto(2) auto-d(3) d(4) db(5) b(6) Default value for that variable is compat(1).
1.3.6.1.4.1.272.4.26.5.1.67ColumnipsecPeerIsdnCBDChanModeread-writecurrentDefine callback D channel mode. The following modes are defined: llc(1) element only subaddr(2) element only llc-and-subaddr(3) information elements llc-subadd…
1.3.6.1.4.1.272.4.26.5.1.73ColumnipsecPeerTyperead-writecurrent
1.3.6.1.4.1.272.4.26.5.1.78ColumnipsecPeerDynAddrPoolIdread-writecurrentIdentifier of Dynamic Address Pool if IP address is assigned via IKE Configuration Method. A value of -1 means that no Pool is assigned.
1.3.6.1.4.1.272.4.26.5.1.79ColumnipsecPeerDynAddrLocalIpread-writecurrentThe local IP address used in the IKE communication when remote IP address is taken from IP address pool.
1.3.6.1.4.1.272.4.26.5.1.80ColumnipsecPeerXauthProfileread-writecurrentThe index from the xauthProfileTable containing a special XAUTH profile to use for this peer. A value of 0 means that no XAUTH profile is assigned.
1.3.6.1.4.1.272.4.26.5.1.81ColumnipsecPeerDynAddrRoleread-writecurrentDetermines if IKE Config Mode is used and which role is performed: none(1), client(2) server(3) In server role ipsecPeerDynAddrPoolId defines IP address pool t…
1.3.6.1.4.1.272.4.26.5.1.82ColumnipsecPeerIkeVersionread-writecurrentIndicates the major version of IKE protocol to use. If set to ikev1 the value of ipsecPeerIkeProfile is used as index into ikeProfileTable. If set to ikev2 the…
1.3.6.1.4.1.272.4.26.5.1.83ColumnipsecPeerLocalIdread-writecurrentThe local ID used for authentication with this profile. Syntax: - X500 distinguished name: <obj-name=obj-value, obj-ID=obj-value, ...> - IPV4-Address: |123.456…
1.3.6.1.4.1.272.4.26.5.1.84ColumnipsecPeerAuthMethodread-writecurrentThis object specifies the authentication method used by default. If the ipsecPeerAuthMethod field of an ipsecPeerEntry and the ikePropAuthMethod field of the i…
1.3.6.1.4.1.272.4.26.5.1.85ColumnipsecPeerCertread-writecurrentThe index of the certificate used for authentication in the certTable. Ignored for AuthMethod == pre_shared_key. (only for IKEv2).
1.3.6.1.4.1.272.4.26.5.1.86ColumnipsecPeerCaCertsread-writecurrentReceives a comma separated list with indices (0..32767) of special certificate authority certificates accepted for this profile. (only for IKEv2).
1.3.6.1.4.1.272.4.26.5.1.87ColumnipsecPeerDynAddrModeread-writecurrentWhen IP address assignment via IKE Config Mode is configured (ipsecPeerDynAddrRole != none) this object specifies the used mode: pull(1), will answer the reque…
1.3.6.1.4.1.272.4.26.5.1.88ColumnipsecPeerMobikeread-writecurrentThis object indicates whether the peer supports MOBIKE or not. Only when both sides of a VPN connection support MOBIKE an IP address change is possible. Possib…
1.3.6.1.4.1.272.4.26.5.1.90ColumnipsecPeerPublicIfIndexread-writecurrentThe index value which uniquely identifies the physical interface that should be used for all ipsec traffic as initiator. When multiple eqivalent routes to the …
1.3.6.1.4.1.272.4.26.5.1.91ColumnipsecPeerPublicIfIndexModeread-writecurrentThis object defines the mode used in conjunction with ipsecPeerPublicIfIndex. force(1), with lower metric is available. preferred(2) with lower metric is avail…
1.3.6.1.4.1.272.4.26.6TableikeProposalTablenot-accessiblecurrentThis table contains the list of IKE proposals. The entries may be concatenated on a logical or basis using the NextChoice field to choices of multiple proposal…
1.3.6.1.4.1.272.4.26.6.1RowikeProposalEntrynot-accessiblecurrentThis object contains an IKE proposal, i.e. the encryption algorithm and the hash algorithm used to protect traffic sent over an IKE SA.
1.3.6.1.4.1.272.4.26.6.1.1ColumnikePropIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.6.1.2ColumnikePropNextChoiceread-writecurrentThis object specifies the index of the next proposal of a choice of proposals. If this object is 0, this marks the end of a proposal chain.
1.3.6.1.4.1.272.4.26.6.1.3ColumnikePropDescriptionread-writecurrentAn optional textual description of the proposal chain beginning at this entry.
1.3.6.1.4.1.272.4.26.6.1.4ColumnikePropEncAlgread-writecurrent
1.3.6.1.4.1.272.4.26.6.1.5ColumnikePropHashAlgread-writecurrent
1.3.6.1.4.1.272.4.26.6.1.7ColumnikePropGroupread-writecurrentIndex of the IKE group used with this proposal. It may be overridden by a valid IKE group index of an IPSec peer or in ipsecGlobDefaultIkeGroup. Possible value…
1.3.6.1.4.1.272.4.26.6.1.8ColumnikePropAuthMethodread-writecurrent
1.3.6.1.4.1.272.4.26.6.1.9ColumnikePropEncKeySizeread-writecurrentThis object specifies the encryption key size used with this proposal. The limits for the individual algorithms can be seen in the ipsecAlgorithmTable. If a le…
1.3.6.1.4.1.272.4.26.6.1.10ColumnikePropEncKeySizeMinread-writecurrentThis object specifies the maximum encryption key size accepted with this proposal. The limits for the individual algorithms can be seen in the ipsecAlgorithmTa…
1.3.6.1.4.1.272.4.26.6.1.11ColumnikePropEncKeySizeMaxread-writecurrentThis object specifies the maximum encryption key size accepted with this proposal. The limits for the individual algorithms can be seen in the ipsecAlgorithmTa…
1.3.6.1.4.1.272.4.26.7TableipsecTrafficTablenot-accessiblecurrentThis table contains lists of Traffic and the actions which should be applied to it, together with the necessary parameters.
1.3.6.1.4.1.272.4.26.7.1RowipsecTrafficEntrynot-accessiblecurrentThis object contains a description of a type of IP traffic and the action which should be applied to it together with the necessary parameters.
1.3.6.1.4.1.272.4.26.7.1.1ColumnipsecTrIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.7.1.2ColumnipsecTrNextIndexread-writecurrentThis object specifies the index of the next traffic entry in hierarchy.
1.3.6.1.4.1.272.4.26.7.1.3ColumnipsecTrDescriptionread-writecurrentAn optional human readable description for this traffic entry.
1.3.6.1.4.1.272.4.26.7.1.4ColumnipsecTrLocalAddressread-writecurrentThe source IP-address of this traffic entry. It maybe either a single address, a network address (in combination with ipsecTrSrcMask), or the first address of …
1.3.6.1.4.1.272.4.26.7.1.5ColumnipsecTrLocalMaskLenread-writecurrentThe length of the network mask for a source network.
1.3.6.1.4.1.272.4.26.7.1.6ColumnipsecTrLocalRangeread-writecurrentThe last address of a source address range. If this field is nonzero, the ipsecTrLocalMaskLen field is ignored and the source is considered as a range of addre…
1.3.6.1.4.1.272.4.26.7.1.7ColumnipsecTrRemoteAddressread-writecurrentThe destination IP-address of this traffic entry. It maybe either a single address, a network address (in combination with ipsecTrDstMask), or the first addres…
1.3.6.1.4.1.272.4.26.7.1.8ColumnipsecTrRemoteMaskLenread-writecurrentThe length of the network mask for a destination network.
1.3.6.1.4.1.272.4.26.7.1.9ColumnipsecTrRemoteRangeread-writecurrentThe last address of a destination address range. If this field is nonzero, the ipsecTrRemoteMaskLen field is ignored and the source is considered as a range of…
1.3.6.1.4.1.272.4.26.7.1.10ColumnipsecTrProtoread-writecurrentThe transport protocol defined for this entry.
1.3.6.1.4.1.272.4.26.7.1.11ColumnipsecTrLocalPortread-writecurrentThe source port defined for this traffic entry.
1.3.6.1.4.1.272.4.26.7.1.12ColumnipsecTrRemotePortread-writecurrentThe destination port defined for this traffic entry.
1.3.6.1.4.1.272.4.26.7.1.13ColumnipsecTrActionread-writecurrent
1.3.6.1.4.1.272.4.26.7.1.14ColumnipsecTrProposalread-onlycurrentThis object specifies an index in the ipsecProposalTable. This may be the first proposal of possibly a choice of multiple, optionally nested proposals which is…
1.3.6.1.4.1.272.4.26.7.1.15ColumnipsecTrForceTunnelModeread-onlycurrent
1.3.6.1.4.1.272.4.26.7.1.16ColumnipsecTrLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable. This lifetime overwrites the lifetimes specified for all proposals referenced by this traffic entry. …
1.3.6.1.4.1.272.4.26.7.1.17ColumnipsecTrGranularityread-onlycurrent
1.3.6.1.4.1.272.4.26.7.1.18ColumnipsecTrKeepAliveread-onlycurrent
1.3.6.1.4.1.272.4.26.7.1.19ColumnipsecTrInterfaceread-writecurrentThis object specifies the interface for which the traffic entry should be valid (pass, drop and protect entries). If this object is set to -1, there is no inte…
1.3.6.1.4.1.272.4.26.7.1.20ColumnipsecTrDirectionread-writecurrent
1.3.6.1.4.1.272.4.26.7.1.21ColumnipsecTrLocalAddressTyperead-writecurrentThe type of the local address specification. This may be either a statically configured address or a dynamic address which is taken from some state information.
1.3.6.1.4.1.272.4.26.7.1.22ColumnipsecTrRemoteAddressTyperead-writecurrentThe type of the remote address specification. This may be either a statically configured address or a dynamic address which is taken from some state informatio…
1.3.6.1.4.1.272.4.26.7.1.23ColumnipsecTrProfileread-writecurrentThe index from the ipsecProfileTable containing a special phase 2 profile to use for this traffic entry.
1.3.6.1.4.1.272.4.26.7.1.36ColumnipsecTrCreatorread-onlycurrentThis object shows the creator of the traffic entry.
1.3.6.1.4.1.272.4.26.8TableipsecProposalTablenot-accessiblecurrentThis table contains the list of IPSec proposals known to the system. The combinations of algorithms allowed are constructed from any combinations of algorithms…
1.3.6.1.4.1.272.4.26.8.1RowipsecProposalEntrynot-accessiblecurrentThis object contains an IPSec proposal, i.e. a proposed set of security parameters applied to traffic sent over an IPSec security association.
1.3.6.1.4.1.272.4.26.8.1.1ColumnipsecPropIndexread-onlycurrentA unique index for this entry.
1.3.6.1.4.1.272.4.26.8.1.2ColumnipsecPropNextread-writecurrentThe index of the next Proposal in the actual chain.
1.3.6.1.4.1.272.4.26.8.1.4ColumnipsecPropDescriptionread-writecurrentAn optional human readable description for this proposal.
1.3.6.1.4.1.272.4.26.8.1.6ColumnipsecPropProtoread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.20ColumnipsecPropIpcompread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.40ColumnipsecPropEspAesread-writecurrentThis object specifies the use of the AES encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.41ColumnipsecPropEspTwofishread-writecurrentThis object specifies the use of the Twofish encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.42ColumnipsecPropEspBlowfishread-writecurrentThis object specifies the use of the Blowfish encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.43ColumnipsecPropEspCastread-writecurrentThis object specifies the use of the Cast encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.44ColumnipsecPropEspDes3read-writecurrentThis object specifies the use of the DES3 encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.45ColumnipsecPropEspDesread-writecurrentThis object specifies the use of the DES encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.46ColumnipsecPropEspNullread-writecurrentThis object specifies the use of the DES encryption algorithm in the proposal. Possible values: 0, 1..7 the encryption algorithms.
1.3.6.1.4.1.272.4.26.8.1.49ColumnipsecPropEspRijndaelread-writecurrentThis object specifies the use of the Rijndael encryption algorithm in the proposal. The use of this object is deprecated since rijndael has been accepted as th…
1.3.6.1.4.1.272.4.26.8.1.50ColumnipsecPropEspMd5read-writecurrentThis object specifies the use of the MD5 authentication algorithm for ESP in the proposal. Possible values: 0, 1..3 the authentication algorithms.
1.3.6.1.4.1.272.4.26.8.1.51ColumnipsecPropEspSha1read-writecurrentThis object specifies the use of the Sha1 authentication algorithm for ESP in the proposal. Possible values: 0, 1..3 the authentication algorithms.
1.3.6.1.4.1.272.4.26.8.1.52ColumnipsecPropEspNoMacread-writecurrentThis object specifies whether ESP without authentication is allowed in the proposal. Possible values: 0, 1..3 its priority among the other authentication algor…
1.3.6.1.4.1.272.4.26.8.1.60ColumnipsecPropAhMd5read-writecurrentThis object specifies the use of the MD5 authentication algorithm for AH in the proposal. Possible values: 0, 1..2 the authentication algorithms.
1.3.6.1.4.1.272.4.26.8.1.61ColumnipsecPropAhSha1read-writecurrentThis object specifies the use of the Sha1 authentication algorithm for AH in the proposal. Possible values: 0, 1..2 the authentication algorithms.
1.3.6.1.4.1.272.4.26.8.1.70ColumnipsecPropIpcompDeflateread-writecurrentThis object specifies the use of the DEFLATE compression algorithm in the proposal. Possible values: 0, 1..1 the compression algorithms.
1.3.6.1.4.1.272.4.26.8.1.80ColumnipsecPropAesKeySizeread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.81ColumnipsecPropAesKeySizeMinread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.82ColumnipsecPropAesKeySizeMaxread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.83ColumnipsecPropBlowfishKeySizeread-writecurrentThis object specifies the key size in bits for the Blowfish algorithm, if enabled. Note: the key size must be a multiple of 8 bits. If not, it will be rounded …
1.3.6.1.4.1.272.4.26.8.1.84ColumnipsecPropBlowfishKeySizeMinread-writecurrentThis object specifies the minimum accepted key size in bits for the Blowfish algorithm, if enabled.
1.3.6.1.4.1.272.4.26.8.1.85ColumnipsecPropBlowfishKeySizeMaxread-writecurrentThis object specifies the maximum accepted key size in bits for the Blowfish algorithm, if enabled.
1.3.6.1.4.1.272.4.26.8.1.86ColumnipsecPropTwofishKeySizeread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.87ColumnipsecPropTwofishKeySizeMinread-writecurrent
1.3.6.1.4.1.272.4.26.8.1.88ColumnipsecPropTwofishKeySizeMaxread-writecurrent
1.3.6.1.4.1.272.4.26.9TableipsecLifeTimeTablenot-accessiblecurrentThis table contains the list of defined lifetimes for IPsec and IKE SAs.
1.3.6.1.4.1.272.4.26.9.1RowipsecLifeTimeEntrynot-accessiblecurrentThis object contains a lifetime, i.e. the soft and hard expiry limits for IPsec and IKE SA's. The usage of this table is deprecated, use the ikePrfLifeXxx and …
1.3.6.1.4.1.272.4.26.9.1.1ColumnipsecLifeIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.9.1.2ColumnipsecLifeTyperead-onlycurrentThis object specifies the type of a lifetime entry.
1.3.6.1.4.1.272.4.26.9.1.5ColumnipsecLifeHardKbread-onlycurrentThe maximum amount of data (in KB) which may be protected by an SA before it is deleted.
1.3.6.1.4.1.272.4.26.9.1.6ColumnipsecLifeHardSecread-onlycurrentThe maximum time (in seconds) after which an SA will be refreshed,.
1.3.6.1.4.1.272.4.26.9.1.7ColumnipsecLifePolicyread-onlycurrentThis object specifies the way the lifetime information is applied. Possible values: loose(1), strict(2), notify(3) than what was proposed use these and send re…
1.3.6.1.4.1.272.4.26.9.1.8ColumnipsecLifeSoftPercentread-onlycurrentThe percentage of the hard lifetimes (traffic and time based) after which rekeying is started.
1.3.6.1.4.1.272.4.26.10NodeipsecStats
1.3.6.1.4.1.272.4.26.10.1ScalaripsecStatsCurrentIkeSasread-onlycurrentCurrent number of IKE SA's (both IKEv1 and IKEv2).
1.3.6.1.4.1.272.4.26.10.2ScalaripsecStatsCurrentIpsecSasread-onlycurrentCurrent number of IPSec SA's.
1.3.6.1.4.1.272.4.26.10.9ScalaripsecStatsTrigread-onlycurrentNumber of packets which triggered an IKE negotiation.
1.3.6.1.4.1.272.4.26.10.10ScalaripsecStatsFragPktread-onlycurrentNumber of partial packets currently being reassembled.
1.3.6.1.4.1.272.4.26.10.11ScalaripsecStatsFragBytesread-onlycurrentTotal size of the partial packets currently being reassembled.
1.3.6.1.4.1.272.4.26.10.12ScalaripsecStatsFragNonfirstread-onlycurrentNumber of non-first fragments currently queued.
1.3.6.1.4.1.272.4.26.10.13ScalaripsecStatsDecryptErrorsread-onlycurrentNumber of decryption errors.
1.3.6.1.4.1.272.4.26.10.14ScalaripsecStatsAuthErrorsread-onlycurrentNumber of authentication errors.
1.3.6.1.4.1.272.4.26.10.15ScalaripsecStatsReplayErrorsread-onlycurrentNumber of replay errors.
1.3.6.1.4.1.272.4.26.10.16ScalaripsecStatsPolicyErrorsread-onlycurrentNumber of policy errors.
1.3.6.1.4.1.272.4.26.10.17ScalaripsecStatsOtherErrorsread-onlycurrentNumber of other receive errors.
1.3.6.1.4.1.272.4.26.10.18ScalaripsecStatsSendErrorsread-onlycurrentNumber of send errors.
1.3.6.1.4.1.272.4.26.10.19ScalaripsecStatsUnknownSpiErrorsread-onlycurrentNumber of unknown SPI errors.
1.3.6.1.4.1.272.4.26.10.20ScalaripsecStatsIkeNumP1read-onlycurrentThe number of IKE phase-1 negotiations performed.
1.3.6.1.4.1.272.4.26.10.21ScalaripsecStatsIkeNumFailedP1read-onlycurrentThe number of failed IKE phase-1 negotiations.
1.3.6.1.4.1.272.4.26.10.22ScalaripsecStatsIkeNumQmread-onlycurrentThe number of IKE quick-mode negotiations performed.
1.3.6.1.4.1.272.4.26.10.23ScalaripsecStatsIkeNumFailedQmread-onlycurrentThe number of failed IKE quick-mode negotiations.
1.3.6.1.4.1.272.4.26.10.24ScalaripsecStatsEspCurrentInboundread-onlycurrentThe number of active inbound ESP SAs.
1.3.6.1.4.1.272.4.26.10.25ScalaripsecStatsEspTotalInboundread-onlycurrentThe number of inbound ESP SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.26ScalaripsecStatsEspCurrentOutboundread-onlycurrentThe number of active outbound ESP SAs.
1.3.6.1.4.1.272.4.26.10.27ScalaripsecStatsEspTotalOutboundread-onlycurrentThe number of outbound ESP SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.28ScalaripsecStatsAhCurrentInboundread-onlycurrentThe number of active inbound AH SAs.
1.3.6.1.4.1.272.4.26.10.29ScalaripsecStatsAhTotalInboundread-onlycurrentThe number of inbound AH SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.30ScalaripsecStatsAhCurrentOutboundread-onlycurrentThe number of active outbound AH SAs.
1.3.6.1.4.1.272.4.26.10.31ScalaripsecStatsAhTotalOutboundread-onlycurrentThe number of outbound AH SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.32ScalaripsecStatsIpcompCurrentInboundread-onlycurrentThe number of active inbound IPComp SAs.
1.3.6.1.4.1.272.4.26.10.33ScalaripsecStatsIpcompTotalInboundread-onlycurrentThe number of inbound IPComp SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.34ScalaripsecStatsIpcompCurrentOutboundread-onlycurrentThe number of active outbound IPComp SAs.
1.3.6.1.4.1.272.4.26.10.35ScalaripsecStatsIpcompTotalOutboundread-onlycurrentThe number of outbound IPComp SAs since the system was started.
1.3.6.1.4.1.272.4.26.10.36ScalaripsecStatsPeersUpread-onlycurrentThe number of Peers currently in state 'up'.
1.3.6.1.4.1.272.4.26.10.37ScalaripsecStatsPeersBlockedread-onlycurrentThe number of Peers currently in state 'blocked'.
1.3.6.1.4.1.272.4.26.10.38ScalaripsecStatsPeersDormantread-onlycurrentThe number of Peers currently in state 'dormant'.
1.3.6.1.4.1.272.4.26.10.39ScalaripsecStatsCurrentIkeSasNegotiatingread-onlycurrentCurrent number of IKE SA's in state 'established' (both IKEv1 and IKEv2).
1.3.6.1.4.1.272.4.26.10.40ScalaripsecStatsCurrentIkeSasEstablishedread-onlycurrentCurrent number of IKE SA's in state 'established' (both IKEv1 and IKEv2).
1.3.6.1.4.1.272.4.26.10.41ScalaripsecStatsCurrentIkeSasDeletedread-onlycurrentCurrent number of IKE SA's in state 'deleted' or 'waiting_for_remove' (both IKEv1 and IKEv2).
1.3.6.1.4.1.272.4.26.10.42ScalaripsecStatsCurrentBundlesread-onlycurrentCurrent number of IPSec bundles.
1.3.6.1.4.1.272.4.26.10.43ScalaripsecStatsCurrentBundlesEstablishedread-onlycurrentCurrent number of IPSec bundles in state 'established'.
1.3.6.1.4.1.272.4.26.10.44ScalaripsecStatsCurrentBundlesNegotiatingread-onlycurrentCurrent number of IPSec bundles in state 'established'.
1.3.6.1.4.1.272.4.26.10.45ScalaripsecStatsInPktread-onlycurrentNumber of packets received.
1.3.6.1.4.1.272.4.26.10.46ScalaripsecStatsInPassread-onlycurrentNumber of inbound packets passed.
1.3.6.1.4.1.272.4.26.10.47ScalaripsecStatsInDropread-onlycurrentNumber of inbound packets dropped (error packets excluded).
1.3.6.1.4.1.272.4.26.10.48ScalaripsecStatsInDecapsread-onlycurrentNumber of inbound error packets.
1.3.6.1.4.1.272.4.26.10.49ScalaripsecStatsInErrorsread-onlycurrentNumber of inbound packets dropped.
1.3.6.1.4.1.272.4.26.10.50ScalaripsecStatsOutPktread-onlycurrentNumber of outbound packets.
1.3.6.1.4.1.272.4.26.10.51ScalaripsecStatsOutPassread-onlycurrentNumber of outbound packets passed.
1.3.6.1.4.1.272.4.26.10.52ScalaripsecStatsOutDropread-onlycurrentNumber of outbound packets dropped (error packets excluded).
1.3.6.1.4.1.272.4.26.10.53ScalaripsecStatsOutEncapsread-onlycurrentNumber of outbound packets encapsulated.
1.3.6.1.4.1.272.4.26.10.55ScalaripsecStatsInEspread-onlycurrentNumber of inbound packets decapsulated by ESP.
1.3.6.1.4.1.272.4.26.10.56ScalaripsecStatsInAhread-onlycurrentNumber of inbound packets decapsulated by AH.
1.3.6.1.4.1.272.4.26.10.57ScalaripsecStatsInIpcompread-onlycurrentNumber of inbound packets decapsulated by IPComP.
1.3.6.1.4.1.272.4.26.10.58ScalaripsecStatsOutEspread-onlycurrentNumber of outbound packets encapsulated by ESP.
1.3.6.1.4.1.272.4.26.10.59ScalaripsecStatsOutAhread-onlycurrentNumber of outbound packets encapsulated by AH.
1.3.6.1.4.1.272.4.26.10.60ScalaripsecStatsOutIpcompread-onlycurrentNumber of outbound packets encapsulated by IPComP.
1.3.6.1.4.1.272.4.26.10.63ScalaripsecStatsIkev2NumIkeSasread-onlycurrentThe number of IKE_SA negotiations performed (only for IKEv2).
1.3.6.1.4.1.272.4.26.10.64ScalaripsecStatsIkev2NumFailedIkeSasread-onlycurrentThe number of failed IKE_SA negotiations (only for IKEv2).
1.3.6.1.4.1.272.4.26.10.65ScalaripsecStatsIkev2NumCreateChildSasread-onlycurrentThe number of CREATE_CHILD_SA exchanges performed (only for IKEv2).
1.3.6.1.4.1.272.4.26.10.66ScalaripsecStatsIkev2NumFailedCreateChildSasread-onlycurrentThe number of failed CREATE_CHILD_SA exchanges (only for IKEv2).
1.3.6.1.4.1.272.4.26.10.544ScalaripsecStatsOutErrorsread-onlycurrentNumber of outbound error packets.
1.3.6.1.4.1.272.4.26.11NodeipsecGlobalsContinued
1.3.6.1.4.1.272.4.26.11.1ScalaripsecGlobContPreIpsecRulesread-writecurrentThis object specifies an index in the IPsec traffic table containing a list of traffic definitions which has to be considered prior to the traffic lists of the…
1.3.6.1.4.1.272.4.26.11.2ScalaripsecGlobContDefaultRuleread-writecurrent
1.3.6.1.4.1.272.4.26.11.4ScalaripsecGlobContUse32BitCpiread-writecurrent
1.3.6.1.4.1.272.4.26.11.5ScalaripsecGlobContNoWellKnownCpisread-writecurrent
1.3.6.1.4.1.272.4.26.11.7ScalaripsecGlobContNoPmtuDiscoveryread-onlycurrent
1.3.6.1.4.1.272.4.26.11.8ScalaripsecGlobContDefaultPmtuTtlread-writecurrentThis object specifies the time-to-live (in minutes) of a PMTU value derived from an ICMP PMTU message received for an IPSec packet. After this time, the mtu is…
1.3.6.1.4.1.272.4.26.11.9ScalaripsecGlobContPrivateInterfaceread-writecurrentThis object specifies the index of the systems' private interface. If the private interface is set (i.e. non-negative), certain address spoofing attacks are ma…
1.3.6.1.4.1.272.4.26.11.10ScalaripsecGlobContSaSyncInterfaceread-writecurrent
1.3.6.1.4.1.272.4.26.11.11ScalaripsecGlobContPostIpsecRulesread-writecurrentThis object specifies an index in the IPsec traffic table containing a list of traffic definitions which has to be considered after the traffic lists of the IP…
1.3.6.1.4.1.272.4.26.11.12ScalaripsecGlobContDefaultPfsIdentityread-writecurrent
1.3.6.1.4.1.272.4.26.11.13ScalaripsecGlobContIkeLoggingLevelread-writecurrentThis object specifies the IKE logging level. IKE log messages are output as syslog messages on level debug. Note that the global syslog table level must be set…
1.3.6.1.4.1.272.4.26.11.14ScalaripsecGlobContDialBlockTimeread-writecurrentAmount of time in minutes how long an ipsecDial entry remains in state blocked-for-outgoing after a cost producing trigger call was detected. Given value denot…
1.3.6.1.4.1.272.4.26.11.15ScalaripsecGlobContPfsIdentityDelayread-writecurrentThis object specifies the number of seconds to wait before deleting the underlying phase 1 SA after a Phase 2 SA has been established, if PFS for identity is c…
1.3.6.1.4.1.272.4.26.11.16ScalaripsecGlobContHeartbeatDefaultread-onlycurrent
1.3.6.1.4.1.272.4.26.11.17ScalaripsecGlobContHeartbeatIntervalread-writecurrentThis object specifies the time interval in seconds between heartbeats. At this rate heartbeats are sent and/or expected if configured (not used for IPv6).
1.3.6.1.4.1.272.4.26.11.18ScalaripsecGlobContHeartbeatToleranceread-writecurrentThis object specifies the maximum number of missing heartbeats allowed before an SA is discarded (not used for IPv6).
1.3.6.1.4.1.272.4.26.11.66ScalaripsecGlobContObsoleteFeatureMaskread-writecurrentSome obsolete features are represented by a bit in this mask and could be re-enabled for testing or compatibility purpose. A mask-bit of 1 enable the approprat…
1.3.6.1.4.1.272.4.26.11.69ScalaripsecGlobContP1Alwaysread-writecurrentThis object specifies whether a phase 1 rekeying is always done immediately before phase 2 rekeying. Note this is different from pfs for identity because the l…
1.3.6.1.4.1.272.4.26.11.70ScalaripsecGlobContHwAccelread-writecurrentEnables/disables usage of encryption engine.
1.3.6.1.4.1.272.4.26.11.71ScalaripsecGlobContSupportVarKeyLength4Twofishread-writecurrentEnables/disables support of variable key sizes for the Twofish algorithm. Note that the Twofish related settings within the ipsecAlgorithmTable will be synchro…
1.3.6.1.4.1.272.4.26.11.72ScalaripsecGlobContIkev2Profileread-writecurrentThis object specifies the default IKE_SA profile to use (only for IKEv2). If set to 0 no profile is configured as default.
1.3.6.1.4.1.272.4.26.11.73ScalaripsecGlobContMaxIkev2Sasread-writecurrentThis object specifies the maximum number of simultaneous IKEv2 Security associations allowed. If this limit is reached, the entries are removed from the databa…
1.3.6.1.4.1.272.4.26.11.74ScalaripsecGlobContPathFinderread-writecurrentEnables/disables the IPSec pathfinder mode, that means all the traffic (IKE, ESP and AH) is embedded within a pseudo HTTPS session between the peers (similar t…
1.3.6.1.4.1.272.4.26.11.75ScalaripsecGlobContXauthTimeoutread-writecurrentIf an extended authentication is requested, this is the time (in seconds) the device will wait for response. A useful value is important when username and pass…
1.3.6.1.4.1.272.4.26.12TableipsecDialTablenot-accessiblecurrentThis table contains dial entries specifying all parameters needed for ISDN triggered call back.
1.3.6.1.4.1.272.4.26.12.1RowipsecDialEntrynot-accessiblecurrentThis object contains a dial entry used for mapping ISDN numbers to peers for ISDN call back feature.
1.3.6.1.4.1.272.4.26.12.1.1ColumnipsecDialIfIndexread-writecurrentIndex that maps to a peer in a unique way.
1.3.6.1.4.1.272.4.26.12.1.2ColumnipsecDialDirectionread-writecurrentCalling direction for which entry applies.
1.3.6.1.4.1.272.4.26.12.1.3ColumnipsecDialNumberread-writecurrentParty number of remote peer. Used for matching calling party number on incoming calls and for called party number on outgoing calls.
1.3.6.1.4.1.272.4.26.12.1.4ColumnipsecDialSubAddressread-writecurrentSubaddress of remote peer. Used for matching calling party subaddress on incoming calls and for called party subaddress on outgoing calls.
1.3.6.1.4.1.272.4.26.12.1.5ColumnipsecDialTypeOfSubAddrread-writecurrentType of subaddress of remote peer. Used for matching calling party subaddress on incoming calls and for called party subaddress on outgoing calls.
1.3.6.1.4.1.272.4.26.12.1.6ColumnipsecDialLocalNumberread-writecurrentLocal Party number. Used for matching called party number on incoming calls and for calling party number on outgoing calls. Special value '*' is treated as wil…
1.3.6.1.4.1.272.4.26.12.1.7ColumnipsecDialLocalSubAddressread-writecurrentLocal subaddress. Used for matching called party subaddress on incoming calls and for calling party subaddress on outgoing calls. Special value '*' is treated …
1.3.6.1.4.1.272.4.26.12.1.8ColumnipsecDialTypeOfLocalSubAddrread-writecurrentType of local subaddress. Used for matching called party subaddress on incoming calls and for calling party subaddress on outgoing calls. Subaddress type is on…
1.3.6.1.4.1.272.4.26.12.1.9ColumnipsecDialAdminStatusread-writecurrentAdministrative status for dial entry. This object allows for temporarily disabling ipsecDial entries without the need to actually deletion them. This is achiev…
1.3.6.1.4.1.272.4.26.12.1.10ColumnipsecDialOperStatusread-onlycurrentOperational status for dial entry. This object indicates current status ipsecDial entry is in. Beside values defined for ipsecDialAdminStatus, status blocked-f…
1.3.6.1.4.1.272.4.26.13NodeipsecRadius
1.3.6.1.4.1.272.4.26.13.1ScalaripsecRadiusPresetStateread-onlycurrentThis object shows the status of the RADIUS preset peers load process.
1.3.6.1.4.1.272.4.26.13.2ScalaripsecRadiusPresetPeersread-onlycurrentThe number of RADIUS preset peers currently loaded.
1.3.6.1.4.1.272.4.26.13.3ScalaripsecRadiusDynamicAuthenticationread-writecurrentThis object enables/disables dynamic authentication via RADIUS. If no peer has been found matching an incoming IKE negotiation, the configured RADIUS servers a…
1.3.6.1.4.1.272.4.26.14TableikeProfileTablenot-accessiblecurrentThis table contains the list of IKE (Phase 1) profiles.
1.3.6.1.4.1.272.4.26.14.1RowikeProfileEntrynot-accessiblecurrentThis object contains an IPSec phase 1 profile.
1.3.6.1.4.1.272.4.26.14.1.1ColumnikePrfIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.14.1.2ColumnikePrfDescriptionread-writecurrentAn optional description for this profile.
1.3.6.1.4.1.272.4.26.14.1.3ColumnikePrfAuthMethodread-writecurrent
1.3.6.1.4.1.272.4.26.14.1.4ColumnikePrfModeread-writecurrent
1.3.6.1.4.1.272.4.26.14.1.5ColumnikePrfProposalread-writecurrentThe index of the first IKE proposal which may be used for IKE SA negotiation with this profile.
1.3.6.1.4.1.272.4.26.14.1.6ColumnikePrfGroupread-writecurrentThis object specifies the IKE group to use with this profile. Possible values: 1: a 768-bit MODP group 2: a 1024-bit MODP group 5: a 1536-bit MODP group
1.3.6.1.4.1.272.4.26.14.1.7ColumnikePrfCertread-writecurrentThe index of the certificate used for authentication in the certTable. Ignored for AuthMethod == pre_shared_key.
1.3.6.1.4.1.272.4.26.14.1.8ColumnikePrfLocalIdread-writecurrentThe local ID used for authentication with this profile. Syntax: - X500 distinguished name: <obj-name=obj-value, obj-ID=obj-value, ...> - IPV4-Address: |123.456…
1.3.6.1.4.1.272.4.26.14.1.9ColumnikePrfCaCertsread-writecurrentReceives a comma separated list with indices (0..32767) of special certificate authority certificates accepted for this profile.
1.3.6.1.4.1.272.4.26.14.1.10ColumnikePrfLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable with the lifetime settings to be used for IKE SA negotiation with this profile. If the lifetime pointe…
1.3.6.1.4.1.272.4.26.14.1.11ColumnikePrfPfsIdentityread-writecurrent
1.3.6.1.4.1.272.4.26.14.1.12ColumnikePrfHeartbeatsread-writecurrent
1.3.6.1.4.1.272.4.26.14.1.13ColumnikePrfBlockTimeread-writecurrentThis object specifies the time in seconds for which a peer is blocked for any IPSec operations after a phase 1 initiator negotiation failed. Special values: -1…
1.3.6.1.4.1.272.4.26.14.1.14ColumnikePrfNatTread-writecurrent
1.3.6.1.4.1.272.4.26.14.1.15ColumnikePrfMtuMaxread-writecurrentThe maximum MTU value allowed for ipsecPeerStatMtu. Zero means use value from global profile, if this is the global profile, 1418 is assumed. Nonzero values sm…
1.3.6.1.4.1.272.4.26.14.1.16ColumnikePrfLifeSecondsread-writecurrentThe maximum time (in seconds) after which an SA will be deleted.
1.3.6.1.4.1.272.4.26.14.1.17ColumnikePrfLifeKBytesread-writecurrentThe maximum amount of data (in KB) which may be protected by an SA before it is deleted.
1.3.6.1.4.1.272.4.26.14.1.18ColumnikePrfLifeRekeyPercentread-writeobsoleteWARNING: this object is obsolete and must not be used.
1.3.6.1.4.1.272.4.26.14.1.19ColumnikePrfLifePolicyread-writecurrent
1.3.6.1.4.1.272.4.26.15TableipsecProfileTablenot-accessiblecurrentThis table contains the list of IPSec (Phase 2) profiles.
1.3.6.1.4.1.272.4.26.15.1RowipsecProfileEntrynot-accessiblecurrentThis object contains an IPSec phase 1 profile.
1.3.6.1.4.1.272.4.26.15.1.1ColumnipsecPrfIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.15.1.2ColumnipsecPrfDescriptionread-writecurrentAn optional description for this profile.
1.3.6.1.4.1.272.4.26.15.1.3ColumnipsecPrfProposalread-writecurrentThe index of the IPSec proposal used for this profile.
1.3.6.1.4.1.272.4.26.15.1.4ColumnipsecPrfPfsGroupread-writecurrentThe Diffie Hellman group used for additional Perfect Forward Secrecy (PFS) DH exponentiations. Possible values: -1: do not use PFS 0: use value from default pr…
1.3.6.1.4.1.272.4.26.15.1.5ColumnipsecPrfLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable. The usage of this object is deprecated, use the ipsecPrfLifeXxx variables directly instead.
1.3.6.1.4.1.272.4.26.15.1.6ColumnipsecPrfHeartbeatsread-writecurrent
1.3.6.1.4.1.272.4.26.15.1.7ColumnipsecPrfPmtuDiscoveryread-writecurrent
1.3.6.1.4.1.272.4.26.15.1.8ColumnipsecPrfGranularityread-writecurrent
1.3.6.1.4.1.272.4.26.15.1.9ColumnipsecPrfKeepAliveread-writecurrent
1.3.6.1.4.1.272.4.26.15.1.10ColumnipsecPrfVerifyPadread-writecurrentThis object is a compatibility option for older ipsec implementations. It enables or disables an old way of ESP padding (no self describing padding). Possible …
1.3.6.1.4.1.272.4.26.15.1.11ColumnipsecPrfForceTunnelModeread-writecurrentThis object specifies the strategy when transport mode is used. By default, the system always uses transport mode, if possible. If this variable is set to true…
1.3.6.1.4.1.272.4.26.15.1.16ColumnipsecPrfLifeSecondsread-writecurrentThe maximum time (in seconds) after which an SA will be deleted.
1.3.6.1.4.1.272.4.26.15.1.17ColumnipsecPrfLifeKBytesread-writecurrentThe maximum amount of data (in KB) which may be protected by an SA before it is deleted.
1.3.6.1.4.1.272.4.26.15.1.18ColumnipsecPrfLifeRekeyPercentread-writecurrentThe percentage of the lifetimes (traffic and time based) after which rekeying is started.
1.3.6.1.4.1.272.4.26.15.1.19ColumnipsecPrfLifePolicyread-writecurrent
1.3.6.1.4.1.272.4.26.16TableipsecBundleTablenot-accessiblecurrentThis table contains the list of currently active IPSec security associations.
1.3.6.1.4.1.272.4.26.16.1RowipsecBundleEntrynot-accessiblecurrentThis object contains an IPSec security association.
1.3.6.1.4.1.272.4.26.16.1.1ColumnipsecBundleIndexread-onlycurrentA unique index for this entry.
1.3.6.1.4.1.272.4.26.16.1.5ColumnipsecBundlePeerIndexread-onlycurrentThe index of the peer for which this bundle was created.
1.3.6.1.4.1.272.4.26.16.1.6ColumnipsecBundleTrafficIndexread-onlycurrentThe index of the traffic entry for which this bundle was created.
1.3.6.1.4.1.272.4.26.16.1.7ColumnipsecBundleStateread-writecurrent
1.3.6.1.4.1.272.4.26.16.1.8ColumnipsecBundleNumSasread-onlycurrentThe number of SAs contained in this bundle.
1.3.6.1.4.1.272.4.26.16.1.9ColumnipsecBundleRoleread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.10ColumnipsecBundleRekeyedBundleread-onlycurrentThis object indicates upon rekeying, which bundle (actually its BundleIndex) is going to be replaced by that one.
1.3.6.1.4.1.272.4.26.16.1.11ColumnipsecBundleRekeyingBundleread-onlycurrentThis object indicates upon rekeying, which bundle (actually its BundleIndex) is going to replace that one.
1.3.6.1.4.1.272.4.26.16.1.12ColumnipsecBundleLastStateChangeread-onlycurrentThis object indicates the time in time ticks from system start by which the state of this bundle entry was changed last. To determine the absolute time, the cu…
1.3.6.1.4.1.272.4.26.16.1.13ColumnipsecBundleHeartbeatsEnabledread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.14ColumnipsecBundleCreatorread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.15ColumnipsecBundleTunnelLocalread-onlycurrentThe local IP address of the outer packet header. For transport mode bundles this address is the same as the ipsecBundleLocalAddress.
1.3.6.1.4.1.272.4.26.16.1.16ColumnipsecBundleTunnelRemoteread-onlycurrentThe remote IP address of the outer packet header. For transport mode bundles, this address is the same as the ipsecBundleRemoteAddress.
1.3.6.1.4.1.272.4.26.16.1.17ColumnipsecBundlePmtuDiscoveryread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.18ColumnipsecBundleKeepAliveread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.19ColumnipsecBundleVerifyPadread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.20ColumnipsecBundleLifeSecondsread-onlycurrentThe period in seconds after which this bundle will be destroyed.
1.3.6.1.4.1.272.4.26.16.1.21ColumnipsecBundleLifeKBytesread-onlycurrentThe amount of data allowed to be protected by this bundle until it is destroyed (ipsecBundleOutBytes or ipecBundleOutBytes).
1.3.6.1.4.1.272.4.26.16.1.22ColumnipsecBundleRekeySecondsread-onlycurrentThe period in seconds after which this bundle will be rekeyed.
1.3.6.1.4.1.272.4.26.16.1.23ColumnipsecBundleRekeyKBytesread-onlycurrentThe amount of data allowed to be protected by this bundle until it is rekeyed (ipsecBundleOutBytes or ipecBundleOutBytes).
1.3.6.1.4.1.272.4.26.16.1.24ColumnipsecBundleProtoread-onlycurrentThe protocol of the traffic selectors.
1.3.6.1.4.1.272.4.26.16.1.25ColumnipsecBundleLocalAddressread-onlycurrentThe local address (host or network or range start address) of the traffic selectors, source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.26ColumnipsecBundleLocalMaskLenread-onlycurrentThe local network masklen of the traffic selectors, source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.27ColumnipsecBundleLocalRangeread-onlycurrentThe local address range end address of the traffic selectors, source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.28ColumnipsecBundleLocalPortread-onlycurrentThe local port of the traffic selectors, source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.29ColumnipsecBundleRemoteAddressread-onlycurrentThe remote address (host or network or range start address) of the traffic selectors source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.30ColumnipsecBundleRemoteMaskLenread-onlycurrentThe remote network masklen of the traffic selectors source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.31ColumnipsecBundleRemoteRangeread-onlycurrentThe remote address range end address of the traffic selectors source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.32ColumnipsecBundleRemotePortread-onlycurrentThe remote port of the traffic selectors source for outbound, destination for inbound.
1.3.6.1.4.1.272.4.26.16.1.33ColumnipsecBundleInPktread-onlycurrentThe total number of inbound packets processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.34ColumnipsecBundleInHbread-onlycurrentThe number of heartbeat packets received over this bundle.
1.3.6.1.4.1.272.4.26.16.1.35ColumnipsecBundleInBytesread-onlycurrentThe number of inbound bytes (including IPSec overhead) processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.37ColumnipsecBundleInBytesNettoread-onlycurrentThe number of inbound bytes (netto: IPSec headers excluded) processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.39ColumnipsecBundleOutPktread-onlycurrentThe total number of outbound packets processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.40ColumnipsecBundleOutHbread-onlycurrentThe number of heartbeat packets sent for this bundle.
1.3.6.1.4.1.272.4.26.16.1.41ColumnipsecBundleOutBytesread-onlycurrentThe number of outbound bytes (including IPSec overhead) processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.43ColumnipsecBundleOutBytesNettoread-onlycurrentThe number of outbound bytes (netto: IPSec headers excluded) processed by this bundle.
1.3.6.1.4.1.272.4.26.16.1.45ColumnipsecBundleNatTread-onlycurrent
1.3.6.1.4.1.272.4.26.16.1.46ColumnipsecBundleNatOaLocalread-onlycurrentThe local IP address as seen by the remote side. Only valid for transport mode bundles with NatT enabled.
1.3.6.1.4.1.272.4.26.16.1.47ColumnipsecBundleNatOaRemoteread-onlycurrentThe remote IP address as seen by the remote side. Only valid for transport mode bundles with NatT enabled.
1.3.6.1.4.1.272.4.26.16.1.48ColumnipsecBundleIkeMajVersionread-onlycurrentThe IKE major version number.
1.3.6.1.4.1.272.4.26.16.1.49ColumnipsecBundleIkeMinVersionread-onlycurrentThe IKE minor version number.
1.3.6.1.4.1.272.4.26.17TableipsecAlgorithmTablenot-accessiblecurrentThis table contains the list of supported IPSec algorithms and their key sizes.
1.3.6.1.4.1.272.4.26.17.1RowipsecAlgorithmEntrynot-accessiblecurrentThis object contains an IPSec algorithm.
1.3.6.1.4.1.272.4.26.17.1.1ColumnipsecAlgIdread-onlycurrent
1.3.6.1.4.1.272.4.26.17.1.3ColumnipsecAlgMinKeySizeread-onlycurrentThe minimum key length in bits possible for this algorithm.
1.3.6.1.4.1.272.4.26.17.1.4ColumnipsecAlgDefKeySizeread-onlycurrentThe default key length in bits used for this algorithm.
1.3.6.1.4.1.272.4.26.17.1.5ColumnipsecAlgMaxKeySizeread-onlycurrentThe maximum key length in bits possible for this algorithm.
1.3.6.1.4.1.272.4.26.17.1.6ColumnipsecAlgUseMinKeySizeread-onlyobsoleteWARNING: this object is obsolete and must not be used.
1.3.6.1.4.1.272.4.26.17.1.7ColumnipsecAlgUseDefKeySizeread-onlyobsoleteWARNING: this object is obsolete and must not be used.
1.3.6.1.4.1.272.4.26.17.1.8ColumnipsecAlgUseMaxKeySizeread-onlyobsoleteWARNING: this object is obsolete and must not be used.
1.3.6.1.4.1.272.4.26.18TablexauthProfileTablenot-accessiblecurrentThis table contains the list of XAUTH profiles.
1.3.6.1.4.1.272.4.26.18.1RowxauthProfileEntrynot-accessiblecurrentThis object contains an XAUTH profile.
1.3.6.1.4.1.272.4.26.18.1.1ColumnxauthPrfIndexread-writecurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.18.1.2ColumnxauthPrfDescriptionread-writecurrentAn optional description for this profile, only used for descriptive purposes (max. 50 characters).
1.3.6.1.4.1.272.4.26.18.1.3ColumnxauthPrfRoleread-writecurrentThis object specifies which role is choosed for this profile. Possible values: server(1) i.e. this side requests extended authentication client(2) i.e. this si…
1.3.6.1.4.1.272.4.26.18.1.4ColumnxauthPrfModeread-writecurrentThis object specifies the kind how to get user data for authentication. Possible values: local(1), of xauthUserListTable that are referenced by xauthPrfUserLis…
1.3.6.1.4.1.272.4.26.18.1.5ColumnxauthPrfAAAServerGroupIdread-writecurrentThis object specifies the group ID which is used for RADIUS authentication to find the associated server entry in radiusSrvTable for XAUTH. See description of …
1.3.6.1.4.1.272.4.26.18.1.6ColumnxauthPrfUserListGroupIdread-writecurrentThis object refers to a group of one or more user entries in xauthUserListTable. This object is only valid for entries with xauthPrfUserMode 'local'.
1.3.6.1.4.1.272.4.26.18.1.7ColumnxauthPrfTimeoutread-writeobsoleteWARNING: this object is obsolete and must not be used.
1.3.6.1.4.1.272.4.26.18.1.8ColumnxauthPrfAdminStatusread-writecurrentMIB entry deletion is performed by this object: - enable : enables xauthPrfTable entry - delete : deletes xauthPrfTable entry.
1.3.6.1.4.1.272.4.26.19TablexauthUserListTablenot-accessiblecurrentThis table contains the list of XAUTH users.
1.3.6.1.4.1.272.4.26.19.1RowxauthUserListEntrynot-accessiblecurrentThis object contains an XAUTH user.
1.3.6.1.4.1.272.4.26.19.1.1ColumnxauthUserListIndexread-writecurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.19.1.2ColumnxauthUserListGroupIdread-writecurrentID for creating logical groups of XAUTH users.
1.3.6.1.4.1.272.4.26.19.1.3ColumnxauthUserListNameread-writecurrentThis object specifies the user name.
1.3.6.1.4.1.272.4.26.19.1.4ColumnxauthUserListPasswordread-writecurrentThis object specifies the user's password. This field serves only as an input field and its contents is replaced with a single asterisk immediately after it is…
1.3.6.1.4.1.272.4.26.19.1.5ColumnxauthUserListPasswordDatanot-accessiblecurrentField used for storing the user's password permanently.
1.3.6.1.4.1.272.4.26.19.1.6ColumnxauthUserListAdminStatusread-writecurrentMIB entry deletion is performed by this object: - enable : enables xauthUserListTable entry - delete : deletes xauthUserListTable entry.
1.3.6.1.4.1.272.4.26.28TableipsecPeerStatTablenot-accessiblecurrentThis table contains the list of IPSec peers status and statistic variables.
1.3.6.1.4.1.272.4.26.28.1RowipsecPeerStatEntrynot-accessiblecurrentThis object contains the status and statistic variables of an IPSec peer.
1.3.6.1.4.1.272.4.26.28.1.1ColumnipsecPeerStatIndexread-onlycurrentA unique index identifying this entry.
1.3.6.1.4.1.272.4.26.28.1.2ColumnipsecPeerStatNextIndexread-onlycurrentThe index of the next peer in hierarchy.
1.3.6.1.4.1.272.4.26.28.1.3ColumnipsecPeerStatCaCertsread-onlycurrentReceives a comma separated list with indices of optional certificate authority certificates accepted for this peer.
1.3.6.1.4.1.272.4.26.28.1.4ColumnipsecPeerStatPeerAddressread-onlycurrentThis object shows the fixed IP-address of the peer, if any.
1.3.6.1.4.1.272.4.26.28.1.5ColumnipsecPeerStatLocalIdread-onlycurrentThe local ID used for authentication. Syntax: - X500 distinguished name: <obj-name=obj-value, obj-ID=obj-value, ...> - IPV4-Address: |123.456.789.012| with or …
1.3.6.1.4.1.272.4.26.28.1.6ColumnipsecPeerStatLocalCertread-onlycurrentThe index of the certificate used for local authentication in the certTable. Only useful for automatically keyed traffic with dsa or rsa authentication.
1.3.6.1.4.1.272.4.26.28.1.7ColumnipsecPeerStatPublicInterfaceread-onlycurrentThis object specifies the index of the public interface for which the traffic list assigned to this peer should be valid. If set to -1, the traffic list is val…
1.3.6.1.4.1.272.4.26.28.1.8ColumnipsecPeerStatIkeProposalsread-onlycurrentIndex of default ike proposal used for peers with empty default ike proposal.
1.3.6.1.4.1.272.4.26.28.1.9ColumnipsecPeerStatPfsIdentityread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.10ColumnipsecPeerStatAuthMethodread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.11ColumnipsecPeerStatIkeGroupread-onlycurrentThis object specifies a special IKE group which is to be used for this peer only. It overrides the setting in the ikeProposal used. Possible values: 0: use the…
1.3.6.1.4.1.272.4.26.28.1.12ColumnipsecPeerStatPfsGroupread-onlycurrentThe Diffie Hellman group used for additional Perfect Forward Secrecy (PFS) DH exponentiations. Possible values: -1: explicitly do not use PFS (overrides ipsecG…
1.3.6.1.4.1.272.4.26.28.1.13ColumnipsecPeerStatPh1Moderead-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.14ColumnipsecPeerStatIkeLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable with the lifetime settings to be used for IKE SA negotiation with this peer. It overrides the setting …
1.3.6.1.4.1.272.4.26.28.1.15ColumnipsecPeerStatIpsecLifeTimeread-onlycurrentThis object specifies an index in the ipsecLifeTimeTable. This lifetime overwrites the lifetimes specified for all traffic entries and their proposals referenc…
1.3.6.1.4.1.272.4.26.28.1.16ColumnipsecPeerStatKeepAliveread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.17ColumnipsecPeerStatGranularityread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.18ColumnipsecPeerStatDontVerifyPadread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.19ColumnipsecPeerStatNoPmtuDiscoveryread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.20ColumnipsecPeerStatOperStatusread-onlycurrentPeer operational state.
1.3.6.1.4.1.272.4.26.28.1.21ColumnipsecPeerStatDefaultIpsecProposalsread-onlycurrentThe index of the default IPSec proposal used for encrypting all the traffic bound to the (optional) logical interface created for this peer.
1.3.6.1.4.1.272.4.26.28.1.22ColumnipsecPeerStatHeartbeatread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.23ColumnipsecPeerStatTtlread-onlycurrentThis object shows the maximum period of time in seconds the peer will remain in the current state.
1.3.6.1.4.1.272.4.26.28.1.24ColumnipsecPeerStatCurrentLocalAddressread-onlycurrentThe currently used local IP-address for this peer.
1.3.6.1.4.1.272.4.26.28.1.25ColumnipsecPeerStatCurrentRemoteAddressread-onlycurrentThe currently known remote IP-address of this peer.
1.3.6.1.4.1.272.4.26.28.1.26ColumnipsecPeerStatNumP1read-onlycurrentThe number of current IKE SAs for this peer.
1.3.6.1.4.1.272.4.26.28.1.27ColumnipsecPeerStatNumP1Negotiatingread-onlycurrentThe number of current IKE SAs in state 'negotiating' for this peer.
1.3.6.1.4.1.272.4.26.28.1.28ColumnipsecPeerStatNumP1Establishedread-onlycurrentThe number of current IKE SAs in state 'established' for this peer.
1.3.6.1.4.1.272.4.26.28.1.29ColumnipsecPeerStatNumP1Deletedread-onlycurrentThe number of current IKE SAs in state 'waiting_for_remove' for this peer.
1.3.6.1.4.1.272.4.26.28.1.30ColumnipsecPeerStatNumBundlesread-onlycurrentThe number of current IPSec SA bundles for this peer.
1.3.6.1.4.1.272.4.26.28.1.31ColumnipsecPeerStatNumBundlesNegotiatingread-onlycurrentThe number of current IPSec SA bundles for this peer.
1.3.6.1.4.1.272.4.26.28.1.32ColumnipsecPeerStatNumBundlesEstablishedread-onlycurrentThe number of current IPSec SA bundles in state 'established' for this peer.
1.3.6.1.4.1.272.4.26.28.1.33ColumnipsecPeerStatPh1LTokenread-onlycurrentLocally generated token that must be used by triggered peer upon call back.
1.3.6.1.4.1.272.4.26.28.1.34ColumnipsecPeerStatPh1RTokenread-onlycurrentRemotely generated token which must be used during phase one of IPsec connection establishment.
1.3.6.1.4.1.272.4.26.28.1.35ColumnipsecPeerStatIsdnCBNextModeread-onlycurrentDefine callback mode that is to be tried next. The following modes are defined: unknown(1) settings d-llc(2) d-subaddr(3) d-llc-subaddr(4) SUBADDR next b(5) De…
1.3.6.1.4.1.272.4.26.28.1.36ColumnipsecPeerStatNatDetectread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.37ColumnipsecPeerStatNatTLocalPortread-onlycurrentThe local port currently usd for NAT-T IKE and ESP SAs with this Peer.
1.3.6.1.4.1.272.4.26.28.1.38ColumnipsecPeerStatNatTRemotePortread-onlycurrentThe remote port currently usd for NAT-T IKE and ESP SAs with this Peer.
1.3.6.1.4.1.272.4.26.28.1.39ColumnipsecPeerStatMturead-onlycurrentThe current MTU of this peer. This value is copied to ifMtu if ipsecPeerVirtualInterface is set to enabled.
1.3.6.1.4.1.272.4.26.28.1.40ColumnipsecPeerStatRxIdleread-onlycurrentThe time period for which no packet has been received from this peer.
1.3.6.1.4.1.272.4.26.28.1.41ColumnipsecPeerStatTxIdleread-onlycurrentThe time period for which no packet has been transmitted to this peer.
1.3.6.1.4.1.272.4.26.28.1.42ColumnipsecPeerStatDPDread-onlycurrent
1.3.6.1.4.1.272.4.26.28.1.43ColumnipsecPeerStatDPDRetriesread-onlycurrentThe nuber of DPD retries currently sent without reply.
1.3.6.1.4.1.272.4.26.28.1.44ColumnipsecPeerStatNumIkeSasread-onlycurrentThe number of current IKE SAs for this peer (only for IKEv2).
1.3.6.1.4.1.272.4.26.28.1.45ColumnipsecPeerStatNumIkeSasNegotiatingread-onlycurrentThe number of current IKE SAs in state 'negotiating' for this peer (only for IKEv2).
1.3.6.1.4.1.272.4.26.28.1.46ColumnipsecPeerStatNumIkeSasEstablishedread-onlycurrentThe number of current IKE SAs in state 'established' for this peer (only for IKEv2).
1.3.6.1.4.1.272.4.26.28.1.47ColumnipsecPeerStatNumIkeSasDeletedread-onlycurrentThe number of current IKE SAs in state 'waiting_for_remove' for this peer (only for IKEv2).
1.3.6.1.4.1.272.4.26.29TableipsecPeerTrafficTablenot-accessiblecurrentThis table contains peer related lists of traffic permitted for Phase 2 negotiation. Note that this table contains optional entries solely, in the default case…
1.3.6.1.4.1.272.4.26.29.1RowipsecPeerTrafficEntrynot-accessiblecurrentThis table contains peer related lists of traffic permitted for Phase 2 negotiation. Note that this table contains optional entries solely, in the default case…
1.3.6.1.4.1.272.4.26.29.1.1ColumnipsecPeerTrafficIfindexread-writecurrent.
1.3.6.1.4.1.272.4.26.29.1.2ColumnipsecPeerTrafficDescriptionread-writecurrentAn optional human readable description for this entry.
1.3.6.1.4.1.272.4.26.29.1.3ColumnipsecPeerTrafficLocalAddressread-writecurrentThe local IP-address of this entry. It maybe either a single address or a network address (in combination with ipsecPeerTrafficLocalMask).
1.3.6.1.4.1.272.4.26.29.1.4ColumnipsecPeerTrafficLocalMaskread-writecurrentThe length of the network mask for a local network.
1.3.6.1.4.1.272.4.26.29.1.5ColumnipsecPeerTrafficLocalPortread-writecurrentThe local port defined for this entry.
1.3.6.1.4.1.272.4.26.29.1.6ColumnipsecPeerTrafficLocalPortRangeread-writecurrentThe local port range defined for this entry.
1.3.6.1.4.1.272.4.26.29.1.7ColumnipsecPeerTrafficRemoteAddressread-writecurrentThe remote IP-address of this entry. It maybe either a single address or a network address (in combination with ipsecPeerTrafficRemoteMask).
1.3.6.1.4.1.272.4.26.29.1.8ColumnipsecPeerTrafficRemoteMaskread-writecurrentThe network mask for a remote network.
1.3.6.1.4.1.272.4.26.29.1.9ColumnipsecPeerTrafficRemotePortread-writecurrentThe remote UDP/TCP port defined for this entry.
1.3.6.1.4.1.272.4.26.29.1.10ColumnipsecPeerTrafficRemotePortRangeread-writecurrentThe remote UDP/TCP port range defined for this entry.
1.3.6.1.4.1.272.4.26.29.1.11ColumnipsecPeerTrafficProtocolread-writecurrentThe transport protocol defined for this entry.
1.3.6.1.4.1.272.4.26.29.1.12ColumnipsecPeerTrafficPolicyread-writecurrentThis object specifies whether this network policy is used for inbound, outbound or both processing. Possible values: delete(1) role-initiator(2) role-responder…
1.3.6.1.4.1.272.4.26.250IdentityipsecMIBVendor specific Management Information for the IPSec Subsystem