FS-VPNPOLICY-MIB
101 objects
The MIB module that describes managed objects of general use by the IPSEC Protocol.
Imported Objects
| IF-MIB | InterfaceIndexOrZero |
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType |
| SNMPv2-SMI | Counter32 enterprises Integer32 MODULE-IDENTITY OBJECT-TYPE |
| SNMPv2-TC | DisplayString RowStatus |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.10876.101.1.143 | IdentityfsVpnPolicy | The MIB module that describes managed objects of general use by the IPSEC Protocol. | ||
| 1.3.6.1.4.1.10876.101.1.143.1 | NodefsVpnObjects | |||
| 1.3.6.1.4.1.10876.101.1.143.1.1 | TablefsVpnTable | not-accessible | current | This table contains the VPN association between a source and destination. It is consulted for authentication and ciphering of inbound and outbound datagrams. D… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1 | RowfsVpnEntry | not-accessible | current | Each entry is a unique parameter to identify the mapping between a particular source and destination address. The entry specifies the authentication algorithm … |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.1 | ColumnfsVpnPolicyName | not-accessible | current | This is the index for accessing Ip Security table entries. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.2 | ColumnfsVpnPolicyType | read-write | current | An entity to identify the type of policy |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.3 | ColumnfsVpnPolicyPriority | read-write | current | An entity to identify the priority of the Policy |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.4 | ColumnfsVpnTunTermAddrType | read-write | current | The tunnel termination IP address type. This object support only ipv4(1), ipv6(2) values. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.5 | ColumnfsVpnLocalTunTermAddr | read-write | current | This address is matched with the local address in the packet during authentication of inbound and outbound datagrams. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.6 | ColumnfsVpnRemoteTunTermAddr | read-write | current | This address is matched with the destination address in the packet during authentication of inbound and outbound datagrams. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.7 | ColumnfsVpnProtectNetworkType | read-write | current | The local protected network address type. This object support only ipv4(1), ipv6(2) values. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.8 | ColumnfsVpnLocalProtectNetwork | read-write | current | This address is used in identifying the source network for a given VPN policy. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.9 | ColumnfsVpnLocalProtectNetworkPrefixLen | read-write | current | The length of the local protected network prefix. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.10 | ColumnfsVpnRemoteProtectNetwork | read-write | current | This address is used in identifying the destination network for a given VPN policy. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.11 | ColumnfsVpnRemoteProtectNetworkPrefixLen | read-write | current | The length of the remote protected network prefix. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.12 | ColumnfsVpnIkeSrcPortRange | read-write | current | This object specifies the Source port range for the Traffic Selectors for IKEv2. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.13 | ColumnfsVpnIkeDstPortRange | read-write | current | This object specifies the Destination port range for the Traffic Selectors for IKEv2. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.14 | ColumnfsVpnSecurityProtocol | read-write | current | Security protocol header used for authentication (AH) or (ESP). |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.15 | ColumnfsVpnInboundSpi | read-write | current | This is an arbitrary 32-bit value identifying the security association for this datagram. This also indicates the SPI for the inbound direction. The Security P… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.16 | ColumnfsVpnOutboundSpi | read-write | current | This is an arbitrary 32-bit value identifying the security association for this datagram. This also indicates the SPI for the outbound direction. The Security … |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.17 | ColumnfsVpnMode | read-write | current | The supporting security association mode The security association mode must be configured as tunnel for a security gateway. A Host can be configured both in tr… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.18 | ColumnfsVpnAuthAlgo | read-write | current | The authentication algorithm configured for the particular security association entry. Setting the algorithm to hmac-md5 (3), hmac-sha1(4),xcbcmac(5),hmac-sha-… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.19 | ColumnfsVpnAhKey | read-write | current | This is the key used for authentication when the algorithm configured is either hmac-md5 , hmac-sha1 ,xcbcmac,hmac-sha-256(12),hmac-sha-384(13) or hmac-sha-512… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.20 | ColumnfsVpnEncrAlgo | read-write | current | The algorithm to be used for Encapsulation Security Payload (ESP) Header. This object is to be configured only if the Security protocol to be used is ESP. This… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.21 | ColumnfsVpnEspKey | read-write | current | This is the key used for encryption/decryption when the algorithm configured is either descbc,3descbc or aes128,aes192 or aes256.For 3descbc this object is use… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.22 | ColumnfsVpnAntiReplay | read-write | current | The object is used for activating the anti replay functionality of the security protocols. This entity is used only for IPSEC-Manual |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.23 | ColumnfsVpnPolicyFlag | read-write | current | The choices that can be applied on any outbound/inbound datagrams. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.24 | ColumnfsVpnProtocol | read-write | current | The Proto index value which uniquely identifies the protocol for which this Selector Table entry exists.In case of no specific protocol any can be used whose v… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.25 | ColumnfsVpnPolicyIntfIndex | read-write | current | This is the interface for which the VPN policy is to be applied. The value zero indicates interface is not configured yet. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.26 | ColumnfsVpnIkePhase1HashAlgo | read-write | current | SHA - Specifies to use Secure Hash Algorithm (SHA) as the hash algorithm. SHA1 produces 160-bit hash values, SHA256 produces 256-bit hash values, SHA384 produc… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.27 | ColumnfsVpnIkePhase1EncryptionAlgo | read-write | current | Specifies which encryption algorithm should be used in Policy negotiation |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.28 | ColumnfsVpnIkePhase1DHGroup | read-write | current | Diffie-Hellman (DH) is a public key cryptography protocol that enables two parties to establish a shared secret over unsecured communications channels. It will… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.29 | ColumnfsVpnIkePhase1LocalIdType | read-write | current | This is Identity Type for supported Local Node. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.30 | ColumnfsVpnIkePhase1LocalIdValue | read-write | current | This is the value for the supported Local Node type of phase 1 |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.31 | ColumnfsVpnIkePhase1PeerIdType | read-write | current | This is Peer Identity Type supported for phase 1 of the IKE negotiation. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.32 | ColumnfsVpnIkePhase1PeerIdValue | read-write | current | This is the Peer Identity value for the supported peer type of phase 1. eg. for ipv4 151.100.10.10, for email abc@xyz.com |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.33 | ColumnfsVpnIkePhase1LifeTimeType | read-write | current | Specifies the IKE life time units. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.34 | ColumnfsVpnIkePhase1LifeTime | read-write | current | Enter the duration, in fsVpnIkePhase1LifeTimeType, of the IKE security association (SA), after which the IKE SA expires and is re-negotiated. if you wish to sa… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.35 | ColumnfsVpnIkePhase1Mode | read-write | current | Specifies the IKE Phase 1 mode, whether main or aggressive. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.36 | ColumnfsVpnIkePhase2AuthAlgo | read-write | current | Specifies which hash algorithm to be used |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.37 | ColumnfsVpnIkePhase2EspEncryptionAlgo | read-write | current | Specifies which encryption algorithm should be used for ESP |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.38 | ColumnfsVpnIkePhase2LifeTimeType | read-write | current | Specifies the IPSec SA life time type. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.39 | ColumnfsVpnIkePhase2LifeTime | read-write | current | Specifies the IPsec security association (SA) lifetime in fsVpnIkePhase2LifeTimeType. The SA is re-negotiated after the time limit elapses. |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.40 | ColumnfsVpnIkePhase2DHGroup | read-write | current | Perfect Forward Secrecy (PFS) generates and uses a unique session key for each encrypted exchange. The unique session key protects the exchange from subsequent… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.41 | ColumnfsVpnIkeVersion | read-write | current | This object is used for configuring the IKE version - IKev1 (1) or IKEv2 (2) protocol to be used for key negotiation |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.42 | ColumnfsVpnCertAlgoType | read-write | current | This object is used for configuring the Authentication Algorithm - RSA (1) or DSA (2) to be used for authentication This object needs to configure as RSA (1) o… |
| 1.3.6.1.4.1.10876.101.1.143.1.1.1.43 | ColumnfsVpnPolicyRowStatus | read-create | current | This object is used to create and delete rows from the fsVpnTable. |
| 1.3.6.1.4.1.10876.101.1.143.1.2 | TablefsVpnRaUsersTable | not-accessible | current | This table is used to identify the remote access users when acting as a RAVPN Server |
| 1.3.6.1.4.1.10876.101.1.143.1.2.1 | RowfsVpnRaUsersEntry | not-accessible | current | This table is used for configuration of usernames and passwords for remote access users |
| 1.3.6.1.4.1.10876.101.1.143.1.2.1.1 | ColumnfsVpnRaUserName | not-accessible | current | User Name is the index for accessing the Remote Users table |
| 1.3.6.1.4.1.10876.101.1.143.1.2.1.2 | ColumnfsVpnRaUserSecret | read-write | current | Password for the remote user |
| 1.3.6.1.4.1.10876.101.1.143.1.2.1.3 | ColumnfsVpnRaUserRowStatus | read-create | current | This object is used to create and delete rows in the fsVpnRaUsersTable. |
| 1.3.6.1.4.1.10876.101.1.143.1.3 | TablefsVpnRaAddressPoolTable | not-accessible | current | This table is used to allocated IP addresses to remote users using local address pool |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1 | RowfsVpnRaAddressPoolEntry | not-accessible | current | This table is used for configuration of local address pool for the remote users. Start and end IP address should be specified for each pool |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.1 | ColumnfsVpnRaAddressPoolName | not-accessible | current | Pool Name is the index for accessing the Remote Access Address Pool table |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.2 | ColumnfsVpnRaAddressPoolAddrType | read-write | current | IP address type of the pool for remote users This object support only ipv4(1), ipv6(2) values. |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.3 | ColumnfsVpnRaAddressPoolStart | read-write | current | Starting IP address of the pool for remote users |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.4 | ColumnfsVpnRaAddressPoolEnd | read-write | current | End IP address of the pool for remote users |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.5 | ColumnfsVpnRaAddressPoolPrefixLen | read-write | current | The prefix length of the address pool |
| 1.3.6.1.4.1.10876.101.1.143.1.3.1.6 | ColumnfsVpnRaAddressPoolRowStatus | read-create | current | This object is used to create and delete rows in the fsVpnRaAddressPoolTable. |
| 1.3.6.1.4.1.10876.101.1.143.1.4 | TablefsVpnRemoteIdTable | not-accessible | current | This table provides VPN tunnels remote users identities information. The remote identity and the preshared key (PSK) bindings are globally available to all the… |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1 | RowfsVpnRemoteIdEntry | not-accessible | current | A row in this table does not support 'notInService' and 'createAndGo'. |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1.1 | ColumnfsVpnRemoteIdType | not-accessible | current | User identity types supported by the gateway chosen to interpret the data of fsVpnRemoteIdValue object. Ip addresses should be represented with 'ipv4' type. A … |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1.2 | ColumnfsVpnRemoteIdValue | not-accessible | current | It represents the value corresponding to the type mentioned in fsVpnRemoteIdType object. The maximum permitted length of an FQDN is 255 bytes. |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1.3 | ColumnfsVpnRemoteIdKey | read-write | current | This is the pre-shared key with the gateway. The PSK will be used by the gateway to authenticate the phase-I IKE transactions with this user. |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1.4 | ColumnfsVpnRemoteIdAuthType | read-write | current | It represents the value corresponding to the Authentication method configured. |
| 1.3.6.1.4.1.10876.101.1.143.1.4.1.5 | ColumnfsVpnRemoteIdStatus | read-create | current | Used to add and delete the remote user identities. A value of 'createAndGo' is not supported because PSK is mandatory to authenticate the user. |
| 1.3.6.1.4.1.10876.101.1.143.1.5 | TablefsVpnCertInfoTable | not-accessible | current | This table provides certificates information that are used for peer authentication. The certificates are globally available to all the VPN tunnels and can be m… |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1 | RowfsVpnCertInfoEntry | not-accessible | current | 'createAndGo' is not supported by this table. |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.1 | ColumnfsVpnCertKeyString | not-accessible | current | Key identity string supported by the gateway choosen to uniquely identify the certificate information. |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.2 | ColumnfsVpnCertKeyType | read-write | current | It represents the type of algorithm used to generate the key which is used to generate the certificate. RSA - Ron Rivest, Adi Shamir and Len Adleman Algorithm,… |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.3 | ColumnfsVpnCertKeyFileName | read-write | current | This is the file in which the key used to generate the certificate is stored. |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.4 | ColumnfsVpnCertFileName | read-write | current | This is the file in which the certificate information is stored. This will be used by the gateway to authenticate the phase-I IKE transactions with this user. |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.5 | ColumnfsVpnCertEncodeType | read-write | current | It represents the encoding type by which the certificate information are encoded PEM - Privacy Enhanced Mail encoding DER - Distinguished Encoding Rules encodi… |
| 1.3.6.1.4.1.10876.101.1.143.1.5.1.6 | ColumnfsVpnCertStatus | read-create | current | 'createAndGo' is not supported by this table. |
| 1.3.6.1.4.1.10876.101.1.143.1.6 | TablefsVpnCaCertInfoTable | not-accessible | current | This table provides Certificate Authority (CA) certificates information. The certificates are globally available to authorize all the VPN certificates and can … |
| 1.3.6.1.4.1.10876.101.1.143.1.6.1 | RowfsVpnCaCertInfoEntry | not-accessible | current | 'createAndGo is not supported by this table. |
| 1.3.6.1.4.1.10876.101.1.143.1.6.1.1 | ColumnfsVpnCaCertKeyString | not-accessible | current | Key identity string supported by the gateway chosen to uniquely identify the CA certificate information. |
| 1.3.6.1.4.1.10876.101.1.143.1.6.1.2 | ColumnfsVpnCaCertFileName | read-write | current | This is the file in which the CA certificate information is stored. This will be used by the gateway to authorize the peer certificates used for security negot… |
| 1.3.6.1.4.1.10876.101.1.143.1.6.1.3 | ColumnfsVpnCaCertEncodeType | read-write | current | It represents the encoding type by which the certificate information are encoded PEM - Privacy Enhanced Mail encoding DER - Distinguished Encoding Rules encodi… |
| 1.3.6.1.4.1.10876.101.1.143.1.6.1.4 | ColumnfsVpnCaCertStatus | read-create | current | 'createAndGo' is not supported by this table. |
| 1.3.6.1.4.1.10876.101.1.143.2 | NodefsVpnScalars | |||
| 1.3.6.1.4.1.10876.101.1.143.2.1 | ScalarfsVpnGlobalStatus | read-write | current | This object enables/disables the IPSEC processing administratively. By Default it is set to disable |
| 1.3.6.1.4.1.10876.101.1.143.2.2 | ScalarfsVpnMaxTunnels | read-only | current | Number of Maximum Tunnels supported by the VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.3 | ScalarfsVpnIpPktsIn | read-only | current | Total Number of Incoming Packets through VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.4 | ScalarfsVpnIpPktsOut | read-only | current | Total Number of Outgoing Packets through VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.5 | ScalarfsVpnPktsSecured | read-only | current | Total Number of Packets Secured by VPN module. |
| 1.3.6.1.4.1.10876.101.1.143.2.6 | ScalarfsVpnPktsDropped | read-only | current | Total Number of Packets Dropped by VPN module. |
| 1.3.6.1.4.1.10876.101.1.143.2.7 | ScalarfsVpnIkeSAsActive | read-only | current | Number of Active IKE Security Associations in VPN module. |
| 1.3.6.1.4.1.10876.101.1.143.2.8 | ScalarfsVpnIkeNegotiations | read-only | current | Total number of IKE Security associations negotiated in VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.9 | ScalarfsVpnIkeRekeys | read-only | current | Total number of IKE security associations Re-Keyed. |
| 1.3.6.1.4.1.10876.101.1.143.2.10 | ScalarfsVpnIkeNegoFailed | read-only | current | Total number of failed IKE security association negotiations. |
| 1.3.6.1.4.1.10876.101.1.143.2.11 | ScalarfsVpnIPSecSAsActive | read-only | current | Number of Active IPSec Security Associations in VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.12 | ScalarfsVpnIPSecNegotiations | read-only | current | Number of Negotiated IPSec Security Associations in VPN Module. |
| 1.3.6.1.4.1.10876.101.1.143.2.13 | ScalarfsVpnIPSecNegoFailed | read-only | current | Number of failed IPSec security association negotiations. |
| 1.3.6.1.4.1.10876.101.1.143.2.14 | ScalarfsVpnTotalRekeys | read-only | current | Total Number of security associations Re-Keyed. |
| 1.3.6.1.4.1.10876.101.1.143.2.15 | ScalarfsVpnRaServer | read-write | current | This object enables/disables the RAVPN server. By Default it is set to enable(ie. Router will act as RAVPN Server) |
| 1.3.6.1.4.1.10876.101.1.143.2.16 | ScalarfsVpnDummyPktGen | read-write | current | This object is to enable/disable the dummy packet generation. Dummy Packet generation is part of Traffic Flow confidentiality and involves generation of packet… |
| 1.3.6.1.4.1.10876.101.1.143.2.17 | ScalarfsVpnDummyPktParam | read-write | current | This object is to specify the length of the Dummy packet. |
| 1.3.6.1.4.1.10876.101.1.143.2.18 | ScalarfsIkeTraceOption | read-write | current | This object is used to enable Trace Statements in Ike Module. A FOUR BYTE integer is used for enabling the level of tracing. Each BIT in the four byte integer,… |
| 1.3.6.1.4.1.10876.101.1.143.2.19 | ScalarfsIpsecTraceOption | read-write | current | This object is used to enable Trace Statements in Ipsec Module. A FOUR BYTE integer is used for enabling the level of tracing. Each BIT in the four byte intege… |