CISCO-IKE-FLOW-MIB

File: CISCO-IKE-FLOW-MIB.mib (48305 bytes)

Imported modules

SNMPv2-SMI SNMPv2-TC SNMPv2-CONF
CISCO-IPSEC-SIGNALING-MIB CISCO-IPSEC-TC CISCO-SMI

Imported symbols

MODULE-IDENTITY OBJECT-TYPE NOTIFICATION-TYPE
Counter32 Counter64 Unsigned32
TruthValue MODULE-COMPLIANCE OBJECT-GROUP
NOTIFICATION-GROUP cisgIpsSgProtocol cisgIpsSgTunIndex
cisgIpsSgTunHistIndex cisgIpsSgFailLocalAddress cisgIpsSgFailRemoteAddress
CIPsecIkeNegoMode CIPsecDiffHellmanGrp ciscoMgmt

Defined Types

CifIkeGlobalStatsEntry  
SEQUENCE    
  cifIkeGlobalInP2Exchgs Counter64
  cifIkeGlobalInP2ExchgInvalids Counter64
  cifIkeGlobalInP2ExchgRejects Counter64
  cifIkeGlobalOutP2Exchgs Counter64
  cifIkeGlobalOutP2ExchgInvalids Counter64
  cifIkeGlobalOutP2ExchgRejects Counter64
  cifIkeGlobalInXauths Counter64
  cifIkeGlobalInXauthFailures Counter64
  cifIkeGlobalOutXauthFailures Counter64
  cifIkeGlobalInNewGrpReqs Counter64
  cifIkeGlobalOutNewGrpReqs Counter64
  cifIkeGlobalInNewGrpRejectReqs Counter64
  cifIkeGlobalOutNewGrpRejectReqs Counter64

CifIkeTunnelEntry  
SEQUENCE    
  cifIkeTunNegoMode CIPsecIkeNegoMode
  cifIkeTunDHGrp CIPsecDiffHellmanGrp
  cifIkeTunSaRefreshThreshold Unsigned32
  cifIkeTunTotalRefreshes Counter32
  cifIkeTunInP2Exchgs Counter32
  cifIkeTunInP2ExchgInvalids Counter32
  cifIkeTunInP2ExchgRejects Counter32
  cifIkeTunInP2SaDelRequests Counter32
  cifIkeTunOutP2Exchgs Counter32
  cifIkeTunOutP2ExchgInvalids Counter32
  cifIkeTunOutP2ExchgRejects Counter32
  cifIkeTunInNewGrpReqs Counter32
  cifIkeTunOutNewGrpReqs Counter32
  cifIkeTunInNewGrpRejectedReqs Counter32
  cifIkeTunOutNewGrpRejectedReqs Counter32
  cifIkeTunInConfigs Counter32
  cifIkeTunOutConfigs Counter32
  cifIkeTunInConfigRejects Counter32
  cifIkeTunOutConfigRejects Counter32

CifIkeTunnelHistEntry  
SEQUENCE    
  cifIkeTunHistNegoMode CIPsecIkeNegoMode
  cifIkeTunHistDHGrp CIPsecDiffHellmanGrp
  cifIkeTunHistTotalRefreshes Counter32
  cifIkeTunHistTotalSas Counter32
  cifIkeTunHistInP2Exchgs Counter32
  cifIkeTunHistInP2ExchgInvalids Counter32
  cifIkeTunHistInP2ExchgRejects Counter32
  cifIkeTunHistOutP2Exchgs Counter32
  cifIkeTunHistOutP2ExchgInvalids Counter32
  cifIkeTunHistOutP2ExchgRejects Counter32
  cifIkeTunHistInNewGrpReqs Counter32
  cifIkeTunHistOutNewGrpReqs Counter32
  cifIkeTunHistInNewGrpRejectReqs Counter32
  cifIkeTunHistOutNewGrpRejectReqs Counter32
  cifIkeTunHistInConfigs Counter32
  cifIkeTunHistOutConfigs Counter32
  cifIkeTunHistInConfigsRejects Counter32
  cifIkeTunHistOutConfigsRejects Counter32

Defined Values

ciscoIkeFlowMIB 1.3.6.1.4.1.9.9.429
This is a MIB module for monitoring the structures and status of IPsec control flows based on Internet Key Exchange protocol. The MIB models standard aspects of the IKE protocol. Synopsis This MIB module models status, performance and failures of the IKEv1- and IKEv2-based signaling in IPsec, FC-SP(and similar) protocols. In practice, the security protocols such as IPsec, FC-SP and CTS use a signaling protocol such as IKE, KINK, or some such. A number of characteristics of these signaling protocols are generic. The generic attributes and status of signaling activity has been modeled in CISCO-IPSEC-SIGNALING-MIB. This MIB module augments CISCO-IPSEC-SIGNALING-MIB with IKE-specific MIB objects. (Signaling protocols are also referred to this document as 'Control Protocols', since they perform session control.) History of the MIB A precursor to this MIB was written by Tivoli and implemented in IBM Nways routers in 1999. That MIB instrumented both IKE(v1) and IPsec in a single module. During late 1999, Cisco adopted the MIB and together with Tivoli published the IPsec Flow Monitor MIB in IETF IPsec WG in draft-ietf-ipsec-flow-monitoring-mib-00.txt. In 2000, the MIB was Cisco-ized and implemented this draft as CISCO-IPSEC-FLOW-MONITOR-MIB in IOS and VPN3000 platforms. With the evolution of IKEv2, the MIB was modified and presented to the IPsec WG again in May 2003 in draft-ietf-ipsec-flow-monitoring-mib-02.txt. This version of the draft is a Cisco-ized version that culls out the IKE-specific aspects of the IPsec Flow Monitor MIB. Overview of MIB The MIB contains five major groups of objects which are used to manage the IKE protocol activity. These groups include the global statistics, IKE tunnel table, IKE History Group and a notification Group. The tunnel table and the history table have a sparse-table relationship with the corresponding tables in the CISCO-IPSEC-SIGNALING-MIB (details in the DESCRIPTION of the respective tables). Acronyms The following acronyms are used in this document: Flow, Tunnel: An ISAKMP SA can be regarded as representing a flow of ISAKMP/IKE traffic. Hence an ISAKMP is referred to as a 'Phase 1 Tunnel' in this document. IPsec: Secure IP Protocol ISAKMP: Internet Security Association and Key Management Protocol IKE: Internet Key Exchange Protocol MM: Main Mode - the process of setting up a Phase 1 SA to secure the exchanges required to setup Phase 2 SAs Phase 2 Tunnel: AN instance of a non-ISAKMP SA bundle in which all the SA share the same proxy identifiers (IDii,IDir) protect the same stream of application traffic. Such an SA bundle is termed a 'Phase 2 Tunnel'. Note that a Phase 2 tunnel may comprise different SA bundles and different number of SA bundles at different times (due to key refresh). QM: Quick Mode - the process of setting up Phase 2 Security Associations using a Phase 1 SA. SA: Security Association (ref: rfc2408). VPN: Virtual Private Network.
MODULE-IDENTITY    

ciscoIkeFlowMIBNotifs 1.3.6.1.4.1.9.9.429.0
OBJECT IDENTIFIER    

ciscoIkeFlowMIBObjects 1.3.6.1.4.1.9.9.429.1
OBJECT IDENTIFIER    

ciscoIkeFlowMIBConform 1.3.6.1.4.1.9.9.429.2
OBJECT IDENTIFIER    

cifIkeCurrentActivity 1.3.6.1.4.1.9.9.429.1.1
OBJECT IDENTIFIER    

cifIkeHistory 1.3.6.1.4.1.9.9.429.1.2
OBJECT IDENTIFIER    

cifIkeNotifControl 1.3.6.1.4.1.9.9.429.1.3
OBJECT IDENTIFIER    

cifIkeGlobalStatsTable 1.3.6.1.4.1.9.9.429.1.1.1
The Phase-1 IKE Global Statistics Table. There is one entry in this table for each Phase-1 IKE, protocol('cpIkev1' and 'cpIkev2') implemented by the managed entity. For all the counter objects in the table below, initially when the IKE Tunnel becomes active and appears in this table, they would contain a value of zero.
OBJECT-TYPE    
  SEQUENCE OF  
    CifIkeGlobalStatsEntry

cifIkeGlobalStatsEntry 1.3.6.1.4.1.9.9.429.1.1.1.1
Each entry contains the global statistics pertaining to the specific IKE protocol.
OBJECT-TYPE    
  CifIkeGlobalStatsEntry  

cifIkeGlobalInP2Exchgs 1.3.6.1.4.1.9.9.429.1.1.1.1.1
The total number of Phase-2 exchanges received by all currently and previously active Phase-1 Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.1.1.1.2
The total number of Phase-2 exchanges which were received and found to be invalid by all currently and previously active Phase-1 Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.1.1.1.3
The total number of Phase-2 exchanges which were received and rejected by all currently and previously active Phase-1 Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutP2Exchgs 1.3.6.1.4.1.9.9.429.1.1.1.1.4
The total number of Phase-2 exchanges which were sent by all currently and previously active IPsec Phase-1 Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.1.1.1.5
The total number of Phase-2 exchanges which were sent and found to be invalid by all currently and previously active Phase-1 Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.1.1.1.6
The total number of Phase-2 exchanges which were sent and rejected by all currently and previously active Phase-1 IKE Tunnels.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInXauths 1.3.6.1.4.1.9.9.429.1.1.1.1.7
The number of times the extended authentication requests was received by the managed entity from a peer.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInXauthFailures 1.3.6.1.4.1.9.9.429.1.1.1.1.8
The number of times the extended authentication information supplied by an IKE peer was found to be invalid by the local entity.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutXauthFailures 1.3.6.1.4.1.9.9.429.1.1.1.1.9
The number of times the extended authentication information supplied by the managed entity to an IKE peer was found to be invalid by the remote peer.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInNewGrpReqs 1.3.6.1.4.1.9.9.429.1.1.1.1.10
The total number of New Group exchanges initiated remotely.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutNewGrpReqs 1.3.6.1.4.1.9.9.429.1.1.1.1.11
The total number of New Group exchanges initiated locally.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalInNewGrpRejectReqs 1.3.6.1.4.1.9.9.429.1.1.1.1.12
The total number of New Group exchanges initiated remotely that ended in reject.
OBJECT-TYPE    
  Counter64  

cifIkeGlobalOutNewGrpRejectReqs 1.3.6.1.4.1.9.9.429.1.1.1.1.13
The total number of New Group exchanges initiated locally that ended in reject.
OBJECT-TYPE    
  Counter64  

cifIkeTunnelTable 1.3.6.1.4.1.9.9.429.1.1.3
The Phase-1 Internet Key Exchange Tunnel Table. There is one entry in this table for each active IPsec Phase-1 IKE Tunnel.
OBJECT-TYPE    
  SEQUENCE OF  
    CifIkeTunnelEntry

cifIkeTunnelEntry 1.3.6.1.4.1.9.9.429.1.1.3.1
Each entry contains the attributes associated with an active Phase-1 IKE Tunnel. The rows in this table correspond 1-to-1 with a subset of the rows in cisgIpsSgTunnelTable, specifically the subset which represent Phase-1 IKE Tunnels. Hence, the value of the index 'cisgIpsSgProtocol' in this table is always 'cpIkev1' or 'cpIkev2'. For all the counter objects in the table below, initially when the Phase-1 IKE Tunnel becomes active and appears in this table, they would contain a value of zero.
OBJECT-TYPE    
  CifIkeTunnelEntry  

cifIkeTunNegoMode 1.3.6.1.4.1.9.9.429.1.1.3.1.1
The negotiation mode of the Phase-1 IKE Tunnel.
OBJECT-TYPE    
  CIPsecIkeNegoMode  

cifIkeTunDHGrp 1.3.6.1.4.1.9.9.429.1.1.3.1.2
The Diffie Hellman Group used in Phase-1 IKE negotiations.
OBJECT-TYPE    
  CIPsecDiffHellmanGrp  

cifIkeTunSaRefreshThreshold 1.3.6.1.4.1.9.9.429.1.1.3.1.3
The security association refresh threshold in seconds. If the tunnel does not refresh its security associations, the value of this MIB object is zero.
OBJECT-TYPE    
  Unsigned32 0..2147483647  

cifIkeTunTotalRefreshes 1.3.6.1.4.1.9.9.429.1.1.3.1.4
The total number of security associations refreshes performed. If the tunnel does not refresh its security associations, the value of this MIB object is never incremented.
OBJECT-TYPE    
  Counter32  

cifIkeTunInP2Exchgs 1.3.6.1.4.1.9.9.429.1.1.3.1.5
The total number of Phase-2 exchanges received by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.1.3.1.6
The total number of Phase-2 exchanges received and found to be invalid by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.1.3.1.7
The total number of Phase-2 exchanges received and rejected by this Phase-1 Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInP2SaDelRequests 1.3.6.1.4.1.9.9.429.1.1.3.1.8
The total number of Phase-2 security association delete requests received by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutP2Exchgs 1.3.6.1.4.1.9.9.429.1.1.3.1.9
The total number of Phase-2 exchanges sent by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.1.3.1.10
The total number of Phase-2 exchanges sent and found to be invalid by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.1.3.1.11
The total number of Phase-2 exchanges sent and rejected by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInNewGrpReqs 1.3.6.1.4.1.9.9.429.1.1.3.1.12
The total number of New Group exchanges initiated remotely using this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutNewGrpReqs 1.3.6.1.4.1.9.9.429.1.1.3.1.13
The total number of New Group exchanges initiated locally using this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInNewGrpRejectedReqs 1.3.6.1.4.1.9.9.429.1.1.3.1.14
The total number of New Group exchanges initiated remotely using this IKE tunnel that ended in reject.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutNewGrpRejectedReqs 1.3.6.1.4.1.9.9.429.1.1.3.1.15
The total number of New Group exchanges initiated locally using this IKE tunnel that ended in reject.
OBJECT-TYPE    
  Counter32  

cifIkeTunInConfigs 1.3.6.1.4.1.9.9.429.1.1.3.1.16
The total number of Mode Configuration settings received (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutConfigs 1.3.6.1.4.1.9.9.429.1.1.3.1.17
The total number of Mode Configuration settings dispatched (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunInConfigRejects 1.3.6.1.4.1.9.9.429.1.1.3.1.18
The total number of Mode Configuration settings which were received (either CFG_REPLY or CFG_SET payloads) and rejected by this entity using the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunOutConfigRejects 1.3.6.1.4.1.9.9.429.1.1.3.1.19
The total number of Mode Configuration settings which were dispatched (either CFG_REPLY or CFG_SET payloads) by this entity and were rejected by the peer (client) using the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunnelHistTable 1.3.6.1.4.1.9.9.429.1.2.1
The Phase-1 Internet Key Exchange Tunnel history table. This table is conceptually a sliding window in which only the last 'N' entries are maintained, where 'N' is the value of the object 'cisgIpsSgHistTableSize' (defined in defined in CISCO-IPSEC-SIGNALING-MIB). If the value of 'cisgIpsSgHistTableSize' is 0, then this table will be empty. For all the counter objects in the table below, initially when the Tunnel entry appears in this table, they would contain a value of zero.
OBJECT-TYPE    
  SEQUENCE OF  
    CifIkeTunnelHistEntry

cifIkeTunnelHistEntry 1.3.6.1.4.1.9.9.429.1.2.1.1
Each entry contains the attributes associated with a previously active Phase-1 IKE Tunnel. This table has a sparse table relationship with the generic Phase-1 Tunnel history table 'cisgIpsSgTunnelHistTable' defined in CISCO-IPSEC-SIGNALING-MIB. However, the value of the index column in this table will always be either 'cpIkev1' or 'cpIkev2'.
OBJECT-TYPE    
  CifIkeTunnelHistEntry  

cifIkeTunHistNegoMode 1.3.6.1.4.1.9.9.429.1.2.1.1.1
The negotiation mode of the Phase-1 IKE Tunnel.
OBJECT-TYPE    
  CIPsecIkeNegoMode  

cifIkeTunHistDHGrp 1.3.6.1.4.1.9.9.429.1.2.1.1.2
The Diffie Hellman Group used in Phase-1 IKE negotiations.
OBJECT-TYPE    
  CIPsecDiffHellmanGrp  

cifIkeTunHistTotalRefreshes 1.3.6.1.4.1.9.9.429.1.2.1.1.3
The total number of security associations refreshes performed.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistTotalSas 1.3.6.1.4.1.9.9.429.1.2.1.1.4
The total number of security associations used during the life of the Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInP2Exchgs 1.3.6.1.4.1.9.9.429.1.2.1.1.5
The total number of Phase-2 exchanges received by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.2.1.1.6
The total number of Phase-2 exchanges received on this tunnel that were found to contain references to unrecognized security parameters.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.2.1.1.7
The total number of Phase-2 exchanges received on this tunnel that were validated but were rejected by the local policy.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutP2Exchgs 1.3.6.1.4.1.9.9.429.1.2.1.1.8
The total number of Phase-2 security association delete requests received by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutP2ExchgInvalids 1.3.6.1.4.1.9.9.429.1.2.1.1.9
The total number of Phase-2 exchanges sent by this Phase-1 IKE Tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutP2ExchgRejects 1.3.6.1.4.1.9.9.429.1.2.1.1.10
The total number of Phase-2 exchanges sent on this tunnel that were rejected by the peer, because it contained references to security parameters not recognized by the peer.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInNewGrpReqs 1.3.6.1.4.1.9.9.429.1.2.1.1.11
The total number of New Group exchanges initiated remotely using this IKE tunnel during its lifetime.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutNewGrpReqs 1.3.6.1.4.1.9.9.429.1.2.1.1.12
The total number of New Group exchanges initiated locally using this IKE tunnel during its lifetime.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInNewGrpRejectReqs 1.3.6.1.4.1.9.9.429.1.2.1.1.13
The total number of New Group exchanges initiated remotely using this IKE tunnel during its lifetime that ended in reject.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutNewGrpRejectReqs 1.3.6.1.4.1.9.9.429.1.2.1.1.14
The total number of New Group exchanges initiated locally using this IKE tunnel during its lifetime that ended in reject.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInConfigs 1.3.6.1.4.1.9.9.429.1.2.1.1.15
The total number of Mode Configuration settings received (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutConfigs 1.3.6.1.4.1.9.9.429.1.2.1.1.16
The total number of Mode Configuration settings dispatched (either CFG_REPLY or CFG_SET payloads) by the local entity on the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistInConfigsRejects 1.3.6.1.4.1.9.9.429.1.2.1.1.17
The total number of Mode Configuration settings which were received (either CFG_REPLY or CFG_SET payloads) and rejected by this entity using the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeTunHistOutConfigsRejects 1.3.6.1.4.1.9.9.429.1.2.1.1.18
The total number of Mode Configuration settings which were dispatched (either CFG_REPLY or CFG_SET payloads) by this entity and were rejected by the peer (client) using the ISAKMP SA represented by this IKE tunnel.
OBJECT-TYPE    
  Counter32  

cifIkeNotifCntlInNewGrpRejected 1.3.6.1.4.1.9.9.429.1.3.1
The generation of the 'ciscoIkeFlowInNewGrpRejected' notification is enabled if and only if this object has the value 'true'.
OBJECT-TYPE    
  TruthValue  

cifIkeNotifCntlOutNewGrpRejected 1.3.6.1.4.1.9.9.429.1.3.2
The generation of the 'ciscoIkeFlowOutNewGrpRejected' notification is enabled if and only if this object has the value 'true'.
OBJECT-TYPE    
  TruthValue  

ciscoIkeFlowInNewGrpRejected 1.3.6.1.4.1.9.9.429.0.1
This notification is generated when the managed entity receives and rejects an incoming new group proposal from an IKE peer identified by 'cisgIpsSgFailRemoteAddress'. 'cisgIpsSgFailLocalAddress' identifies the address of the local peer. The ISAKMP context of the exchange can be obtained from the IKE tunnel index which is contained in the index of the varbind objects of this trap.
NOTIFICATION-TYPE    

ciscoIkeFlowOutNewGrpRejected 1.3.6.1.4.1.9.9.429.0.2
This notification is generated when the managed entity issues a new group proposal to the remote peer identified by 'cisgIpsSgFailRemoteAddress' and the peer rejects the proposal. 'cisgIpsSgFailLocalAddress' identifies the address of the local peer. The ISAKMP context of the exchange can be obtained from the IKE tunnel index which is contained in the index of the varbind objects of this trap.
NOTIFICATION-TYPE    

ciscoIkeFlowMIBCompliances 1.3.6.1.4.1.9.9.429.2.1
OBJECT IDENTIFIER    

ciscoIkeFlowMIBGroups 1.3.6.1.4.1.9.9.429.2.2
OBJECT IDENTIFIER    

ciscoIkeFlowMIBCompliance 1.3.6.1.4.1.9.9.429.2.1.1
The compliance statement for SNMP entities implementing this MIB.
MODULE-COMPLIANCE    

ciscoIkeFlowActivityGroup 1.3.6.1.4.1.9.9.429.2.2.1
This group consists of objects that track the current IKE protocol activity: 1) IKE Global Objects 2) IKE Tunnel table.
OBJECT-GROUP    

cifIkeFlowNewGroupGroup 1.3.6.1.4.1.9.9.429.2.2.2
This group consists of: 1) Global metrics about new group negotiations 2) IKE Tunnel-wise new group metrics
OBJECT-GROUP    

cifIkeFlowXauthGroup 1.3.6.1.4.1.9.9.429.2.2.3
This group consists of metrics pertaining to IKE extended authentication. Devices that do not support Xauth need not implement this group.
OBJECT-GROUP    

cifIkeFlowModeConfigGroup 1.3.6.1.4.1.9.9.429.2.2.4
This group consists of metrics pertaining to IKE extended authentication. Devices that do not support Xauth need not implement this group.
OBJECT-GROUP    

cifIkeFlowHistoryGroup 1.3.6.1.4.1.9.9.429.2.2.5
This group consists of the core (mandatory) objects pertaining to maintaining history of Internet Key Exchange protocol activity.
OBJECT-GROUP    

cifIkeFlowNewGroupHistoryGroup 1.3.6.1.4.1.9.9.429.2.2.6
This group consists of archive of new group activity pertaining to expired IKE Phase-1 tunnels.
OBJECT-GROUP    

cifIkeFlowModeConfigHistoryGroup 1.3.6.1.4.1.9.9.429.2.2.7
This group consists of archive of mode config activity pertaining to expired IKE Phase-1 Tunnels.
OBJECT-GROUP    

cifIkeFlowNotifCntlGroup 1.3.6.1.4.1.9.9.429.2.2.8
This group of objects controls the sending of notifications pertaining to Phase-1 IKE operations.
OBJECT-GROUP    

cifIkeFlowNotificationGroup 1.3.6.1.4.1.9.9.429.2.2.9
This group contains the notifications pertaining to Phase-1 IKE operations.
NOTIFICATION-GROUP