IPsec global system policy group table

The IPsec global system policy group table indicates the global system policy group that is to be applied on ingress packets (that is, arriving at an interface from a network) when a given endpoint does not contain a policy definition in the spdEndpointToGroupTable.

Usage Guidelines

The IPsec global system policy group table values can be used as an index into the spdGroupContentsTable to retrieve a list of policies. A zero length string indicates that no system-wide policy exists and the default policy of "drop" should be executed for ingress packets until one is imposed by either this object or by the endpoint processing a given packet. This object must be persistent.

MIB objects

Name, OID, and Syntax Access Description
spdGroupContentsTable

1.3.6.1.2.1.153.1.3

Syntax: Sequence of SpdGroupContentsEntry

None This table contains a list of rules and/or subgroups contained within a given policy group.
spdGroupContName

1.3.6.1.2.1.153.1.3.1.1

Syntax: SnmpAdminString

None The administrative name of the group associated with this row. A"group" is formed by all the rows in this table that have the same value of this object.
spdGroupContPriority

1.3.6.1.2.1.153.1.3.1.2

Syntax: Integer32

None The priority (sequence number) of the subcomponent in a group that this row represents. This value indicates the order in which each row of this table must be processed from low to high. For example, a row with a priority of 0 is processed before a row with a priority of 1, a 1 before a 2, and so on.
spdGroupContFilter

1.3.6.1.2.1.153.1.3.1.3

Syntax: VariablePointer

Read-create Points to a filter that is evaluated to determine whether the spdGroupContComponentName within this row is exercised. Managers can use this object to classify groups of rules or subgroups together in order to achieve a greater degree of control and optimization over the execution order of the items within the group. If the filter evaluates to false, the rule or subgroup will be skipped and the next rule or subgroup will be evaluated instead.
Note: Only Read operation is supported.
spdGroupContComponentType

1.3.6.1.2.1.153.1.3.1.4

Syntax: INTEGER { group(1), rule(2) }

Read-create Indicates whether the spdGroupContComponentName object is the name of another group defined within the spdGroupContentsTable or is the name of a rule defined within the spdRuleDefinitionTable.
Note: Only the Read operation is supported.
spdGroupContComponentName

1.3.6.1.2.1.153.1.3.1.5

Syntax: SnmpAdminString

Read-create The name of the policy rule or subgroup contained within this row, as indicated by the spdGroupContComponentType object.
Note: Only the Read operation is supported.
spdGroupContLastChanged

1.3.6.1.2.1.153.1.3.1.6

Syntax: Timestamp

Read-only The value of sysUpTime when this row was last modified or created either through SNMP SETs or by some other external means.

This object value is 00:00:00.00.

spdGroupContStorageType

1.3.6.1.2.1.153.1.3.1.7

Syntax: StorageType

Read-create The storage type for this row. Rows in this table that were created through an external process may have a storage type of readOnly or permanent.
spdGroupContRowStatus

1.3.6.1.2.1.153.1.3.1.8

Syntax: RowStatus

Read-create This object indicates the conceptual status of this row. This object will always be Active(1).
Note: Only the Read operation is supported.

History

Release version History
08.0.70 This MIB was introduced.