IPSec notifications

By default, IPSec (ESP) and IKEv2 notifications are enabled. To disable notification, issue the no snmp-server enable traps ipsec and no snmp-server enable traps ikev2 commands at the device CLI.

The following traps are generated for the IPSec objects supported only on the RUCKUS ICX 7450 devices.

Trap name and number

Varbinds

Severity

Description and trap message

brcdIKEInvalidMsgTypeNotification

brcdIp.1.1.15.1.0.8

spdIPSourceType, spdIPSourceAddress, spdIPDestinationType, spdIPDestinationAddress, brcdIPSecSPIValue, brcdIKEMessageType

Informational

The SNMP trap that is generated when an invalid IKE message Type is received.

Sample format:

RUCKUS trap: IKEv2: Invalid Message Type Received with Source <source-address> Destination <destination-address> SPI <SPI-ID> MessageType <x>.

Where <x> is the value of unsupported message type in IKEv2 packet. It is UINT8 value.

The value will not be one of the following (from RFC 5996):

  • IKE_SA_INIT - 34
  • IKE_AUTH - 35
  • CREATE_CHILD_SA - 36
  • INFORMATIONAL - 37

brcdIKEInvalidPayloadNotification

brcdIp.1.1.15.1.0.9

spdIPSourceType, spdIPSourceAddress, spdIPDestinationType, spdIPDestinationAddress, brcdIPSecSPIValue,brcdIKEPayloadType

Informational

The SNMP trap that is generated when an invalid IKE payload is received.

Sample format:

RUCKUS trap: IKEv2: Invalid Payload Type Received with Source <source-address> Destination address type <type> Destination <destination-address> SPI <SPI-ID> PayloadType <x>.

Where <x> is the value of unsupported payload type in IKEv2 packet. It is UINT8 value.

Values supported are 0,33 to 48 for payload type where "0" indicates No next payload.

brcdIPSecSessionNotification

brcdIp.1.1.15.1.0.12

brcdIPSecSessionState, spdIPSourceType, spdIPSourceAddress, spdIPDestinationType, spdIPDestinationAddress, brcdIPsecVRFValue, brcdIPSecSPIValue, spdPacketDirection

Informational

The SNMP trap that is generated when IPsec session state is changed.

brcdIKESessionNotification

brcdIp.1.1.15.1.0.13

brcdIPSecSessionState, spdIPSourceType, spdIPSourceAddress, spdIPDestinationType, spdIPDestinationAddress, brcdIPsecVRFValue, brcdIPSecSPIValue

Informational

The SNMP trap that is generated when IKEv2 session state is changed.

Note: This notification is supported only on the RUCKUS ICX 7450 device.

brcdIPSecModuleNotification

brcdIp.1.1.15.1.0.14

brcdIPSecSlotNumber, brcdIPSecUnitNumber, brcdIPSecModuleState

Informational

The SNMP trap that is generated when IPsec module state is changed.

Note: This notification is supported only on the RUCKUS ICX 7450 device.

brcdIKEMaxPeerReachedStacking Notification

brcdIp.1.1.15.1.0.15

 

Warning

The SNMP trap that is generated when maximum IKE peer limit is reached.

Note: This notification is supported only on the RUCKUS ICX 7450 device.

brcdIKERecoveredMaxPeerLimit StackingNotification

brcdIp.1.1.15.1.0.16

 

Warning

The SNMP trap that is generated when the system recovers from the maximum IKE peer limit condition.

Note: This notification is supported only on the RUCKUS ICX 7450 device.