Counters support for IPSec

The following table lists the MIB counters supported for IPSec.

Object name

Object identifier

Access/Description

ifInOctets

1.3.6.1.2.1.2.2.1.10

Read-only

ifInUcastPkts

1.3.6.1.2.1.2.2.1.11

Read-only

ifOutOctets

1.3.6.1.2.1.2.2.1.16

Read-only

ifOutUcastPkts

1.3.6.1.2.1.2.2.1.17

Read-only

ifHCInOctets

1.3.6.1.2.1.31.1.1.1.6

Read-only

ifHCInUcastPkts

1.3.6.1.2.1.31.1.1.1.7

Read-only

ifHCOutOctets

1.3.6.1.2.1.31.1.1.1.10

Read-only

ifHCOutUcastPkts

1.3.6.1.2.1.31.1.1.1.11

Read-only

The following MIB objects or tables are updated to extend support for IPSec.

Object name

Object Identifier

Description

tunnelIfSecurity

1.3.6.1.2.1.10.131.1.1.1.1.5

Read-only. Returns ipsec(2) value for IPSec tunnels.

spdEndpointToGroupTable

1.3.6.1.2.1.153.1.2

This table maps policies (groupings) onto an endpoint (interface). A new row is added for ipsec tunnel policy to an endpoint mapping. The “spdEndGroupName” is formed by vrf_id, tunnel_id, dir, ip protocol name, spi value, authentication algorithm, and encryption algorithm. show ipsec sa and show ipsec policy commands can be used to see the corresponding entries from CLI.

spdGroupContentsTable

1.3.6.1.2.1.153.1.3

This table contains a list of rules and/or subgroups contained within a given policy group. A new row is added to this table for each rule (or subgroup or a subgroup of rules) within a policy group for ipsec tunnel. The “spdGroupContComponentName” is formed by vrf_id, tunnel_id, dir, and priority. show ipsec sa and show ipsec policy commands can be used to see the corresponding entries from CLI.

spdRuleDefinitionTable

1.3.6.1.2.1.153.1.4

This table defines a rule by associating a filter or a set of filters to an action to be executed. A new row is added to this table for each spdRuleDefName that is the administrative assigned name of the rule referred to by the spdGroupContComponentName. The “spdRuleDefDescription” is formed by vrf_id, tunnel_id, dir, and priority. show ipsec sa and show ipsec policy commands can be used to see the corresponding entries from CLI.