IPsec endpoint to group table

The IPsec endpoint table maps policies (groupings) onto an endpoint (interface). A policy group assigned to an endpoint is then used to control access to the network traffic passing through that endpoint.

Usage Guidelines

If an endpoint has been configured with a policy group and no rule within that policy group matches that packet, the default action is to drop the packet.

If no policy group has been assigned to an endpoint, then the policy group specified by spdIngressPolicyGroupName must be used on traffic inbound from the network through that endpoint, and the policy group specified by spdEgressPolicyGroupName must be used for traffic outbound to the network through that endpoint.

MIB objects

Name, OID, and Syntax Access Description
spdEndpointToGroupTable

1.3.6.1.2.1.153.1.2

Syntax: Sequence of SpdEndpointToGroupEntry

None This table maps policies (groupings) onto an endpoint (interface). A policy group assigned to an endpoint is then used to control access to the network traffic passing through that endpoint.
spdEndGroupDirection

1.3.6.1.2.1.153.1.2.1.1

Syntax: IfDirection

None This object indicates which direction of packets crossing the interface are associated with which spdEndGroupName object. Ingress packets, or packets into the device match, when this value is inbound(1). Egress packets, or packets out of the device, match when this value is outbound(2).
spdEndGroupInterface

1.3.6.1.2.1.153.1.2.1.2

Syntax: InterfaceIndex

None This object can be used to uniquely identify an endpoint to which a set of policy groups is applied.
spdEndGroupName

1.3.6.1.2.1.153.1.2.1.3

Syntax: SnmpAdminString

Read-create The policy group name to apply at this endpoint.
Note: Only the Read operation is supported.
spdEndGroupLastChanged

1.3.6.1.2.1.153.1.2.1.4

Syntax: TimeStamp

Read-only The value of sysUpTime when this row was last modified or created either through SNMP SETs or by some other external means. If this row has not been modified since the last re-initialization of the network management subsystem, this object should have a zero value.

This object value is 00:00:00.00.

spdEndGroupStorageType

1.3.6.1.2.1.153.1.2.1.5

Syntax: StorageType

Read-create The storage type for this row. Rows in this table that were created through an external process may have a storage type of readOnly or permanent.
Note: Only the Read operation is supported. This object will always be nonvolatile(3).
spdEndGroupRowStatus

1.3.6.1.2.1.153.1.2.1.6

Syntax: RowStatus

Read-create This object indicates the conceptual status of this row.
Note: Only the Read operation is supported. This object will always be Active(1).

History

Release version History
08.0.70 This MIB was introduced.