APSECURITY-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsAPSECURITY-MIB

Organization: Acme Packet, Inc

Last Updated: 2012-07-16

Category: Telephony and VoIP, VPN and Security, Vendor: Acme Packet

Description: Covers security policy enforcement on Acme Packet SBCs, encompassing ACLs, IPsec, and DoS prevention mechanisms.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is APSECURITY-MIB?

APSECURITY-MIB is an Acme Packet vendor MIB for the Net-Net Session Border Controller, covering security policy enforcement mechanisms including IPsec tunnels, IKE negotiation, TACACS+ AAA, and certificate management. Scalars apSecurityIPsecTunCount and apSecurityIPsecTunCapPct report the number and license-capacity percentage of active IPsec tunnels; apSecurityIkeInterfaceStatsTable, indexed by IKE-interface address type/address, exposes a wide range of IKE negotiation failure counters — CPU overload rejections, cookie/auth/EAP/TS/CP/KE/proposal/syntax/critical-payload errors, plus threshold-crossing-alert counters for auth failures, tunnel removals, and dead-peer-detection; apSecurityTacacsTable tracks per-server TACACS+ CLI-command, authentication, and authorization success/failure counts; and further tables cover IKE-interface info and certificates. This gives a security operator visibility into whether IPsec/IKE tunnels are being established successfully, whether TACACS+ AAA is functioning, and where in the negotiation handshake failures are concentrated — critical for diagnosing failed VPN peers or AAA outages on a security-facing SBC. It depends on ACMEPACKET-SMI's acmepacketMgmt root and INET-ADDRESS-MIB's InetAddress types, and is deployed on Acme Packet Net-Net SBCs; security teams can perform an APSECURITY-MIB download when instrumenting IPsec/IKE and TACACS+ monitoring on these platforms.

IPNetwork Monitor allows you to monitor SNMP objects defined in APSECURITY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Acme Packet Net-Net Session Border Controllers

Monitoring Examples

An operator polls apSecurityIkeInterfaceStatsTable for a given IKE-interface and watches apSecurityIkeInterfaceAuthErrors and apSecurityIkeInterfaceProposalErrors rise while apSecurityIPsecTunCount stays flat; this pattern would indicate a remote IPsec peer is failing IKE negotiation rather than tunnels simply not being attempted.

What Can Be Monitored

  • active IPsec tunnel count and license capacity percentage
  • per-IKE-interface negotiation error counters (auth, proposal, cookie, EAP, syntax)
  • IKE threshold-crossing alert counters (auth failure, tunnel removal, DPD)
  • per-TACACS+-server authentication/authorization success and failure counts
  • TACACS+ CLI command accounting count
Imported Objects

From ACMEPACKET-SMI

acmepacketMgmtOBJECT-IDENTITY

From INET-ADDRESS-MIB

InetAddress
InetAddressType
InetPortNumber

From SNMPv2-CONF

NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
TruthValue
OIDs

RFC description

Acme Packet SBC security policy enforcement including ACLs, IPsec, and DoS prevention.

Start monitoring Acme Packet (Oracle) Net-Net Session Border Controllers with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download APSECURITY-MIB