CISCO-ENHANCED-IPSEC-FLOW-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-ENHANCED-IPSEC-FLOW-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2013-06-28

Category: Cisco Devices, VPN and Security

Description: Monitors IPSec tunnel flow statistics on Cisco security devices, tracking SA negotiations, encrypted packet counts, and flow lifetimes.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-ENHANCED-IPSEC-FLOW-MIB?

This MIB monitors IPSec-based VPN flows on Cisco security devices, tracking IKE/ISAKMP security association negotiations and the resulting encrypted traffic flows, designed to align with IETF standardization rather than expose vendor-specific IPSec extensions. It exposes global tunnel counts (active and previous tunnels) alongside detailed inbound/outbound traffic counters: octets, decompressed octets, packets, drops, replay drops, authentication successes/failures, and decrypt successes/failures. This is a performance-counter and fault-oriented MIB used to monitor the software/service status of IPSec VPN processing, confirming tunnels are established and healthy, and detecting authentication or decryption failures that indicate misconfigured or attacked IPSec sessions, rather than physical hardware sensors. Its module description explicitly notes it was designed for potential IETF standardization and deliberately excludes vendor-specific IPSec features, referencing standard IPSec/IKE/ISAKMP terminology. It is deployed on Cisco routers, firewalls, and VPN concentrators terminating IPSec site-to-site or remote-access VPN tunnels. Engineers can download the CISCO-ENHANCED-IPSEC-FLOW-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-ENHANCED-IPSEC-FLOW-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco router/firewall/VPN concentrator terminating IPSec tunnels

Monitoring Examples

An administrator would poll ceipSecGlobalActiveTunnels against ceipSecGlobalPreviousTunnels to track tunnel churn, and watch ceipSecGlobalInAuthFails and ceipSecGlobalInDecryptFails for signs of misconfigured pre-shared keys or an active attack. ceipSecGlobalInDrops and ceipSecGlobalInReplayDrops reveal packet loss or replay-attack mitigation activity, while ceipSecGlobalInOctets/ceipSecGlobalOutOctets and ceipSecGlobalInDecompOctets provide throughput and compression-ratio visibility into VPN traffic.

What Can Be Monitored

  • active/previous IPSec tunnel counts
  • inbound/outbound octet and packet counters
  • authentication failures
  • decryption failures
  • replay-attack drops
Imported Objects

From CISCO-IPSEC-TC

CIPsecAuthAlgorithm
CIPsecCompAlgorithm
CIPsecControlProtocol
CIPsecDiffHellmanGrp
CIPsecEncapMode
CIPsecEncryptAlgorithm
CIPsecEncryptionKeySize
CIPsecEndPtType
CIPsecNATTraversalMode
CIPsecPhase1TunnelIndexOrZero
CIPsecPhase2SaDirection
CIPsecPhase2TunnelIndex
CIPsecPmtu
CIPsecProtocol
CIPsecSpi
CIPsecTunnelStatus

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoIpProtocol
CiscoPort

From IF-MIB

InterfaceIndex
ifIndexOBJECT-TYPE

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
TimeInterval
TimeStamp
TruthValue

How to Use in IPNetwork Monitor

Example using ceipSecGlobalPreviousTunnels OID:

Select a Cisco router/firewall/VPN concentrator terminating IPsec tunnel as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type ceipSecGlobalPreviousTunnels into the Find box to locate it in the OID tree, then select it and click OK. The total number of previously active IPsec Phase-2 Tunnels. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline (in Tunnels), since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Monitors IPsec tunnel status, security associations, encryption algorithms, and flow statistics for VPN networks.

Start monitoring Cisco router/firewall/VPN concentrator terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-ENHANCED-IPSEC-FLOW-MIB