CISCO-ENHANCED-IPSEC-FLOW-MIB :: ciscoEnhIpsecFlowCertExpiry

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-ENHANCED-IPSEC-FLOW-MIBciscoEnhIpsecFlowCertExpiry

ciscoEnhIpsecFlowCertExpiry

Module: CISCO-ENHANCED-IPSEC-FLOW-MIB

OID (symbolic): CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhIpsecFlowCertExpiry

OID (numeric): 1.3.6.1.4.1.9.9.432.0.6

Node type: NOTIFICATION-TYPE

Description: This notification is generated to notify that an X.509 certificate is going to expire. The notification is triggered the time threshold configured on the application for notification before the certificate is going to expire, which is when the value of ceipSecCertExpiryStatus is changed from certOK(1) to certGoingExpired(2). The user should take action to renew the certificate identified in the notification prior to the certificate expiration, which is at the validity notAfter time provided in the notification.

Examples

Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):

snmptrap -v2c -c public <manager> '' CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhIpsecFlowCertExpiry
snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.9.9.432.0.6

Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):

snmptrapd -f -Lo -c /dev/null authCommunity log public

Example snmptrapd log entry:

zoo11-linux.zoo [UDP: [192.168.30.111]:60967->[192.168.30.10]:162]:
  DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (352262183) 40 days, 18:30:21.83
  SNMPv2-MIB::snmpTrapOID.0 = OID: CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhIpsecFlowCertExpiry

Start monitoring Cisco router/firewall/VPN concentrator terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-ENHANCED-IPSEC-FLOW-MIB::ciscoEnhIpsecFlowCertExpiry OID value, configure state conditions and alerts, and monitor any Cisco router/firewall/VPN concentrator terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.432ciscoEnhancedIpsecFlowMIBCISCO-ENHANCED-IPSEC-FLOW-MIB
1.3.6.1.4.1.9.9.432.0ciscoEnhancedIpsecFlowMIBNotifsCISCO-ENHANCED-IPSEC-FLOW-MIB
1.3.6.1.4.1.9.9.432.0.6ciscoEnhIpsecFlowCertExpiryCISCO-ENHANCED-IPSEC-FLOW-MIB