CISCO-IPSEC-SIGNALING-MIB :: cisgIpsSgTunHistEncryptKeySize

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IPSEC-SIGNALING-MIBcisgIpsSgTunHistEncryptKeySize

cisgIpsSgTunHistEncryptKeySize

Module: CISCO-IPSEC-SIGNALING-MIB

OID (symbolic): CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgTunHistEncryptKeySize

OID (numeric): 1.3.6.1.4.1.9.9.438.1.3.2.1.16

Node type: OBJECT-TYPE

Type: CIPsecEncryptionKeySize

Access: read-only

Description: The size in bits of the key which was negotiated for the control tunnel to be used with the algorithm denoted by the column 'cisgIpsSgTunEncryptAlgo'. For DES and 3DES the key size is respectively 56 and 168. For AES, this will denote the negotiated key size.

What is cisgIpsSgTunHistEncryptKeySize?

This preserves the size in bits of the key negotiated for the algorithm used by a now-expired control tunnel, per its description, and the description specifically notes DES uses 56 bits and 3DES uses 168 bits, while AES's key size varies with what was actually negotiated. It's the historical strength record paired with HistEncryptAlgo, letting an admin confirm not just which algorithm but exactly how strong a variant a since-closed tunnel used. A history entry showing AES with only 128 bits when a partner's contract specified AES-256 would be concrete evidence of a compliance gap during that connection's lifetime.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.3.2.1.16
snmpwalk -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgTunHistEncryptKeySize

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.3.2.1.16.1
snmpget -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgTunHistEncryptKeySize.1

Start monitoring Cisco VPN gateway equipment with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgTunHistEncryptKeySize OID value, configure state conditions and alerts, and monitor any Cisco VPN gateway equipment from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.438ciscoIPsecSignalingMIBCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1ciscoIPsecSigMIBObjectsCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.3cisgIpsSgHistoryCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.3.2cisgIpsSgTunnelHistTableCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.3.2.1cisgIpsSgTunnelHistEntryCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.3.2.1.16cisgIpsSgTunHistEncryptKeySizeCISCO-IPSEC-SIGNALING-MIB