CISCO-SSL-PROXY-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-SSL-PROXY-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2012-09-18

Category: Cisco Devices, VPN and Security, Web and Application Servers

Description: Manages SSL proxy and offload sessions including certificate handling and connection statistics on Cisco devices.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-SSL-PROXY-MIB?

CISCO-SSL-PROXY-MIB manages Cisco SSL/TLS proxy devices that terminate and accelerate SSL and TLS transactions on behalf of backend servers or clients, part of Cisco's security/application-acceleration MIB family. It exposes global proxy configuration such as software version and FIPS mode, supported cipher suites (RC4-MD5, RC4-SHA, DES-CBC-SHA, 3DES-CBC-SHA), a table of individual proxy server instances, and notifications for operational status changes and certificate expiration. Its monitoring value spans both software configuration and operational/fault status: administrators track cspGcNotifyProxyServOperStatus traps to detect a proxy server going down, and cspGcNotifyPSCertExpiring alerts (tied to cspGcPSCertExpireInterval) to catch SSL certificates approaching expiration before they cause an outage. It is a self-contained Cisco proprietary MIB, though it interoperates with standard SSL/TLS protocol semantics rather than another SNMP MIB. It is deployed on Cisco SSL offload/proxy appliances or modules front-ending secure web and application servers. Engineers can download the CISCO-SSL-PROXY-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-SSL-PROXY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco SSL proxy/offload appliances

Monitoring Examples

An administrator would poll cspPsTable/cspPsEntry, keyed by cspPsName, to check the operational status of each configured SSL proxy server instance, and confirm cspGcFIPSMode reflects the required compliance posture. Subscribing to cspGcNotifyPSCertExpiring, driven by the cspGcPSCertExpireInterval threshold, would give advance warning of an expiring server certificate before cspGcNotifyProxyServOperStatus reports the proxy going down due to a failed handshake.

What Can Be Monitored

  • proxy server operational status per instance
  • FIPS mode state
  • supported cipher suites
  • certificate expiration warnings
  • software/firmware version
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoPort

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

RowStatus
TimeStamp
TruthValue

How to Use in IPNetwork Monitor

Example using cspTcConnInit OID:

Select a Cisco SSL proxy/offload appliance as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cspTcConnInit into the Find box to locate it in the OID tree, then select it and click OK. The total number of TCP connections initiated by the proxy device. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline (in number of connections), since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Manages Cisco SSL/TLS proxy device for terminating and accelerating SSL transactions. Supports SSL server and client proxy modes with optional re-encryption.

Start monitoring Cisco SSL proxy/offload appliances with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-SSL-PROXY-MIB