All MIBs › COSINE-ORION-MIB › csOrionDynamicCryptoMapPfs
csOrionDynamicCryptoMapPfs
Module: COSINE-ORION-MIB
OID (symbolic): COSINE-ORION-MIB::csOrionDynamicCryptoMapPfs
OID (numeric): 1.3.6.1.4.1.3085.3.1.6.5.2.1.13
Node type: OBJECT-TYPE
Type: INTEGER
Access: read-create
Description: This object is used to request Perfect Forward Secrecy for this Dynamic Crypto Map.
What is csOrionDynamicCryptoMapPfs?
This INTEGER, group1, group2, or none, is described as requesting Perfect Forward Secrecy for this Dynamic Crypto Map, naming which Diffie-Hellman group to use if PFS is requested. An admin enables a PFS group so that compromise of one session key cannot be used to derive past or future session keys, at the cost of extra negotiation overhead per rekey. For example, an admin protecting highly sensitive traffic might set this to 'group2' rather than 'none', accepting the added CPU cost of PFS for stronger key independence.
OID Breakdown
Upper-level ancestors (9 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.3085 | csRoot | COSINE-GLOBAL-REG |
| 1.3.6.1.4.1.3085.3 | csProduct | COSINE-GLOBAL-REG |
| 1.3.6.1.4.1.3085.3.1 | csOrionMIB | COSINE-GLOBAL-REG |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.3085.3.1.6 | csOrionServiceInfo | COSINE-ORION-MIB |
| 1.3.6.1.4.1.3085.3.1.6.5 | csOrionEncryptInfo | COSINE-ORION-MIB |
| 1.3.6.1.4.1.3085.3.1.6.5.2 | csOrionDynamicCryptoMapTable | COSINE-ORION-MIB |
| 1.3.6.1.4.1.3085.3.1.6.5.2.1 | csOrionDynamicCryptoMapEntry | COSINE-ORION-MIB |
| 1.3.6.1.4.1.3085.3.1.6.5.2.1.13 | csOrionDynamicCryptoMapPfs | COSINE-ORION-MIB |