HH3C-NDEC-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsHH3C-NDEC-MIB

Organization: Hangzhou H3C Tech. Co., Ltd.

Last Updated: 2004-09-15

Category: Technology: SDN/OpenFlow, Vendor: H3C/HH3C

Description: Manages Network Device Edge Controller (NDEC) functions for SD-WAN and edge device orchestration on H3C platforms.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is HH3C-NDEC-MIB?

HH3C-NDEC-MIB is an H3C MIB for managing Network Device Edge Controller (NDEC) functionality, used in SD-WAN and edge-device orchestration, with a notable focus on IPsec Security Association (SA) parameters between edge devices. It exposes SA list tables containing peer IP address, protocol, SPI, encryption/authentication algorithms, and SA lifetime (in kilobytes and seconds), along with negotiation-mode settings. Its monitoring role centers on confirming secure tunnel/session health between SD-WAN edge nodes, checking that IPsec SAs are established with the correct algorithms and haven't expired, a software/security-configuration status concern rather than physical hardware monitoring. It depends conceptually on standard IPsec/IKE concepts (SPI, SA lifetime) similar to those found in IETF IPsec-related MIBs, even though this is H3C's own SD-WAN-oriented implementation. It is typically deployed on H3C SD-WAN edge routers/controllers establishing encrypted overlay tunnels across an NDEC-managed fabric. Engineers can download the HH3C-NDEC-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in HH3C-NDEC-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • H3C SD-WAN edge router
  • H3C NDEC controller

Monitoring Examples

An admin would poll hh3chipsNDECSAListTable, keyed by hh3chipsSPI, to check hh3chipsPeerIpAddr, hh3chipsEncAlgorithm, hh3chipsAuthAlgorithm, and remaining hh3chipsSaLifeSecond/hh3chipsSaLifeKBytes for each active IPsec SA between SD-WAN edge nodes. An SA nearing its lifetime limit without renegotiation, or a mismatch in hh3chipsNegotiateSaMode between peers, would reveal an impending or active tunnel-drop condition. The hh3chipsTraps group would notify the operator when an SA is established or torn down.

What Can Be Monitored

  • IPsec SA peer address
  • SA encryption/authentication algorithm
  • SA lifetime remaining
  • SA negotiation mode
  • SA establishment/teardown events
Imported Objects

From HH3C-OID-MIB

hh3cmlsrOBJECT-IDENTITY

From SNMPv2-SMI

Counter32
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
TruthValue

How to Use in IPNetwork Monitor

Example using hh3chipsInPac OID:

Select an H3C SD-WAN edge router/NDEC controller (IPsec SA between edge devices) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type hh3chipsInPac into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. It reports the total packets of the NDEC recieved. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

H3C NDEC device MIB for network data encryption/security. Manages security associations, IKE policies, and cryptographic parameters.

Start monitoring H3C SD-WAN edge router/NDEC controller (IPsec SA between edge devices) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download HH3C-NDEC-MIB