IPSEC-IPSECACTION-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsIPSEC-IPSECACTION-MIB

Organization: IETF IP Security Policy Working Group

Last Updated: 2006-10-17

Category: Domain: Security, Standard: IETF, VPN and Security

Description: IETF IPsec action MIB defining SNMP objects for IPsec security policy action rules including encryption and authentication parameters.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is IPSEC-IPSECACTION-MIB?

IPSEC-IPSECACTION-MIB is an IETF standards-track MIB (from draft-ietf-ipsp-ipsecaction-mib, part of the IPsec Security Policy Database framework alongside IPSEC-SPD-MIB) that defines the "action" objects invoked when IPsec policy rules match traffic — the concrete AH/ESP/IPComp transform and lifetime parameters applied to a security association. Its central ipsaSaPreconfiguredActionTable ties an action name and direction (ipsaSaPreActActionName, ipsaSaPreActSADirection) to lifetime limits (ipsaSaPreActActionLifetimeSec/KB), DF-bit handling, and references into per-protocol transform tables — ipsaAhTransformTable, ipsaEspTransformTable, and ipsaIpcompTransformTable — which carry algorithm identifiers, key lengths, replay-window sizes, and RowStatus/StorageType lifecycle objects. It depends on IPSEC-SPD-MIB for the policy rules that invoke these actions and on SNMP-FRAMEWORK-MIB/INET-ADDRESS-MIB for administrative naming and addressing conventions. It is deployed on IPsec gateways and hosts implementing SNMP-manageable IPsec policy, and administrators consulting standards documentation for the IPSEC-IPSECACTION-MIB RFC use it to understand how configured security actions map to negotiated SA parameters.

IPNetwork Monitor allows you to monitor SNMP objects defined in IPSEC-IPSECACTION-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • vendor-neutral, standards-based MIB (IETF draft-ietf-ipsp-ipsecaction-mib), not tied to a specific manufacturer — applies to IPsec-capable gateways and hosts

Monitoring Examples

An operator polls ipsaSaPreconfiguredActionTable to review ipsaSaPreActESPTransformName and ipsaSaPreActActionLifetimeSec for a given action, then cross-checks ipsaEspTransformTable for the referenced cipher and key length; an action row with an ipsaSaPreActRowStatus other than active, or a transform whose replay-window size looks misconfigured, would indicate an IPsec policy action that will fail to negotiate or provide inadequate protection.

What Can Be Monitored

  • preconfigured SA action table entries
  • AH/ESP/IPComp transform parameters
  • SA lifetime (seconds/KB) limits
  • replay protection window size
  • action/transform row status and storage type
Imported Objects

From DIFFSERV-MIB

IfDirection

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From IPSEC-SPD-MIB

SpdAdminStatus
SpdIPPacketLogging
spdActionsOBJECT-IDENTITY

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Integer32
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

RowStatus
StorageType
TEXTUAL-CONVENTION
TimeStamp
TruthValue
OIDs

RFC description

IPsec security policy and actions management including packet logging and administrative status control.

Start monitoring Vendor-neutral IETF standard (IPsec gateway/host, security action parameters) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download IPSEC-IPSECACTION-MIB