IPSEC-SPD-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsIPSEC-SPD-MIB

Organization: IETF IP Security Policy Working Group

Last Updated: 2007-02-07

Category: VPN and Security

Description: Defines managed objects for configuring IPsec Security Policy Database (SPD) entries via SNMP.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring IPSEC-SPD-MIB with a free 30-day trial of IPNetwork Monitor.

What Is IPSEC-SPD-MIB?

IPSEC-SPD-MIB is an IETF standards-track MIB, published as the IPSEC-SPD-MIB RFC (RFC 4807), defining managed objects for configuring and inspecting an IPsec Security Policy Database (SPD), applicable anywhere IPsec security services are implemented -- hosts, gateways, firewalls, routers, or bump-in-the-wire devices. It exposes configuration data for security policy groups, including ingress/egress policy group names, endpoint-to-group mappings with direction and interface bindings, and the ordered contents of policy groups that determine how traffic is matched against IPsec policies. Its monitoring value is primarily software/configuration status: confirming which security policy group is bound to which interface and direction (spdEndGroupDirection, spdEndGroupInterface), verifying row status and last-changed timestamps to catch unexpected policy changes, rather than hardware environmental data. It explicitly depends on and complements companion IPsec MIBs for Security Associations and IKE, since the SPD determines which traffic is subject to those associations. It is deployed on any IPsec-capable network device -- security gateways, firewalls, VPN concentrators, or hosts -- where administrators need to audit or provision IPsec policy configuration via SNMP.

IPNetwork Monitor allows you to monitor SNMP objects defined in IPSEC-SPD-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer
  • IPsec-capable gateway, firewall, router, or host

Monitoring Examples

An administrator would poll spdEndpointToGroupTable/spdEndpointToGroupEntry to check spdEndGroupInterface and spdEndGroupDirection, confirming which policy group (spdEndGroupName) is applied to a given interface for ingress or egress traffic, and cross-reference spdIngressPolicyGroupName/spdEgressPolicyGroupName for the overall device-level policy assignment. Checking spdEndGroupLastChanged alongside spdEndGroupRowStatus can reveal whether a security policy group was recently and perhaps unexpectedly modified, which combined with spdGroupContentsTable would show exactly which policy rules changed.

What Can Be Monitored

  • security policy group assignment per interface/direction
  • policy group row status
  • policy configuration last-changed timestamp
  • policy group contents/ordering
  • ingress/egress policy group naming
Imported Objects

From DIFFSERV-MIB

IfDirection
diffServMIBMultiFieldClfrGroupOBJECT-GROUP
diffServMultiFieldClfrNextFreeOBJECT-TYPE

From IF-MIB

InterfaceIndex

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32
mib-2

From SNMPv2-TC

RowStatus
StorageType
TEXTUAL-CONVENTION
TimeStamp
TruthValue
VariablePointer
OIDs

FAQ

What does IPSEC-SPD-MIB let me verify on a VPN gateway or firewall?
It exposes IPsec Security Policy Database configuration: ingress/egress policy group names, endpoint-to-group mappings with direction and interface bindings, and the ordered contents of policy groups that determine how traffic is matched against IPsec policies.

How would an administrator use this MIB to audit IPsec policy configuration?
Per RFC 4807, an administrator can poll spdEndGroupDirection and spdEndGroupInterface to confirm which security policy group is bound to which interface and direction, and check row status and last-changed timestamps to catch unexpected policy changes, complementing companion MIBs that track the actual IPsec Security Associations and IKE state.

RFC description

IPsec Security Policy Database management (RFC 6207).

Start monitoring Vendor-neutral IETF standard, RFC 4807 (IPsec-capable gateway, firewall, router, or host) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download IPSEC-SPD-MIB