JNX-IPSEC-MONITOR-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsJNX-IPSEC-MONITOR-MIB

Organization: Juniper Networks, Inc.

Last Updated: 2012-02-10

Category: VPN and Security, Vendor: Juniper

Description: Provides monitoring objects for IPsec security associations and tunnel statistics on Juniper Networks devices.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is JNX-IPSEC-MONITOR-MIB?

JNX-IPSEC-MONITOR-MIB is a Juniper Networks enterprise MIB providing runtime monitoring of IPsec security associations (SAs) and VPN tunnels on Juniper routing/security platforms. It exposes tunnel and SA status, traffic/byte and packet counters, and likely negotiation or failure statistics that indicate whether IPsec tunnels are up and passing traffic correctly. As a software-status MIB it is used to verify VPN health -- confirming SAs are established, tunnels haven't dropped, and no abnormal rekey/negotiation failures are occurring -- rather than reporting chassis hardware sensors. It depends on the underlying IPsec/IKE protocol suite and typically complements standard interface and tunnel MIBs (e.g., IF-MIB) for correlating tunnel state with logical interfaces. It is deployed on Juniper SRX firewalls and routers terminating site-to-site or remote-access IPsec VPNs in enterprise or service-provider networks. Engineers can download the JNX-IPSEC-MONITOR-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in JNX-IPSEC-MONITOR-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Juniper SRX firewall
  • Juniper router with IPsec VPN termination

Monitoring Examples

An administrator would poll IPsec SA/tunnel status objects to detect a tunnel that has gone down or failed to renegotiate, correlating it with traffic counters that show a sudden drop to zero bytes/packets. No sample objects were extracted for this module, so specific table names cannot be cited, but the MIB's purpose implies an SA table keyed by tunnel/peer identifiers with status and byte-count columns. This is primarily useful for VPN uptime and throughput monitoring rather than general chassis health.

What Can Be Monitored

  • IPsec tunnel/SA status
  • tunnel traffic byte/packet counts
  • SA negotiation failures
  • VPN peer connectivity
Imported Objects

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From JUNIPER-SMI

jnxMibsOBJECT-IDENTITY

From JUNIPER-SP-MIB

jnxSpSvcSetNameOBJECT-TYPE

From SNMPv2-SMI

Counter32
Counter64
Integer32
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
TEXTUAL-CONVENTION
TimeInterval

How to Use in IPNetwork Monitor

Example using jnxIkeTunInOctets OID:

Select a Juniper SRX firewall / router (IPsec VPN tunnel monitoring) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type jnxIkeTunInOctets into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. The total number of octets received by this IPsec Phase-1 IKE security association. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline (in Octets), since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Juniper IPsec monitoring MIB for monitoring IPsec Phase-1 and Phase-2 tunnels, security associations, and IKE tunnel status on Juniper devices.

Start monitoring Juniper SRX firewall / router (IPsec VPN tunnel monitoring) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download JNX-IPSEC-MONITOR-MIB