Juniper-IP-POLICY-MIB

MIB Reference — IPNetwork Monitor

All MIBsJuniper-IP-POLICY-MIB

Organization: Juniper Networks, Inc.

Last Updated: 2007-01-25

Category: Technology: Routing, Vendor: Juniper

Description:

Provides managed objects for IP route policy configuration, filter lists, and policy statistics on Juniper Networks E-series routers.

Imported Objects

From Juniper-MIBs

juniMibsMODULE-IDENTITY

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE

From SNMPv2-TC

DisplayString
RowStatus
TEXTUAL-CONVENTION
TruthValue

What Is Juniper-IP-POLICY-MIB?

Juniper-IP-POLICY-MIB is a vendor-specific SNMP module for Juniper Networks E-series (ERX) routers, defining objects to configure and inspect IP route/access policies such as numbered and named IP access lists used for traffic filtering and route-map-style policy application. Each access-list entry specifies match criteria (source/destination address and mask, protocol) and an action, with RowStatus-controlled entries for dynamic creation and deletion via SNMP. Because it is a configuration/policy MIB rather than a hardware-sensor MIB, its monitoring value lies in verifying that route-filtering policy state matches intent -- confirming an access-list entry's RowStatus is active and its match criteria/action are correctly applied is essential to diagnosing traffic being unexpectedly permitted or denied. It depends on Juniper's broader enterprise MIB tree and general IP addressing conventions rather than a standard IETF policy MIB. It is deployed on Juniper E-series edge/aggregation routers used by service providers for subscriber and route-policy enforcement. Engineers can download the Juniper-IP-POLICY-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in Juniper-IP-POLICY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • IP access list entry status
  • access list match criteria (src/dst/protocol)
  • access list action (permit/deny)
  • named access list configuration
  • policy rule row status

Supported Devices

  • Juniper Networks E-series (ERX) router

Monitoring Examples

An operator troubleshooting unexpected packet drops would inspect juniIpAccessListTable/juniIpAccessListEntry for a given juniIpAccessListId and juniIpAccessListElemId, checking juniIpAccessListAction against the configured juniIpAccessListSrc/SrcMask and juniIpAccessListDst/DstMask to confirm the filter matches the intended traffic. An entry stuck with juniIpAccessListRowStatus not "active" would explain why a policy rule isn't being enforced, while juniIpNamedAccessListTable would be checked when policies are referenced by name rather than numeric ID.

OIDs
OID symbolicOID numericTypeAccessDescription
juniIpPolicyMIB1.3.6.1.4.1.4874.2.2.13The IP Policy MIB for the Juniper Networks enterprise.
juniIpPolicyObjects1.3.6.1.4.1.4874.2.2.13.1
juniIpAccessList1.3.6.1.4.1.4874.2.2.13.1.1
juniIpAccessListTable1.3.6.1.4.1.4874.2.2.13.1.1.1not-accessibleThis table contains entries for elements of IP access lists. Entries belonging to the same access list are ordered, and comparisons to those entries are performed in that order until a match is detected. If no match is found, the default action is to 'deny'.
juniIpAccessListEntry1.3.6.1.4.1.4874.2.2.13.1.1.1.1not-accessibleEach entry describes the characteristics of an IP access list element.
I32 juniIpAccessListId1.3.6.1.4.1.4874.2.2.13.1.1.1.1.1Integer32not-accessibleThe number of the access list to which this entry belongs.
I32 juniIpAccessListElemId1.3.6.1.4.1.4874.2.2.13.1.1.1.1.2Integer32not-accessibleThe relative position of this entry within its access list. Access list entries are searched in this sequence (low to high values) until a match is found. NOTE: The value zero is reserved for use with SET operations to perform special-purpose table entry creations/deletions; see the DESCRIPTION of juniIpAccessListRowStatus for details. Get/GetNext/GetBulk retrievals never return an entry for which this object is zero-valued.
ROW juniIpAccessListRowStatus1.3.6.1.4.1.4874.2.2.13.1.1.1.1.3RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy Two configuration levels are defined, limited and full. EARLY IMPLEMENTATIONS MIGHT PROVIDE ONLY THE LIMITED LEVEL OF CONFIGURATION CAPABILITY. *** LIMITED ACCESS LIST CONFIGURATION LEVEL *** 1) RowStatus createAndGo/destroy operations directed to a target table entry for which juniIpAccessListElemId is ZERO, have the following special-purpose semantics: createAndGo Create an entry having the specified configuration and append it to the target list, i.e. assign it a value of juniIpAccessListElemId that is one greater than the current last element in the list. destroy Destroy the specified list and all of its constituent elements. 2) RowStatus createAndGo/destroy operations directed to a target table entry for which juniIpAccessListElemId is NONZERO are disallowed. *** FULL ACCESS LIST CONFIGURATION LEVEL *** Permit conventional RowStatus-based management of table entries having a nonzero value for juniIpAccessListElemId, IN ADDITION TO the special RowStatus semantics applied to entries having a zero value for juniIpAccessListElemId. To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpAccessListRowStatus In addition, when creating an entry the following conditions must hold: The value of juniIpAccessListElemId is nonzero. Once created, element attributes cannot be modified except by a RowStatus destroy operation to delete the list element.
JUN juniIpAccessListAction1.3.6.1.4.1.4874.2.2.13.1.1.1.1.4JuniIpPolicyPolicyread-createSpecifies the disposition of an item that matches the comparison criteria described by this entry.
IP juniIpAccessListSrc1.3.6.1.4.1.4874.2.2.13.1.1.1.1.5IpAddressread-createA source IP address. A subject IP address is first masked with the value of juniIpAccessListSrcMask, then the result is compared to this value. Setting both this object and its corresponding mask to 0.0.0.0 acts as a wildcard, matching any source IP address.
IP juniIpAccessListSrcMask1.3.6.1.4.1.4874.2.2.13.1.1.1.1.6IpAddressread-createThe IP address mask to be applied to a subject source IP address before comparing it to juniIpAccessListSrc. Ones in the mask identify which bits in the subject IP address are significant for the comparison. To be considered valid, a nonzero value for this object must contain a single contiguous string of ones, beginning with the most significant bit of the mask.
IP juniIpAccessListDst1.3.6.1.4.1.4874.2.2.13.1.1.1.1.7IpAddressread-createA destination IP address. A subject IP address is first masked with the value of juniIpAccessListDstMask, then the result is compared to this value. Setting both this object and its corresponding mask to 0.0.0.0 acts as a wildcard, matching any destination IP address.
IP juniIpAccessListDstMask1.3.6.1.4.1.4874.2.2.13.1.1.1.1.8IpAddressread-createThe IP address mask to be applied to a subject destination IP address before comparing it to juniIpAccessListDst. Ones in the mask identify which bits in the IP address are significant for the comparison. To be considered valid, a nonzero value for this object must contain a single contiguous string of ones, beginning with the most significant bit of the mask.
I32 juniIpAccessListProtocol1.3.6.1.4.1.4874.2.2.13.1.1.1.1.9Integer32read-createAn IP Protocol value. Nonzero values match a specific IP Protocol value (e.g. 6 for TCP) carried in an IP packet; a value of zero acts as a wildcard, matching any IP Protocol.
juniIpNamedAccessList1.3.6.1.4.1.4874.2.2.13.1.2
juniIpNamedAccessListTable1.3.6.1.4.1.4874.2.2.13.1.2.1not-accessibleThis table contains entries for elements of IP access lists. Entries belonging to the same access list are ordered, and comparisons to those entries are performed in that order until a match is detected. If no match is found, the default action is to 'deny'.
juniIpNamedAccessListEntry1.3.6.1.4.1.4874.2.2.13.1.2.1.1not-accessibleEach entry describes the characteristics of an IP access list element.
JUN juniIpNamedAccessListName1.3.6.1.4.1.4874.2.2.13.1.2.1.1.1JuniIpPolicyNamenot-accessibleThe name of the access list to which this entry belongs.
I32 juniIpNamedAccessListElemId1.3.6.1.4.1.4874.2.2.13.1.2.1.1.2Integer32not-accessibleThe relative position of this entry within its access list. Access list entries are searched in this sequence (low to high values) until a match is found. NOTE: The value zero is reserved for use with SET operations to perform special-purpose table entry creations/deletions; see the DESCRIPTION of juniIpNamedAccessListRowStatus for details. Get/GetNext/GetBulk retrievals never return an entry for which this object is zero-valued.
ROW juniIpNamedAccessListRowStatus1.3.6.1.4.1.4874.2.2.13.1.2.1.1.3RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy Two configuration levels are defined, limited and full. EARLY IMPLEMENTATIONS MIGHT PROVIDE ONLY THE LIMITED LEVEL OF CONFIGURATION CAPABILITY. *** LIMITED ACCESS LIST CONFIGURATION LEVEL *** 1) RowStatus createAndGo/destroy operations directed to a target table entry for which juniIpNamedAccessListElemId is ZERO, have the following special-purpose semantics: createAndGo Create an entry having the specified configuration and append it to the target list, i.e. assign it a value of juniIpNamedAccessListElemId that is one greater than the current last element in the list. destroy Destroy the specified list and all of its constituent elements. 2) RowStatus createAndGo/destroy operations directed to a target table entry for which juniIpNamedAccessListElemId is NONZERO are disallowed. *** FULL ACCESS LIST CONFIGURATION LEVEL *** Permit conventional RowStatus-based management of table entries having a nonzero value for juniIpNamedAccessListElemId, IN ADDITION TO the special RowStatus semantics applied to entries having a zero value for juniIpNamedAccessListElemId. To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpNamedAccessListRowStatus In addition, when creating an entry the following conditions must hold: The value of juniIpNamedAccessListElemId is nonzero. Once created, element attributes cannot be modified except by a RowStatus destroy operation to delete the list element.
JUN juniIpNamedAccessListAction1.3.6.1.4.1.4874.2.2.13.1.2.1.1.4JuniIpPolicyPolicyread-createSpecifies the disposition of an item that matches the comparison criteria described by this entry.
IP juniIpNamedAccessListSrc1.3.6.1.4.1.4874.2.2.13.1.2.1.1.5IpAddressread-createA source IP address. A subject IP address is first masked with the value of juniIpNamedAccessListSrcMask, then the result is compared to this value. Setting both this object and its corresponding mask to 0.0.0.0 acts as a wildcard, matching any source IP address.
IP juniIpNamedAccessListSrcMask1.3.6.1.4.1.4874.2.2.13.1.2.1.1.6IpAddressread-createThe IP address mask to be applied to a subject source IP address before comparing it to juniIpNamedAccessListSrc. Ones in the mask identify which bits in the subject IP address are significant for the comparison. To be considered valid, a nonzero value for this object must contain a single contiguous string of ones, beginning with the most significant bit of the mask.
IP juniIpNamedAccessListDst1.3.6.1.4.1.4874.2.2.13.1.2.1.1.7IpAddressread-createA destination IP address. A subject IP address is first masked with the value of juniIpNamedAccessListDstMask, then the result is compared to this value. Setting both this object and its corresponding mask to 0.0.0.0 acts as a wildcard, matching any destination IP address.
IP juniIpNamedAccessListDstMask1.3.6.1.4.1.4874.2.2.13.1.2.1.1.8IpAddressread-createThe IP address mask to be applied to a subject destination IP address before comparing it to juniIpNamedAccessListDst. Ones in the mask identify which bits in the IP address are significant for the comparison. To be considered valid, a nonzero value for this object must contain a single contiguous string of ones, beginning with the most significant bit of the mask.
I32 juniIpNamedAccessListProtocol1.3.6.1.4.1.4874.2.2.13.1.2.1.1.9Integer32read-createAn IP Protocol value. Nonzero values match a specific IP Protocol value (e.g. 6 for TCP) carried in an IP packet; a value of zero acts as a wildcard, matching any IP Protocol.
juniIpAspAccessList1.3.6.1.4.1.4874.2.2.13.1.3
juniIpAspAccessTable1.3.6.1.4.1.4874.2.2.13.1.3.1not-accessibleThis table contains entries for elements of IP AS-Path access entries.
juniIpAspAccessEntry1.3.6.1.4.1.4874.2.2.13.1.3.1.1not-accessibleEach entry describes the characteristics of an IP AS-Path access element.
JUN juniIpAspAccessName1.3.6.1.4.1.4874.2.2.13.1.3.1.1.1JuniIpPolicyNamenot-accessibleThe name of the AS-Path Access List to which this entry belongs.
I32 juniIpAspAccessElemId1.3.6.1.4.1.4874.2.2.13.1.3.1.1.2Integer32not-accessibleThe element ID portion of the IP AS-Path for this entry.
T/F juniIpAspAccessCreatedInternally1.3.6.1.4.1.4874.2.2.13.1.3.1.1.3TruthValueread-onlyIndicated whether this entry was created internally by the system, or dynamically via a management interface. A true value for this object indicates that this entry was created internally; false indicates externally.
JUN juniIpAspAccessPolicy1.3.6.1.4.1.4874.2.2.13.1.3.1.1.4JuniIpPolicyPolicyread-createIndicates the action to take for this AS-Path access list.
OCT juniIpAspAccessExpression1.3.6.1.4.1.4874.2.2.13.1.3.1.1.5OCTET STRINGread-createThe AS-Path access list expression for this entry.
ROW juniIpAspAccessRowStatus1.3.6.1.4.1.4874.2.2.13.1.3.1.1.6RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpCommunityRowStatus In addition, when creating an entry the following conditions must hold: Once created, only certain attributes can be modified.
juniIpPrefixList1.3.6.1.4.1.4874.2.2.13.1.4
juniIpPrefixListTable1.3.6.1.4.1.4874.2.2.13.1.4.1not-accessibleThis table contains entries for elements of IP prefix lists. Entries belonging to the same prefix list are ordered, and comparisons to those entries are performed in that order until a match is detected. If no match is found, the default action is to 'deny'.
juniIpPrefixListEntry1.3.6.1.4.1.4874.2.2.13.1.4.1.1not-accessibleEach entry describes the characteristics of an IP prefix list element.
JUN juniIpPrefixListName1.3.6.1.4.1.4874.2.2.13.1.4.1.1.1JuniIpPolicyNamenot-accessibleThe name of the prefix list to which this entry belongs.
I32 juniIpPrefixListElemId1.3.6.1.4.1.4874.2.2.13.1.4.1.1.2Integer32not-accessibleThe relative position of this entry within its prefix list. Access list entries are searched in this sequence (low to high values) until a match is found.
IP juniIpPrefixListIpAddress1.3.6.1.4.1.4874.2.2.13.1.4.1.1.3IpAddressnot-accessibleThe IP Address portion of the IP List value for this entry.
I32 juniIpPrefixListLength1.3.6.1.4.1.4874.2.2.13.1.4.1.1.4Integer32not-accessibleThe length portion of the IP List value for this entry.
JUN juniIpPrefixListPolicy1.3.6.1.4.1.4874.2.2.13.1.4.1.1.5JuniIpPolicyPolicyread-createThe IP Prefix list action to perform for this entry.
I32 juniIpPrefixListGeValue1.3.6.1.4.1.4874.2.2.13.1.4.1.1.6Integer32read-createThe minimum prefix length to apply to address.
I32 juniIpPrefixListLeValue1.3.6.1.4.1.4874.2.2.13.1.4.1.1.7Integer32read-createThe maximum prefix length to apply to address.
STR juniIpPrefixListDescription1.3.6.1.4.1.4874.2.2.13.1.4.1.1.8DisplayStringread-createThe administratively assigned description for this entry.
C32 juniIpPrefixListHitCount1.3.6.1.4.1.4874.2.2.13.1.4.1.1.9Counter32read-onlyThe number of hits for this entry.
ROW juniIpPrefixListRowStatus1.3.6.1.4.1.4874.2.2.13.1.4.1.1.10RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpPrefixListRowStatus In addition, when creating an entry the following conditions must hold: The value of juniIpPrefixListElemId is nonzero. Once created, only certain attributes can be modified.
juniIpPrefixTree1.3.6.1.4.1.4874.2.2.13.1.5
juniIpPrefixTreeTable1.3.6.1.4.1.4874.2.2.13.1.5.1not-accessibleThis table contains entries for elements of IP prefix trees. Entries belonging to the same prefix tree are ordered, and comparisons to those entries are performed in that order until a match is detected. If no match is found, the default action is to 'deny'.
juniIpPrefixTreeEntry1.3.6.1.4.1.4874.2.2.13.1.5.1.1not-accessibleEach entry describes the characteristics of an IP prefix tree element.
JUN juniIpPrefixTreeName1.3.6.1.4.1.4874.2.2.13.1.5.1.1.1JuniIpPolicyNamenot-accessibleThe name of the prefix tree to which this entry belongs.
IP juniIpPrefixTreeIpAddress1.3.6.1.4.1.4874.2.2.13.1.5.1.1.2IpAddressnot-accessibleThe IP Address portion of the IP Prefix value for this entry.
I32 juniIpPrefixTreeLength1.3.6.1.4.1.4874.2.2.13.1.5.1.1.3Integer32not-accessibleThe length portion of the IP Prefix value for this entry.
JUN juniIpPrefixTreePolicy1.3.6.1.4.1.4874.2.2.13.1.5.1.1.4JuniIpPolicyPolicyread-createThe IP Prefix tree policy perform for this entry.
STR juniIpPrefixTreeDescription1.3.6.1.4.1.4874.2.2.13.1.5.1.1.5DisplayStringread-createThe administratively assigned description for this entry.
C32 juniIpPrefixTreeHitCount1.3.6.1.4.1.4874.2.2.13.1.5.1.1.6Counter32read-onlyThe number of hits for this entry.
ROW juniIpPrefixTreeRowStatus1.3.6.1.4.1.4874.2.2.13.1.5.1.1.7RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpPrefixTreeRowStatus In addition, when creating an entry the following conditions must hold: The value of juniIpPrefixTreeIpAddress and juniIpPrefixTreeLength are nonzero. Once created, only certain attributes can be modified.
juniIpCommunityList1.3.6.1.4.1.4874.2.2.13.1.6
juniIpCommunityListTable1.3.6.1.4.1.4874.2.2.13.1.6.1not-accessibleThis table contains entries for elements of IP Community Lists. Entries belonging to the same Community List are ordered. The table supports standard and extended community lists.
juniIpCommunityListEntry1.3.6.1.4.1.4874.2.2.13.1.6.1.1not-accessibleEach entry describes the characteristics of an IP Community List element.
JUN juniIpCommunityListName1.3.6.1.4.1.4874.2.2.13.1.6.1.1.1JuniIpPolicyNamenot-accessibleThe name of the Community List to which this entry belongs.
I32 juniIpCommunityListElemId1.3.6.1.4.1.4874.2.2.13.1.6.1.1.2Integer32not-accessibleThe IP Address portion of the IP Prefix value for this entry.
T/F juniIpCommunityListCreatedInternally1.3.6.1.4.1.4874.2.2.13.1.6.1.1.3TruthValueread-onlyIndicated whether this entry was created internally by the system, or dynamically via a management interface. A true value for this object indicates that this entry was created internally; false indicates externally.
T/F juniIpCommunityListExtended1.3.6.1.4.1.4874.2.2.13.1.6.1.1.4TruthValueread-createIndicates whether this entry is a standard or extended Community List. True indicates extended, false indicates standard
JUN juniIpCommunityListPolicy1.3.6.1.4.1.4874.2.2.13.1.6.1.1.5JuniIpPolicyPolicyread-createIndicates the policy action to perform for this list.
OCT juniIpCommunityListExpression1.3.6.1.4.1.4874.2.2.13.1.6.1.1.6OCTET STRINGread-createThe community list expression for this entry.
ROW juniIpCommunityListRowStatus1.3.6.1.4.1.4874.2.2.13.1.6.1.1.7RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpCommunityRowStatus In addition, when creating an entry the following conditions must hold: Once created, only certain attributes can be modified.
juniIpExtCommunityListTable1.3.6.1.4.1.4874.2.2.13.1.6.2not-accessibleThis table contains entries for Extended IP Community Lists. Entries belonging to the same Extended Community List are ordered.
juniIpExtCommunityListEntry1.3.6.1.4.1.4874.2.2.13.1.6.2.1not-accessibleEach entry describes the characteristics of an Extended IP Community List element.
JUN juniIpExtCommunityListName1.3.6.1.4.1.4874.2.2.13.1.6.2.1.1JuniIpPolicyNamenot-accessibleThe name of the Extended Community List to which this entry belongs.
I32 juniIpExtCommunityListElemId1.3.6.1.4.1.4874.2.2.13.1.6.2.1.2Integer32not-accessibleThe element ID value for this entry.
T/F juniIpExtCommunityListCreatedInternally1.3.6.1.4.1.4874.2.2.13.1.6.2.1.3TruthValueread-onlyIndicated whether this entry was created internally by the system, or dynamically via a management interface. A true value for this object indicates that this entry was created internally; false indicates externally.
JUN juniIpExtCommunityListPolicy1.3.6.1.4.1.4874.2.2.13.1.6.2.1.4JuniIpPolicyPolicyread-createIndicates the policy action to perform for this list.
OCT juniIpExtCommunityListExpression1.3.6.1.4.1.4874.2.2.13.1.6.2.1.5OCTET STRINGread-createThe extended community list expression for this entry.
ROW juniIpExtCommunityListRowStatus1.3.6.1.4.1.4874.2.2.13.1.6.2.1.6RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpExtCommunityRowStatus In addition, when creating an entry the following conditions must hold: The value of juniIpExtCommunityListElemId is included in this table as a key for future use. It must be the value zero. Once created, only certain attributes can be modified.
juniIpRedistributeList1.3.6.1.4.1.4874.2.2.13.1.7
juniIpDynRedistributeTable1.3.6.1.4.1.4874.2.2.13.1.7.1not-accessibleThis table contains entries for elements of IP Dynamic Route Redistribution elements.
juniIpDynRedistributeEntry1.3.6.1.4.1.4874.2.2.13.1.7.1.1not-accessibleEach entry describes the characteristics of a dynamic IP Route Redistribute element.
JUN juniIpDynRedistributeToProtocol1.3.6.1.4.1.4874.2.2.13.1.7.1.1.1JuniIpDynRedistributeProtocolnot-accessibleIdentifies the protocol associated with this Dynamic Route Redistribution element that routes are redistributed to.
JUN juniIpDynRedistributeState1.3.6.1.4.1.4874.2.2.13.1.7.1.1.2JuniIpPolicyAdminStatusread-createIndicates the enable/disable state of this redistribution element.
ROW juniIpDynRedistributeRowStatus1.3.6.1.4.1.4874.2.2.13.1.7.1.1.3RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpDynRedistributeRowStatus Once created, only the juniIpDynRedistributeState object can be modified.
juniIpRedistributeTable1.3.6.1.4.1.4874.2.2.13.1.7.2not-accessibleThis table contains entries for elements of IP Route Redistribution elements.
juniIpRedistributeEntry1.3.6.1.4.1.4874.2.2.13.1.7.2.1not-accessibleEach entry describes the characteristics of an IP Route Redistribution element.
JUN juniIpRedistributeToProtocol1.3.6.1.4.1.4874.2.2.13.1.7.2.1.1JuniIpRedistributeProtocolnot-accessibleIdentifies the protocol for this element that routes are redistributed to.
JUN juniIpRedistributeFromProtocol1.3.6.1.4.1.4874.2.2.13.1.7.2.1.2JuniIpRedistributeProtocolnot-accessibleIdentifies the protocol for this element that routes are redistributed from.
JUN juniIpRedistributeState1.3.6.1.4.1.4874.2.2.13.1.7.2.1.3JuniIpPolicyAdminStatusread-createIndicates the enable/disable state of this redistribution element.
JUN juniIpRedistributeRouteMapName1.3.6.1.4.1.4874.2.2.13.1.7.2.1.4JuniIpPolicyNameread-createIdentifies the IP route-map associated with this IP Route Redistribution element.
ROW juniIpRedistributeRowStatus1.3.6.1.4.1.4874.2.2.13.1.7.2.1.5RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpRedistributeRowStatus juniIpRedistributeRouteMapName Once created, only the juniIpRedistributeState object can be modified.
juniIpRouteMapTree1.3.6.1.4.1.4874.2.2.13.1.8
juniIpRouteMapTable1.3.6.1.4.1.4874.2.2.13.1.8.1not-accessibleThis table contains entries for elements of IP Route Maps.
juniIpRouteMapEntry1.3.6.1.4.1.4874.2.2.13.1.8.1.1not-accessibleEach entry describes the characteristics of an IP Route Map element.
JUN juniIpRouteMapName1.3.6.1.4.1.4874.2.2.13.1.8.1.1.1JuniIpPolicyNamenot-accessibleThe name of the route map to which this entry belongs.
I32 juniIpRouteMapSequenceNum1.3.6.1.4.1.4874.2.2.13.1.8.1.1.2Integer32not-accessibleThe element ID value for this entry.
I32 juniIpRouteMapElemId1.3.6.1.4.1.4874.2.2.13.1.8.1.1.3Integer32not-accessibleThe element ID to which this entry belongs.
I32 juniIpRouteMapSubElemId1.3.6.1.4.1.4874.2.2.13.1.8.1.1.4Integer32not-accessibleThe sub-element ID to which this entry belongs.
T/F juniIpRouteMapCreatedInternally1.3.6.1.4.1.4874.2.2.13.1.8.1.1.5TruthValueread-onlyIndicated whether this entry was created internally by the system, or dynamically via a management interface. A true value for this object indicates that this entry was created internally; false indicates externally.
JUN juniIpRouteMapPolicy1.3.6.1.4.1.4874.2.2.13.1.8.1.1.6JuniIpPolicyPolicyread-onlyIndicates the policy action performed by this element.
OCT juniIpRouteMapDisplay1.3.6.1.4.1.4874.2.2.13.1.8.1.1.7OCTET STRINGread-onlyTextual information taken from the NVT ASCII character set (i.e. RFC1903 DisplayString), but with increased length. The information in this object is the series of set, match, and/or match & set clauses for this route map. It is assumed that the information conveyed in this object is used for display purposes and in general, is not parsed. The information in this string is a concatentation of routemap clauses configured via the systems non SNMP interface.
juniIpRouteMapV2Table1.3.6.1.4.1.4874.2.2.13.1.8.2not-accessibleThis table contains entries for route maps instances.
juniIpRouteMapV2Entry1.3.6.1.4.1.4874.2.2.13.1.8.2.1not-accessibleEach entry is a specific instance of the Route Map.
JUN juniIpRouteMapV2Name1.3.6.1.4.1.4874.2.2.13.1.8.2.1.1JuniIpPolicyNamenot-accessibleThe name of the route map to which this instance entry belongs.
I32 juniIpRouteMapV2SequenceNum1.3.6.1.4.1.4874.2.2.13.1.8.2.1.2Integer32not-accessibleMultiple instances of the same route map can be created by assigning a different sequence number to it. Each instance is identified by the route map name and the sequence number. The value of the sequence number associated with the particular route map instance determines the order in which the routing protocol evaluates routes; the instance of having lowest sequence number is evaluated first. If the routes pass all the match conditions specified in the lowest-numbered instance, and if all set clause elements are successfully configured, then no other instance of the route map is considered. However, any routes that do not pass all the match conditions are evaluated against the next instance of the route map.
JUN juniIpRouteMapV2Policy1.3.6.1.4.1.4874.2.2.13.1.8.2.1.3JuniIpPolicyPolicyread-createIndicates the policy action performed by this route map instance.
ROW juniIpRouteMapV2RowStatus1.3.6.1.4.1.4874.2.2.13.1.8.2.1.4RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create an entry in this table, the following entry objects MUST be explicitly configured: juniIpRouteMapV2RowStatus To delete an entry in this table, the following entry objects MUST be explicitly configured: juniIpRouteMapV2RowStatus Once created, juniIpRouteMapV2Policy attribute can be modified. To modify juniIpRouteMapV2Policy, set juniIpRouteMapV2RowStatus also. Note: Match, match-set and set clause elements can be configured for a specific instance of the route map. First create the route map instance to make use of the same to configure in the clause table. Deletion of the route map instance will also delete all the clause elements confgured for that instance as clause elements are configured for that instance.
juniIpRouteMapClauseTable1.3.6.1.4.1.4874.2.2.13.1.8.3not-accessibleThis table contains entries for instances of the route map clause elements.
juniIpRouteMapClauseEntry1.3.6.1.4.1.4874.2.2.13.1.8.3.1not-accessibleEach entry describes the characteristics of one route map clause element instance.
INT juniIpRouteMapClauseElemId1.3.6.1.4.1.4874.2.2.13.1.8.3.1.1INTEGERnot-accessibleThe clause element selection option. Select the appropriate element option to configure each element instance of match, match-set and set clauses. For the complete configuration map table refer to the juniIpRouteMapClauseRowStatus object's DESCRIPTION.
I32 juniIpRouteMapClauseSubElemId1.3.6.1.4.1.4874.2.2.13.1.8.3.1.2Integer32not-accessibleThe clause element sub ID used to distinguish specific instance of the element. This value is determined by choosing the next available by walking the table.
INT juniIpRouteMapClauseElemIdAddon1.3.6.1.4.1.4874.2.2.13.1.8.3.1.3INTEGERread-createThis represents clause element instance add-on option selected along with the main option (juniIpRouteMapClauseElemId) whenever it applies. For more information on how to map this object value to each value, refer to the mapping table in the juniIpRouteMapClauseRowStatus object's DESCRIPTION.
STR juniIpRouteMapClauseElementValue1.3.6.1.4.1.4874.2.2.13.1.8.3.1.4DisplayStringread-createThis represents set, match-set and match clauses' different element instance values in character string form. Whatever may be the data type of the attribute element instance value, it is always interpreted as a set of characters for both configuration and display purposes. It is up to the user to know the element's data type mapping in order to input the correct value while configuring. Refer to the mapping table in the juniIpRouteMapClauseRowStatus object descrption for detailed information.
ROW juniIpRouteMapClauseRowStatus1.3.6.1.4.1.4874.2.2.13.1.8.3.1.5RowStatusread-createControls creation/deletion of entries in this table according to the RowStatus textual convention, constrained to support the following values only: createAndGo destroy To create/delete an entry in this table, the following entry objects MUST be explicitly configured: juniIpRouteMapClauseElementValue juniIpRouteMapClauseRowStatus Additional object juniIpRouteMapClauseElemIdAddon may become OPTIONAL for some elements creation/deletion along with the above. Refer the mapping table below to determine which elements are required. The table entry elements may not be modified. Only create and delete are allowed. Note#1: Make sure route map(s) are created before configuring their corresponding clause elements. Note#2: The mapping table below is the extensive guide for the options, values and ranges of the table objects juniIpRouteMapClauseElemId, juniIpRouteMapClauseElemIdAddon and juniIpRouteMapClauseElementValue. Clause element configuration selection mapping table ==================================================== ClauseElemId ClauseElemIdAddon ClauseElementValue ============ ================= ================== matchAsPath notApplicable DisplayString (SIZE(1..32)) matchCommunity exact/ DisplayString (SIZE(1..32)) notApplicable matchExtendedCommunity exact/ DisplayString (SIZE(1..32)) notApplicable Note#3: At a given time only one can be configured for access list and prefix-list/trees'. matchAccessList notApplicable DisplayString (SIZE(1..32)) matchPrefixList notApplicable DisplayString (SIZE(1..32)) matchPrefixTree notApplicable DisplayString (SIZE(1..32)) matchNextHop notApplicable DisplayString (SIZE(1..32)) matchNextHopPreList notApplicable DisplayString (SIZE(1..32)) matchNextHopPreTree notApplicable DisplayString (SIZE(1..32)) Note#4: For matchLevel, matchMetricType and matchRouteType element selection choose the exact case-sensitive string to set the option. Example: For matchLevel, option levelOne, levelOneAndTwo, etc. can be set. matchLevel notApplicable { levelOne, levelOneAndTwo, levelTwo, backbone, stubArea } matchMetricType notApplicable { internal or typeOne, external or typeTwo } matchRouteType notApplicable { external, internal, internalInter, internalIntra } matchDistance notApplicable Integer32 (0..255) matchMetric notApplicable Unsigned32 matchTag notApplicable Unsigned32 matchPolicyList notApplicable DisplayString (SIZE(1..32)) setAsPath notApplicable DisplayString (SIZE(1..32)) setCommunityAdd notApplicable DisplayString (SIZE(1..32)) setCommList delete/ DisplayString (SIZE(1..32)) notApplicable setCommunity notApplicable DisplayString (SIZE(1..32)) Note#5: For below elements selection choose the exact case-sensitive string to set the option. Example: For setOrigin, egp or igp or incomplete will be the valid options to select. setAutoTag notApplicable { autoTag } setCommunityNone notApplicable { communityNone } Note#6: setCommunityCreateList and setCommunityCreateListAdd will have only one instance and all will be set in one instance of the element (either setCommunityCreateList or setCommunityCreateListAdd), i.e., all options and values will aggregate in one SubElementId. setCommunityCreateList notApplicable Unsigned32 setCommunityCreateListAdd notApplicable Unsigned32 setCommunityCreateList notApplicable { none, localAs, noAdvertise, noExport } setCommunityCreateListAdd notApplicable { none, localAs, noAdvertise, noExport } setLevel notApplicable { backbone, levelOne, levelOneAndTwo, levelTwo, stubArea } setRouteType notApplicable { external, internal, internalInter, internalIntra } setNextHopPeerAddr notApplicable { peerAddress } setMetricType notApplicable { external, internal } setOrigin notApplicable { egp, igp, incomplete } setAsPathCreateList notApplicable Interger32 (1..65535) setTag notApplicable Unsigned32 setWeight notApplicable Unsigned32 setDistance notApplicable Interger32 (1..255) setLocalPref notApplicable Unsigned32 setMetric relativeNeg/ Unsigned32 relativePos/ notApplicable Note#7: setExtendedCommunityCreate and setExtendedCommunityCreateAdd will have only one instance and all will be set in one instance of the element (either setExtendedCommunityCreate or setExtendedCommunityCreateAdd) i.e. all options and values will aggregate in one SubElementId. setExtendedCommunityCreate extCommRt/ IPADDRESS:Unsigned32 or notApplicable IPADDRESS-in-ASN:Unsigned32 setExtendedCommunityCreate extCommSoo/ IPADDRESS:Unsigned32 or notApplicable IPADDRESS-in-ASN:Unsigned32 setExtendedCommunityCreateAdd extCommRt/ IPADDRESS:Unsigned32 or notApplicable IPADDRESS-in-ASN:Unsigned32 setExtendedCommunityCreateAdd extCommSoo/ IPADDRESS:Unsigned32 notApplicable IPADDRESS-in-ASN:Unsigned32 Note#8: Damping element has only one instance at any given time. It can be deleted by just refering to the instance (elementID and subElementId) without refering the exact value; i.e., while deleting, values doesn't matter. setDampingCreate notApplicable 1. HalfLifeiTime-Interger32 (1..45) 2. RtSuppressTime-Interger32 (1..20000) 3. SuppressedRtReuseTime-Interger32 (1..20000) 4. MaxRtSuppressTime-Interger32 (1..255) 5. UnreachableRtHalfLifeTime-Interger32 (1..45) Note#9: 1, 2, 3 and 4 values are MUST values to be specified (in minutes) for route flap damping and 5th one is optional. Format for specifying the values are very rigid and strict. Always specify four MUST values. The first value shouldn't be preceded with space characters and last the value always should be followed with one space character. From first value to till last value, all the values will be separated from each other by one space character. setNextHop interfaceValue/ Unsigned32 notApplicable setNextHop ipAddress/ IPADDRESS notApplicable
juniIpPolicyConformance1.3.6.1.4.1.4874.2.2.13.4
juniIpPolicyCompliances1.3.6.1.4.1.4874.2.2.13.4.1
juniIpPolicyCompliance1.3.6.1.4.1.4874.2.2.13.4.1.1An obsolete compliance statement for entities that implement the Juniper IP Policy MIB. This statement became obsolete when support was added for the IP Named Access List.
juniIpPolicyCompliance21.3.6.1.4.1.4874.2.2.13.4.1.2An obsolete compliance statement for entities that implement the Juniper IP Policy MIB. This statement became obsolete when support was added for the IP ASP Access List, the IP Prefix List, the IP Prefix Tree, the IP Community List, the IP Extended Community List, IP Dynamic Route Redistribution, and the IP Route Map.
juniIpPolicyCompliance31.3.6.1.4.1.4874.2.2.13.4.1.3An obsolete compliance statement for entities that implement the Juniper IP Policy MIB. This statement became obsolete when support was added for the IP Route Map configurations.
juniIpPolicyCompliance41.3.6.1.4.1.4874.2.2.13.4.1.4The compliance statement for entities that implement the Juniper IP Policy MIB.
juniIpPolicyGroups1.3.6.1.4.1.4874.2.2.13.4.2
juniIpAccessListGroup1.3.6.1.4.1.4874.2.2.13.4.2.1A collection of objects for managing IP access list capabilities in a Juniper product.
juniIpNamedAccessListGroup1.3.6.1.4.1.4874.2.2.13.4.2.2A named collection of objects for managing IP access list capabilities in a Juniper product.
juniIpAspAccessListGroup1.3.6.1.4.1.4874.2.2.13.4.2.3A named collection of objects for managing AS-Path access list capabilities in a Juniper product.
juniIpPrefixListGroup1.3.6.1.4.1.4874.2.2.13.4.2.4A named collection of objects for managing Prefix list capabilities in a Juniper product.
juniIpPrefixTreeGroup1.3.6.1.4.1.4874.2.2.13.4.2.5A named collection of objects for managing Prefix Tree capabilities in a Juniper product.
juniIpCommunityListGroup1.3.6.1.4.1.4874.2.2.13.4.2.6A named collection of objects for managing Community List capabilities in a Juniper product.
juniIpExtCommunityListGroup1.3.6.1.4.1.4874.2.2.13.4.2.7A named collection of objects for managing Extended Community List capabilities in a Juniper product.
juniIpRedistributeGroup1.3.6.1.4.1.4874.2.2.13.4.2.8A collection of objects for managing IP route redistribution list capabilities in a Juniper product.
juniIpRouteMapGroup1.3.6.1.4.1.4874.2.2.13.4.2.9A collection of objects for managing IP route map list capabilities in a Juniper product.
juniIpRouteMapGroup21.3.6.1.4.1.4874.2.2.13.4.2.10A collection of objects for managing IP route map list capabilities in a Juniper product.

RFC description

Manages IP routing policies including access lists, prefix lists, and route maps for traffic engineering.

Start monitoring Juniper Networks E-series (ERX) router (IP access-list/route policy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download Juniper-IP-POLICY-MIB