Juniper-IPsec-Tunnel-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsJuniper-IPsec-Tunnel-MIB

Organization: Juniper Networks, Inc.

Last Updated: 2004-04-06

Category: VPN and Security, Vendor: Juniper

Description: Provides managed objects for IPsec VPN tunnel configuration, status, and traffic statistics on Juniper Networks E-series routers.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is Juniper-IPsec-Tunnel-MIB?

This is a Juniper Networks enterprise MIB for the E-series (ERX) router line, providing managed objects for configuring and monitoring IPsec VPN tunnel interfaces. It exposes an IPsec tunnel interface table capturing tunnel name, type, associated virtual router, local and remote IP endpoints, transform set, and source address type/value used to establish each tunnel. Monitoring this MIB centers on the software/protocol status of VPN connectivity, checking whether a tunnel's endpoints and transform set match the expected security policy, and (via the broader juniIpsecTunnel/juniIpsecSystem subtree) tracking tunnel up/down state and traffic statistics that reveal VPN negotiation failures or dropped tunnels. It depends conceptually on IPsec/IKE standards for the tunnel negotiation it configures and reports on. Typical deployment is on Juniper E-series (ERX) edge routers used by service providers to terminate large numbers of customer IPsec VPN tunnels. Engineers can download the Juniper-IPsec-Tunnel-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in Juniper-IPsec-Tunnel-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Juniper Networks E-series (ERX) edge router

Monitoring Examples

An operator would poll juniIpsecTunnelInterfaceTable/juniIpsecTunnelInterfaceEntry, indexed by juniIpsecTunnelIfIndex, for juniIpsecTunnelLocalEndPt, juniIpsecTunnelRemoteEndPt, and juniIpsecTunnelTransformSet to verify a customer VPN tunnel is configured correctly. If juniIpsecTunnelSrcAddr doesn't match the expected juniIpsecTunnelSrcType, or the tunnel's transport virtual router (juniIpsecTunnelTransportVirtualRouter) is wrong, the tunnel will fail to establish, showing up as a missing or errored entry keyed by juniIpsecTunnelName. juniIpsecTunnelNextIfIndex is used by the agent to allocate new tunnel interface indexes as tunnels are provisioned.

What Can Be Monitored

  • IPsec tunnel local/remote endpoints
  • tunnel transform set
  • tunnel type and virtual router association
  • tunnel source address type/value
  • number of provisioned tunnel interfaces
Imported Objects

From IF-MIB

InterfaceIndex

From Juniper-MIBs

juniMibsMODULE-IDENTITY

From Juniper-TC

JuniName
JuniNextIfIndex

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
RowStatus
TEXTUAL-CONVENTION

How to Use in IPNetwork Monitor

Example using juniIpsecTunnelStatInbUserRecvPkts OID:

Select a Juniper Networks E-series (ERX) edge router (IPsec VPN tunnel interfaces) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type juniIpsecTunnelStatInbUserRecvPkts into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. It reports the total number of inbound user packets received (successfully, with no errors) for this IPsec tunnel. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter stops increasing while the tunnel is expected to be passing traffic, since a stalled counter often means the tunnel has stopped forwarding. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Juniper IPsec Tunnel MIB for managing IPsec VPN tunnel configuration, status, identity types, and encryption transform parameters.

Start monitoring Juniper Networks E-series (ERX) edge router (IPsec VPN tunnel interfaces) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download Juniper-IPsec-Tunnel-MIB