All MIBs › WATCHGUARD-IPSEC-SA-MON-MIB-EXT
Organization: WatchGuard Technologies, Inc.
Last Updated: 2007-01-25
Category: WatchGuard Security Appliances
Description: Extends IPsec security association monitoring on WatchGuard devices with additional tunnel lifetime and rekeying statistics.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is WATCHGUARD-IPSEC-SA-MON-MIB-EXT?
WATCHGUARD-IPSEC-SA-MON-MIB-EXT is a WatchGuard-specific extension MIB that adds vendor objects on top of the generic IPsec security-association monitoring objects defined in the IETF draft "draft-ietf-ipsec-monitor-mib-01," for WatchGuard firewall/UTM appliances. It exposes IPsec VPN tunnel monitoring data, extending the base IPsec SA table with additional tunnel lifetime and rekeying statistics specific to WatchGuard's implementation. In a monitoring context it is used to track VPN tunnel software-level health: how long a tunnel's keys remain valid, how often rekeying occurs, and whether rekeying is succeeding, which helps an admin detect an IPsec tunnel that is flapping due to rekey failures or approaching key expiration. It explicitly depends on the base IETF IPsec Monitoring MIB draft for its core SA objects, adding only the extension objects itself. It is deployed on WatchGuard firewall appliances terminating site-to-site or remote-access IPsec VPN tunnels in enterprise/branch network security deployments. Engineers can download the WATCHGUARD-IPSEC-SA-MON-MIB-EXT file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in WATCHGUARD-IPSEC-SA-MON-MIB-EXT. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- WatchGuard firewall/UTM appliance
Monitoring Examples
No specific object/table names were supplied for this MIB beyond its relationship to the base IETF IPsec monitoring draft, so exact OIDs cannot be cited. Based on its stated purpose, an admin would typically extend a poll of the base IPsec SA table with this module's tunnel-lifetime and rekey-count extension objects to see how close a given VPN tunnel's security association is to expiring and how many rekey events have occurred. A rising rekey-failure count or an SA nearing its lifetime limit without a successful rekey would flag a tunnel at risk of dropping.
What Can Be Monitored
- IPsec tunnel lifetime remaining
- rekeying event count
- IPsec security association state
- rekey success/failure
This MIB depends on
- IPSEC-ISAKMP-IKE-DOI-TC
- RFC1213-MIB
- SNMPv2-SMI
- SNMPv2-TC
- WATCHGUARD-MIB
Related MIBs
Imported Objects
From RFC1213-MIB
| ifIndex |
From SNMPv2-SMI
| Counter32 | |
| Gauge32 | |
| Integer32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-IDENTITY | |
| OBJECT-TYPE | |
| enterprises |
From SNMPv2-TC
| TEXTUAL-CONVENTION | |
| TruthValue |
From WATCHGUARD-MIB
| watchguard | OBJECT-IDENTITY |
How to Use in IPNetwork Monitor
Example using wgIpsecEspTotalInboundSAs OID:
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| G32 wgIpsecAhCurrentInboundSAs | 1.3.6.1.4.1.3097.3.1.2.5 | Gauge32 | read-only | The current number of inbound AH SAs in the entity. |
| G32 wgIpsecAhCurrentOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.7 | Gauge32 | read-only | The current number of outbound AH SAs in the entity. |
| C32 wgIpsecAhTotalInboundSAs | 1.3.6.1.4.1.3097.3.1.2.6 | Counter32 | read-only | The total number of inbound AH SAs created in the entity since boot time. |
| C32 wgIpsecAhTotalOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.8 | Counter32 | read-only | The total number of outbound AH SAs created in the entity since boot time. |
| C32 wgIpsecAuthenticationErrors | 1.3.6.1.4.1.3097.3.1.3.2 | Counter32 | read-only | The total number of packets received by the entity in SAs since boot time with authentication errors. This includes all packets in which the hash value is determined to be invalid, for both ESP and AH SAs. |
| C32 wgIpsecDecryptionErrors | 1.3.6.1.4.1.3097.3.1.3.1 | Counter32 | read-only | The total number of packets received by the entity in SAs since boot time with decryption errors. |
| G32 wgIpsecEspCurrentInboundSAs | 1.3.6.1.4.1.3097.3.1.2.1 | Gauge32 | read-only | The current number of inbound ESP SAs in the entity. |
| G32 wgIpsecEspCurrentOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.3 | Gauge32 | read-only | The current number of outbound ESP SAs in the entity. |
| C32 wgIpsecEspTotalInboundSAsEx | 1.3.6.1.4.1.3097.3.1.2.2 | Counter32 | read-only | The total number of inbound ESP SAs created in the entity since boot time. |
| C32 wgIpsecEspTotalOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.4 | Counter32 | read-only | The total number of outbound ESP SAs created in the entity since boot time. |
| G32 wgIpsecIpcompCurrentInboundSAs | 1.3.6.1.4.1.3097.3.1.2.9 | Gauge32 | read-only | The current number of inbound IPCOMP SAs in the entity. |
| G32 wgIpsecIpcompCurrentOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.11 | Gauge32 | read-only | The current number of outbound IPCOMP SAs in the entity. |
| C32 wgIpsecIpcompTotalInboundSAs | 1.3.6.1.4.1.3097.3.1.2.10 | Counter32 | read-only | The total number of inbound IPCOMP SAs created in the entity since boot time. |
| C32 wgIpsecIpcompTotalOutboundSAs | 1.3.6.1.4.1.3097.3.1.2.12 | Counter32 | read-only | The total number of outbound IPCOMP SAs created in the entity since boot time. |
| C32 wgIpsecOtherReceiveErrors | 1.3.6.1.4.1.3097.3.1.3.5 | Counter32 | read-only | The total number of packets received by the entity in SAs since boot time and discarded due to errors not due to decryption, authentication, replay or policy. |
| C32 wgIpsecPolicyErrors | 1.3.6.1.4.1.3097.3.1.3.4 | Counter32 | read-only | The total number of packets received by the entity in SAs since boot time and discarded due to policy errors. This includes packets that had selectors that were invalid for the SA that carried them. |
| C32 wgIpsecReplayErrors | 1.3.6.1.4.1.3097.3.1.3.3 | Counter32 | read-only | The total number of packets received by the entity in SAs since boot time with replay errors. |
| C32 wgIpsecSaAhInAccKbytes | 1.3.6.1.4.1.3097.3.1.1.2.1.16 | Counter32 | read-only | The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic. |
| C32 wgIpsecSaAhInAccSeconds | 1.3.6.1.4.1.3097.3.1.1.2.1.15 | Counter32 | read-only | The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed. |
| IP wgIpsecSaAhInAddress | 1.3.6.1.4.1.3097.3.1.1.2.1.1 | IpAddress | read-only | The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaAhInAuthAlg | 1.3.6.1.4.1.3097.3.1.1.2.1.12 | IpsecDoiAhTransform | read-only | A unique value representing the hash algorithm applied to traffic carried by this SA if it uses ESP or 0 if there is no authentication applied by ESP. |
| C32 wgIpsecSaAhInAuthErrors | 1.3.6.1.4.1.3097.3.1.1.2.1.19 | Counter32 | read-only | The number of packets discarded by the SA due to authentication errors. |
| IPS wgIpsecSaAhInCreator | 1.3.6.1.4.1.3097.3.1.1.2.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| OCT wgIpsecSaAhInDestId | 1.3.6.1.4.1.3097.3.1.1.2.1.3 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation. |
| IPS wgIpsecSaAhInDestIdType | 1.3.6.1.4.1.3097.3.1.1.2.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaAhInDestId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaAhInDestPort | 1.3.6.1.4.1.3097.3.1.1.2.1.8 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaAhInEncapsulation | 1.3.6.1.4.1.3097.3.1.1.2.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| wgIpsecSaAhInEntry | 1.3.6.1.4.1.3097.3.1.1.2.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec inbound AH SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| I32 wgIpsecSaAhInLimitKbytes | 1.3.6.1.4.1.3097.3.1.1.2.1.14 | Integer32 | read-only | The maximum traffic in Kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated. |
| I32 wgIpsecSaAhInLimitSeconds | 1.3.6.1.4.1.3097.3.1.1.2.1.13 | Integer32 | read-only | The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated. |
| C32 wgIpsecSaAhInOtherReceiveErrors | 1.3.6.1.4.1.3097.3.1.1.2.1.22 | Counter32 | read-only | The number of packets discarded by the SA due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the authentication element. |
| C32 wgIpsecSaAhInPackets | 1.3.6.1.4.1.3097.3.1.1.2.1.18 | Counter32 | read-only | The number of packets handled by the SA. |
| C32 wgIpsecSaAhInPolicyErrors | 1.3.6.1.4.1.3097.3.1.1.2.1.21 | Counter32 | read-only | The number of packets discarded by the SA due to policy errors. This includes packets where the next protocol is invalid. |
| I32 wgIpsecSaAhInProtocol | 1.3.6.1.4.1.3097.3.1.1.2.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaAhInReplayErrors | 1.3.6.1.4.1.3097.3.1.1.2.1.20 | Counter32 | read-only | The number of packets discarded by the SA due to replay errors. |
| OCT wgIpsecSaAhInSourceId | 1.3.6.1.4.1.3097.3.1.1.2.1.5 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation. |
| IPS wgIpsecSaAhInSourceIdType | 1.3.6.1.4.1.3097.3.1.1.2.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaAhInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaAhInSourcePort | 1.3.6.1.4.1.3097.3.1.1.2.1.9 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| I32 wgIpsecSaAhInSpi | 1.3.6.1.4.1.3097.3.1.1.2.1.2 | Integer32 | read-only | The security parameters index of the SA. |
| wgIpsecSaAhInTable | 1.3.6.1.4.1.3097.3.1.1.2 | not-accessible | The (conceptual) table containing information on IPSec inbound AH SAs. There should be one row for every inbound AH security association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaAhInUserOctets | 1.3.6.1.4.1.3097.3.1.1.2.1.17 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit. |
| C32 wgIpsecSaAhOutAccKbytes | 1.3.6.1.4.1.3097.3.1.1.5.1.16 | Counter32 | read-only | The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic. |
| C32 wgIpsecSaAhOutAccSeconds | 1.3.6.1.4.1.3097.3.1.1.5.1.15 | Counter32 | read-only | The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed. |
| IP wgIpsecSaAhOutAddress | 1.3.6.1.4.1.3097.3.1.1.5.1.1 | IpAddress | read-only | The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaAhOutAuthAlg | 1.3.6.1.4.1.3097.3.1.1.5.1.12 | IpsecDoiAhTransform | read-only | A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used. |
| IPS wgIpsecSaAhOutCreator | 1.3.6.1.4.1.3097.3.1.1.5.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| OCT wgIpsecSaAhOutDestId | 1.3.6.1.4.1.3097.3.1.1.5.1.5 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaAhOutDestIdType | 1.3.6.1.4.1.3097.3.1.1.5.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaAhOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaAhOutDestPort | 1.3.6.1.4.1.3097.3.1.1.5.1.9 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaAhOutEncapsulation | 1.3.6.1.4.1.3097.3.1.1.5.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| wgIpsecSaAhOutEntry | 1.3.6.1.4.1.3097.3.1.1.5.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec Outbound AH SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| I32 wgIpsecSaAhOutLimitKbytes | 1.3.6.1.4.1.3097.3.1.1.5.1.14 | Integer32 | read-only | The maximum traffic in Kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated. |
| I32 wgIpsecSaAhOutLimitSeconds | 1.3.6.1.4.1.3097.3.1.1.5.1.13 | Integer32 | read-only | The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated. |
| C32 wgIpsecSaAhOutPackets | 1.3.6.1.4.1.3097.3.1.1.5.1.18 | Counter32 | read-only | The number of packets handled by the SA. |
| I32 wgIpsecSaAhOutProtocol | 1.3.6.1.4.1.3097.3.1.1.5.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaAhOutSendErrors | 1.3.6.1.4.1.3097.3.1.1.5.1.19 | Counter32 | read-only | The number of packets discarded by the SA due to any error. This may include errors due to a lack of transmit buffers. |
| OCT wgIpsecSaAhOutSourceId | 1.3.6.1.4.1.3097.3.1.1.5.1.3 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaAhOutSourceIdType | 1.3.6.1.4.1.3097.3.1.1.5.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaAhOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaAhOutSourcePort | 1.3.6.1.4.1.3097.3.1.1.5.1.8 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| I32 wgIpsecSaAhOutSpi | 1.3.6.1.4.1.3097.3.1.1.5.1.2 | Integer32 | read-only | The security parameters index of the SA. |
| wgIpsecSaAhOutTable | 1.3.6.1.4.1.3097.3.1.1.5 | not-accessible | The (conceptual) table containing information on IPSec Outbound AH SAs. There should be one row for every outbound AH security association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaAhOutUserOctets | 1.3.6.1.4.1.3097.3.1.1.5.1.17 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit. |
| C32 wgIpsecSaEspInAccKbytes | 1.3.6.1.4.1.3097.3.1.1.1.1.18 | Counter32 | read-only | The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic. |
| C32 wgIpsecSaEspInAccSeconds | 1.3.6.1.4.1.3097.3.1.1.1.1.17 | Counter32 | read-only | The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed. |
| IP wgIpsecSaEspInAddress | 1.3.6.1.4.1.3097.3.1.1.1.1.1 | IpAddress | read-only | The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaEspInAuthAlg | 1.3.6.1.4.1.3097.3.1.1.1.1.14 | IpsecDoiAuthAlgorithm | read-only | A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used. |
| C32 wgIpsecSaEspInAuthErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.22 | Counter32 | read-only | The number of packets discarded by the SA due to authentication errors. |
| IPS wgIpsecSaEspInCreator | 1.3.6.1.4.1.3097.3.1.1.1.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| C32 wgIpsecSaEspInDecryptErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.21 | Counter32 | read-only | The number of packets discarded by the SA due to decryption errors. |
| OCT wgIpsecSaEspInDestId | 1.3.6.1.4.1.3097.3.1.1.1.1.3 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchanged during SA creation negotiation. |
| IPS wgIpsecSaEspInDestIdType | 1.3.6.1.4.1.3097.3.1.1.1.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaEspInDestId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaEspInDestPort | 1.3.6.1.4.1.3097.3.1.1.1.1.8 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaEspInEncAlg | 1.3.6.1.4.1.3097.3.1.1.1.1.12 | IpsecDoiEspTransform | read-only | A unique value representing the encryption algorithm applied to traffic or 0 if there is no encryption used. |
| IPS wgIpsecSaEspInEncapsulation | 1.3.6.1.4.1.3097.3.1.1.1.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| I32 wgIpsecSaEspInEncKeyLength | 1.3.6.1.4.1.3097.3.1.1.1.1.13 | Integer32 | read-only | The length of the encryption key in bits used for the algorithm specified in the 'wgIpsecSaEspInEncAlg' object, or 0 if the key length is implicit in the specified algorithm or there is no encryption specified. |
| wgIpsecSaEspInEntry | 1.3.6.1.4.1.3097.3.1.1.1.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec inbound ESP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| I32 wgIpsecSaEspInLimitKbytes | 1.3.6.1.4.1.3097.3.1.1.1.1.16 | Integer32 | read-only | The maximum traffic in kilobytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated. |
| I32 wgIpsecSaEspInLimitSeconds | 1.3.6.1.4.1.3097.3.1.1.1.1.15 | Integer32 | read-only | The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated. |
| C32 wgIpsecSaEspInOtherReceiveErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.26 | Counter32 | read-only | The number of packets discarded by the SA due to errors other than decryption, authentication or replay errors. This may include packets dropped due to a lack of receive buffers, and may include packets dropped due to congestion at the decryption element. |
| C32 wgIpsecSaEspInPackets | 1.3.6.1.4.1.3097.3.1.1.1.1.20 | Counter32 | read-only | The number of packets handled by the SA. |
| C32 wgIpsecSaEspInPadErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.25 | Counter32 | read-only | The number of packets discarded by the SA due to pad value errors. Implementations that do not check this must not support this object. |
| C32 wgIpsecSaEspInPolicyErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.24 | Counter32 | read-only | The number of packets discarded by the SA due to policy errors. This includes packets where the next protocol is invalid. |
| I32 wgIpsecSaEspInProtocol | 1.3.6.1.4.1.3097.3.1.1.1.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaEspInReplayErrors | 1.3.6.1.4.1.3097.3.1.1.1.1.23 | Counter32 | read-only | The number of packets discarded by the SA due to replay errors. |
| OCT wgIpsecSaEspInSourceId | 1.3.6.1.4.1.3097.3.1.1.1.1.5 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during SA creation negotiation. |
| IPS wgIpsecSaEspInSourceIdType | 1.3.6.1.4.1.3097.3.1.1.1.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaEspInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaEspInSourcePort | 1.3.6.1.4.1.3097.3.1.1.1.1.9 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| I32 wgIpsecSaEspInSpi | 1.3.6.1.4.1.3097.3.1.1.1.1.2 | Integer32 | read-only | The security parameters index of the SA. |
| wgIpsecSaEspInTable | 1.3.6.1.4.1.3097.3.1.1.1 | not-accessible | The (conceptual) table containing information on IPSec inbound ESP SAs. There should be one row for every inbound ESP security association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaEspInUserOctets | 1.3.6.1.4.1.3097.3.1.1.1.1.19 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit. |
| C32 wgIpsecSaEspOutAccKbytes | 1.3.6.1.4.1.3097.3.1.1.4.1.18 | Counter32 | read-only | The amount of traffic accumulated that counts against the SA's expiration by traffic limitation, measured in Kbytes. This value may be 0 if the SA does not expire based on traffic. |
| C32 wgIpsecSaEspOutAccSeconds | 1.3.6.1.4.1.3097.3.1.1.4.1.17 | Counter32 | read-only | The number of seconds accumulated against the SA's expiration by time. This is also the number of seconds that the SA has existed. |
| IP wgIpsecSaEspOutAddress | 1.3.6.1.4.1.3097.3.1.1.4.1.1 | IpAddress | read-only | The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaEspOutAuthAlg | 1.3.6.1.4.1.3097.3.1.1.4.1.14 | IpsecDoiAuthAlgorithm | read-only | A unique value representing the hash algorithm applied to traffic or 0 if there is no authentication used. |
| IPS wgIpsecSaEspOutCreator | 1.3.6.1.4.1.3097.3.1.1.4.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| OCT wgIpsecSaEspOutDestId | 1.3.6.1.4.1.3097.3.1.1.4.1.5 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaEspOutDestIdType | 1.3.6.1.4.1.3097.3.1.1.4.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaEspOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaEspOutDestPort | 1.3.6.1.4.1.3097.3.1.1.4.1.9 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaEspOutEncAlg | 1.3.6.1.4.1.3097.3.1.1.4.1.12 | IpsecDoiEspTransform | read-only | A unique value representing the encryption algorithm applied to traffic or 0 if there is no encryption used. |
| IPS wgIpsecSaEspOutEncapsulation | 1.3.6.1.4.1.3097.3.1.1.4.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| I32 wgIpsecSaEspOutEncKeyLength | 1.3.6.1.4.1.3097.3.1.1.4.1.13 | Integer32 | read-only | The length of the encryption key in bits used for the algorithm specified in the 'wgIpsecSaEspOutEncAlg' object, or 0 if the key length is implicit in the specified algorithm or there is no encryption specified. |
| wgIpsecSaEspOutEntry | 1.3.6.1.4.1.3097.3.1.1.4.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec Outbound ESP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| I32 wgIpsecSaEspOutLimitKbytes | 1.3.6.1.4.1.3097.3.1.1.4.1.16 | Integer32 | read-only | The maximum traffic in kbytes that the SA is allowed to support, or 0 if there is no traffic constraint on its expiration. The display value is limited to 4294967295 kilobytes; values greater than that value will be truncated. |
| I32 wgIpsecSaEspOutLimitSeconds | 1.3.6.1.4.1.3097.3.1.1.4.1.15 | Integer32 | read-only | The maximum lifetime in seconds of the SA, or 0 if there is no time constraint on its expiration. The display value is limited to 4294967295 seconds (more than 136 years); values greater than that value will be truncated. |
| C32 wgIpsecSaEspOutPackets | 1.3.6.1.4.1.3097.3.1.1.4.1.20 | Counter32 | read-only | The number of packets handled by the SA. |
| I32 wgIpsecSaEspOutProtocol | 1.3.6.1.4.1.3097.3.1.1.4.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaEspOutSendErrors | 1.3.6.1.4.1.3097.3.1.1.4.1.21 | Counter32 | read-only | The number of packets discarded by the SA due to any error. This may include errors due to a lack of transmit buffers. |
| OCT wgIpsecSaEspOutSourceId | 1.3.6.1.4.1.3097.3.1.1.4.1.3 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation. This value is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaEspOutSourceIdType | 1.3.6.1.4.1.3097.3.1.1.4.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaEspOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation. |
| I32 wgIpsecSaEspOutSourcePort | 1.3.6.1.4.1.3097.3.1.1.4.1.8 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| I32 wgIpsecSaEspOutSpi | 1.3.6.1.4.1.3097.3.1.1.4.1.2 | Integer32 | read-only | The security parameters index of the SA. |
| wgIpsecSaEspOutTable | 1.3.6.1.4.1.3097.3.1.1.4 | not-accessible | The (conceptual) table containing information on IPSec Outbound ESP SAs. There should be one row for every outbound ESP security association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaEspOutUserOctets | 1.3.6.1.4.1.3097.3.1.1.4.1.19 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit. |
| IP wgIpsecSaIpcompInAddress | 1.3.6.1.4.1.3097.3.1.1.3.1.1 | IpAddress | read-only | The destination address of the SA. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaIpcompInCpi | 1.3.6.1.4.1.3097.3.1.1.3.1.2 | IpsecDoiIpcompTransform | read-only | The CPI of the SA. Since the lower values of CPIs are reserved to be the same as the algorithm, the syntax for this object is the same as the transform. |
| IPS wgIpsecSaIpcompInCreator | 1.3.6.1.4.1.3097.3.1.1.3.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| IPS wgIpsecSaIpcompInDecompAlg | 1.3.6.1.4.1.3097.3.1.1.3.1.12 | IpsecDoiIpcompTransform | read-only | A unique value representing the decompression algorithm applied to traffic. |
| C32 wgIpsecSaIpcompInDecompErrors | 1.3.6.1.4.1.3097.3.1.1.3.1.16 | Counter32 | read-only | The number of packets discarded by the SA due to decompression errors. |
| OCT wgIpsecSaIpcompInDestId | 1.3.6.1.4.1.3097.3.1.1.3.1.3 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during SA creation negotiation. |
| IPS wgIpsecSaIpcompInDestIdType | 1.3.6.1.4.1.3097.3.1.1.3.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaIpcompInDestId', or 0 if unknown or if the SA uses transport mode, or 0 if this SA is used with multiple SAs in protection suites. |
| I32 wgIpsecSaIpcompInDestPort | 1.3.6.1.4.1.3097.3.1.1.3.1.8 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaIpcompInEncapsulation | 1.3.6.1.4.1.3097.3.1.1.3.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| wgIpsecSaIpcompInEntry | 1.3.6.1.4.1.3097.3.1.1.3.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec inbound IPCOMP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| C32 wgIpsecSaIpcompInOtherReceiveErrors | 1.3.6.1.4.1.3097.3.1.1.3.1.17 | Counter32 | read-only | The number of packets discarded by the SA due to errors other than decompression errors. This may include packets dropped due to a lack of receive buffers, and packets dropped due to congestion at the decompression element. |
| C32 wgIpsecSaIpcompInPackets | 1.3.6.1.4.1.3097.3.1.1.3.1.15 | Counter32 | read-only | The number of packets handled by the SA. |
| I32 wgIpsecSaIpcompInProtocol | 1.3.6.1.4.1.3097.3.1.1.3.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaIpcompInSeconds | 1.3.6.1.4.1.3097.3.1.1.3.1.13 | Counter32 | read-only | The number of seconds that the SA has existed. |
| OCT wgIpsecSaIpcompInSourceId | 1.3.6.1.4.1.3097.3.1.1.3.1.5 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during SA creation negotiation. |
| IPS wgIpsecSaIpcompInSourceIdType | 1.3.6.1.4.1.3097.3.1.1.3.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaIpcompInSourceId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. |
| I32 wgIpsecSaIpcompInSourcePort | 1.3.6.1.4.1.3097.3.1.1.3.1.9 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| wgIpsecSaIpcompInTable | 1.3.6.1.4.1.3097.3.1.1.3 | not-accessible | The (conceptual) table containing information on IPSec inbound IPCOMP SAs. There should be one row for every inbound IPCOMP (security) association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaIpcompInUserOctets | 1.3.6.1.4.1.3097.3.1.1.3.1.14 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. |
| IP wgIpsecSaIpcompOutAddress | 1.3.6.1.4.1.3097.3.1.1.6.1.1 | IpAddress | read-only | The destination address of the SA. If the IPCOMP SA is shared across multiple SAs in protection suites, this value may be 0. For implementations that do not support IPv6, this address should appear as one of the IPv4-mapped IPv6 addresses as defined in Section 2.5.4 of [IPV6AA]. Specifically, the prefix '0000:0000:0000:0000:0000:FFFF:' is used for IPv4 only nodes, while the prefix '0000:0000:0000:0000:0000:0000:' is used for bi-lingual nodes. |
| IPS wgIpsecSaIpcompOutCompAlg | 1.3.6.1.4.1.3097.3.1.1.6.1.12 | IpsecDoiIpcompTransform | read-only | A unique value representing the compression algorithm applied to traffic. |
| IPS wgIpsecSaIpcompOutCpi | 1.3.6.1.4.1.3097.3.1.1.6.1.2 | IpsecDoiIpcompTransform | read-only | The CPI of the SA. Since the lower values of CPIs are reserved to be the same as the algorithm, the syntax for this object is the same as the transform. |
| IPS wgIpsecSaIpcompOutCreator | 1.3.6.1.4.1.3097.3.1.1.6.1.10 | IpsecSaCreatorIdent | read-only | The creator of this SA. This MIB makes no assumptions about how the SAs are created. They may be created statically, or by a key exchange protocol such as IKE, or by some other method. |
| OCT wgIpsecSaIpcompOutDestId | 1.3.6.1.4.1.3097.3.1.1.6.1.5 | OCTET STRING | read-only | The destination identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaIpcompOutDestIdType | 1.3.6.1.4.1.3097.3.1.1.6.1.6 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaIpcompOutDestId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. |
| I32 wgIpsecSaIpcompOutDestPort | 1.3.6.1.4.1.3097.3.1.1.6.1.9 | Integer32 | read-only | The destination port number of the protocol that this SA carries, or 0 if it carries any port number. |
| IPS wgIpsecSaIpcompOutEncapsulation | 1.3.6.1.4.1.3097.3.1.1.6.1.11 | IpsecDoiEncapsulationMode | read-only | The type of encapsulation used by this SA. |
| wgIpsecSaIpcompOutEntry | 1.3.6.1.4.1.3097.3.1.1.6.1 | not-accessible | An entry (conceptual row) containing the information on a particular IPSec Outbound IPCOMP SA. A row in this table cannot be created or deleted by SNMP operations on columns of the table. | |
| C32 wgIpsecSaIpcompOutPackets | 1.3.6.1.4.1.3097.3.1.1.6.1.15 | Counter32 | read-only | The number of packets handled by the SA. |
| I32 wgIpsecSaIpcompOutProtocol | 1.3.6.1.4.1.3097.3.1.1.6.1.7 | Integer32 | read-only | The transport-layer protocol number that this SA carries, or 0 if it carries any protocol. |
| C32 wgIpsecSaIpcompOutSeconds | 1.3.6.1.4.1.3097.3.1.1.6.1.13 | Counter32 | read-only | The number of seconds that the SA has existed. |
| OCT wgIpsecSaIpcompOutSourceId | 1.3.6.1.4.1.3097.3.1.1.6.1.3 | OCTET STRING | read-only | The source identifier of the SA, or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. This value, if non-zero, is taken directly from the optional ID payloads that are exchange during phase 2 negotiations. |
| IPS wgIpsecSaIpcompOutSourceIdType | 1.3.6.1.4.1.3097.3.1.1.6.1.4 | IpsecDoiIdentType | read-only | The type of identifier presented by 'wgIpsecSaIpcompOutSourceId', or 0 if unknown or if the SA uses transport mode encapsulation, or 0 if this SA is used with multiple SAs in protection suites. |
| I32 wgIpsecSaIpcompOutSourcePort | 1.3.6.1.4.1.3097.3.1.1.6.1.8 | Integer32 | read-only | The source port number of the protocol that this SA carries, or 0 if it carries any port number. |
| wgIpsecSaIpcompOutTable | 1.3.6.1.4.1.3097.3.1.1.6 | not-accessible | The (conceptual) table containing information on IPSec Outbound IPCOMP SAs. There should be one row for every outbound IPCOMP (security) association that exists in the entity. The maximum number of rows is implementation dependent. | |
| C32 wgIpsecSaIpcompOutUserOctets | 1.3.6.1.4.1.3097.3.1.1.6.1.14 | Counter32 | read-only | The amount of user level traffic measured in bytes handled by the SA. This is not necessarily the same as the amount of traffic applied against the traffic expiration limit. |
| wgIpsecSaMonitorMIB | 1.3.6.1.4.1.3097.3.1 | This is the base object identifier for all IPSec branches. | ||
| wgIpsecSaMonModule | 1.3.6.1.4.1.3097.3 | The MIB module describes generic IPSec objects defined in IETF working draft 'draft-ieft-ipsec-monitor-mib-01' and WatchGuard's extension. | ||
| C32 wgIpsecSendErrors | 1.3.6.1.4.1.3097.3.1.3.6 | Counter32 | read-only | The total number of packets to be sent by the entity in SAs since boot time and discarded due to errors. |
| C32 wgIpsecUnknownSpiErrors | 1.3.6.1.4.1.3097.3.1.3.7 | Counter32 | read-only | The total number of packets received by the entity since boot time with SPIs or CPIs that were not valid. |
| wgSaErrors | 1.3.6.1.4.1.3097.3.1.3 | This is the base object identifier for all objects which are global error counters for IPSec security associations. | ||
| wgSaStatistics | 1.3.6.1.4.1.3097.3.1.2 | This is the base object identifier for all objects which are global counters for IPSec security associations. | ||
| wgSaTables | 1.3.6.1.4.1.3097.3.1.1 | This is the base object identifier for all SA tables. |
RFC description
WatchGuard IPSec Security Association monitoring MIB extension extending IPSec SA monitoring with WatchGuard-specific metrics for firewall security associations (vendor-private extension).
Start monitoring WatchGuard firewall/UTM appliance (IPsec tunnel rekey/lifetime status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.