<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO-IPSEC-FLOW-MONITOR-MIB in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556341#M922707</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if there's a way for you to check. I was one of the reviewers when the IPSec MIB was initially implemented, and I remember those traps were defined but not implemented at the time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Oct 2010 13:56:36 GMT</pubDate>
    <dc:creator>wzhang</dc:creator>
    <dc:date>2010-10-27T13:56:36Z</dc:date>
    <item>
      <title>CISCO-IPSEC-FLOW-MONITOR-MIB</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556338#M922702</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 7600 used for ipsec encryption.&lt;/P&gt;&lt;P&gt;I would like to catch the ipsec related trap but the cisco documentation is incomplete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance let's consider the "&lt;STRONG&gt;cipSecTunnelStart&lt;/STRONG&gt;" trap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the cisco web site&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=cipSecTunnelStart&amp;amp;translate=Translate&amp;amp;submitValue=SUBMIT&amp;amp;submitClicked=true" target="_blank"&gt;http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=cipSecTunnelStart&amp;amp;translate=Translate&amp;amp;submitValue=SUBMIT&amp;amp;submitClicked=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;it says it has two Components: &lt;SPAN style="text-decoration: underline;"&gt;cipSecTunLifeTime&lt;/SPAN&gt; &amp;amp; &lt;SPAN style="text-decoration: underline;"&gt;cipSecTunLifeSize &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;while if I run a "debug snmp packet" on the machine I have the following output:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; sysUpTime.0 = 371592487 &lt;BR /&gt; snmpTrapOID.0 = cipSecTunnelStart &lt;BR /&gt; cipSecTunLifeTime.7 = 3600 &lt;BR /&gt; cipSecTunLifeSize.7 = 4508392 &lt;BR /&gt; cipSecEndPtLocalType.7.1 = 1 &lt;BR /&gt; cipSecEndPtLocalAddr1.7.1 = 0C 11&amp;nbsp; aa E6&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; cipSecEndPtLocalAddr2.7.1 = 0C 11&amp;nbsp; aa E6&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; cipSecEndPtRemoteType.7.1 = 1 &lt;BR /&gt; cipSecEndPtRemoteAddr1.7.1 = 0C 02&amp;nbsp; bb F2&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; cipSecEndPtRemoteAddr2.7.1 = 0C 02&amp;nbsp; bb F2&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; cipSecEndPtLocalProtocol.7.1 = 47 &lt;BR /&gt; cipSecEndPtLocalPort.7.1 = 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;which gives more useful informations for the tunnel identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know the real strucutre of other traps like &lt;STRONG&gt;cipSecEarlyTunTerm &lt;/STRONG&gt;(&lt;EM&gt;"This notification is generated when an an IPsec Phase-2 Tunnel is terminated earily or before expected."&lt;/EM&gt;)&lt;STRONG&gt; &lt;/STRONG&gt;and &lt;STRONG&gt;cipSecProtocolFailure&lt;/STRONG&gt; (&lt;EM&gt;"This notification is generated when the processing for an IPsec Phase-2 Tunnel experiences a protocol related error."&lt;/EM&gt;)&lt;STRONG&gt; &lt;/STRONG&gt;but I am not able to force their generation from the command line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how to force their generation?&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;Do you know where can I find informations about the real trap returned value?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556338#M922702</guid>
      <dc:creator>lemmocisco</dc:creator>
      <dc:date>2020-02-21T12:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO-IPSEC-FLOW-MONITOR-MIB</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556339#M922704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know, &lt;STRONG&gt;cipSecEarlyTunTerm &lt;/STRONG&gt;&lt;SPAN&gt;and&lt;/SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;cipSecProtocolFailure&lt;/STRONG&gt; traps are not sent in IOS today. Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 14:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556339#M922704</guid>
      <dc:creator>wzhang</dc:creator>
      <dc:date>2010-10-20T14:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO-IPSEC-FLOW-MONITOR-MIB</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556340#M922705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for answering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how I can check wheter they are implemented or not?&lt;/P&gt;&lt;P&gt;I tried the "&lt;SPAN style="color: #333333; text-decoration: underline; "&gt;show snmp mib&lt;/SPAN&gt;" command but id doesn't even show up the "&lt;STRONG&gt;cipSecTunnelStart&lt;/STRONG&gt;" mib&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the output of all the lines brginning with cipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;cipSecMibLevel&lt;BR /&gt;cipSecGlobalActiveTunnels&lt;BR /&gt;cipSecGlobalPreviousTunnels&lt;BR /&gt;cipSecGlobalInOctets&lt;BR /&gt;cipSecGlobalHcInOctets&lt;BR /&gt;cipSecGlobalInOctWraps&lt;BR /&gt;cipSecGlobalInDecompOctets&lt;BR /&gt;cipSecGlobalHcInDecompOctets&lt;BR /&gt;cipSecGlobalInDecompOctWraps&lt;BR /&gt;cipSecGlobalInPkts&lt;BR /&gt;cipSecGlobalInDrops&lt;BR /&gt;cipSecGlobalInReplayDrops&lt;BR /&gt;cipSecGlobalInAuths&lt;BR /&gt;cipSecGlobalInAuthFails&lt;BR /&gt;cipSecGlobalInDecrypts&lt;BR /&gt;cipSecGlobalInDecryptFails&lt;BR /&gt;cipSecGlobalOutOctets&lt;BR /&gt;cipSecGlobalHcOutOctets&lt;BR /&gt;cipSecGlobalOutOctWraps&lt;BR /&gt;cipSecGlobalOutUncompOctets&lt;BR /&gt;cipSecGlobalHcOutUncompOctets&lt;BR /&gt;cipSecGlobalOutUncompOctWraps&lt;BR /&gt;cipSecGlobalOutPkts&lt;BR /&gt;cipSecGlobalOutDrops&lt;BR /&gt;cipSecGlobalOutAuths&lt;BR /&gt;cipSecGlobalOutAuthFails&lt;BR /&gt;cipSecGlobalOutEncrypts&lt;BR /&gt;cipSecGlobalOutEncryptFails&lt;BR /&gt;cipSecGlobalProtocolUseFails&lt;BR /&gt;cipSecGlobalNoSaFails&lt;BR /&gt;cipSecGlobalSysCapFails&lt;BR /&gt;cipSecTunIkeTunnelIndex&lt;BR /&gt;cipSecTunIkeTunnelAlive&lt;BR /&gt;cipSecTunLocalAddr&lt;BR /&gt;cipSecTunRemoteAddr&lt;BR /&gt;cipSecTunKeyType&lt;BR /&gt;cipSecTunEncapMode&lt;BR /&gt;cipSecTunLifeSize&lt;BR /&gt;cipSecTunLifeTime&lt;BR /&gt;cipSecTunActiveTime&lt;BR /&gt;cipSecTunSaLifeSizeThreshold&lt;BR /&gt;cipSecTunSaLifeTimeThreshold&lt;BR /&gt;cipSecTunTotalRefreshes&lt;BR /&gt;cipSecTunExpiredSaInstances&lt;BR /&gt;cipSecTunCurrentSaInstances&lt;BR /&gt;cipSecTunInSaDiffHellmanGrp&lt;BR /&gt;cipSecTunInSaEncryptAlgo&lt;BR /&gt;cipSecTunInSaAhAuthAlgo&lt;BR /&gt;cipSecTunInSaEspAuthAlgo&lt;BR /&gt;cipSecTunInSaDecompAlgo&lt;BR /&gt;cipSecTunOutSaDiffHellmanGrp&lt;BR /&gt;cipSecTunOutSaEncryptAlgo&lt;BR /&gt;cipSecTunOutSaAhAuthAlgo&lt;BR /&gt;cipSecTunOutSaEspAuthAlgo&lt;BR /&gt;cipSecTunOutSaCompAlgo&lt;BR /&gt;cipSecTunInOctets&lt;BR /&gt;cipSecTunHcInOctets&lt;BR /&gt;cipSecTunInOctWraps&lt;BR /&gt;cipSecTunInDecompOctets&lt;BR /&gt;cipSecTunHcInDecompOctets&lt;BR /&gt;cipSecTunInDecompOctWraps&lt;BR /&gt;cipSecTunInPkts&lt;BR /&gt;cipSecTunInDropPkts&lt;BR /&gt;cipSecTunInReplayDropPkts&lt;BR /&gt;cipSecTunInAuths&lt;BR /&gt;cipSecTunInAuthFails&lt;BR /&gt;cipSecTunInDecrypts&lt;BR /&gt;cipSecTunInDecryptFails&lt;BR /&gt;cipSecTunOutOctets&lt;BR /&gt;cipSecTunHcOutOctets&lt;BR /&gt;cipSecTunOutOctWraps&lt;BR /&gt;cipSecTunOutUncompOctets&lt;BR /&gt;cipSecTunHcOutUncompOctets&lt;BR /&gt;cipSecTunOutUncompOctWraps&lt;BR /&gt;cipSecTunOutPkts&lt;BR /&gt;cipSecTunOutDropPkts&lt;BR /&gt;cipSecTunOutAuths&lt;BR /&gt;cipSecTunOutAuthFails&lt;BR /&gt;cipSecTunOutEncrypts&lt;BR /&gt;cipSecTunOutEncryptFails&lt;BR /&gt;cipSecTunStatus&lt;BR /&gt;cipSecEndPtLocalName&lt;BR /&gt;cipSecEndPtLocalType&lt;BR /&gt;cipSecEndPtLocalAddr1&lt;BR /&gt;cipSecEndPtLocalAddr2&lt;BR /&gt;cipSecEndPtLocalProtocol&lt;BR /&gt;cipSecEndPtLocalPort&lt;BR /&gt;cipSecEndPtRemoteName&lt;BR /&gt;cipSecEndPtRemoteType&lt;BR /&gt;cipSecEndPtRemoteAddr1&lt;BR /&gt;cipSecEndPtRemoteAddr2&lt;BR /&gt;cipSecEndPtRemoteProtocol&lt;BR /&gt;cipSecEndPtRemotePort&lt;BR /&gt;cipSecSpiDirection&lt;BR /&gt;cipSecSpiValue&lt;BR /&gt;cipSecSpiProtocol&lt;BR /&gt;cipSecSpiStatus&lt;BR /&gt;cipSecHistTableSize&lt;BR /&gt;cipSecHistCheckPoint&lt;BR /&gt;cipSecTunHistTermReason&lt;BR /&gt;cipSecTunHistActiveIndex&lt;BR /&gt;cipSecTunHistIkeTunnelIndex&lt;BR /&gt;cipSecTunHistLocalAddr&lt;BR /&gt;cipSecTunHistRemoteAddr&lt;BR /&gt;cipSecTunHistKeyType&lt;BR /&gt;cipSecTunHistEncapMode&lt;BR /&gt;cipSecTunHistLifeSize&lt;BR /&gt;cipSecTunHistLifeTime&lt;BR /&gt;cipSecTunHistStartTime&lt;BR /&gt;cipSecTunHistActiveTime&lt;BR /&gt;cipSecTunHistTotalRefreshes&lt;BR /&gt;cipSecTunHistTotalSas&lt;BR /&gt;cipSecTunHistInSaDiffHellmanGrp&lt;BR /&gt;cipSecTunHistInSaEncryptAlgo&lt;BR /&gt;cipSecTunHistInSaAhAuthAlgo&lt;BR /&gt;cipSecTunHistInSaEspAuthAlgo&lt;BR /&gt;cipSecTunHistInSaDecompAlgo&lt;BR /&gt;cipSecTunHistOutSaDiffHellmanGrp&lt;BR /&gt;cipSecTunHistOutSaEncryptAlgo&lt;BR /&gt;cipSecTunHistOutSaAhAuthAlgo&lt;BR /&gt;cipSecTunHistOutSaEspAuthAlgo&lt;BR /&gt;cipSecTunHistOutSaCompAlgo&lt;BR /&gt;cipSecTunHistInOctets&lt;BR /&gt;cipSecTunHistHcInOctets&lt;BR /&gt;cipSecTunHistInOctWraps&lt;BR /&gt;cipSecTunHistInDecompOctets&lt;BR /&gt;cipSecTunHistHcInDecompOctets&lt;BR /&gt;cipSecTunHistInDecompOctWraps&lt;BR /&gt;cipSecTunHistInPkts&lt;BR /&gt;cipSecTunHistInDropPkts&lt;BR /&gt;cipSecTunHistInReplayDropPkts&lt;BR /&gt;cipSecTunHistInAuths&lt;BR /&gt;cipSecTunHistInAuthFails&lt;BR /&gt;cipSecTunHistInDecrypts&lt;BR /&gt;cipSecTunHistInDecryptFails&lt;BR /&gt;cipSecTunHistOutOctets&lt;BR /&gt;cipSecTunHistHcOutOctets&lt;BR /&gt;cipSecTunHistOutOctWraps&lt;BR /&gt;cipSecTunHistOutUncompOctets&lt;BR /&gt;cipSecTunHistHcOutUncompOctets&lt;BR /&gt;cipSecTunHistOutUncompOctWraps&lt;BR /&gt;cipSecTunHistOutPkts&lt;BR /&gt;cipSecTunHistOutDropPkts&lt;BR /&gt;cipSecTunHistOutAuths&lt;BR /&gt;cipSecTunHistOutAuthFails&lt;BR /&gt;cipSecTunHistOutEncrypts&lt;BR /&gt;cipSecTunHistOutEncryptFails&lt;BR /&gt;cipSecEndPtHistTunIndex&lt;BR /&gt;cipSecEndPtHistActiveIndex&lt;BR /&gt;cipSecEndPtHistLocalName&lt;BR /&gt;cipSecEndPtHistLocalType&lt;BR /&gt;cipSecEndPtHistLocalAddr1&lt;BR /&gt;cipSecEndPtHistLocalAddr2&lt;BR /&gt;cipSecEndPtHistLocalProtocol&lt;BR /&gt;cipSecEndPtHistLocalPort&lt;BR /&gt;cipSecEndPtHistRemoteName&lt;BR /&gt;cipSecEndPtHistRemoteType&lt;BR /&gt;cipSecEndPtHistRemoteAddr1&lt;BR /&gt;cipSecEndPtHistRemoteAddr2&lt;BR /&gt;cipSecEndPtHistRemoteProtocol&lt;BR /&gt;cipSecEndPtHistRemotePort&lt;BR /&gt;cipSecFailTableSize&lt;BR /&gt;cipSecFailReason&lt;BR /&gt;cipSecFailTime&lt;BR /&gt;cipSecFailTunnelIndex&lt;BR /&gt;cipSecFailSaSpi&lt;BR /&gt;cipSecFailPktSrcAddr&lt;BR /&gt;cipSecFailPktDstAddr&lt;BR /&gt;cipSecTrapCntlIkeTunnelStart&lt;BR /&gt;cipSecTrapCntlIkeTunnelStop&lt;BR /&gt;cipSecTrapCntlIkeSysFailure&lt;BR /&gt;cipSecTrapCntlIkeCertCrlFailure&lt;BR /&gt;cipSecTrapCntlIkeProtocolFail&lt;BR /&gt;cipSecTrapCntlIkeNoSa&lt;BR /&gt;cipSecTrapCntlIpSecTunnelStart&lt;BR /&gt;cipSecTrapCntlIpSecTunnelStop&lt;BR /&gt;cipSecTrapCntlIpSecSysFailure&lt;BR /&gt;cipSecTrapCntlIpSecSetUpFailure&lt;BR /&gt;cipSecTrapCntlIpSecEarlyTunTerm&lt;BR /&gt;cipSecTrapCntlIpSecProtocolFail&lt;BR /&gt;cipSecTrapCntlIpSecNoSa&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 11:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556340#M922705</guid>
      <dc:creator>lemmocisco</dc:creator>
      <dc:date>2010-10-26T11:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO-IPSEC-FLOW-MONITOR-MIB</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556341#M922707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if there's a way for you to check. I was one of the reviewers when the IPSec MIB was initially implemented, and I remember those traps were defined but not implemented at the time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 13:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ipsec-flow-monitor-mib/m-p/1556341#M922707</guid>
      <dc:creator>wzhang</dc:creator>
      <dc:date>2010-10-27T13:56:36Z</dc:date>
    </item>
  </channel>
</rss>

