- Table of Contents
- Related Documents
-
| Title | Size | Download |
|---|---|---|
| 01-HH3C-IKE-MONITOR-MIB | 525.32 KB |
Contents
hh3cIKEGlobalInP2SaDelRequests
hh3cIKEGlobalOutP2ExchgRejects
hh3cIKEGlobalOutP2SaDelRequests
hh3cIKEGlobalInvalidCookieFails
hh3cIKEGlobalNoProposalChosenFails
hh3cIKEGlobalUnsportExchTypeFails
hh3cIKEGlobalCertTypeUnsuppFails
hh3cIKEGlobalInvalidCertAuthFails
hh3cIKEGlobalCertUnavailableFails
hh3cIKEInvalidProposalTrapCntl
hh3cIKEUnsportExchTypeTrapCntl
hh3cIKEInvalidProtocolTrapCntl
hh3cIKEInvalidCertAuthTrapCntl
hh3cIKECertUnavailableTrapCntl
HH3C-IKE-MONITOR-MIB
About this MIB
Use this MIB to obtain IKE monitor information, including IKE tunnel, IKE trap, and IKE MIB version information.
MIB file name
hh3c-ike-monitor.mib
Root object
iso(1).org(3).dod(6).internet(1).private(4).enterprises(1).hh3c(25506).hh3cCommon(2).hh3cIKEMonitor(30)
Scalar objects
hh3cIKEGlobalActiveTunnels
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalActiveTunnels (1.3.6.1.4.1.25506.2.30.1.3.1) |
read-only |
Gauge32 |
Gauge32 (0..4294967295) |
Number of currently active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInOctets
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInOctets (1.3.6.1.4.1.25506.2.30.1.3.2) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of octets received by all currently and previously active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInPkts
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInPkts (1.3.6.1.4.1.25506.2.30.1.3.3) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of packets received by all currently and previously active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInDropPkts
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInDropPkts (1.3.6.1.4.1.25506.2.30.1.3.4) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of inbound packets dropped by all currently and previously active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInP2Exchgs
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInP2Exchgs (1.3.6.1.4.1.25506.2.30.1.3.5) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges received by all currently and previously active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInP2ExchgRejects
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInP2ExchgRejects (1.3.6.1.4.1.25506.2.30.1.3.6) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges received and rejected by all currently and previously active Phase-1 IKE Tunnels. |
As per the MIB. |
hh3cIKEGlobalInP2SaDelRequests
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInP2SaDelRequests (1.3.6.1.4.1.25506.2.30.1.3.7) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 SA deletion requests received by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalInNotifys
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInNotifys (1.3.6.1.4.1.25506.2.30.1.3.8) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of notifications received by all Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutOctets
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutOctets (1.3.6.1.4.1.25506.2.30.1.3.9) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of octets sent by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutPkts
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutPkts (1.3.6.1.4.1.25506.2.30.1.3.10) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of packets sent by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutDropPkts
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutDropPkts (1.3.6.1.4.1.25506.2.30.1.3.11) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of outbound packets dropped by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutP2Exchgs
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutP2Exchgs (1.3.6.1.4.1.25506.2.30.1.3.12) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges sent by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutP2ExchgRejects
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutP2ExchgRejects (1.3.6.1.4.1.25506.2.30.1.3.13) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges sent and rejected by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutP2SaDelRequests
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutP2SaDelRequests (1.3.6.1.4.1.25506.2.30.1.3.14) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 SA deletion requests sent by all currently and previously active Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalOutNotifys
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalOutNotifys (1.3.6.1.4.1.25506.2.30.1.3.15) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of notifications sent by all Phase-1 IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalInitTunnels
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInitTunnels (1.3.6.1.4.1.25506.2.30.1.3.16) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of locally initiated IKE tunnels. |
As per the MIB. |
hh3cIKEGlobalInitTunnelFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInitTunnelFails (1.3.6.1.4.1.25506.2.30.1.3.17) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of IKE tunnels that were locally initiated but failed to activate. |
As per the MIB. |
hh3cIKEGlobalRespTunnels
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalRespTunnels (1.3.6.1.4.1.25506.2.30.1.3.18) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of IKE tunnels that were remotely initiated. |
As per the MIB. |
hh3cIKEGlobalRespTunnelFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalRespTunnelFails (1.3.6.1.4.1.25506.2.30.1.3.19) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of IKE tunnels that were remotely initiated but failed to activate. |
As per the MIB. |
hh3cIKEGlobalAuthFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalAuthFails (1.3.6.1.4.1.25506.2.30.1.3.20) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of IKE authentication failures. |
As per the MIB. |
hh3cIKEGlobalNoSaFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalNoSaFails (1.3.6.1.4.1.25506.2.30.1.3.21) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of Phase-2 SA deletion failures because of nonexistent Phase-1 SAs. |
As per the MIB. |
hh3cIKEGlobalInvalidCookieFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInvalidCookieFails (1.3.6.1.4.1.25506.2.30.1.3.22) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of invalid cookie failures occurred during packet header checking. |
As per the MIB. |
hh3cIKEGlobalAttrNotSuppFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalAttrNotSuppFails (1.3.6.1.4.1.25506.2.30.1.3.23) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of attributes-not-supported failures occurred during packet Transform payload checking. |
Not supported |
hh3cIKEGlobalNoProposalChosenFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalNoProposalChosenFails (1.3.6.1.4.1.25506.2.30.1.3.24) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of no proposal chosen failures occurred during the packet Proposal payload checking. |
As per the MIB. |
hh3cIKEGlobalUnsportExchTypeFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalUnsportExchTypeFails (1.3.6.1.4.1.25506.2.30.1.3.25) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of packet drops caused by unsupported exchange type. |
As per the MIB. |
hh3cIKEGlobalInvalidIdFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInvalidIdFails (1.3.6.1.4.1.25506.2.30.1.3.26) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of invalid ID failures occurred during the packet ID payload checking. |
As per the MIB. |
hh3cIKEGlobalInvalidProFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInvalidProFails (1.3.6.1.4.1.25506.2.30.1.3.27) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of invalid Protocol ID failures occurred during the packet Proposal payload checking. |
As per the MIB. |
hh3cIKEGlobalCertTypeUnsuppFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalCertTypeUnsuppFails (1.3.6.1.4.1.25506.2.30.1.3.28) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of certificate type unsupported failures occurred during the packet ID payload checking. |
As per the MIB. |
hh3cIKEGlobalInvalidCertAuthFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInvalidCertAuthFails (1.3.6.1.4.1.25506.2.30.1.3.29) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of invalid CA failures occurred during the packet ID payload checking. |
Not supported |
hh3cIKEGlobalInvalidSignFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalInvalidSignFails (1.3.6.1.4.1.25506.2.30.1.3.30) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of invalid signature failures occurred during the packet HASH payload checking. |
Not supported |
hh3cIKEGlobalCertUnavailableFails
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEGlobalCertUnavailableFails (1.3.6.1.4.1.25506.2.30.1.3.31) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Number of certificate unavailable failures occurred during the packet ID payload checking. |
As per the MIB. |
hh3cIKETrapGlobalCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKETrapGlobalCntl (1.3.6.1.4.1.25506.2.30.1.5.1) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable trap notifications for IKE events globally. |
As per the MIB. |
hh3cIKETunnelStartTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKETunnelStartTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.2) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKETunnelStart trap notifications. |
As per the MIB. |
hh3cIKETunnelStopTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKETunnelStopTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.3) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKETunnelStop trap notifications. |
As per the MIB. |
hh3cIKENoSaTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKENoSaTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.4) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKENoSa trap notifications. |
As per the MIB. |
hh3cIKEEncryFailureTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEEncryFailureTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.5) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEEncryFailure trap notifications. |
As per the MIB. |
hh3cIKEDecryFailureTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEDecryFailureTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.6) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEDecryFailure trap notifications. |
As per the MIB. |
hh3cIKEInvalidProposalTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidProposalTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.7) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidProposal trap notifications. |
As per the MIB. |
hh3cIKEAuthFailTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEAuthFailTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.8) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEAuthFail trap notifications. |
As per the MIB. |
hh3cIKEInvalidCookieTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidCookieTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.9) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidCookie trap notifications. |
As per the MIB. |
hh3cIKEInvalidSpiTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidSpiTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.10) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidSpi trap notifications. |
As per the MIB. |
hh3cIKEAttrNotSuppTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEAttrNotSuppTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.11) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEAttrNotSupp trap notifications. |
As per the MIB. |
hh3cIKEUnsportExchTypeTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEUnsportExchTypeTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.12) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEUnsportExchTypeTrapCntl trap notifications. |
As per the MIB. |
hh3cIKEInvalidIdTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidIdTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.13) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidId trap notifications. |
As per the MIB. |
hh3cIKEInvalidProtocolTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidProtocolTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.14) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidProtocol trap notifications. |
As per the MIB. |
hh3cIKECertTypeUnsuppTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKECertTypeUnsuppTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.15) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKECertTypeUnsupp trap notifications. |
As per the MIB. |
hh3cIKEInvalidCertAuthTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidCertAuthTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.16) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidCertAuth trap notifications. |
As per the MIB. |
hh3cIKEInvalidSignTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEInvalidSignTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.17) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEInvalidSign trap notifications. |
As per the MIB. |
hh3cIKECertUnavailableTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKECertUnavailableTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.18) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKECertUnavailable trap notifications. |
As per the MIB. |
hh3cIKEProposalAddTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEProposalAddTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.19) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEProposalAdd trap notifications. |
As per the MIB. |
hh3cIKEProposalDelTrapCntl
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEProposalDelTrapCntl (1.3.6.1.4.1.25506.2.30.1.5.20) |
read-write |
Hh3cTrapStatus |
Integer32 (1,2) |
Whether to enable hh3cIKEProposalDel trap notifications. |
As per the MIB. |
hh3cIKEProposalNumber
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEProposalNumber (1.3.6.1.4.1.25506.2.30.1.4.1) |
accessible-for-notify |
Integer32 |
Integer32 (0..2147483647) |
Number of an IKE proposal in a trap notification. |
As per the MIB. |
hh3cIKEProposalSize
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEProposalSize (1.3.6.1.4.1.25506.2.30.1.4.2) |
accessible-for-notify |
Integer32 |
Integer32 (0..2147483647) |
Number of IKE proposals in a trap notification. |
As per the MIB. |
hh3cIKEIdInformation
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEIdInformation (1.3.6.1.4.1.25506.2.30.1.4.3) |
accessible-for-notify |
DisplayString |
OCTET STRING (0..255) |
ID information in a trap notification. |
As per the MIB. |
hh3cIKEProtocolNum
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEProtocolNum (1.3.6.1.4.1.25506.2.30.1.4.4) |
accessible-for-notify |
Integer32 |
Integer32 (0..2147483647) |
Protocol number in a trap notification. |
As per the MIB. |
hh3cIKECertInformation
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKECertInformation (1.3.6.1.4.1.25506.2.30.1.4.5) |
accessible-for-notify |
DisplayString |
OCTET STRING (0..255) |
Certificate information in a trap notification. |
As per the MIB. |
hh3cIKEMIBVersion
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKEMIBVersion (1.3.6.1.4.1.25506.2.30.1.7.1) |
read-only |
DisplayString |
OCTET STRING (0..255) |
Version information of the IKE MIB. |
As per the MIB. |
Tabular objects
hh3cIKETunnelTable
About this table
This table contains IKE tunnel information.
Support for operations
|
Create |
Edit/Modify |
Delete |
Read |
|
Not supported |
Not supported |
Not supported |
Supported |
Columns
The table index is hh3cIKETunIndex.
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKETunIndex (1.3.6.1.4.1.25506.2.30.1.1.1.1) |
accessible-for-notify |
Integer32 |
Integer32 (1..2147483647) |
Index of a tunnel. |
As per the MIB. |
|
hh3cIKETunLocalType (1.3.6.1.4.1.25506.2.30.1.1.1.2) |
read-only |
Hh3cIKEIDType |
Integer32 (0..11) |
Type of the local ID of the tunnel. |
As per the MIB. |
|
hh3cIKETunLocalValue1 (1.3.6.1.4.1.25506.2.30.1.1.1.3) |
read-only |
Display String |
OCTET STRING (0..255) |
Value of the local ID of the tunnel. |
For a local ID that exceeds 255 bytes, this object displays only the first 255 bytes of information. The complete ID information is displayed by hh3cIKETunLocalValue3. |
|
hh3cIKETunLocalValue2 (1.3.6.1.4.1.25506.2.30.1.1.1.4) |
read-only |
Display String |
OCTET STRING (0..255) |
The second specification of the local end's IP address. |
Not supported |
|
hh3cIKETunLocalAddr (1.3.6.1.4.1.25506.2.30.1.1.1.5) |
read-only |
IPad dress |
IPad dress |
IP address of the tunnel local end. |
Replaced by hh3cIKETunLocalInetAddr. |
|
hh3cIKETunRemoteType (1.3.6.1.4.1.25506.2.30.1.1.1.6) |
read-only |
Hh3cIKEIDType |
Integer32 (0..11) |
Type of the remote ID of the tunnel. |
As per the MIB. |
|
hh3cIKETunRemoteValue1 (1.3.6.1.4.1.25506.2.30.1.1.1.7) |
read-only |
DisplayString |
OCTET STRING (0..255) |
Value of the remote ID of the tunnel. |
For a remote ID that exceeds 255 bytes, this object displays only the first 255 bytes of information. The complete ID information is displayed by hh3cIKETunRemoteValue3. |
|
hh3cIKETunRemoteValue2 (1.3.6.1.4.1.25506.2.30.1.1.1.8) |
read-only |
DisplayString |
OCTET STRING (0..255) |
The second specification of the remote end's IP address. |
Not supported |
|
hh3cIKETunRemoteAddr (1.3.6.1.4.1.25506.2.30.1.1.1.9) |
read-only |
IpAddress |
OCTET STRING (4) |
IP address of the tunnel remote end. |
Replaced by hh3cIKETunRemoteInetAddr. |
|
hh3cIKETunInitiator (1.3.6.1.4.1.25506.2.30.1.1.1.10) |
read-only |
INTEGER |
Integer32 (1,2) |
Initiator of the tunnel. |
As per the MIB. |
|
hh3cIKETunNegoMode (1.3.6.1.4.1.25506.2.30.1.1.1.11) |
read-only |
Hh3cIKENegoMode |
Integer32 (2,4,32,128) |
Negotiation mode of the IKE tunnel. |
As per the MIB. |
|
hh3cIKETunDiffHellmanGrp (1.3.6.1.4.1.25506.2.30.1.1.1.12) |
read-only |
Hh3cDiffHellmanGrp |
Integer32 (0,1,2,5,14,24,2147483647) |
DH group used in IKE Phase-1 negotiations. |
As per the MIB. |
|
hh3cIKETunEncryptAlgo (1.3.6.1.4.1.25506.2.30.1.1.1.13) |
read-only |
Hh3cEncryptAlgo |
Integer32(0..14,128..131,2147483647) |
Encryption algorithm used in IKE Phase-1 negotiations. |
As per the MIB. |
|
hh3cIKETunHashAlgo (1.3.6.1.4.1.25506.2.30.1.1.1.14) |
read-only |
Hh3cAuthAlgo |
Integer32(0..5,128,2147483647) |
Hash algorithm used in IKE Phase-1 negotiations. |
As per the MIB. |
|
hh3cIKETunAuthMethod (1.3.6.1.4.1.25506.2.30.1.1.1.15) |
read-only |
Hh3cIKEAuthMethod |
Integer32(0..3,5,6) |
Authentication method used in IKE Phase-1 negotiations. |
As per the MIB. |
|
hh3cIKETunLifeTime (1.3.6.1.4.1.25506.2.30.1.1.1.16) |
read-only |
Integer32 |
Integer32(1..2147483647) |
Negotiated lifetime of the IKE tunnel. |
Range from 1 to 2147483647 |
|
hh3cIKETunActiveTime (1.3.6.1.4.1.25506.2.30.1.1.1.17) |
read-only |
Integer32 |
Integer32(1..2147483647) |
Active period of time of the IKE tunnel. |
Range from 1 to 2147483647 |
|
hh3cIKETunRemainTime (1.3.6.1.4.1.25506.2.30.1.1.1.18) |
read-only |
Integer32 |
Integer32(1..2147483647) |
Remaining lifetime of the IKE tunnel. |
Range from 1 to 2147483647 |
|
hh3cIKETunTotalRefreshes (1.3.6.1.4.1.25506.2.30.1.1.1.19) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of IKE SA refreshes. |
As per the MIB. |
|
hh3cIKETunState (1.3.6.1.4.1.25506.2.30.1.1.1.20) |
read-only |
Hh3cIKETunnelState |
Integer32(1,2) |
State of the IKE tunnel. |
As per the MIB. |
|
hh3cIKETunDpdIntervalTime (1.3.6.1.4.1.25506.2.30.1.1.1.21) |
read-only |
Integer32 |
Integer32(1..2147483647) |
Interval for sending DPD requests. |
Not supported |
|
hh3cIKETunDpdTimeOut (1.3.6.1.4.1.25506.2.30.1.1.1.22) |
read-only |
Integer32 |
Integer32(1..2147483648) |
Timeout time of a DPD request. |
Not supported |
|
hh3cIKETunLocalInetAddrType (1.3.6.1.4.1.25506.2.30.1.1.1.23) |
read-only |
InetAddressType |
Integer32(1,2) |
IP address type of the tunnel local end. |
As per the MIB. |
|
hh3cIKETunLocalInetAddr (1.3.6.1.4.1.25506.2.30.1.1.1.24) |
read-only |
InetAddress |
OCTET STRING (4) |
IP address of the tunnel local end. |
As per the MIB. |
|
hh3cIKETunRemoteInetAddrType (1.3.6.1.4.1.25506.2.30.1.1.1.25) |
read-only |
InetAddressType |
Integer32(1,2) |
IP address type of the tunnel remote end. |
As per the MIB. |
|
hh3cIKETunRemoteInetAddr (1.3.6.1.4.1.25506.2.30.1.1.1.26) |
read-only |
InetAddress |
OCTET STRING (4) |
IP address of the tunnel remote end. |
As per the MIB. |
hh3cIKETunnelStatTable
About this table
This table contains IKE tunnel packet statistics.
Support for operations
|
Create |
Edit/Modify |
Delete |
Read |
|
Not supported |
Not supported |
Not supported |
Supported |
Columns
The table index is hh3cIKETunIndex.
|
Object (OID) |
Access |
Syntax |
Value range |
Description |
Implementation |
|
hh3cIKETunInOctets (1.3.6.1.4.1.25506.2.30.1.2.1.1) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of octets received by the tunnel. |
As per the MIB. |
|
hh3cIKETunInPkts (1.3.6.1.4.1.25506.2.30.1.2.1.2) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of packets received by the tunnel. |
As per the MIB. |
|
hh3cIKETunInDropPkts (1.3.6.1.4.1.25506.2.30.1.2.1.3) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of inbound packets dropped by the tunnel. |
As per the MIB. |
|
hh3cIKETunInP2Exchgs (1.3.6.1.4.1.25506.2.30.1.2.1.4) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges received by the tunnel. |
As per the MIB. |
|
hh3cIKETunInP2ExchgRejets (1.3.6.1.4.1.25506.2.30.1.2.1.5) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of inbound Phase-2 exchanges dropped by the tunnel. |
As per the MIB. |
|
hh3cIKETunInP2SaDelRequests (1.3.6.1.4.1.25506.2.30.1.2.1.6) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of requests received by the tunnel for deleting Phase-2 exchanges. |
As per the MIB. |
|
hh3cIKETunInP1SaDelRequests (1.3.6.1.4.1.25506.2.30.1.2.1.7) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of requests received by the tunnel for deleting Phase-1 SAs. |
As per the MIB. |
|
hh3cIKETunInNotifys (1.3.6.1.4.1.25506.2.30.1.2.1.8) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of notifications received by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutOctets (1.3.6.1.4.1.25506.2.30.1.2.1.9) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of octets sent by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutPkts (1.3.6.1.4.1.25506.2.30.1.2.1.10) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of packets sent by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutDropPkts (1.3.6.1.4.1.25506.2.30.1.2.1.11) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of outbound packets dropped by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutP2Exchgs (1.3.6.1.4.1.25506.2.30.1.2.1.12) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges sent by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutP2ExchgRejects (1.3.6.1.4.1.25506.2.30.1.2.1.13) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of Phase-2 exchanges sent and rejected by the tunnel. |
As per the MIB. |
|
hh3cIKETunOutP2SaDelRequests (1.3.6.1.4.1.25506.2.30.1.2.1.14) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of requests sent by the tunnel for deleting Phase-2 SAs. |
As per the MIB. |
|
hh3cIKETunOutP1SaDelRequests (1.3.6.1.4.1.25506.2.30.1.2.1.15) |
read-only |
Counter64 |
Counter64 (0..18446744073709551615) |
Total number of requests sent by the tunnel for deleting Phase-1 SAs. |
As per the MIB. |
|
hh3cIKETunOutNotifys (1.3.6.1.4.1.25506.2.30.1.2.1.16) |
read-only |
Counter32 |
Counter32 (0..4294967295) |
Total number of notifications sent by the tunnel. |
As per the MIB. |
Notifications
The following information describes the notifications generated by HH3C-IKE-MONITOR-MIB.
hh3cIKETunnelStart
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506. 2.30.1.6.1.1 |
IKE tunnel created. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE tunnel is created.
System impact
No negative impact on services.
Status control
ON
· CLI: Use the snmp-agent trap enable ike tunnel-start command.
· MIB: Set hh3cIKETunnelStartTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike tunnel-start command
· MIB: Set hh3cIKETunnelStartTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.16 (hh3cIKETunLifeTime) |
Lifetime of the IKE tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
No action is required.
hh3cIKETunnelStop
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.2 |
IKE tunnel deleted. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE tunnel is deleted.
This notification might be generated when the following events occur:
· IKE DPD times out.
· IKE keepalive detection times out.
· The IKE SA is accidentally deleted when you modify other configurations or manually deleted.
· Hard timeout of the phase-1 IKE negotiation occurs (no new IKE SA is negotiated successfully).
· A new IKE SA takes over the old IKE SA.
· The remote end asks to delete the IKE SA.
· Other events.
System impact
The IKE tunnel is deleted.
Status control
ON
· CLI: Use the snmp-agent trap enable ike tunnel-stop command
· MIB: Set hh3cIKETunnelStopTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike tunnel-stop command
· MIB: Set hh3cIKETunnelStopTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.17 (hh3cIKETunActiveTime) |
Active period of time of the tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue, take the following operations according to the corresponding notification generation reasons:
· Use the ping command to verify that the links are reachable. If the links are unreachable, troubleshoot the links and network configurations.
· Use the ping command to verify that the links are reachable. If the links are unreachable, troubleshoot the links. Then check whether the keepalive configurations on both ends are correct. If the keepalive configurations are incorrect, modify the configurations.
· Check whether the reset ike sa command has been executed to delete the IKE SA. If yes, no action is required. Then check whether the IKE configurations on the local end are correct. If no, modify the configurations.
· Check whether the IKE SA lifetime is appropriate. If no, modify the IKE SA lifetime.
· If a new IKE SA takes over the old IKE SA, no action is required.
· View the logs on the remote end and identify the IKE tunnel deletion reasons.
· Collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKENoSaFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.3 |
IKE tunnel received nonexistent SA. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE tunnel receives a nonexistent SA.
System impact
The device cannot encrypt or decrypt packets through the IKE tunnel.
Status control
ON
· CLI: Use the snmp-agent trap enable ike no-sa-failure command.
· MIB: Set hh3cIKENoSaTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike no-sa-failure command.
· MIB: Set hh3cIKENoSaTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the display ike sa command to check whether IKE SAs exist.
¡ If no, use the reset ike sa command to delete the nonexistent SA so as to trigger IKE SA negotiation.
¡ If yes, go to step 2.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEEncryFailFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.4 |
IKE tunnel encryption failure. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE tunnel has an encryption failure.
System impact
The device cannot send packets encrypted by the IKE tunnel.
Status control
ON
· CLI: Use the snmp-agent trap enable ike encrypt-failure command.
· MIB: Set hh3cIKEEncryFailureTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike encrypt-failure command.
· MIB: Set hh3cIKEEncryFailureTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEDecryFailFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.5 |
IKE tunnel decryption failure. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE tunnel has a decryption failure.
System impact
The device cannot decrypt the received IKE tunnel-encrypted packets.
Status control
ON
· CLI: Use the snmp-agent trap enable ike decrypt-failure command.
· MIB: Set hh3cIKEDecryFailureTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike decrypt-failure command.
· MIB: Set hh3cIKEDecryFailureTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEInvalidProposalFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.6 |
Invalid proposal received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an invalid proposal is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-proposal command.
· MIB: SET hh3cIKEInvalidProposalTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-proposal command.
· MIB: SET hh3cIKEInvalidProposalTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEAuthFailFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.7 |
IKE Phase-1 authentication failure. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when the IKE Phase-1 authentication fails.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike auth-failure command.
· MIB: Set hh3cIKEAuthFailTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike auth-failure command.
· MIB: Set hh3cIKEAuthFailTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEInvalidCookieFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.8 |
Invalid cookie received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an invalid cookie is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-cookie command.
· MIB: Set hh3cIKEInvalidCookieTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-cookie command.
· MIB: Set hh3cIKEInvalidCookieTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEAttrNotSuppFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.9 |
Attributes not supported received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an unsupported attribute is received during IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike attr-not-support command.
· MIB: Set hh3cIKEAttrNotSuppTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike attr-not-support command.
· MIB: Set hh3cIKEAttrNotSuppTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEUnsportExchTypeFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.10 |
Unsupported exchange type received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an unsupported exchange type is received during the IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike unsupport-exch-type command.
· MIB: Set hh3cIKEUnsportExchTypeTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike unsupport-exch-type command.
· MIB: Set hh3cIKEUnsportExchTypeTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEInvalidIdFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.11 |
Invalid ID received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an invalid ID is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-id command.
· MIB: Set hh3cIKEInvalidIdTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-id command.
· MIB: Set hh3cIKEInvalidIdTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.3 (hh3cIKEIdInformation) |
ID of the IKE negotiation. |
N/A |
DisplayString |
OCTET STRING (SIZE (0..255)) |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEInvalidProtocolFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.12 |
IKE tunnel protocol error. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when a protocol related error occurs during the processing for an IKE tunnel.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-protocol command.
· MIB: Set hh3cIKEInvalidProtocolTrapCntl to enabled(1)
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-protocol command.
· MIB: Set hh3cIKEInvalidProtocolTrapCntl to disabled(2)
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.4 (hh3cIKEProtocolNum) |
IKE protocol number |
N/A |
Integer32 |
-2147483648..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKECertTypeUnsuppFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.13 |
Unsupported certificate type received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an unsupported certificate type is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike cert-type-unsupport command.
· MIB: Set hh3cIKECertTypeUnsuppTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike cert-type-unsupport command.
· MIB: Set hh3cIKECertTypeUnsuppTrapCntl to disabled(2).
Objects
|
OID (object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.5 (hh3cIKECertInformation) |
Certificate information |
N/A |
DisplayString |
OCTET STRING (SIZE (0..255)) |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEInvalidCertAuthFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.14 |
Invalid certificate received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an invalid certificate is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-cert-auth command.
· MIB: Set hh3cIKEInvalidCertAuthTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-cert-auth command.
· MIB: Set hh3cIKEInvalidCertAuthTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.5 (hh3cIKECertInformation) |
Certificate information. |
N/A |
DisplayString |
OCTET STRING (SIZE (0..255)) |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKElInvalidSignFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.15 |
Invalid signature received in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an invalid signature is received during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike invalid-sign command.
· MIB: Set hh3cIKEInvalidSignTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike invalid-sign command.
· MIB: Set hh3cIKEInvalidSignTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.5 (hh3cIKECertInformation) |
Certificate information. |
N/A |
DisplayString |
OCTET STRING (SIZE (0..255)) |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Use the reset ipsec sa command to delete IPsec SAs and use the reset ike sa command to delete IKE SAs so as to trigger IKE SA negotiation.
2. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKECertUnavailableFailure
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.16 |
Certificate unavailable in IKE Phase-1 negotiation. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when a certificate is unavailable during an IKE Phase-1 SA negotiation.
System impact
The Phase-1 IKE tunnel cannot be established.
Status control
ON
· CLI: Use the snmp-agent trap enable ike cert-unavailable command.
· MIB: Set hh3cIKECertUnavailableTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike cert-unavailable command.
· MIB: Set hh3cIKECertUnavailableTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.1.1.5 (hh3cIKETunLocalAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.9 (hh3cIKETunRemoteAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
IpAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.5 (hh3cIKECertInformation) |
Certificate information. |
N/A |
DisplayString |
OCTET STRING (SIZE (0..255)) |
|
1.3.6.1.4.1.25506.2.30.1.1.1.1 (hh3cIKETunIndex) |
Index of a tunnel. |
hh3cIKETunIndex |
Integer32 |
1..2147483647 |
|
1.3.6.1.4.1.25506.2.30.1.1.1.23 (hh3cIKETunLocalInetAddrType) |
IP address type of the tunnel local end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.24 (hh3cIKETunLocalInetAddr) |
IP address of the tunnel local end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.25 (hh3cIKETunRemoteInetAddrType) |
IP address type of the tunnel remote end. |
hh3cIKETunIndex |
InetAddressType |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.1.1.26 (hh3cIKETunRemoteInetAddr) |
IP address of the tunnel remote end. |
hh3cIKETunIndex |
InetAddress |
Standard MIB values. |
Recommended action
To resolve this issue:
1. Check whether a PKI domain is specified in the IKE profile used for IKE negotiation.
¡ If no, use the certificate domain command in IKE profile view to specify a PKI domain for the IKE profile used for IKE negotiation.
¡ If yes, go to step 2.
2. Use the display pki certificate domain command in system view to view whether the CA certificate and local certificates exist in the PKI domain, and whether key pairs are specified.
¡ If no, import the certificates to the PKI domain in online or offline mode and specify the key pairs.
¡ If yes, go to step 3.
3. If the issue persists, collect alarm information and configuration data, and then contact H3C Support for help.
hh3cIKEProposalAdd
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.17 |
IKE proposal added. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE proposal is added.
System impact
No negative impact on services.
Status control
ON
· CLI: Use the snmp-agent trap enable ike proposal-add command.
· MIB: Set hh3cIKEProposalAddTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike proposal-add command.
· MIB: Set hh3cIKEProposalAddTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.4.1 (hh3cIKEProposalNumber) |
IKE proposal number. |
N/A |
Integer32 |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.2 (hh3cIKEProposalSize) |
Number of IKE proposals. |
N/A |
Integer32 |
Standard MIB values. |
Recommended action
No action is required.
hh3cIKEProposalDel
Basic information
|
OID |
Event |
Type |
Severity |
Recovery notification |
Default status |
|
1.3.6.1.4.1.25506.2.30.1.6.1.18 |
IKE proposal deleted. |
Informational |
Warning |
N/A |
OFF |
Notification triggers
This notification is generated when an IKE proposal is deleted.
System impact
No negative impact on services.
Status control
ON
· CLI: Use the snmp-agent trap enable ike proposal-delete command.
· MIB: Set hh3cIKEProposalDelTrapCntl to enabled(1).
OFF
· CLI: Use the undo snmp-agent trap enable ike proposal-delete command.
· MIB: Set hh3cIKEProposalDelTrapCntl to disabled(2).
Objects
|
OID(object name) |
Description |
Index nodes |
Type |
Value range |
|
1.3.6.1.4.1.25506.2.30.1.4.1 (hh3cIKEProposalNumber) |
IKE proposal number. |
N/A |
Integer32 |
Standard MIB values. |
|
1.3.6.1.4.1.25506.2.30.1.4.2 (hh3cIKEProposalSize) |
Number of IKE proposals. |
N/A |
Integer32 |
Standard MIB values. |
Recommended action
No action is required.
