| ceipSecGlobalActiveTunnels | 
      .1.3.6.1.4.1.9.9.432.1.1.1.1 | 
    
    
      | 
        The total number of currently active
        IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalPreviousTunnels | 
      .1.3.6.1.4.1.9.9.432.1.1.1.2 | 
    
    
      | 
        The total number of previously active
        IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.1.3 | 
    
    
      | 
        A high capacity count of the total number of
        octets received by all current and previous
        IPsec Phase-2 Tunnels. This value is accumulated
        BEFORE determining whether or not the packet
        should be decompressed.
       | 
    
    
      | ceipSecGlobalInDecompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.1.4 | 
    
    
      | 
        A high capacity count of the total number
        of decompressed octets received by all current
        and previous IPsec Phase-2 Tunnels.  This value
        is accumulated AFTER the packet is decompressed.
        If compression is not being used, this value
        will match the value of ceipSecGlobalInOctets.
       | 
    
    
      | ceipSecGlobalInPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.5 | 
    
    
      | 
        The total number of packets received
        by all current and previous
        IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInDrops | 
      .1.3.6.1.4.1.9.9.432.1.1.1.6 | 
    
    
      | 
        The total number of packets dropped
        during receive processing by all current and
        previous IPsec Phase-2 Tunnels. This count does
        NOT include packets dropped due to
        Anti-Replay processing.
       | 
    
    
      | ceipSecGlobalInReplayDrops | 
      .1.3.6.1.4.1.9.9.432.1.1.1.7 | 
    
    
      | 
        The total number of packets dropped during
        receive processing due to Anti-Replay
        processing by all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.1.8 | 
    
    
      | 
        The total number of inbound authentication's
        performed by all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.9 | 
    
    
      | 
        The total number of inbound authentication's
        which ended in failure by all current and
        previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInDecrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.10 | 
    
    
      | 
        The total number of inbound decryption's
        performed by all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalInDecryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.11 | 
    
    
      | 
        The total number of inbound decryption's
        which ended in failure by all current and
        previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.1.12 | 
    
    
      | 
        A high capacity count of the total number
        of octets sent by all current and previous
        IPsec Phase-2 Tunnels.  This value is accumulated
        AFTER determining whether or not the packet should
        be compressed.
       | 
    
    
      | ceipSecGlobalOutUncompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.1.13 | 
    
    
      | 
        A high capacity count of the total number of
        uncompressed octets sent by all current and previous
        IPsec Phase-2 Tunnels.  This value is accumulated
        BEFORE the packet is compressed.  If compression is
        not being used, this value will match the
        value of ceipSecGlobalOutOctets.
       | 
    
    
      | ceipSecGlobalOutPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.14 | 
    
    
      | 
        The total number of packets sent by all
        current and previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutDrops | 
      .1.3.6.1.4.1.9.9.432.1.1.1.15 | 
    
    
      | 
        The total number of packets dropped during send
        processing by all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.1.16 | 
    
    
      | 
        The total number of outbound authentication's
        performed by all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.17 | 
    
    
      | 
        The total number of outbound authentication's
        which ended in failure
        by all current and previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutEncrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.18 | 
    
    
      | 
        The total number of outbound encryption's performed
        by all current and previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutEncryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.19 | 
    
    
      | 
        The total number of outbound encryption's
        which ended in failure by all current and
        previous IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalProtocolUseFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.20 | 
    
    
      | 
        The total number of protocol use failures
        which occurred during processing of all current
        and previously active IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalNoSaFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.21 | 
    
    
      | 
        The total number of non-existent Security
        Association in failures which occurred during
        processing of all current and previous IPsec
        Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalSysCapFails | 
      .1.3.6.1.4.1.9.9.432.1.1.1.22 | 
    
    
      | 
        The total number of system capacity failures
        which occurred during processing of all current
        and previously active IPsec Phase-2 Tunnels.
       | 
    
    
      | ceipSecGlobalOutCompressedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.23 | 
    
    
      | 
        The cumulative number of outbound packets across all
        IPsec flows terminating at this device which were
        successfully compressed.
       | 
    
    
      | ceipSecGlobalOutCompSkippedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.24 | 
    
    
      | 
        The total number of outbound packets across all
        IPsec flows terminating at this devices that were
        to be compressed but which were skipped due to
        the compression hysteresis.
       | 
    
    
      | ceipSecGlobalOutCompFailPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.25 | 
    
    
      | 
        The total number of outbound packets across all IPsec
        flows terminating at this device that failed compression
        because they grew in size after compression.
       | 
    
    
      | ceipSecGlobalOutCompTooSmallPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.1.26 | 
    
    
      | 
        The total number of outbound packets across all IPsec
        flows terminating at this device that were to be
        compressed but were smaller than the compression
        threshold size. This number is cumulative since the
        last system start.
        
       | 
    
    
      | ceipSecTunnelEntry | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1 | 
    
    
      | 
        Each entry contains the attributes
        associated with an active IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecEndPtEntry | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1 | 
    
    
      | 
        An IPsec Phase-2 Tunnel Endpoint entry.
       | 
    
    
      | ceipSecSaEntry | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1 | 
    
    
      | 
        Each entry contains the attributes associated with
        active and expiring IPsec Phase-2
        security associations.
       | 
    
    
      | ceipSecTunnelSaEntry | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1 | 
    
    
      | 
        Each entry contains the attributes and statistics
        associated with an active or expiring IPsec Phase-2
        security associations.
       | 
    
    
      | ceipSecIfTunnelEntry | 
      .1.3.6.1.4.1.9.9.432.1.1.6.1 | 
    
    
      | 
        Each entry contains the IPsec Phase-2 Tunnel
        associated with an interface.
       | 
    
    
      | ceipSecHistTableSize | 
      .1.3.6.1.4.1.9.9.432.1.2.1.1.1 | 
    
    
      | 
        The window size of the IPsec Phase-2 History Tables.
        The IPsec Phase-2 History Tables are implemented as
        a sliding window in which only the last 'N' entries
        are maintained.  This object is used specify the number
        of entries which will be maintained in the IPsec
        Phase-2 History Tables.
        An implementation may choose suitable minimum and
        maximum values for this element based on the local
        policy and available resources. If an SNMP SET request
        specifies a value outside this window for this element,
        in appropriate SNMP error code should be returned.
        Setting this value to zero is equivalent to deleting
        all conceptual rows in the archiving tables
        ('ceipSecHistTable' and 'ceipSecEndPtHistTable') and
        disabling the archiving of entries in the tables. 
       | 
    
    
      | ceipSecTunnelHistEntry | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1 | 
    
    
      | 
        Each entry contains the attributes associated
        with a previously active IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecEndPtHistEntry | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1 | 
    
    
      | 
        Each entry contains the attributes associated with
        a previously active IPsec Phase-2 Tunnel Endpoint.
       | 
    
    
      | ceipSecFailTableSize | 
      .1.3.6.1.4.1.9.9.432.1.3.1.1.1 | 
    
    
      | 
        The window size of the IPsec Phase-2 Failure Table.
        The IPsec Phase-2 Failure Tables are implemented as
        a sliding window in which only the last N entries are
        maintained. This object is used specify the number of
        entries which will be maintained in the IPsec Phase-2
        Failure Tables.
        An implementation may choose suitable minimum and
        maximum values for this element based on the local
        policy and available resources. If an SNMP SET
        request specifies a value outside this window for
        this element, an appropriate SNMP error vode must
        be returned.
        Setting this value to zero is equivalent to deleting
        all conceptual rows in the archiving table
        'ceipSecFailTable' and disabling the archiving of
        entries in these tables.
       | 
    
    
      | ceipSecFailEntry | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1 | 
    
    
      | 
        Each entry contains the attributes associated with
        an IPsec Phase-1 failure.
       | 
    
    
      | ceipSecNotiCntlIpSecAllNotifs | 
      .1.3.6.1.4.1.9.9.432.1.5.1 | 
    
    
      | 
        This object
        sending any notification
        defined in this MIB module. That is, a particular
        notification 'foo' defined in this MIB module is
        enabled if and only if the expression
        (ceipSecNotiCntlIpSecAllNotifs && ceipSecNotiCntl<foo>)
        evaluates to 'true', where ceipSecNotiCntl<foo> is a
        notification defined in this MIB module.
        
       | 
    
    
      | ceipSecNotifCntlIpSecTunnelStart | 
      .1.3.6.1.4.1.9.9.432.1.5.2 | 
    
    
      | 
        This object defines the administrative state
        of sending the IPsec Phase-2 Tunnel Start TRAP.
        If the value of this object is 'true', the issuing
        of the notification 'ciscoEnhIpsecFlowTunnelStart'
        is enabled. 
       | 
    
    
      | ceipSecNotifCntlIpSecTunnelStop | 
      .1.3.6.1.4.1.9.9.432.1.5.3 | 
    
    
      | 
        This object defines the administrative state of
        sending the IPsec Phase-2 Tunnel Stop TRAP.
        If the value of this object is 'true', the issuing
        of the notification 'ciscoEnhIpsecFlowTunnelStop'
        is enabled.
       | 
    
    
      | ceipSecNotifCntlIpSecSysFailure | 
      .1.3.6.1.4.1.9.9.432.1.5.4 | 
    
    
      | 
        This object defines the administrative state
        of sending the IPsec Phase-2 System Failure TRAP.
        If the value of this object is 'true', the issuing
        of the notification 'ciscoEnhIpsecFlowSysFailure'
        is enabled.
       | 
    
    
      | ceipSecNotifCntlIpSecSetUpFail | 
      .1.3.6.1.4.1.9.9.432.1.5.5 | 
    
    
      | 
        This object defines the administrative state
        of sending the IPsec Phase-2 Set Up Failure TRAP.
        If the value of this object is 'true', the issuing
        of the notification 'ciscoEnhIpsecFlowSetupFail'
        is enabled.
       | 
    
    
      | ceipSecNotifCntlIpSecBadSa | 
      .1.3.6.1.4.1.9.9.432.1.5.6 | 
    
    
      | 
        This object defines the administrative state of
        sending the IPsec Phase-2  No Security Association
        trap.
        If the value of this object is 'true', the issuing
        of the notification 'ciscoEnhIpsecFlowBadSa' is
        enabled.
       | 
    
  
  
    
      | ceipSecTunIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.1 | 
    
    
      | 
        The index of the IPsec Phase-2 Tunnel Table.
        The value of the index is a number which begins
        at 1 and is incremented with each tunnel that is
        created. The value of this object will wrap at
        2,147,483,647.
        Since this object must correspond to a valid
        Phase-2 IPsec tunnel, this object may not assume
        the value of 0.
       | 
    
    
      | ceipSecTunLocalAddressType | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.2 | 
    
    
      | 
        The type of the IP address of the local endpoint
        for the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunLocalAddress | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.3 | 
    
    
      | 
        The IP address of the local endpoint
        for the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunRemoteAddressType | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.4 | 
    
    
      | 
        The type of the IP address of the remote
        endpoint for the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunRemoteAddress | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.5 | 
    
    
      | 
        The IP address of the remote endpoint for
        the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunControlProtocol | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.6 | 
    
    
      | 
        Identifies the protocol used to setup and
        administer this Phase-2 IPsec tunnel.
        In case this tunnel was spawned by an IPsec
        signaling protocol, this MIB object contains the
        value of the object 'cisgIpsSgProtocol' defined
        in CISCO-IPSEC-SIGNALING-MIB in the table
        'cisgIpsSgTunnelTable' in the row corresponding
        to the control tunnel.
        A value of 'cpManual' is indicative of a
        manually installed and administered Phase-2
        tunnel.
       | 
    
    
      | ceipSecTunControlTunnelIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.7 | 
    
    
      | 
        The index of the associated IPsec Phase-1
        Tunnel. In case this tunnel was spawned by an
        IPsec signaling protocol, this MIB object
        contains the value of the object 'cisgIpsSgTunIndex'
        defined in CISCO-IPSEC-SIGNALING-MIB in the table
        'cisgIpsSgTunnelTable' in the row corresponding to
        the control tunnel.
        A value of 0 identifies that this Phase-2 tunnel
        was setup manually.
       | 
    
    
      | ceipSecTunControlTunnelAlive | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.8 | 
    
    
      | 
        An indicator which specifies whether or not the
        IPsec Phase-1 Tunnel that spawned this Phase-2
        tunnel currently exists.
       | 
    
    
      | ceipSecTunEncapMode | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.9 | 
    
    
      | 
        The encapsulation mode used by the
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunNATTraversalMode | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.10 | 
    
    
      | 
        The encapsulation used by the IPsec Phase-2
        tunnel for NAT traversal.
        The value of this object is constrained based on
        the value of the column 'ceipSecTunEncapMode'. If
        the value of 'ceipSecTunEncapMode' is 'encapTransport',
        then this object may not assume the values
        'natEncapIPsecOverUdp' or 'natEncapIPsecOverTcp'.
        
       | 
    
    
      | ceipSecTunLifeSize | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.11 | 
    
    
      | 
        The negotiated LifeSize of the
        IPsec Phase-2 Tunnel in kilobytes.
       | 
    
    
      | ceipSecTunLifeTime | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.12 | 
    
    
      | 
        The negotiated LifeTime of the IPsec Phase-2
        Tunnel in seconds.
        If the tunnel was setup manually, the value of this
        MIB element should be 0.
       | 
    
    
      | ceipSecTunActiveTime | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.13 | 
    
    
      | 
        The length of time the IPsec Phase-2
        Tunnel has been active in hundredths of seconds.
       | 
    
    
      | ceipSecTunSaLifeSizeThreshold | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.14 | 
    
    
      | 
        The security association LifeSize refresh
        threshold in kilobytes.
        If the tunnel was setup manually, the value of this
        MIB element should be 0.
       | 
    
    
      | ceipSecTunSaLifeTimeThreshold | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.15 | 
    
    
      | 
        The security association LifeTime refresh
        threshold in seconds.
        If the tunnel was setup manually, the value of this
        MIB element should be 0.
       | 
    
    
      | ceipSecTunTotalRefreshes | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.16 | 
    
    
      | 
        The total number of security
        association refreshes performed.
       | 
    
    
      | ceipSecTunExpiredSaInstances | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.17 | 
    
    
      | 
        The total number of security associations
        which have expired.
        If the tunnel was setup manually, the value of this
        MIB element should be 0.
       | 
    
    
      | ceipSecTunCurrentSaInstances | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.18 | 
    
    
      | 
        The number of security associations
        which are currently active or expiring.
       | 
    
    
      | ceipSecTunInSaDHGrp | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.19 | 
    
    
      | 
        The Diffie Hellman Group used
        by the inbound security association of the
        IPsec Phase-2 Tunnel.
        If the tunnel was setup manually, the value of this
        MIB element would be `none'.
       | 
    
    
      | ceipSecTunInSaEncryptAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.20 | 
    
    
      | 
        The encryption algorithm used by the inbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInSaEncryptKeySize | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.21 | 
    
    
      | 
        The key size in bits of the negotiated key to be
        used with the algorithm denoted by
        'ceipSecTunInSaEncryptAlgo'.
        For DES and 3DES the key size is respectively 56 and
        168. For AES, this will denote the negotiated key size. 
       | 
    
    
      | ceipSecTunInSaAhAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.22 | 
    
    
      | 
        The authentication algorithm used by the inbound
        authentication header (AH) security association of
        the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInSaEspAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.23 | 
    
    
      | 
        The authentication algorithm used by the inbound
        ecapsulation security protocol (ESP) security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInSaDecompAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.24 | 
    
    
      | 
        The decompression algorithm used by the inbound
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutSaDHGrp | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.25 | 
    
    
      | 
        The Diffie Hellman Group used by the outbound security
        association of the IPsec Phase-2 Tunnel.
        If the tunnel was setup manually, the value of this
        MIB element would be 'none'.
       | 
    
    
      | ceipSecTunOutSaEncryptAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.26 | 
    
    
      | 
        The encryption algorithm used by the outbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutSaEncryptKeySize | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.27 | 
    
    
      | 
        The key size in bits of the negotiated key to be
        used with the algorithm denoted by
        'ceipSecTunOutSaEncryptAlgo'.
        For DES and 3DES the key size is respectively 56 and
        168. For AES, this will denote the negotiated key size.
       | 
    
    
      | ceipSecTunOutSaAhAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.28 | 
    
    
      | 
        The authentication algorithm used by the outbound
        authentication header (AH) security association of
        the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutSaEspAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.29 | 
    
    
      | 
        The authentication algorithm used by the inbound
        encapsulation security protocol (ESP)
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutSaCompAlgo | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.30 | 
    
    
      | 
        The compression algorithm used by the inbound
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunPmtu | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.31 | 
    
    
      | 
        The Path MTU for this IPsec Phase-2 tunnel, which has
        been either learnt from the network or which has been
        specified by the administrator. The lower end of the
        range is 68 which is the minimum MTU for IPv4.
       | 
    
    
      | ceipSecTunInOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.32 | 
    
    
      | 
        A high capacity count of the total number of octets
        received by this IPsec Phase-2 Tunnel.  This value is
        accumulated BEFORE determining whether or not the packet
        should be decompressed.
       | 
    
    
      | ceipSecTunInDecompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.33 | 
    
    
      | 
        A high capacity count of the total number of decompressed
        octets received by this IPsec Phase-2 Tunnel.  This value
        is accumulated AFTER the packet is decompressed. If
        compression is not being used, this value will match the
        value of ceipSecTunInOctets.
       | 
    
    
      | ceipSecTunInPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.34 | 
    
    
      | 
        The total number of packets received by this IPsec
        Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.35 | 
    
    
      | 
        The total number of packets dropped
        during receive processing by this IPsec Phase-2
        Tunnel. This count does NOT include
        packets dropped due to Anti-Replay processing.
       | 
    
    
      | ceipSecTunInReplayDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.36 | 
    
    
      | 
        The total number of packets dropped during
        receive processing due to Anti-Replay processing
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.37 | 
    
    
      | 
        The total number of inbound
        authentication's performed by this
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.38 | 
    
    
      | 
        The total number of inbound authentication's
        which ended in failure by this IPsec Phase-2 Tunnel .
       | 
    
    
      | ceipSecTunInDecrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.39 | 
    
    
      | 
        The total number of inbound decryption's performed
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunInDecryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.40 | 
    
    
      | 
        The total number of inbound decryption's
        which ended in failure by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.41 | 
    
    
      | 
        A high capacity count of the total number of octets
        sent by this IPsec Phase-2 Tunnel.  This value is
        accumulated AFTER determining whether or not the
        packet should be compressed.
       | 
    
    
      | ceipSecTunOutUncompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.42 | 
    
    
      | 
        A high capacity count of the total number
        of uncompressed octets sent by this IPsec
        Phase-2 Tunnel.  This value is accumulated BEFORE
        the packet is compressed. If compression
        is not being used, this value will match the value
        of ceipSecTunOutOctets.
       | 
    
    
      | ceipSecTunOutPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.43 | 
    
    
      | 
        The total number of packets sent by this
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.44 | 
    
    
      | 
        The total number of packets dropped during
        send processing by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.45 | 
    
    
      | 
        The total number of outbound authentication's performed
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.46 | 
    
    
      | 
        The total number of outbound
        authentication's which ended in failure
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutEncrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.47 | 
    
    
      | 
        The total number of outbound encryption's performed
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutEncryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.48 | 
    
    
      | 
        The total number of outbound encryption's
        which ended in failure by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunOutCompressedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.49 | 
    
    
      | 
        The total number of outbound packets
        which were successfully compressed.
       | 
    
    
      | ceipSecTunOutCompSkippedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.50 | 
    
    
      | 
        The total number of outbound packets that were to be
        compressed but which were skipped due to the compression
        hysteresis.
       | 
    
    
      | ceipSecTunOutCompFailPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.51 | 
    
    
      | 
        The total number of outbound packets that failed
        compression because they grew in size after compression.
       | 
    
    
      | ceipSecTunOutCompTooSmallPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.52 | 
    
    
      | 
        The total number of outbound packets that were to be
        compressed but were smaller than the compression threshold
        size.
       | 
    
    
      | ceipSecIfIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.53 | 
    
    
      | 
        This object represents the ifIndex of an interface
        where this tunnel is created.
        Multiple IPsec tunnels can be created using the same
        interface.
       | 
    
    
      | ceipSecTunStatus | 
      .1.3.6.1.4.1.9.9.432.1.1.2.1.54 | 
    
    
      | 
        The status of the MIB table row.
        This object can be used to bring the tunnel down
        or force a rekeying.
        When the value is set to destroy(5), the SA
        bundle is destroyed and this row is deleted
        from this table.  When the value is set to rekey(6),
        then rekeying is forced on this tunnel.
        When this MIB value is queried, the value of
        active(4) is always returned, if the instance
        exists.
        This object cannot be used to create a MIB
        table row.
       | 
    
    
      | ceipSecEndPtIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.1 | 
    
    
      | 
        The number of the Endpoint associated with the
        IPsec Phase-2 Tunnel Table.  The value of this
        index is a number which begins at one and
        is incremented with each Endpoint associated
        with an IPsec Phase-2 Tunnel.
        The value of this object will wrap at 4,294,967,295.
       | 
    
    
      | ceipSecEndPtLocalName | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.2 | 
    
    
      | 
        The DNS name of the local Endpoint.
       | 
    
    
      | ceipSecEndPtLocalType | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.3 | 
    
    
      | 
        The type of identity for the local Endpoint.
       | 
    
    
      | ceipSecEndPtLocalAddrType1 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.4 | 
    
    
      | 
        The type of the IP address for this local Endpoint's
        first IP address.
       | 
    
    
      | ceipSecEndPtLocalAddr1 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.5 | 
    
    
      | 
        The local Endpoint's first IP address specification.
        If the local Endpoint type is single IP address,
        then this is the value of the IP address.
        If the local Endpoint type is IP subnet, then this
        is the value of the subnet.
        If the local Endpoint type is IP address range,
        then this is the value of beginning IP address
        of the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        ceipSecEndPtLocalType.
       | 
    
    
      | ceipSecEndPtLocalAddrType2 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.6 | 
    
    
      | 
        The type of the IP address for this local Endpoint's
        second IP address.
       | 
    
    
      | ceipSecEndPtLocalAddr2 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.7 | 
    
    
      | 
        The local Endpoint's second IP address specification.
        If the local Endpoint type is single IP address,
        then this is the value of the IP address.
        If the local Endpoint type is IP subnet, then this
        is the value of the subnet mask.
        If the local Endpoint type is IP address range,
        then this is the value of ending IP address
        of the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        ceipSecEndPtLocalType.
       | 
    
    
      | ceipSecEndPtLocalProtocol | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.8 | 
    
    
      | 
        The protocol number of the local Endpoint's traffic.
       | 
    
    
      | ceipSecEndPtLocalPort | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.9 | 
    
    
      | 
        The port number of the local Endpoint's traffic.
       | 
    
    
      | ceipSecEndPtRemoteName | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.10 | 
    
    
      | 
        The DNS name of the remote Endpoint.
       | 
    
    
      | ceipSecEndPtRemoteType | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.11 | 
    
    
      | 
        The type of identity for the remote Endpoint.
       | 
    
    
      | ceipSecEndPtRemoteAddrType1 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.12 | 
    
    
      | 
        The type of the IP address for this remote Endpoint's
        first IP address.
       | 
    
    
      | ceipSecEndPtRemoteAddr1 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.13 | 
    
    
      | 
        The remote Endpoint's first IP address specification.
        If the remote Endpoint type is single IP address,
        then this is the value of the IP address.
        If the remote Endpoint type is IP subnet, then this
        is the value of the subnet.
        If the remote Endpoint type is IP address range,
        then this is the value of beginning IP address
        of the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        ceipSecEndPtRemoteType.
       | 
    
    
      | ceipSecEndPtRemoteAddrType2 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.14 | 
    
    
      | 
        The type of the IP address for this remote Endpoint's
        second IP address.
       | 
    
    
      | ceipSecEndPtRemoteAddr2 | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.15 | 
    
    
      | 
        The remote Endpoint's second IP address specification.
        If the remote Endpoint type is single IP address,
        then this is the value of the IP address.
        If the remote Endpoint type is IP subnet, then this
        is the value of the subnet mask.
        If the remote Endpoint type is IP address range,
        then this is the value of ending IP address of
        the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        ceipSecEndPtRemoteType.
       | 
    
    
      | ceipSecEndPtRemoteProtocol | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.16 | 
    
    
      | 
        The protocol number of the remote Endpoint's traffic.
       | 
    
    
      | ceipSecEndPtRemotePort | 
      .1.3.6.1.4.1.9.9.432.1.1.3.1.17 | 
    
    
      | 
        The port number of the remote Endpoint's traffic.
       | 
    
    
      | ceipSecSaProtocol | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1.1 | 
    
    
      | 
        This column represents the security protocol (AH,
        ESP or IPComp) for which this security association
        was setup. 
       | 
    
    
      | ceipSecSaIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1.2 | 
    
    
      | 
        The object, in the context of the IPsec tunnel
        'ceipSecTunIndex', is an index of security
        associations comprising the Phase-2 IPsec tunnel
        represented by the tunnel index 'ceipSecTunIndex'.
        The value of this index is a number which begins at
        1 and is incremented with each SPI associated with
        the corresponding IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecSaDirection | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1.3 | 
    
    
      | 
        Phase-2 IPsec security associations are simplex.
        Hence a particular security association is used either
        for securing outgoing traffic or decoding incoming
        traffic. This column identifies the direction of the
        security association represented by this entry. 
       | 
    
    
      | ceipSecSaValue | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1.4 | 
    
    
      | 
        This is the value of the Security Protection Index
        (SPI) assigned by the system to the security
        association represented by this entry. 
       | 
    
    
      | ceipSecSaStatus | 
      .1.3.6.1.4.1.9.9.432.1.1.4.1.5 | 
    
    
      | 
         This column represents the status of the security
        association represented by this conceptual row. If
        the status of the SA is 'active', the SA is ready
        for active use. The status 'expiring' represents any
        of the various states that the security association
        transitions through before being purged. 
       | 
    
    
      | ceipSecTunSaProtocol | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.1 | 
    
    
      | 
        This column represents the security protocol (AH,
        ESP or IPComp) for which this security association
        was setup. 
       | 
    
    
      | ceipSecTunSaIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.2 | 
    
    
      | 
        The object, in the context of the IPsec tunnel
        'ceipSecTunIndex', is an index of security
        associations comprising the Phase-2 IPsec tunnel
        represented by the tunnel index 'ceipSecTunIndex'.
        The value of this index is a number which begins at
        1 and is incremented with each SPI associated with
        the corresponding IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunSaDirection | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.3 | 
    
    
      | 
        Phase-2 IPsec security associations are simplex.
        Hence a particular security association is used either
        for securing outgoing traffic or decoding incoming
        traffic. This column identifies the direction of the
        security association represented by this entry. 
       | 
    
    
      | ceipSecTunSaValue | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.4 | 
    
    
      | 
        This is the value of the Security Protection Index
        (SPI) assigned by the system to the security
        association represented by this entry. 
       | 
    
    
      | ceipSecTunSaIfIndex | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.5 | 
    
    
      | 
        This object represents the ifIndex of an interface
        where a tunnel with ceipSecTunIndex is created.
        Multiple IPsec tunnels can be created using the same
        interface.
       | 
    
    
      | ceipSecTunSaInOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.6 | 
    
    
      | 
        A high capacity count of the total number of octets
        received by using this SA. This value is
        accumulated BEFORE determining whether or not the packet
        should be decompressed.
       | 
    
    
      | ceipSecTunSaInDecompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.7 | 
    
    
      | 
        A high capacity count of the total number of decompressed
        octets received by using this SA.  This value
        is accumulated AFTER the packet is decompressed. If
        compression is not being used, this value will match the
        value of ceipSecTunSaTunInOctets.
       | 
    
    
      | ceipSecTunSaInPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.8 | 
    
    
      | 
        The total number of packets received by using this SA.
       | 
    
    
      | ceipSecTunSaInDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.9 | 
    
    
      | 
        The total number of packets dropped
        during receive process by using this SA.
        This count does NOT include packets dropped due
        to Anti-Replay processing.
       | 
    
    
      | ceipSecTunSaInReplayDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.10 | 
    
    
      | 
        The total number of packets dropped during
        receive processing due to Anti-Replay processing
        by using this SA.
       | 
    
    
      | ceipSecTunSaInAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.11 | 
    
    
      | 
        The total number of inbound authentication's
        performed by using this SA.
       | 
    
    
      | ceipSecTunSaInAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.12 | 
    
    
      | 
        The total number of inbound authentication's
        which ended in failure by using this SA.
       | 
    
    
      | ceipSecTunSaInDecrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.13 | 
    
    
      | 
        The total number of inbound decryption's performed
        by this SA.
       | 
    
    
      | ceipSecTunSaInDecryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.14 | 
    
    
      | 
        The total number of inbound decryption's
        which ended in failure by using this SA.
       | 
    
    
      | ceipSecTunSaOutOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.15 | 
    
    
      | 
        A high capacity count of the total number of octets
        sent by using this SA. This value is
        accumulated AFTER determining whether or not the packet
        should be compressed.
       | 
    
    
      | ceipSecTunSaOutUncompOctets | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.16 | 
    
    
      | 
        A high capacity count of the total number
        of uncompressed octets sent by using this SA.
        This value is accumulated BEFORE
        the packet is compressed. If compression
        is not being used, this value will match the value
        of ceipSecTunSaTunOutOctets.
       | 
    
    
      | ceipSecTunSaOutPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.17 | 
    
    
      | 
        The total number of packets sent by using this SA.
       | 
    
    
      | ceipSecTunSaOutDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.18 | 
    
    
      | 
        The total number of packets dropped during
        send processing by using this SA.
       | 
    
    
      | ceipSecTunSaOutAuths | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.19 | 
    
    
      | 
        The total number of outbound authentication's performed
        by using this SA.
       | 
    
    
      | ceipSecTunSaOutAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.20 | 
    
    
      | 
        The total number of outbound
        authentication's which ended in failure
        by using this SA.
       | 
    
    
      | ceipSecTunSaOutEncrypts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.21 | 
    
    
      | 
        The total number of outbound encryption's performed
        by using this SA.
       | 
    
    
      | ceipSecTunSaOutEncryptFails | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.22 | 
    
    
      | 
        The total number of outbound encryption's
        which ended in failure by using this SA.
       | 
    
    
      | ceipSecTunSaOutCompressedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.23 | 
    
    
      | 
        The total number of outbound packets
        which were successfully compressed by using this
        SA.
       | 
    
    
      | ceipSecTunSaOutCompSkippedPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.24 | 
    
    
      | 
        The total number of outbound packets that were to be
        compressed but which were skipped due to the compression
        hysteresis when using this SA.
       | 
    
    
      | ceipSecTunSaOutCompFailPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.25 | 
    
    
      | 
        The total number of outbound packets that failed
        compression because they grew in size after compression
        when using this SA.
       | 
    
    
      | ceipSecTunSaOutCompTooSmallPkts | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.26 | 
    
    
      | 
        The total number of outbound packets that were to be
        compressed but were smaller than the compression threshold
        size when using this SA.
       | 
    
    
      | ceipSecTunSaStatus | 
      .1.3.6.1.4.1.9.9.432.1.1.5.1.27 | 
    
    
      | 
         This column represents the status of the security
        association represented by this conceptual row. If
        the status of the SA is 'active', the SA is ready
        for active use. The status 'expiring' represents any
        of the various states that the security association
        transitions through before being purged. 
       | 
    
    
      | ceipSecIfTunnelStatus | 
      .1.3.6.1.4.1.9.9.432.1.1.6.1.1 | 
    
    
      | 
        This object corresponds to the status of
        a IPsec Phase-2 Tunnel in ceipSecTunnelTable
        indexed by ceipSecTunIndex. The valid status
        this object can have are 'active' and
        'awaitCommit'.
       | 
    
    
      | ceipSecTunHistIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.1 | 
    
    
      | 
        The index of the IPsec Phase-2 Tunnel History Table.
        The value of the index is a number which
        begins at one and is incremented with each tunnel
        that ends. The value
        of this object will wrap at 4,294,967,295.
       | 
    
    
      | ceipSecTunHistTermReason | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.2 | 
    
    
      | 
        The reason the IPsec Phase-2 Tunnel was terminated.
        Possible reasons include:
        1 = other
        2 = normal termination
        3 = operator request
        4 = peer delete request was received
        5 = contact with peer was lost
        6 = applicationInitiated (eg: L2TP requesting the
        termination)
        7 = failure of extended authentication
        8 = local failure occurred
        9 = operator initiated check point request
       | 
    
    
      | ceipSecTunHistActiveIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.3 | 
    
    
      | 
        The index of the previously active IPsec Phase-2
        Tunnel.
        This object must correspond to an expired IPsec
        tunnel; hence this object may not assume the value
        of 0. 
       | 
    
    
      | ceipSecTunHistLocalAddressType | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.4 | 
    
    
      | 
        The type of the IP address of the local endpoint for
        the IPsec Phase-2 Tunnel. 
       | 
    
    
      | ceipSecTunHistLocalAddress | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.5 | 
    
    
      | 
        The IP address of the local endpoint for
        the IPsec Phase-2 Tunnel. 
       | 
    
    
      | ceipSecTunHistRemoteAddressType | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.6 | 
    
    
      | 
        The type of the IP address of the remote endpoint
        for the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistRemoteAddress | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.7 | 
    
    
      | 
        The IP address of the remote endpoint for
        the IPsec Phase-2 Tunnel. 
       | 
    
    
      | ceipSecTunHistControlProtocol | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.8 | 
    
    
      | 
        Identifies the protocol that was used to setup
        and administer Phase-2 IPsec tunnel. 
       | 
    
    
      | ceipSecTunHistControlTunnelIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.9 | 
    
    
      | 
        The index of the IPsec Phase-1 Tunnel that spawned
        this Phase-2 tunnel (in case of IKE, this value
        would refer to 'csikeTunIndex' in the 'csikeTunnelTable').
        If the IPsec tunnel corresponding to this entry
        was setup manually, the value of this object should
        be zero. 
       | 
    
    
      | ceipSecTunHistEncapMode | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.10 | 
    
    
      | 
        The encapsulation mode used by the
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistNATTraversalMode | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.11 | 
    
    
      | 
        The encapsulation used by the IPsec Phase-2
        tunnel corresponding to this conceptual row
        for NAT traversal.
       | 
    
    
      | ceipSecTunHistLifeSize | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.12 | 
    
    
      | 
        The negotiated LifeSize of the IPsec Phase-2 Tunnel in
        kilobytes.
       | 
    
    
      | ceipSecTunHistLifeTime | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.13 | 
    
    
      | 
        The negotiated LifeTime of the IPsec Phase-2 Tunnel in
        seconds.
       | 
    
    
      | ceipSecTunHistStartTime | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.14 | 
    
    
      | 
        The value of sysUpTime in hundredths of seconds
        when the IPsec Phase-2 Tunnel was started.
       | 
    
    
      | ceipSecTunHistActiveTime | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.15 | 
    
    
      | 
        The length of time the IPsec Phase-2 Tunnel has been
        active in hundredths of seconds.
       | 
    
    
      | ceipSecTunHistTotalRefreshes | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.16 | 
    
    
      | 
        The total number of security association refreshes
        performed.
       | 
    
    
      | ceipSecTunHistTotalSas | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.17 | 
    
    
      | 
        The total number of security associations used
        during the life of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInSaDHGrp | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.18 | 
    
    
      | 
        The Diffie Hellman Group used by the inbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInSaEncryptAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.19 | 
    
    
      | 
        The encryption algorithm used by the inbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInSaEncryptKeySize | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.20 | 
    
    
      | 
        The size in bits of the key which was negotiated to
        be used with the encryption transform used with this
        tunnel denoted by ceipSecTunHistInSaEncryptAlgo.
        For DES and 3DES the key size is respectively 56 and
        168. For AES, this will denote the negotiated key size.
       | 
    
    
      | ceipSecTunHistInSaAhAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.21 | 
    
    
      | 
        The authentication algorithm used by the inbound
        authentication header (AH) security association of
        the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInSaEspAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.22 | 
    
    
      | 
        The authentication algorithm used by the inbound
        encapsulation security protocol (ESP)
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInSaDecompAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.23 | 
    
    
      | 
        The decompression algorithm used by the inbound
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutSaDHGrp | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.24 | 
    
    
      | 
        The Diffie Hellman Group used by the outbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutSaEncryptAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.25 | 
    
    
      | 
        The encryption algorithm used by the outbound security
        association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutSaEncryptKeySz | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.26 | 
    
    
      | 
        The size in bits of the key which was negotiated to
        be used with the encryption transform used with this
        tunnel denoted by ceipSecTunHistOutSaEncryptAlgo.
        For DES and 3DES the key size is respectively 56 and
        168. For AES, this will denote the negotiated key
        size.
       | 
    
    
      | ceipSecTunHistOutSaAhAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.27 | 
    
    
      | 
        The authentication algorithm used by the outbound
        authentication header (AH) security association of
        the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutSaEspAuthAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.28 | 
    
    
      | 
        The authentication algorithm used by the inbound
        ecapsulation security protocol (ESP)
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutSaCompAlgo | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.29 | 
    
    
      | 
        The compression algorithm used by the inbound
        security association of the IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistPmtu | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.30 | 
    
    
      | 
        The Path MTU that was determined for this IPsec
        Phase-2 tunnel.
       | 
    
    
      | ceipSecTunHistInOctets | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.31 | 
    
    
      | 
        A high capacity count of the total number of octets
        received by this IPsec Phase-2 Tunnel. This value
        is accumulated BEFORE determining whether or not
        the packet should be decompressed.
       | 
    
    
      | ceipSecTunHistInDecompOctets | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.32 | 
    
    
      | 
        A high capacity count of the total number of
        decompressed octets received by this IPsec Phase-2 Tunnel.
        This value is accumulated AFTER the packet is
        decompressed.
        If compression is not being used, this value will match
        the value of ceipSecTunInOctets. 
       | 
    
    
      | ceipSecTunHistInPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.33 | 
    
    
      | 
        The total number of packets received by this
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.34 | 
    
    
      | 
        The total number of packets dropped during
        receive processing by this IPsec Phase-2 Tunnel.
        This count does NOT include packets
        dropped due to Anti-Replay processing.
       | 
    
    
      | ceipSecTunHistInReplayDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.35 | 
    
    
      | 
        The total number of packets dropped during
        receive processing due to Anti-Replay processing
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInAuths | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.36 | 
    
    
      | 
        The total number of inbound authentication's
        performed by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.37 | 
    
    
      | 
        The total number of inbound authentication's
        which ended in failure by this IPsec Phase-2 Tunnel .
       | 
    
    
      | ceipSecTunHistInDecrypts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.38 | 
    
    
      | 
        The total number of inbound decryption's performed
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistInDecryptFails | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.39 | 
    
    
      | 
        The total number of inbound decryption's
        which ended in failure by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutOctets | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.40 | 
    
    
      | 
        A high capacity count of the total number of octets
        sent by this IPsec Phase-2 Tunnel.  This value
        is accumulated AFTER determining whether or not
        the packet should be compressed.
       | 
    
    
      | ceipSecTunHistOutUncompOctets | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.41 | 
    
    
      | 
        A high capacity count of the total
        number of uncompressed octets sent by this
        IPsec Phase-2 Tunnel.  This value is accumulated
        BEFORE the packet is compressed. If compression
        is not being used, this value will match the value
        of 'ceipSecTunOutOctets'.
       | 
    
    
      | ceipSecTunHistOutPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.42 | 
    
    
      | 
        The total number of packets sent by this
        IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutDropPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.43 | 
    
    
      | 
        The total number of packets dropped during
        send processing by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutAuths | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.44 | 
    
    
      | 
        The total number of outbound authentication's
        performed by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutAuthFails | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.45 | 
    
    
      | 
        The total number of outbound authentication's
        which ended in failure by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutEncrypts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.46 | 
    
    
      | 
        The total number of outbound encryption's performed
        by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutEncryptFails | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.47 | 
    
    
      | 
        The total number of outbound encryption's
        which ended in failure by this IPsec Phase-2 Tunnel.
       | 
    
    
      | ceipSecTunHistOutCompressedPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.48 | 
    
    
      | 
        The total number of outbound packets
        which were successfully compressed.
       | 
    
    
      | ceipSecTunHistOutCompSkippedPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.49 | 
    
    
      | 
        The total number of outbound packets that were to be
        compressed but which were skipped due to the
        compression hysteresis.
       | 
    
    
      | ceipSecTunHistOutCompFailPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.50 | 
    
    
      | 
        The total number of outbound packets that failed
        compression because they grew in size after compression.
       | 
    
    
      | ceipSecTunHistOutCompSmallPkts | 
      .1.3.6.1.4.1.9.9.432.1.2.2.1.51 | 
    
    
      | 
        The total number of outbound packets that were
        to be compressed but were smaller than the
        compression threshold size.
       | 
    
    
      | ceipSecEndPtHistIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.1 | 
    
    
      | 
        The number of the previously active Endpoint
        associated with a IPsec Phase-2 Tunnel Table.
        The value of this index is a number which begins
        at one and is incremented with each Endpoint
        associated with an IPsec Phase-2 Tunnel.
        The value of this object will wrap at 4,294,967,295.
       | 
    
    
      | ceipSecEndPtHistTunIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.2 | 
    
    
      | 
        The index  of the previously active IPsec
        Phase-2 Tunnel Table.
       | 
    
    
      | ceipSecEndPtHistActiveIndex | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.3 | 
    
    
      | 
        The index  of the previously active Endpoint.
       | 
    
    
      | ceipSecEndPtHistLocalName | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.4 | 
    
    
      | 
        The DNS name of the local Endpoint.
       | 
    
    
      | ceipSecEndPtHistLocalType | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.5 | 
    
    
      | 
        The type of identity for the local Endpoint.
       | 
    
    
      | ceipSecEndPtHistLocalAddrType1 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.6 | 
    
    
      | 
        The type of the IP address for this local Endpoint's
        first IP address.
       | 
    
    
      | ceipSecEndPtHistLocalAddr1 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.7 | 
    
    
      | 
        The local Endpoint's first IP address specification.
        If the local Endpoint type is single IP address,
        then this is the value of the IP address.
        If the local Endpoint type is IP subnet, then this
        is the value of the subnet.
        If the local Endpoint type is IP address range,
        then this is the value of beginning IP address of
        the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        cceipSecEndPtLocalType.
        
       | 
    
    
      | ceipSecEndPtHistLocalAddrType2 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.8 | 
    
    
      | 
        The type of the IP address for this local Endpoint's
        second IP address.
       | 
    
    
      | ceipSecEndPtHistLocalAddr2 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.9 | 
    
    
      | 
        The local Endpoint's second IP address
        specification.
        If the local Endpoint type is single IP address,
        then this is the value of the IP address.
        If the local Endpoint type is IP subnet, then this
        is the value of the subnet mask.
        If the local Endpoint type is IP address range,
        then this is the value of ending IP address of
        the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        cceipSecEndPtLocalType.
        
       | 
    
    
      | ceipSecEndPtHistLocalProtocol | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.10 | 
    
    
      | 
        The protocol number of the local Endpoint's
        traffic.
       | 
    
    
      | ceipSecEndPtHistLocalPort | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.11 | 
    
    
      | 
        The port number of the local Endpoint's traffic.
       | 
    
    
      | ceipSecEndPtHistRemoteName | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.12 | 
    
    
      | 
        The DNS name of the remote Endpoint.
       | 
    
    
      | ceipSecEndPtHistRemoteType | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.13 | 
    
    
      | 
        The type of identity for the remote Endpoint.
       | 
    
    
      | ceipSecEndPtHistRemoteAddrType1 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.14 | 
    
    
      | 
        The type of the IP address for this remote Endpoint's
        first IP address.
       | 
    
    
      | ceipSecEndPtHistRemoteAddr1 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.15 | 
    
    
      | 
        The remote Endpoint's first IP address
        specification.
        If the remote Endpoint type is single IP address,
        then this is the value of the IP address.
        If the remote Endpoint type is IP subnet, then this
        is the value of the subnet.
        If the remote Endpoint type is IP address range,
        then this is the value of beginning IP address of
        the range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        cceipSecEndPtRemoteType.
        
       | 
    
    
      | ceipSecEndPtHistRemoteAddrType2 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.16 | 
    
    
      | 
        The type of the IP address for this remote Endpoint's
        second IP address.
       | 
    
    
      | ceipSecEndPtHistRemoteAddr2 | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.17 | 
    
    
      | 
        The remote Endpoint's second IP address
        specification.
        If the remote Endpoint type is single IP address,
        then this is the value of the IP address.
        If the remote Endpoint type is IP subnet, then this
        is the value of the subnet mask.
        If the remote Endpoint type is IP address range,
        then this is the value of ending IP address of the
        range.
        If the type is an IP address, a range or a subnet,
        the type of the address can be inferred from
        cceipSecEndPtRemoteType.
       | 
    
    
      | ceipSecEndPtHistRemoteProtocol | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.18 | 
    
    
      | 
        The protocol number of the remote Endpoint's traffic.
       | 
    
    
      | ceipSecEndPtHistRemotePort | 
      .1.3.6.1.4.1.9.9.432.1.2.3.1.19 | 
    
    
      | 
        The port number of the remote Endpoint's traffic.
       | 
    
    
      | ceipSecFailIndex | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.1 | 
    
    
      | 
        The IPsec Phase-2 Failure Table index.
        The value of the index is a number which
        begins at one and is incremented with each
        IPsec Phase-1 failure. The value of this
        object will wrap at 4,294,967,295.
       | 
    
    
      | ceipSecFailReason | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.2 | 
    
    
      | 
        The reason for the failure.  Possible reasons
        include:
        1 = other
        2 = internal error occurred
        3 = peer encoding error
        4 = proposal failure
        5 = protocol use failure
        6 = non-existent security association
        7 = decryption failure
        8 = encryption failure
        9 = inbound authentication failure
        10 = outbound authentication failure
        11 = compression failure
        12 = system capacity failure
        13 = peer delete request was received
        14 = contact with peer was lost
        15 = sequence number rolled over
        16 = operator requested termination.
       | 
    
    
      | ceipSecFailTime | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.3 | 
    
    
      | 
        The value of sysUpTime in hundredths of seconds
        at the time of the failure.
       | 
    
    
      | ceipSecFailTunnelIndex | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.4 | 
    
    
      | 
        The Phase-2 Tunnel index (ceipSecTunIndex).
        If this conceptual row corresponds to an operation
        failure (that is, the failure of an established
        Phase-2 IPsec tunnel), then the value of this object
        may not be zero.
       | 
    
    
      | ceipSecFailSaSpi | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.5 | 
    
    
      | 
        The security association SPI value.
        If this conceptual row corresponds to a setup
        failure (failure to establish the tunnel), the
        value of this MIB object is undefined.
       | 
    
    
      | ceipSecFailPktSrcAddressType | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.6 | 
    
    
      | 
        The type of the packet's source IP address.
       | 
    
    
      | ceipSecFailPktSrcAddress | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.7 | 
    
    
      | 
        The packet's source IP address.
       | 
    
    
      | ceipSecFailPktDstAddressType | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.8 | 
    
    
      | 
        The type of the packet's destination IP address.
       | 
    
    
      | ceipSecFailPktDstAddress | 
      .1.3.6.1.4.1.9.9.432.1.3.2.1.9 | 
    
    
      | 
        The packet's destination IP address.
       |