Restrictions for IPsec SNMP Support
-
Only the following tunnel setup failure logs are supported with the IPsec--SNMP Support feature: - NOTIFY_MIB_IPSEC_PROPOSAL_INVALID
- “A tunnel could not be established because the peer did not supply an acceptable proposal.”
- NOTIFY_MIB_IPSEC_ENCRYPT_FAILURE
- “A tunnel could not be established because it failed to encrypt a packet to be sent to a peer.”
- NOTIFY_MIB_IPSEC_SYSCAP_FAILURE
- “A tunnel could not be established because the system ran out of resources.”
- NOTIFY_MIB_IPSEC_LOCAL_FAILURE
- “A tunnel could not be established because of an internal error.”
Note that these failure notices are recorded in the failure tables, but are not available as SNMP notifications (traps).
-
The following functions are not supported with the IPsec MIB feature: - Checkpointing
- The Dynamic Cryptomap table of the CISCO-IPSEC-MIB
-
The CISCO-IPSEC-POLICY-MAP-MIB (ciscoIpSecPolMap) defines no notifications (the “IPSec Policy Map Notifications Group” is empty).