ANYSEC
tmnxAnySecMkaOperStateChanged
Property name | Value |
---|---|
Application name | ANYSEC |
Event ID |
2002 |
Event name | tmnxAnySecMkaOperStateChanged |
SNMP notification prefix and OID | TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.2 |
Default severity | warning |
Source stream |
main |
Message format string | MKA Oper State Changed to $tmnxAnySecMkaStatsOperStateNotif$ - Encryption Group: $tmnxAnySecEncryptGroupNameNotif$, Remote Peer: $tmnxAnySecPeerAddrNotif$, CAK Name: $tmnxAnySecCakNameNotif$ |
Cause |
The tmnxAnySecMkaOperStateChanged notification is sent when a change occurs in the operational state of the MACSec Key Agreement (MKA) used by the Connectivity Association (CA) specified for the specified encryption group. |
Effect | Informational. |
Recovery |
N/A. |
tmnxAnySecMkaPskRollover
Property name | Value |
---|---|
Application name | ANYSEC |
Event ID |
2001 |
Event name | tmnxAnySecMkaPskRollover |
SNMP notification prefix and OID | TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.1 |
Default severity | warning |
Source stream |
main |
Message format string | PSK Rollover for MKA over IP - Encryption Group: $tmnxAnySecEncryptGroupNameNotif$, Remote Peer: $tmnxAnySecPeerAddrNotif$, CAK Name: $tmnxAnySecNewCakNameNotif$, Key Entry Number: $tmnxAnySecKeyEntryNumberNotif$ |
Cause | The tmnxAnySecMkaPskRollover notification is sent when a pre-shared key (PSK) rollover occurs for the MACSec Key Agreement (MKA) used by the Connectivity Association (CA) specified for the specified encryption group. |
Effect | Informational. |
Recovery |
N/A. |
tmnxAnySecMkaSessionInitiation
Property name | Value |
---|---|
Application name | ANYSEC |
Event ID |
2003 |
Event name | tmnxAnySecMkaSessionInitiation |
SNMP notification prefix and OID | TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.3 |
Default severity | warning |
Source stream |
main |
Message format string | ANYsec MKA session initiated for peer $tmnxAnySecPeerAddrNotif$ in encryption group $tmnxAnySecEncryptGroupNameNotif$ |
Cause | The tmnxAnySecMkaSessionInitiation notification is sent when all of the four entities (security termination policy, connectivity association, encryption group, and peer) associated with an ANYsec MKA session are administratively enabled. |
Effect | The enabling of all associated entities causes the initiation of the ANYsec MKA session and MKA session negotiation will begin. If negotiation is successful, notification tmnxAnySecMkaOperStateChanged will be sent with a change to 'up'. |
Recovery | N/A. |
tmnxAnySecMkaSessionTermination
Property name | Value |
---|---|
Application name |
ANYSEC |
Event ID | 2004 |
Event name | tmnxAnySecMkaSessionTermination |
SNMP notification prefix and OID |
TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.4 |
Default severity |
warning |
Source stream | main |
Message format string | ANYsec MKA session terminated for peer $tmnxAnySecPeerAddrNotif$ in encryption group $tmnxAnySecEncryptGroupNameNotif$ - $tmnxAnySecMkaSessTermReasonNotif$ is administratively disabled - traffic is being dropped |
Cause | The tmnxAnySecMkaSessionTermination notification is sent when either the security termination policy or the connectivity association associated with the ANYsec MKA session is administratively disabled. This notification is not sent when either the associated peer or encryption group is administratively disabled because the disabling of either of those causes unencrypted traffic to be transmitted resulting in the critical notification tmnxAnySecSessionDisabled being sent. |
Effect | The disabling of either the security termination policy or the connectivity association causes the termination of the ANYsec MKA session. The associated MKA encryption will stop, and its traffic will be dropped in the data path. |
Recovery | To restart transmission, enable all entities associated with the MKA session. |
tmnxAnySecPeerInconsisRxSciClrd
Property name | Value |
---|---|
Application name |
ANYSEC |
Event ID | 2008 |
Event name | tmnxAnySecPeerInconsisRxSciClrd |
SNMP notification prefix and OID |
TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.8 |
Default severity |
warning |
Source stream | main |
Message format string | ANYsec inconsistent Rx SCI cleared - transmission to peer $tmnxAnySecPeerAddrNotif$ in encryption group $tmnxAnySecEncryptGroupNameNotif$ resumed |
Cause | The tmnxAnySecPeerInconsisRxSciClrd notification is sent when the condition that caused the previous tmnxAnySecPeerInconsisRxSciDtctd to be triggered is cleared, i.e.: the peer encryption SID label is made to be consistent with the local encryption SID label. |
Effect | Traffic will be sent to this peer. |
Recovery |
N/A, informational. |
tmnxAnySecPeerInconsisRxSciDtctd
Property name | Value |
---|---|
Application name | ANYSEC |
Event ID |
2007 |
Event name | tmnxAnySecPeerInconsisRxSciDtctd |
SNMP notification prefix and OID | TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.7 |
Default severity | warning |
Source stream |
main |
Message format string | ANYsec inconsistent Rx SCI detected - transmission to peer $tmnxAnySecPeerAddrNotif$ in encryption group $tmnxAnySecEncryptGroupNameNotif$ stopped - Rx SCI: $tmnxAnySecPeerIncsRxSciNotif$ - reason: $tmnxAnySecPeerIncsRxSciResnNotif$ |
Cause | The tmnxAnySecPeerInconsisRxSciDtctd notification is sent when the peer sends an SCI that is not consistent with the local encryption SID label. |
Effect | Traffic will not be sent to this peer. |
Recovery | To resume transmission, the peer encryption SID label must be made consistent with the local encryption SID label. |
tmnxAnySecSessionDisabled
Property name | Value |
---|---|
Application name |
ANYSEC |
Event ID | 2006 |
Event name | tmnxAnySecSessionDisabled |
SNMP notification prefix and OID |
TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.6 |
Default severity |
critical |
Source stream | main |
Message format string | ANYsec session disabled for peer $tmnxAnySecPeerAddrNotif$ (peer admin state: $tmnxAnySecPeerAdminState$) in encryption group $tmnxAnySecEncryptGroupNameNotif$ (group admin state: $tmnxAnySecEncryptGrpAdminState$) - Clear text transmission occurring |
Cause |
The tmnxAnySecSessionEnabled notification is sent when either a peer or its associated encryption group is administratively disabled. |
Effect | Encryption of traffic to the peer will be stopped and clear text traffic will be transmitted. |
Recovery | To resume encryption (and stop clear text transmission), administratively enable both the peer and its associated encryption group. |
tmnxAnySecSessionEnabled
Property name | Value |
---|---|
Application name |
ANYSEC |
Event ID | 2005 |
Event name | tmnxAnySecSessionEnabled |
SNMP notification prefix and OID |
TIMETRA-ANYSEC-MIB.tmnxAnySecNotifications.5 |
Default severity |
warning |
Source stream | main |
Message format string | ANYsec session enabled for peer $tmnxAnySecPeerAddrNotif$ in encryption group $tmnxAnySecEncryptGroupNameNotif$ |
Cause | The tmnxAnySecSessionEnabled notification is sent when a peer and its associated encryption group are both administratively enabled. |
Effect | Encrypted traffic will be transmitted to the specified peer when tmnxAnySecMkaStatsOperState transitions to 'up'. Until tmnxAnySecMkaStatsOperState transitions to 'up', traffic will be dropped. |
Recovery | N/A. |