class CIM_IKEAction : CIM_SANegotiationAction

Description:

IKEAction specifies the parameters to use for an IPsec IKE phase 1 negotiation.

Definition:

Feature Type Class Origin Qualifiers
InstanceID string CIM_ManagedElement
Description InstanceID is an optional property that may be used to opaquely and uniquely identify an instance of this class within the scope of the instantiating Namespace. Various subclasses of this class may override this property to make it required, or a key. Such subclasses may also modify the preferred algorithms for ensuring uniqueness that are defined below. To ensure uniqueness within the NameSpace, the value of InstanceID should be constructed using the following "preferred" algorithm: <OrgID>:<LocalID> Where <OrgID> and <LocalID> are separated by a colon (:), and where <OrgID> must include a copyrighted, trademarked, or otherwise unique name that is owned by the business entity that is creating or defining the InstanceID or that is a registered ID assigned to the business entity by a recognized global authority. (This requirement is similar to the <Schema Name>_<Class Name> structure of Schema class names.) In addition, to ensure uniqueness, <OrgID> must not contain a colon (:). When using this algorithm, the first colon to appear in InstanceID must appear between <OrgID> and <LocalID>. <LocalID> is chosen by the business entity and should not be reused to identify different underlying (real-world) elements. If not null and the above "preferred" algorithm is not used, the defining entity must assure that the resulting InstanceID is not reused across any InstanceIDs produced by this or other providers for the NameSpace of this instance. If not set to null for DMTF-defined instances, the "preferred" algorithm must be used with the <OrgID> set to CIM.
Caption string CIM_ManagedElement
Description The Caption property is a short textual description (one- line string) of the object.
MaxLen 64
Description string CIM_ManagedElement
Description The Description property provides a textual description of the object.
ElementName string CIM_ManagedElement
Description A user-friendly name for the object. This property allows each instance to define a user-friendly name in addition to its key properties, identity data, and description information. Note that the Name property of ManagedSystemElement is also defined as a user-friendly name. But, it is often subclassed to be a Key. It is not reasonable that the same property can convey both identity and a user-friendly name, without inconsistencies. Where Name exists and is not a Key (such as for instances of LogicalDevice), the same information can be present in both the Name and ElementName properties.
CommonName string CIM_Policy
Description A user-friendly name of this policy-related object.
PolicyKeywords string[] CIM_Policy
Description An array of keywords for characterizing / categorizing policy objects. Keywords are of one of two types: - Keywords defined in this and other MOFs, or in DMTF white papers. These keywords provide a vendor- independent, installation-independent way of characterizing policy objects. - Installation-dependent keywords for characterizing policy objects. Examples include 'Engineering', 'Billing', and 'Review in December 2000'. This MOF defines the following keywords: 'UNKNOWN', 'CONFIGURATION', 'USAGE', 'SECURITY', 'SERVICE', 'MOTIVATIONAL', 'INSTALLATION', and 'EVENT'. These concepts are self-explanatory and are further discussed in the SLA/Policy White Paper. One additional keyword is defined: 'POLICY'. The role of this keyword is to identify policy-related instances that may not be otherwise identifiable, in some implementations. The keyword 'POLICY' is NOT mutually exclusive of the other keywords specified above.
SystemCreationClassName string CIM_PolicyAction
Key TRUE
Description The name of the class or the subclass used in the creation of the System object in whose scope this PolicyAction is defined. This property helps to identify the System object in whose scope this instance of PolicyAction exists. For a rule-specific PolicyAction, this is the System in whose context the PolicyRule is defined. For a reusable PolicyAction, this is the instance of PolicyRepository (which is a subclass of System) that holds the Action. Note that this property, and the analogous property SystemName, do not represent propagated keys from an instance of the class System. Instead, they are properties defined in the context of this class, which repeat the values from the instance of System to which this PolicyAction is related, either directly via the PolicyActionInPolicyRepository association or indirectly via the PolicyActionInPolicyRule aggregation.
MaxLen 256
SystemName string CIM_PolicyAction
Key TRUE
Description The name of the System object in whose scope this PolicyAction is defined. This property completes the identification of the System object in whose scope this instance of PolicyAction exists. For a rule-specific PolicyAction, this is the System in whose context the PolicyRule is defined. For a reusable PolicyAction, this is the instance of PolicyRepository (which is a subclass of System) that holds the Action.
MaxLen 256
PolicyRuleCreationClassName string CIM_PolicyAction
Key TRUE
Description For a rule-specific PolicyAction, the CreationClassName of the PolicyRule object with which this Action is associated. For a reusable PolicyAction, a special value, 'NO RULE', should be used to indicate that this Action is reusable and not associated with a single PolicyRule.
MaxLen 256
PolicyRuleName string CIM_PolicyAction
Key TRUE
Description For a rule-specific PolicyAction, the name of the PolicyRule object with which this Action is associated. For a reusable PolicyAction, a special value, 'NO RULE', should be used to indicate that this Action is reusable and not associated with a single PolicyRule.
MaxLen 256
CreationClassName string CIM_PolicyAction
Key TRUE
Description CreationClassName indicates the name of the class or the subclass used in the creation of an instance. When used with the other key properties of this class, this property allows all instances of this class and its subclasses to be uniquely identified.
MaxLen 256
PolicyActionName string CIM_PolicyAction
Key TRUE
Description A user-friendly name of this PolicyAction.
MaxLen 256
DoActionLogging boolean CIM_PolicyAction
Description DoActionLogging causes a log message to be generated when the action is performed.
DoPacketLogging boolean CIM_SAAction
Description DoPacketLogging causes a log message to be generated when the action is applied to a packet.
MappingStrings IPSP Policy Model.IETF|SAAction.DoPacketLogging
ModelCorrespondence CIM_SecurityAssociationEndpoint.PacketLoggingActive
MinLifetimeSeconds uint64 CIM_SANegotiationAction
Description MinLifetimeSeconds prevents certain denial of service attacks where the peer requests an arbitrarily low lifetime value, causing renegotiations with expensive Diffie-Hellman operations. The property specifies the minimum lifetime, in seconds, that will be accepted from the peer. A value of zero (the default) indicates that there is no minimum value. A non-zero value specifies the minimum seconds lifetime.
Units Seconds
MappingStrings IPSP Policy Model.IETF|IKENegotiationAction.MinLifetimeSeconds
ModelCorrespondence CIM_SecurityAssociationEndpoint.LifetimeSeconds
IdleDurationSeconds uint64 CIM_SANegotiationAction
Description IdleDurationSeconds is the time an SA can remain idle (i.e., no traffic protected using the security association) before it is automatically deleted. The default (zero) value indicates that there is no idle duration timer and that the SA is deleted based upon the SA seconds and kilobyte lifetimes. Any non-zero value indicates the number of seconds that the SA may remain unused.
Units Seconds
MappingStrings IPSP Policy Model.IETF|IKENegotiationAction.IdleDurationSeconds
ModelCorrespondence CIM_SecurityAssociationEndpoint.IdleDurationSeconds
MinLifetimeKilobytes uint64 CIM_SANegotiationAction
Description MinLifetimeKilobytes prevents certain denial of service attacks where the peer requests an arbitrarily low lifetime value, causing renegotiations with expensive Diffie-Hellman operations. The property specifies the minimum lifetime, in kilobytes, that will be accepted from the peer. A value of zero (the default) indicates that there is no minimum value. A non-zero value specifies the minimum kilobytes lifetime. Note that there has been considerable debate regarding the usefulness of applying kilobyte lifetimes to phase 1 security associations, so it is likely that this property will only apply to the subclass, IPsecAction.
Units KiloBytes
MappingStrings IPSP Policy Model.IETF|IKENegotiationAction.MinLifetimeKilobytes
ModelCorrespondence CIM_SecurityAssociationEndpoint.LifetimeKilobytes
ExchangeMode uint16 CIM_IKEAction
Description The ExchangeMode designates the mode IKE should use for its key negotiations.
ValueMap 2, 3, 4
Values "Base" [2]
"Main" [3]
"Aggressive" [4]
MappingStrings IPSP Policy Model.IETF|IKEAction.ExchangeMode
UseIKEIdentityType uint16 CIM_IKEAction
Description UseIKEIdentityType specifies what network identity type should be used when negotiating with the peer. It is used in conjunction with the available IPNetworkIdentity instances, that are associated with an IPProtocolEndpoint.
ValueMap 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, .., 0x8000..
Values "Other" [1]
"IPV4 Address" [2]
"FQDN" [3]
"User FQDN" [4]
"IPV4 Subnet Address" [5]
"IPV6 Address" [6]
"IPV6 Subnet Address" [7]
"IPV4 Address Range" [8]
"IPV6 Address Range" [9]
"DER ASN1 DN" [10]
"DER ASN1 GN" [11]
"KEY ID" [12]
"DMTF Reserved" [..]
"Vendor Reserved" [0x8000..]
MappingStrings IPSP Policy Model.IETF|IKEAction.UseIKEIdentityType, RFC2407.IETF|Section 4.6.2.1
ModelCorrespondence CIM_IPNetworkIdentity.IdentityType
VendorID string CIM_IKEAction
Description VendorID specifies the value to be used in the Vendor ID payload. An empty string (the default) means that the Vendor ID payload will not be generated or accepted. A non-NULL value means that a Vendor ID payload will be generated (when acting as an initiator) or is expected (when acting as a responder).
MappingStrings IPSP Policy Model.IETF|IKEAction.VendorID
AggressiveModeGroupID uint16 CIM_IKEAction
Description When IKEAction.ExchangeMode is set to "Aggressive" (4), this property specifies the key exchange groupID to use in the first packets of the phase 1 negotiation. This property is ignored unless the ExchangeMode is 'aggressive'. If the GroupID number is from the vendor- specific range (32768-65535), the VendorID qualifies the group number. Well-known group identifiers from RFC2412, Appendix E, are: Group 1='768 bit prime', Group 2='1024 bit prime', Group 3='Elliptic Curve Group with 155 bit field element', Group 4='Large Elliptic Curve Group with 185 bit field element', and Group 5='1536 bit prime'.
ValueMap 0, 1, 2, 3, 4, 5, .., 0x8000..
Values "No Group/Non-Diffie-Hellman Exchange" [0]
"DH-768 bit prime" [1]
"DH-1024 bit prime" [2]
"EC2N-155 bit field element" [3]
"EC2N-185 bit field element" [4]
"DH-1536 bit prime" [5]
"Standard Group - Reserved" [..]
"Vendor Reserved" [0x8000..]
MappingStrings IPSP Policy Model.IETF|IKEAction.AggressiveModeGroupID, RFC2412.IETF|Appendix E
ModelCorrespondence CIM_IKEAction.VendorID

Typographical Conventions:

  1. Inherited properties are italicized.
  2. Local properties are bolded.
  3. Key properties are highlighted in gold

Generated by mof2html v.2.1.0(002). simplewbem.org Mon Nov 2 09:43:14 2009