MIB Viewer

CISCO-FIREWALL-MIB

87 objects
MIB module for monitoring Cisco Firewalls.
Imported Objects
CISCO-SMIciscoMgmt
IF-MIBInterfaceIndexOrZero
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP
SNMPv2-SMICounter32 Gauge32 IpAddress MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32
SNMPv2-TCDateAndTime RowPointer TEXTUAL-CONVENTION
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.147IdentityciscoFirewallMIBMIB module for monitoring Cisco Firewalls.
1.3.6.1.4.1.9.9.147.1NodeciscoFirewallMIBObjects
1.3.6.1.4.1.9.9.147.1.1NodecfwEvents
1.3.6.1.4.1.9.9.147.1.1.1NodecfwBasicEvents
1.3.6.1.4.1.9.9.147.1.1.1.1ScalarcfwBasicEventsTableLastRowread-onlycurrentThe index value of the most recently created row in the cfwBasicEventsTable. This number starts at 1 and increase by one with each new log entry. When this num…
1.3.6.1.4.1.9.9.147.1.1.1.2TablecfwBasicEventsTablenot-accessiblecurrentTable of basic data for firewall events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. The oldest …
1.3.6.1.4.1.9.9.147.1.1.1.2.1RowcfwBasicEventsEntrynot-accessiblecurrentAn entry in the table, containing general information about an event. This table will always be sparse, i.e., each row will instanciate only a subet of the col…
1.3.6.1.4.1.9.9.147.1.1.1.2.1.1ColumncfwBasicEventIndexnot-accessiblecurrentAn index that uniquely identifies an entry in the log table. These indices are assigned beginning with 1 and increase by one with each new event logged.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.2ColumncfwBasicEventTimeread-onlycurrentThe time that the event occurred.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.3ColumncfwBasicSecurityEventTyperead-onlycurrentThe type of security-related event that this row contains. If the event is not security-related this object will not be instantiated.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.4ColumncfwBasicContentInspEventTyperead-onlycurrentThe type of content inspection-related event that this row contains. If the event is not content inspection-related this object will not be instantiated.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.5ColumncfwBasicConnectionEventTyperead-onlycurrentThe type of connection-related event that this row contains. If the event is not connection-related this object will not be instantiated.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.6ColumncfwBasicAccessEventTyperead-onlycurrentThe type of access-related event that this row contains. If the event is not access-related this object will not be instantiated.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.7ColumncfwBasicAuthenticationEventTyperead-onlycurrentThe type of authentication-related event that this row contains. If the event is not authentication-related this object will not be instantiated.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.8ColumncfwBasicGenericEventTyperead-onlycurrentThe type of generic event that this row contains. If the event does not fall into one of the other categories this object will be populated. Otherwise, this ob…
1.3.6.1.4.1.9.9.147.1.1.1.2.1.9ColumncfwBasicEventDescriptionread-onlycurrentA description of the event. The value of the object may be a zero-length string.
1.3.6.1.4.1.9.9.147.1.1.1.2.1.10ColumncfwBasicEventDetailsTableRowread-onlycurrentA pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appe…
1.3.6.1.4.1.9.9.147.1.1.2NodecfwNetEvents
1.3.6.1.4.1.9.9.147.1.1.2.1ScalarcfwNetEventsTableLastRowread-onlycurrentThe index value of the last row in the cfwNetEventsTable. This number starts at 1 and increase by one with each new log entry. When this number wraps, all even…
1.3.6.1.4.1.9.9.147.1.1.2.2TablecfwNetEventsTablenot-accessiblecurrentTable of detailed data for network events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. It is an …
1.3.6.1.4.1.9.9.147.1.1.2.2.1RowcfwNetEventsEntrynot-accessiblecurrentAn entry in the table, containing detailed information about an event. Note that this table may be sparse. If Network Address Translation is not enabled cfwNet…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.1ColumncfwNetEventIndexnot-accessiblecurrentAn index that uniquely identifies an entry in the log table. These indices are assigned beginning with one and increase by one with each new log entry. When th…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.2ColumncfwNetEventInterfaceread-onlycurrentThe interface most closely associated with this event. For example, for an event that relates to the receipt of a packet, this object identifies the interface …
1.3.6.1.4.1.9.9.147.1.1.2.2.1.3ColumncfwNetEventSrcIpAddressread-onlycurrentSource IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is th…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.4ColumncfwNetEventInsideSrcIpAddressread-onlycurrentSource IP address after Network Address Translation has been applied. If NAT has not been applied to the source address in this packet this object will not be …
1.3.6.1.4.1.9.9.147.1.1.2.2.1.5ColumncfwNetEventDstIpAddressread-onlycurrentDestination IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event …
1.3.6.1.4.1.9.9.147.1.1.2.2.1.6ColumncfwNetEventInsideDstIpAddressread-onlycurrentDestination IP address after Network Address Translation has been applied. If NAT has not been applied to the destination address in this packet this object wi…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.7ColumncfwNetEventSrcIpPortread-onlycurrentSource UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is …
1.3.6.1.4.1.9.9.147.1.1.2.2.1.8ColumncfwNetEventInsideSrcIpPortread-onlycurrentSource UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the source port in this packet this object will not be inst…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.9ColumncfwNetEventDstIpPortread-onlycurrentDestination UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the even…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.10ColumncfwNetEventInsideDstIpPortread-onlycurrentDestination UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the Destination port in this packet this object will n…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.11ColumncfwNetEventServiceread-onlycurrentThe identification of the type of service involved with this event.
1.3.6.1.4.1.9.9.147.1.1.2.2.1.12ColumncfwNetEventServiceInformationread-onlycurrentSpecific service information. This can be used to describe the particular service indentified by cfwNetEventService and can reflect whether the service is a lo…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.13ColumncfwNetEventIdentityread-onlycurrentThis object will contain a description of the entity that caused the event. The entity could be a userid, username, processid or other identifier for the entit…
1.3.6.1.4.1.9.9.147.1.1.2.2.1.14ColumncfwNetEventDescriptionread-onlycurrentA detailed description of the event.
1.3.6.1.4.1.9.9.147.1.2NodecfwSystem
1.3.6.1.4.1.9.9.147.1.2.1NodecfwStatus
1.3.6.1.4.1.9.9.147.1.2.1.1TablecfwHardwareStatusTablenot-accessiblecurrentTable of firewall cfwHardwareStatusEntry entries.
1.3.6.1.4.1.9.9.147.1.2.1.1.1RowcfwHardwareStatusEntrynot-accessiblecurrentAn entry in the table, containing status information about a resource.
1.3.6.1.4.1.9.9.147.1.2.1.1.1.1ColumncfwHardwareTypenot-accessiblecurrentThe hardware type for which this row provides status information.
1.3.6.1.4.1.9.9.147.1.2.1.1.1.2ColumncfwHardwareInformationread-onlycurrentA detailed textual description of the resource identified by cfwHardwareType.
1.3.6.1.4.1.9.9.147.1.2.1.1.1.3ColumncfwHardwareStatusValueread-onlycurrentThis object contains the current status of the resource.
1.3.6.1.4.1.9.9.147.1.2.1.1.1.4ColumncfwHardwareStatusDetailread-onlycurrentA detailed textual description of the current status of the resource which may provide a more specific description than cfwHardwareStatusValue.
1.3.6.1.4.1.9.9.147.1.2.2NodecfwStatistics
1.3.6.1.4.1.9.9.147.1.2.2.1TablecfwBufferStatsTablenot-accessiblecurrentA table conatining status information about a firewall's buffers.
1.3.6.1.4.1.9.9.147.1.2.2.1.1RowcfwBufferStatsEntrynot-accessiblecurrentAn entry in the table, containing status information about a particular statistic for the set of buffers of a particular size.
1.3.6.1.4.1.9.9.147.1.2.2.1.1.1ColumncfwBufferStatSizenot-accessiblecurrentThis object contains the size of the set of buffers for which this row contains the statistics given by cfwBufferStatType.
1.3.6.1.4.1.9.9.147.1.2.2.1.1.2ColumncfwBufferStatTypenot-accessiblecurrentThis object identifies the type of statistic given by this row for the particular set of buffers identified by cfwBufferStatSize.
1.3.6.1.4.1.9.9.147.1.2.2.1.1.3ColumncfwBufferStatInformationread-onlycurrentA detailed textual description of the statistic identified by cfwBufferStatType.
1.3.6.1.4.1.9.9.147.1.2.2.1.1.4ColumncfwBufferStatValueread-onlycurrentThe value of the buffer statistic.
1.3.6.1.4.1.9.9.147.1.2.2.2TablecfwConnectionStatTablenot-accessiblecurrentTable of firewall statistic instances.
1.3.6.1.4.1.9.9.147.1.2.2.2.1RowcfwConnectionStatEntrynot-accessiblecurrentAn entry in the table, containing information about a firewall statistic.
1.3.6.1.4.1.9.9.147.1.2.2.2.1.1ColumncfwConnectionStatServicenot-accessiblecurrentThe identification of the type of connection providing statistics.
1.3.6.1.4.1.9.9.147.1.2.2.2.1.2ColumncfwConnectionStatTypenot-accessiblecurrentThe state of the connections that this row contains statistics for.
1.3.6.1.4.1.9.9.147.1.2.2.2.1.3ColumncfwConnectionStatDescriptionread-onlycurrentA detailed textual description of this statistic.
1.3.6.1.4.1.9.9.147.1.2.2.2.1.4ColumncfwConnectionStatCountread-onlycurrentThis is an integer that contains the value of the resource statistic. If a type of 'gauge' is more appropriate this object will be omitted resulting in a spars…
1.3.6.1.4.1.9.9.147.1.2.2.2.1.5ColumncfwConnectionStatValueread-onlycurrentThis is an integer that contains the value of the resource statistic. If a type of 'counter' is more appropriate this object will be omitted resulting in a spa…
1.3.6.1.4.1.9.9.147.1.2.2.3ScalarcfwConnectionPerSecondread-onlycurrentThe current cps rate on the firewall.
1.3.6.1.4.1.9.9.147.1.2.2.4ScalarcfwConnectionPerSecondPeakread-onlycurrentThe peak cps rate hit on the firewall.
1.3.6.1.4.1.9.9.147.2NodeciscoFirewallMIBNotificationPrefix
1.3.6.1.4.1.9.9.147.2.0NodeciscoFirewallMIBNotifications
1.3.6.1.4.1.9.9.147.2.0.2NotificationcfwSecurityNotificationcurrentThis notification is used for events involving security events. The included objects provide more detailed information about the event.
1.3.6.1.4.1.9.9.147.2.0.3NotificationcfwContentInspectNotificationcurrentThis notification is used to notify the NMS of content inspection events. The included objects provide more detailed information about the event.
1.3.6.1.4.1.9.9.147.2.0.4NotificationcfwConnNotificationcurrentThis notification is used to notify the NMS of connection-oriented events. The included objects provide more detailed information about the event.
1.3.6.1.4.1.9.9.147.2.0.5NotificationcfwAccessNotificationcurrentThis notification is used to notify the NMS of access events. The included objects provide more detailed information about the event.
1.3.6.1.4.1.9.9.147.2.0.6NotificationcfwAuthNotificationcurrentThis notification is used to notify the NMS of authentication events. The included objects provide more detailed information about the event.
1.3.6.1.4.1.9.9.147.2.0.7NotificationcfwGenericNotificationcurrentThis notification is used to notify the NMS of events that do not fall into the other categories. The included objects provide more detailed information about …
1.3.6.1.4.1.9.9.147.3NodeciscoFirewallMIBConformance
1.3.6.1.4.1.9.9.147.3.1NodeciscoFirewallMIBCompliances
1.3.6.1.4.1.9.9.147.3.1.1ComplianceciscoFirewallMIBCompliancedeprecatedThe compliance statement for entities which implement the Cisco FirewallMIB.
1.3.6.1.4.1.9.9.147.3.1.2ComplianceciscoFirewallMIBComplianceRev1currentThe compliance statement for entities which implement the Cisco FirewallMIB.
1.3.6.1.4.1.9.9.147.3.2NodeciscoFirewallMIBGroups
1.3.6.1.4.1.9.9.147.3.2.1GroupciscoFirewallMIBEventsGroupcurrentFirewall events
1.3.6.1.4.1.9.9.147.3.2.2GroupciscoFirewallMIBStatisticsGroupcurrentFirewall statistics
1.3.6.1.4.1.9.9.147.3.2.3GroupciscoFirewallMIBNotificationGroupobsoleteFirewall Notifications
1.3.6.1.4.1.9.9.147.3.2.4GroupciscoFirewallMIBNotificationGroupRev1currentFirewall Notifications
Type Definitions
NameSyntaxStatusDescription
AccessEventINTEGER { other(1), grant(2), deny(3), denyMult(4), error(5) }currentThis textual convention is used to describe various events and statistics that are related to the access control on a firewall. other : Miscellaneous access event. grant : A service has allowed access based on all of it…
AuthenticationEventINTEGER { other(1), succ(2), error(3), fail(4), succPriv(5), failPriv(6), failMult(7) }currentThis textual convention is used to describe various events and statistics that are related to authorization. other : Miscellaneous authentication event. succ : A client successfuly authenticated. error : Error while aut…
ConnectionEventINTEGER { other(1), accept(2), error(3), drop(4), close(5), timeout(6), refused(7), reset(8), noResp(9) }currentThis textual convention is used to describe various events and statistics that are related to the connections that occur on a firewall. other : A generic connection event. accept : A connection has been acccepted. error…
ConnectionStatINTEGER { other(1), totalOpen(2), currentOpen(3), currentClosing(4), currentHalfOpen(5), currentInUse(6), high(7) }currentThis textual convention is used to describe various connections statistics. other : A generic connection event. totalOpen : Total open connections since reboot. currentOpen : The number of connections currently open. cu…
ContentInspectionEventINTEGER { other(1), okay(2), error(3), found(4), clean(5), reject(6), saved(7) }currentContent inspection events, these events report that something was found in the application payload. The details entry in the event can report on what was found (eg., virus, company private info., etc), what it was found…
GenericEventINTEGER { abnormal(1), okay(2), error(3) }currentGeneric Events - events for which there is no more specific enumeration abnormal : An abnormal event has occurred that is neither 'okay' nor an 'error'. okay : A normal event occurred or the system has changed from an a…
HardwareINTEGER { memory(1), disk(2), power(3), netInterface(4), cpu(5), primaryUnit(6), secondaryUnit(7), other(8) }currentThis textual convention is used to describe various hardware resouces that can be monitored by the firewall. memory - identifies memory. disk - identifies disk. power - identifies power. netInterface - identifies a netw…
HardwareStatusINTEGER { other(1), up(2), down(3), error(4), overTemp(5), busy(6), noMedia(7), backup(8), active(9), standby(10) }currentThis textual convention is used to describe various events that are related to the resources on a firewall. other : Generic resource event. up : The resource is in service. down : The resource is not in service. error :…
ResourceStatisticsINTEGER { highUse(1), highLoad(2), maximum(3), minimum(4), low(5), high(6), average(7), free(8), inUse(9) }currentThis textual convention is used to identify various statistics that are related to the resources on a firewall. highUse : The highest load the resource has had for a time period. The time period will be implementation d…
SecurityEventINTEGER { other(1), none(2), dos(3), recon(4), pakFwd(5), addrSpoof(6), svcSpoof(7), thirdParty(8), complete(9), invalPak(10), illegCom(11), policy(12) }currentThis textual convention is used to describe various security-related events and statistics on a firewall. other : Generic attack event. none : No attack is occurring, an informational event. dos : A denial of service at…
ServicesINTEGER { otherFWService(1), fileXferFtp(2), fileXferTftp(3), fileXferFtps(4), loginTelnet(5), loginRlogin(6), loginTelnets(7), remoteExecSunRPC(8), remoteExecMSRPC(9), remoteExecRsh(10), remoteExecXserver(11), webHttp(12), webHttps(13), mailSmtp(14), multimediaStreamworks(15), multimediaH323(16), multimediaNetShow(17), multimediaVDOLive(18), multimediaRealAV(19), multimediaRTSP(20), dbOracle(21), dbMSsql(22), contInspProgLang(23), contInspUrl(24), directoryNis(25), directoryDns(26), directoryNetbiosns(27), directoryNetbiosdgm(28), directoryNetbiosssn(29), directoryWins(30), qryWhois(31), qryFinger(32), qryIdent(33), fsNfsStatus(34), fsNfs(35), fsCifs(36), protoIcmp(37), protoTcp(38), protoUdp(39), protoIp(40), protoSnmp(41) }currentThis textual convention is used to describe various services that are monitored by the firewall. otherFWService - a service that does not fit into any other category. fileXferFtp - identifies FTP, File Transfer Protocol…