CISCO-FIREWALL-MIB
87 objects
MIB module for monitoring Cisco Firewalls.
Imported Objects
| CISCO-SMI | ciscoMgmt |
| IF-MIB | InterfaceIndexOrZero |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP |
| SNMPv2-SMI | Counter32 Gauge32 IpAddress MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | DateAndTime RowPointer TEXTUAL-CONVENTION |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.9.9.147 | IdentityciscoFirewallMIB | MIB module for monitoring Cisco Firewalls. | ||
| 1.3.6.1.4.1.9.9.147.1 | NodeciscoFirewallMIBObjects | |||
| 1.3.6.1.4.1.9.9.147.1.1 | NodecfwEvents | |||
| 1.3.6.1.4.1.9.9.147.1.1.1 | NodecfwBasicEvents | |||
| 1.3.6.1.4.1.9.9.147.1.1.1.1 | ScalarcfwBasicEventsTableLastRow | read-only | current | The index value of the most recently created row in the cfwBasicEventsTable. This number starts at 1 and increase by one with each new log entry. When this num… |
| 1.3.6.1.4.1.9.9.147.1.1.1.2 | TablecfwBasicEventsTable | not-accessible | current | Table of basic data for firewall events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. The oldest … |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1 | RowcfwBasicEventsEntry | not-accessible | current | An entry in the table, containing general information about an event. This table will always be sparse, i.e., each row will instanciate only a subet of the col… |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.1 | ColumncfwBasicEventIndex | not-accessible | current | An index that uniquely identifies an entry in the log table. These indices are assigned beginning with 1 and increase by one with each new event logged. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.2 | ColumncfwBasicEventTime | read-only | current | The time that the event occurred. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.3 | ColumncfwBasicSecurityEventType | read-only | current | The type of security-related event that this row contains. If the event is not security-related this object will not be instantiated. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.4 | ColumncfwBasicContentInspEventType | read-only | current | The type of content inspection-related event that this row contains. If the event is not content inspection-related this object will not be instantiated. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.5 | ColumncfwBasicConnectionEventType | read-only | current | The type of connection-related event that this row contains. If the event is not connection-related this object will not be instantiated. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.6 | ColumncfwBasicAccessEventType | read-only | current | The type of access-related event that this row contains. If the event is not access-related this object will not be instantiated. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.7 | ColumncfwBasicAuthenticationEventType | read-only | current | The type of authentication-related event that this row contains. If the event is not authentication-related this object will not be instantiated. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.8 | ColumncfwBasicGenericEventType | read-only | current | The type of generic event that this row contains. If the event does not fall into one of the other categories this object will be populated. Otherwise, this ob… |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.9 | ColumncfwBasicEventDescription | read-only | current | A description of the event. The value of the object may be a zero-length string. |
| 1.3.6.1.4.1.9.9.147.1.1.1.2.1.10 | ColumncfwBasicEventDetailsTableRow | read-only | current | A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appe… |
| 1.3.6.1.4.1.9.9.147.1.1.2 | NodecfwNetEvents | |||
| 1.3.6.1.4.1.9.9.147.1.1.2.1 | ScalarcfwNetEventsTableLastRow | read-only | current | The index value of the last row in the cfwNetEventsTable. This number starts at 1 and increase by one with each new log entry. When this number wraps, all even… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2 | TablecfwNetEventsTable | not-accessible | current | Table of detailed data for network events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. It is an … |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1 | RowcfwNetEventsEntry | not-accessible | current | An entry in the table, containing detailed information about an event. Note that this table may be sparse. If Network Address Translation is not enabled cfwNet… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.1 | ColumncfwNetEventIndex | not-accessible | current | An index that uniquely identifies an entry in the log table. These indices are assigned beginning with one and increase by one with each new log entry. When th… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.2 | ColumncfwNetEventInterface | read-only | current | The interface most closely associated with this event. For example, for an event that relates to the receipt of a packet, this object identifies the interface … |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.3 | ColumncfwNetEventSrcIpAddress | read-only | current | Source IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is th… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.4 | ColumncfwNetEventInsideSrcIpAddress | read-only | current | Source IP address after Network Address Translation has been applied. If NAT has not been applied to the source address in this packet this object will not be … |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.5 | ColumncfwNetEventDstIpAddress | read-only | current | Destination IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event … |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.6 | ColumncfwNetEventInsideDstIpAddress | read-only | current | Destination IP address after Network Address Translation has been applied. If NAT has not been applied to the destination address in this packet this object wi… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.7 | ColumncfwNetEventSrcIpPort | read-only | current | Source UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is … |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.8 | ColumncfwNetEventInsideSrcIpPort | read-only | current | Source UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the source port in this packet this object will not be inst… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.9 | ColumncfwNetEventDstIpPort | read-only | current | Destination UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the even… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.10 | ColumncfwNetEventInsideDstIpPort | read-only | current | Destination UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the Destination port in this packet this object will n… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.11 | ColumncfwNetEventService | read-only | current | The identification of the type of service involved with this event. |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.12 | ColumncfwNetEventServiceInformation | read-only | current | Specific service information. This can be used to describe the particular service indentified by cfwNetEventService and can reflect whether the service is a lo… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.13 | ColumncfwNetEventIdentity | read-only | current | This object will contain a description of the entity that caused the event. The entity could be a userid, username, processid or other identifier for the entit… |
| 1.3.6.1.4.1.9.9.147.1.1.2.2.1.14 | ColumncfwNetEventDescription | read-only | current | A detailed description of the event. |
| 1.3.6.1.4.1.9.9.147.1.2 | NodecfwSystem | |||
| 1.3.6.1.4.1.9.9.147.1.2.1 | NodecfwStatus | |||
| 1.3.6.1.4.1.9.9.147.1.2.1.1 | TablecfwHardwareStatusTable | not-accessible | current | Table of firewall cfwHardwareStatusEntry entries. |
| 1.3.6.1.4.1.9.9.147.1.2.1.1.1 | RowcfwHardwareStatusEntry | not-accessible | current | An entry in the table, containing status information about a resource. |
| 1.3.6.1.4.1.9.9.147.1.2.1.1.1.1 | ColumncfwHardwareType | not-accessible | current | The hardware type for which this row provides status information. |
| 1.3.6.1.4.1.9.9.147.1.2.1.1.1.2 | ColumncfwHardwareInformation | read-only | current | A detailed textual description of the resource identified by cfwHardwareType. |
| 1.3.6.1.4.1.9.9.147.1.2.1.1.1.3 | ColumncfwHardwareStatusValue | read-only | current | This object contains the current status of the resource. |
| 1.3.6.1.4.1.9.9.147.1.2.1.1.1.4 | ColumncfwHardwareStatusDetail | read-only | current | A detailed textual description of the current status of the resource which may provide a more specific description than cfwHardwareStatusValue. |
| 1.3.6.1.4.1.9.9.147.1.2.2 | NodecfwStatistics | |||
| 1.3.6.1.4.1.9.9.147.1.2.2.1 | TablecfwBufferStatsTable | not-accessible | current | A table conatining status information about a firewall's buffers. |
| 1.3.6.1.4.1.9.9.147.1.2.2.1.1 | RowcfwBufferStatsEntry | not-accessible | current | An entry in the table, containing status information about a particular statistic for the set of buffers of a particular size. |
| 1.3.6.1.4.1.9.9.147.1.2.2.1.1.1 | ColumncfwBufferStatSize | not-accessible | current | This object contains the size of the set of buffers for which this row contains the statistics given by cfwBufferStatType. |
| 1.3.6.1.4.1.9.9.147.1.2.2.1.1.2 | ColumncfwBufferStatType | not-accessible | current | This object identifies the type of statistic given by this row for the particular set of buffers identified by cfwBufferStatSize. |
| 1.3.6.1.4.1.9.9.147.1.2.2.1.1.3 | ColumncfwBufferStatInformation | read-only | current | A detailed textual description of the statistic identified by cfwBufferStatType. |
| 1.3.6.1.4.1.9.9.147.1.2.2.1.1.4 | ColumncfwBufferStatValue | read-only | current | The value of the buffer statistic. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2 | TablecfwConnectionStatTable | not-accessible | current | Table of firewall statistic instances. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1 | RowcfwConnectionStatEntry | not-accessible | current | An entry in the table, containing information about a firewall statistic. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1.1 | ColumncfwConnectionStatService | not-accessible | current | The identification of the type of connection providing statistics. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1.2 | ColumncfwConnectionStatType | not-accessible | current | The state of the connections that this row contains statistics for. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1.3 | ColumncfwConnectionStatDescription | read-only | current | A detailed textual description of this statistic. |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1.4 | ColumncfwConnectionStatCount | read-only | current | This is an integer that contains the value of the resource statistic. If a type of 'gauge' is more appropriate this object will be omitted resulting in a spars… |
| 1.3.6.1.4.1.9.9.147.1.2.2.2.1.5 | ColumncfwConnectionStatValue | read-only | current | This is an integer that contains the value of the resource statistic. If a type of 'counter' is more appropriate this object will be omitted resulting in a spa… |
| 1.3.6.1.4.1.9.9.147.1.2.2.3 | ScalarcfwConnectionPerSecond | read-only | current | The current cps rate on the firewall. |
| 1.3.6.1.4.1.9.9.147.1.2.2.4 | ScalarcfwConnectionPerSecondPeak | read-only | current | The peak cps rate hit on the firewall. |
| 1.3.6.1.4.1.9.9.147.2 | NodeciscoFirewallMIBNotificationPrefix | |||
| 1.3.6.1.4.1.9.9.147.2.0 | NodeciscoFirewallMIBNotifications | |||
| 1.3.6.1.4.1.9.9.147.2.0.2 | NotificationcfwSecurityNotification | current | This notification is used for events involving security events. The included objects provide more detailed information about the event. | |
| 1.3.6.1.4.1.9.9.147.2.0.3 | NotificationcfwContentInspectNotification | current | This notification is used to notify the NMS of content inspection events. The included objects provide more detailed information about the event. | |
| 1.3.6.1.4.1.9.9.147.2.0.4 | NotificationcfwConnNotification | current | This notification is used to notify the NMS of connection-oriented events. The included objects provide more detailed information about the event. | |
| 1.3.6.1.4.1.9.9.147.2.0.5 | NotificationcfwAccessNotification | current | This notification is used to notify the NMS of access events. The included objects provide more detailed information about the event. | |
| 1.3.6.1.4.1.9.9.147.2.0.6 | NotificationcfwAuthNotification | current | This notification is used to notify the NMS of authentication events. The included objects provide more detailed information about the event. | |
| 1.3.6.1.4.1.9.9.147.2.0.7 | NotificationcfwGenericNotification | current | This notification is used to notify the NMS of events that do not fall into the other categories. The included objects provide more detailed information about … | |
| 1.3.6.1.4.1.9.9.147.3 | NodeciscoFirewallMIBConformance | |||
| 1.3.6.1.4.1.9.9.147.3.1 | NodeciscoFirewallMIBCompliances | |||
| 1.3.6.1.4.1.9.9.147.3.1.1 | ComplianceciscoFirewallMIBCompliance | deprecated | The compliance statement for entities which implement the Cisco FirewallMIB. | |
| 1.3.6.1.4.1.9.9.147.3.1.2 | ComplianceciscoFirewallMIBComplianceRev1 | current | The compliance statement for entities which implement the Cisco FirewallMIB. | |
| 1.3.6.1.4.1.9.9.147.3.2 | NodeciscoFirewallMIBGroups | |||
| 1.3.6.1.4.1.9.9.147.3.2.1 | GroupciscoFirewallMIBEventsGroup | current | Firewall events | |
| 1.3.6.1.4.1.9.9.147.3.2.2 | GroupciscoFirewallMIBStatisticsGroup | current | Firewall statistics | |
| 1.3.6.1.4.1.9.9.147.3.2.3 | GroupciscoFirewallMIBNotificationGroup | obsolete | Firewall Notifications | |
| 1.3.6.1.4.1.9.9.147.3.2.4 | GroupciscoFirewallMIBNotificationGroupRev1 | current | Firewall Notifications |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| AccessEvent | INTEGER { other(1), grant(2), deny(3), denyMult(4), error(5) } | current | This textual convention is used to describe various events and statistics that are related to the access control on a firewall. other : Miscellaneous access event. grant : A service has allowed access based on all of it… |
| AuthenticationEvent | INTEGER { other(1), succ(2), error(3), fail(4), succPriv(5), failPriv(6), failMult(7) } | current | This textual convention is used to describe various events and statistics that are related to authorization. other : Miscellaneous authentication event. succ : A client successfuly authenticated. error : Error while aut… |
| ConnectionEvent | INTEGER { other(1), accept(2), error(3), drop(4), close(5), timeout(6), refused(7), reset(8), noResp(9) } | current | This textual convention is used to describe various events and statistics that are related to the connections that occur on a firewall. other : A generic connection event. accept : A connection has been acccepted. error… |
| ConnectionStat | INTEGER { other(1), totalOpen(2), currentOpen(3), currentClosing(4), currentHalfOpen(5), currentInUse(6), high(7) } | current | This textual convention is used to describe various connections statistics. other : A generic connection event. totalOpen : Total open connections since reboot. currentOpen : The number of connections currently open. cu… |
| ContentInspectionEvent | INTEGER { other(1), okay(2), error(3), found(4), clean(5), reject(6), saved(7) } | current | Content inspection events, these events report that something was found in the application payload. The details entry in the event can report on what was found (eg., virus, company private info., etc), what it was found… |
| GenericEvent | INTEGER { abnormal(1), okay(2), error(3) } | current | Generic Events - events for which there is no more specific enumeration abnormal : An abnormal event has occurred that is neither 'okay' nor an 'error'. okay : A normal event occurred or the system has changed from an a… |
| Hardware | INTEGER { memory(1), disk(2), power(3), netInterface(4), cpu(5), primaryUnit(6), secondaryUnit(7), other(8) } | current | This textual convention is used to describe various hardware resouces that can be monitored by the firewall. memory - identifies memory. disk - identifies disk. power - identifies power. netInterface - identifies a netw… |
| HardwareStatus | INTEGER { other(1), up(2), down(3), error(4), overTemp(5), busy(6), noMedia(7), backup(8), active(9), standby(10) } | current | This textual convention is used to describe various events that are related to the resources on a firewall. other : Generic resource event. up : The resource is in service. down : The resource is not in service. error :… |
| ResourceStatistics | INTEGER { highUse(1), highLoad(2), maximum(3), minimum(4), low(5), high(6), average(7), free(8), inUse(9) } | current | This textual convention is used to identify various statistics that are related to the resources on a firewall. highUse : The highest load the resource has had for a time period. The time period will be implementation d… |
| SecurityEvent | INTEGER { other(1), none(2), dos(3), recon(4), pakFwd(5), addrSpoof(6), svcSpoof(7), thirdParty(8), complete(9), invalPak(10), illegCom(11), policy(12) } | current | This textual convention is used to describe various security-related events and statistics on a firewall. other : Generic attack event. none : No attack is occurring, an informational event. dos : A denial of service at… |
| Services | INTEGER { otherFWService(1), fileXferFtp(2), fileXferTftp(3), fileXferFtps(4), loginTelnet(5), loginRlogin(6), loginTelnets(7), remoteExecSunRPC(8), remoteExecMSRPC(9), remoteExecRsh(10), remoteExecXserver(11), webHttp(12), webHttps(13), mailSmtp(14), multimediaStreamworks(15), multimediaH323(16), multimediaNetShow(17), multimediaVDOLive(18), multimediaRealAV(19), multimediaRTSP(20), dbOracle(21), dbMSsql(22), contInspProgLang(23), contInspUrl(24), directoryNis(25), directoryDns(26), directoryNetbiosns(27), directoryNetbiosdgm(28), directoryNetbiosssn(29), directoryWins(30), qryWhois(31), qryFinger(32), qryIdent(33), fsNfsStatus(34), fsNfs(35), fsCifs(36), protoIcmp(37), protoTcp(38), protoUdp(39), protoIp(40), protoSnmp(41) } | current | This textual convention is used to describe various services that are monitored by the firewall. otherFWService - a service that does not fit into any other category. fileXferFtp - identifies FTP, File Transfer Protocol… |