MIB Viewer

CISCO-IP-URPF-MIB

47 objects
Unicast Reverse Path Forwarding (URPF) is a function that checks the validity of the source address of IP packets received on an interface. This in an attempt to prevent Denial of Service attacks based on IP address spoofing. URPF checks validity of a source address by determining whether the packet would be successfully routed as a destination address. Based on configuration, the check made can be for existence of any route for the address, or more strictly for a route out the interface on which the packet was received by the device. When a violating packet is detected, it can be dropped. This MIB allows detection of spoofingevents.
Imported Objects
CISCO-SMIciscoMgmt
IF-MIBifIndex
SNMP-FRAMEWORK-MIBSnmpAdminString
SNMPv2-CONFMODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP
SNMPv2-SMICounter32 Gauge32 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE Unsigned32
SNMPv2-TCTEXTUAL-CONVENTION TimeStamp TruthValue
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.451IdentityciscoIpUrpfMIBUnicast Reverse Path Forwarding (URPF) is a function that checks the validity of the source address of IP packets received on an interface. This in an attempt …
1.3.6.1.4.1.9.9.451.0NodeciscoIpUrpfMIBNotifs
1.3.6.1.4.1.9.9.451.0.1NotificationcipUrpfIfDropRateNotifycurrentThis notification is generated when cipUrpfIfDropRateNotifyEnable is set to true and the calculated URPF drop rate (cipUrpfIfDropRate) exceeds the notification…
1.3.6.1.4.1.9.9.451.1NodeciscoIpUrpfMIBObjects
1.3.6.1.4.1.9.9.451.1.1NodecipUrpfScalar
1.3.6.1.4.1.9.9.451.1.1.1ScalarcipUrpfDropRateWindowread-writecurrentThe window of time in the recent past over which the drop count used in the drop rate computation is collected. This global value applies for the computation o…
1.3.6.1.4.1.9.9.451.1.1.2ScalarcipUrpfComputeIntervalread-writecurrentThe time between rate computations. This global value applies for the computation of all URPF rates, global and per-interface. When the value of cipUrpfCompute…
1.3.6.1.4.1.9.9.451.1.1.3ScalarcipUrpfDropNotifyHoldDownTimeread-writecurrentThe minimum time between issuance of cipUrpfIfDropRateNotify notifications for a particular interface and packet forwarding type. Notifications are generated f…
1.3.6.1.4.1.9.9.451.1.2NodecipUrpfStatistics
1.3.6.1.4.1.9.9.451.1.2.1TablecipUrpfTablenot-accessiblecurrentThis table contains summary information for the managed device on URPF dropping.
1.3.6.1.4.1.9.9.451.1.2.1.1RowcipUrpfEntrynot-accessiblecurrentIf the managed device supports URPF dropping, a row exists for each IP version type (v4 and v6). A row contains summary information on URPF dropping over the e…
1.3.6.1.4.1.9.9.451.1.2.1.1.1ColumncipUrpfIpVersionnot-accessiblecurrentSpecifies the version of IP forwarding on an interface to which the table row URPF counts, rates, and configuration apply.
1.3.6.1.4.1.9.9.451.1.2.1.1.2ColumncipUrpfDropsread-onlycurrentSum of dropped IP version cipUrpfIpVersion packets failing a URPF check. This value is the sum of drops of packets received on all interfaces of the managed de…
1.3.6.1.4.1.9.9.451.1.2.1.1.3ColumncipUrpfDropRateread-onlycurrentThe rate of packet drops of IP version cipUrpfIpVersion packets due to URPF for the managed device. The per-interface drop rate notification is issued on rates…
1.3.6.1.4.1.9.9.451.1.2.2TablecipUrpfIfMonTablenot-accessiblecurrentThis table contains information on URPF dropping on an interface.
1.3.6.1.4.1.9.9.451.1.2.2.1RowcipUrpfIfMonEntrynot-accessiblecurrentIf IPv4 packet forwarding is configured on an interface, and is configured to perform URPF checking, a row appears in this table with indices [ifIndex][ipv4]. …
1.3.6.1.4.1.9.9.451.1.2.2.1.1ColumncipUrpfIfIpVersionnot-accessiblecurrentSpecifies the version of IP forwarding on an interface to which the table row URPF counts, rates, and configuration apply.
1.3.6.1.4.1.9.9.451.1.2.2.1.2ColumncipUrpfIfDropsread-onlycurrentThe number of IP packets of version cipUrpfIfIpVersion failing the URPF check and dropped by the managed device on a particular interface. Discontinuities in t…
1.3.6.1.4.1.9.9.451.1.2.2.1.3ColumncipUrpfIfSuppressedDropsread-onlycurrentThe number of IP packets of version cipUrpfIfIpVersion failing the URPF check but given a reprieve and not dropped by the managed device. Depending on the devi…
1.3.6.1.4.1.9.9.451.1.2.2.1.4ColumncipUrpfIfDropRateread-onlycurrentThe rate of packet drops of IP version cipUrpfIfIpVersion packets due to URPF on the interface. This object is the average rate of dropping over the most recen…
1.3.6.1.4.1.9.9.451.1.2.2.1.5ColumncipUrpfIfDiscontinuityTimeread-onlycurrentThe value of sysUpTime on the most recent occasion at which this interface's counters suffered a discontinuity. If no such discontinuities have occurred since …
1.3.6.1.4.1.9.9.451.1.2.3TablecipUrpfVrfIfTablenot-accessiblecurrentThis table contains statistics information for interfaces performing URPF using VRF table to determine reachability.
1.3.6.1.4.1.9.9.451.1.2.3.1RowcipUrpfVrfIfEntrynot-accessiblecurrentAn entry exists for a VRF and interface if and only if the VRF associated with the interface is configured to perform IP URPF checking using the routing table …
1.3.6.1.4.1.9.9.451.1.2.3.1.2ColumncipUrpfVrfIfDropsread-onlycurrentThe number of packets failing the URPF check for a VRF on the interface and dropped by the managed device. Discontinuities in the value of this variable can oc…
1.3.6.1.4.1.9.9.451.1.2.3.1.3ColumncipUrpfVrfIfDiscontinuityTimeread-onlycurrentThe value of sysUpTime on the most recent occasion at which the URPF counters for this VRF on this interface suffered a discontinuity. If no such discontinuiti…
1.3.6.1.4.1.9.9.451.1.3NodecipUrpfInterfaceConfig
1.3.6.1.4.1.9.9.451.1.3.1TablecipUrpfIfConfTablenot-accessiblecurrentThis table contains statistics information on URPF on an interface.
1.3.6.1.4.1.9.9.451.1.3.1.1RowcipUrpfIfConfEntrynot-accessiblecurrentA row exists in this table if a row exists in cipUrpfIfMonTable.
1.3.6.1.4.1.9.9.451.1.3.1.1.1ColumncipUrpfIfDropRateNotifyEnableread-writecurrentThis object specifies whether the system produces the cipUrpfIfDropRateNotify notification as a result of URPF dropping of version cipUrpfIfIpVersion IP packet…
1.3.6.1.4.1.9.9.451.1.3.1.1.2ColumncipUrpfIfNotifyDropRateThresholdread-writecurrentWhen the calculated rate of URPF packet drops (cipUrpfIfDropRate) meets or exceeds the value specified by this object, a cipUrpfIfDropRateNotify notification i…
1.3.6.1.4.1.9.9.451.1.3.1.1.3ColumncipUrpfIfNotifyDrHoldDownResetread-writecurrentSetting this object to true causes the five-minute hold-down timer for emitting URPF drop rate notifications for IP version cipUrpfIfIpVersion on the interface…
1.3.6.1.4.1.9.9.451.1.3.1.1.4ColumncipUrpfIfCheckStrictread-onlycurrentInterface configuration indicating the strictness of the reachability check performed on the interface. - strict: check that source addr is reachable via the i…
1.3.6.1.4.1.9.9.451.1.3.1.1.5ColumncipUrpfIfWhichRouteTableIDread-onlycurrentInterface configuration indicating the routing table consulted for the reachability check: - default: the non-private routing table for of the managed system. …
1.3.6.1.4.1.9.9.451.1.3.1.1.6ColumncipUrpfIfVrfNameread-onlycurrentIf the value of cipUrpfIfWhichRouteTableID is 'vrf', the name of the VRF Table. Otherwise a zero-length string.
1.3.6.1.4.1.9.9.451.1.4NodecipUrpfVrf
1.3.6.1.4.1.9.9.451.1.4.1TablecipUrpfVrfTablenot-accessiblecurrentThis table enables indexing URPF drop statistics by Virtual Routing and Forwarding instances.
1.3.6.1.4.1.9.9.451.1.4.1.1RowcipUrpfVrfEntrynot-accessiblecurrentAn entry exists for a VRF if and only if the VRF is associated with an interface that is configured to perform IP URPF checking using the routing table for tha…
1.3.6.1.4.1.9.9.451.1.4.1.1.1ColumncipUrpfVrfNameread-onlycurrentThis field is used to specify the VRF Table name.
1.3.6.1.4.1.9.9.451.2NodeciscoIpUrpfMIBConformance
1.3.6.1.4.1.9.9.451.2.1NodeciscoIpUrpfMIBCompliances
1.3.6.1.4.1.9.9.451.2.1.1ComplianceciscoIpUrpfMIBCompliancecurrentAn SNMP entity can implement this module to provide URPF problem diagnosis information.
1.3.6.1.4.1.9.9.451.2.2NodeciscoIpUrpfMIBGroups
1.3.6.1.4.1.9.9.451.2.2.1GroupciscoIpUrpfMIBMainObjectGroupcurrentThe collection of common counter objects, those needed by other objects, and the common interface table.
1.3.6.1.4.1.9.9.451.2.2.2GroupciscoIpUrpfMIBVrfObjectGroupcurrentThe collection of objects needed to index by VRF.
1.3.6.1.4.1.9.9.451.2.2.6GroupciscoIpUrpfMIBNotifyGroupcurrentThe collection of objects which are used to specify notifications for URPF.
Type Definitions
NameSyntaxStatusDescription
UnicastRpfOptionsBITS { allowDefault(0), allowSelfPing(1) }currentA bit string describing unicast Reverse Path Forwarding (RPF) options: 'allowDefault' Allows the use of the default route for RPF verification. 'allowSelfPing' Allows a router to ping its own interface or interfaces.
UnicastRpfTypeINTEGER { strict(1), loose(2), disabled(3) }currentAn enumerated integer-value describing the type of unicast Reverse Path Forwarding (RPF) a system applies to traffic received on an interface. UnicastRpfTypes 'strict' and 'loose' RPF methods are defined in RFC3704. 'di…