FIREWALL-MIB
184 objects
The MIB module to describe the Firewall .
Imported Objects
| INET-ADDRESS-MIB | InetAddress InetAddressPrefixLength InetAddressType |
| SNMPv2-SMI | Counter32 enterprises Integer32 IpAddress MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE TimeTicks Unsigned32 |
| SNMPv2-TC | DisplayString RowPointer RowStatus TEXTUAL-CONVENTION TimeStamp TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.10876.101.1.16 | Identityfirewall | The MIB module to describe the Firewall . | ||
| 1.3.6.1.4.1.10876.101.1.16.1 | NodefwlGlobal | |||
| 1.3.6.1.4.1.10876.101.1.16.1.1 | ScalarfwlGlobalMasterControlSwitch | read-write | current | This switch is used to enable or disable the entire firewall service. The default value for this switch is 'enabled' (1). |
| 1.3.6.1.4.1.10876.101.1.16.1.2 | ScalarfwlGlobalICMPControlSwitch | read-write | current | This switch is used to generate or suppress the ICMP generation when a packet is rejected by the firewall. The default value for this switch is 'suppress'(2). |
| 1.3.6.1.4.1.10876.101.1.16.1.3 | ScalarfwlGlobalIpSpoofFiltering | read-write | current | This switch is used to determine whether the inbound packets (packets arriving on the external interface or the interface connected to the Internet)are to be e… |
| 1.3.6.1.4.1.10876.101.1.16.1.4 | ScalarfwlGlobalSrcRouteFiltering | read-write | deprecated | **************** THIS OBJECT IS DEPRECATED **************** This switch is used to determine whether the inbound packets (packets arriving on the external inte… |
| 1.3.6.1.4.1.10876.101.1.16.1.5 | ScalarfwlGlobalTinyFragmentFiltering | read-write | deprecated | **************** THIS OBJECT IS DEPRECATED **************** This switch is used to determine whether the inbound packets (packets arriving on the external inte… |
| 1.3.6.1.4.1.10876.101.1.16.1.6 | ScalarfwlGlobalTcpIntercept | read-write | current | This switch is used to determine whether packets are to be examined for a potential Denial of service attack (TCP SYN Flooding attack). The default value for t… |
| 1.3.6.1.4.1.10876.101.1.16.1.7 | ScalarfwlGlobalTrap | read-write | current | This switch is used to control the different types of Trap sent to the administrator in case of memory failure or any attacks has occurred. If this switch is e… |
| 1.3.6.1.4.1.10876.101.1.16.1.8 | ScalarfwlGlobalTrace | read-write | current | This is used to enable trace statements in Firewall Module. A four byte integer value is specified for enabling the level of tracing. Each Bit in the four byte… |
| 1.3.6.1.4.1.10876.101.1.16.1.9 | ScalarfwlGlobalDebug | read-write | current | This is used to enable/disable Debug Statements in Firewall Module. |
| 1.3.6.1.4.1.10876.101.1.16.1.10 | ScalarfwlGlobalMaxFilters | read-only | current | This specifies the maximum number of memory blocks that can be allocated for filters. |
| 1.3.6.1.4.1.10876.101.1.16.1.11 | ScalarfwlGlobalMaxRules | read-only | current | This specifies the maximum number of memory blocks that can be allocated for rules. |
| 1.3.6.1.4.1.10876.101.1.16.1.12 | ScalarfwlGlobalUrlFiltering | read-write | current | This enables or disables URL filtering. The default value for this switch is 'disable'(2). |
| 1.3.6.1.4.1.10876.101.1.16.1.13 | ScalarfwlGlobalNetBiosFiltering | read-write | current | This enables or disables NETBIOS filtering. The default value for this switch is 'disable'(2). |
| 1.3.6.1.4.1.10876.101.1.16.1.14 | ScalarfwlGlobalNetBiosLan2Wan | read-write | current | This enables or disables NETBIOS LAN to WAN control switch. The default value for this switch is 'disable'(2). |
| 1.3.6.1.4.1.10876.101.1.16.1.15 | ScalarfwlGlobalICMPv6ControlSwitch | read-write | current | This switch is used to generate or suppress the ICMPv6 generation when a packet is rejected by the firewall. When this is enabled, ICMPv6 error message is gene… |
| 1.3.6.1.4.1.10876.101.1.16.1.16 | ScalarfwlGlobalIpv6SpoofFiltering | read-write | current | This switch is used to determine whether the inbound packets (packets arriving on the external interface or the interface connected to the Internet)are to be e… |
| 1.3.6.1.4.1.10876.101.1.16.1.17 | ScalarfwlGlobalLogFileSize | read-write | current | This is the maximum file size in bytes of the firewall log file. |
| 1.3.6.1.4.1.10876.101.1.16.1.18 | ScalarfwlGlobalLogSizeThreshold | read-write | current | This is the threshold value of the Log storage space with respect to the maximum Log Storage Space. It is entered as a percentage value. |
| 1.3.6.1.4.1.10876.101.1.16.1.19 | ScalarfwlGlobalIdsLogSize | read-write | current | This is the maximum file size in bytes of the IDS log file. |
| 1.3.6.1.4.1.10876.101.1.16.1.20 | ScalarfwlGlobalIdsLogThreshold | read-write | current | This is the threshold value of the Log storage space with respect to the maximum Log Storage Space. It is entered as a percentage value. |
| 1.3.6.1.4.1.10876.101.1.16.1.21 | ScalarfwlGlobalIdsVersionInfo | read-only | current | This Object shows the Current version of IDS (Intrusion Detection System) |
| 1.3.6.1.4.1.10876.101.1.16.1.22 | ScalarfwlGlobalReloadIds | read-write | current | This Object reload IDS process (Intrusion Detection System) with the new set of rules/configurations. |
| 1.3.6.1.4.1.10876.101.1.16.1.23 | ScalarfwlGlobalIdsStatus | read-write | current | This Object is used to enable or disable IDS (Intrusion Detection System) service in the system. By default IDS is enabled. |
| 1.3.6.1.4.1.10876.101.1.16.1.24 | ScalarfwlGlobalLoadIdsRules | read-write | current | This Object loads the existing regular expressions of rules to Pattern Matching Engine (PME) if exists. Also reloads IDS process (Intrusion Detection System). … |
| 1.3.6.1.4.1.10876.101.1.16.2 | NodefwlDefinition | |||
| 1.3.6.1.4.1.10876.101.1.16.2.1 | ScalarfwlDefnTcpInterceptThreshold | read-write | current | The number of TCP Connection requests (TCP SYN packets) entering into the firewall module within a timeout period. The default value is 50 connections. |
| 1.3.6.1.4.1.10876.101.1.16.2.2 | ScalarfwlDefnInterceptTimeout | read-write | current | The interval after which the Connection requests exceeding the threshold will be discarded. The default value is 1 second. This timeout value applies for TCP,U… |
| 1.3.6.1.4.1.10876.101.1.16.2.3 | TablefwlDefnFilterTable | not-accessible | current | This table is used to configure the Filters in the Firewall. The Filters can be configured as 'Filter1 10.0.0.0/24 108.0.4.1/32 6'. It means that in Filter1, t… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1 | RowfwlDefnFilterEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.1 | ColumnfwlFilterFilterName | not-accessible | current | This Filter name uniquely identifies the particular Filter configured. |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.2 | ColumnfwlFilterSrcAddress | read-create | current | The source IP address and the source mask to be checked against the packet. The default value is 0.0.0.0/0. The address value should not be specified without t… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.3 | ColumnfwlFilterDestAddress | read-create | current | The destination IP address and the destination mask to be checked against the packet. The default value is 0.0.0.0/0. The address value should not be specified… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.4 | ColumnfwlFilterProtocol | read-create | current | The type of protocol to be checked against the packet. The default value is 'any' (255). If the value is 'any' (255), it means that the protocol type can be an… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.5 | ColumnfwlFilterSrcPort | read-create | current | The source port to be checked against the packet. The range of port can be specified by using the symbols like '>', '<', '!=', '=', '<=', '>='. For example the… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.6 | ColumnfwlFilterDestPort | read-create | current | The destination port to be checked against the packet. The range of port can be specified by using the symbols like '>', '<', '!=', '=', '<=', '>='. For exampl… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.7 | ColumnfwlFilterAckBit | read-create | deprecated | **************** THIS OBJECT IS DEPRECATED **************** The TCP ACK bit to be checked against the packet. The default value is 'any'(3). It means that ACK … |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.8 | ColumnfwlFilterRstBit | read-create | deprecated | **************** THIS OBJECT IS DEPRECATED **************** The TCP RST bit to be checked against the packet. The default value is 'any'(3). It means that RST … |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.9 | ColumnfwlFilterTos | read-create | current | The IP TOS bit to be checked against the packet. This is a single byte integer of which the last three bits (least significant bits) indicate Delay, Throughput… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.10 | ColumnfwlFilterAccounting | read-write | current | This object is used to enable or disable the filter accounting of this filter. If this object is enabled then the Hit count of this filter will be incremented … |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.11 | ColumnfwlFilterHitClear | read-write | current | This object is used to clear the hit count of this filter. The default value is 'false'. When this object is true, the Hit count for the respective filter will… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.12 | ColumnfwlFilterHitsCount | read-only | current | The number of times this Filter is matched while processing the packet. |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.13 | ColumnfwlFilterAddrType | read-create | current | The address type of the source and destination address. This object is limited to IPv4 and IPv6 addresses. |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.14 | ColumnfwlFilterFlowId | read-create | current | The flow label identifier is specific to an IPv6 header as its to classify the same flow of packets between a source and destination in IPv6 |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.15 | ColumnfwlFilterDscp | read-create | current | The IP DSCP value is applicable for both IPv4 and IPv6, but when DSCP is specified TOS value(fwlFilterTos) should not be configured. Also TOS value (fwlFilterT… |
| 1.3.6.1.4.1.10876.101.1.16.2.3.1.16 | ColumnfwlFilterRowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.2.4 | TablefwlDefnRuleTable | not-accessible | current | The table used to configure the Rules by assigning a set of Filters.(Rule1 = Filter1 & Filter2; Rule2 = Filter1 , Filter2; etc.). |
| 1.3.6.1.4.1.10876.101.1.16.2.4.1 | RowfwlDefnRuleEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.4.1.1 | ColumnfwlRuleRuleName | not-accessible | current | The name that identifies the particular Rule configured in the Firewall . |
| 1.3.6.1.4.1.10876.101.1.16.2.4.1.2 | ColumnfwlRuleFilterSet | read-create | current | A set of Filters combined to form a Rule and this Rule is configured globally or on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.2.4.1.3 | ColumnfwlRuleRowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.2.5 | TablefwlDefnAclTable | not-accessible | current | The ACL table will associate the filter or a combination of filters to a specific Action. The ACL name should map with the rule name |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1 | RowfwlDefnAclEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.1 | ColumnfwlAclIfIndex | not-accessible | current | The interface number in which the filters are to be configured. The value ranges from 0 to 1000. If the value specified is 0, it means that the filters will be… |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.2 | ColumnfwlAclAclName | not-accessible | current | The name that uniquely identifies the particular Filter or Rule configured in the Firewall . |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.3 | ColumnfwlAclDirection | not-accessible | current | This specifies in which direction the Filters or Rules are to be applied on the packets, either to incoming or outgoing packets. |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.4 | ColumnfwlAclAction | read-create | current | This specifies the action to be taken against the packet. If the action value is 'permit', then the packet will be permitted if the filter or rule matches. If … |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.5 | ColumnfwlAclSequenceNumber | read-create | current | This specifies the order in which the Filters are to be matched against the packets from a particular interface. The sequence number should not be zero. The se… |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.6 | ColumnfwlAclAclType | read-only | deprecated | **************** THIS OBJECT IS DEPRECATED **************** This specifies whether the access list configured on a particular interface is a Filter or a Rule (… |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.7 | ColumnfwlAclLogTrigger | read-create | current | This specifies whether the log details should be in brief or detail or none .The default value is 'brief(1)'. |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.8 | ColumnfwlAclFragAction | read-create | current | This specifies whether the fragmentation has to permitted or denied. |
| 1.3.6.1.4.1.10876.101.1.16.2.5.1.9 | ColumnfwlAclRowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.2.6 | TablefwlDefnIfTable | not-accessible | current | This table is used for interface specific filtering like filtering based on IP options, Fragments, ICMP Type and Code, etc. |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1 | RowfwlDefnIfEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.1 | ColumnfwlIfIfIndex | not-accessible | current | The interface number in which the filters or rules are to be configured. |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.2 | ColumnfwlIfIfType | read-create | current | This specifies whether the interface is an external interface (interface connected to the internet) or internal interface. The default value is 'external'(2). |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.3 | ColumnfwlIfIpOptions | read-create | current | The IP options to be checked against the packet. If the packet matches with the IP option specified, then the packet will be dropped. The default value is 'any… |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.4 | ColumnfwlIfFragments | read-create | current | The Fragment type to be checked against the packet. If the packet matches with the fragment type, then the packet will be dropped. The default value is anyFrag… |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.5 | ColumnfwlIfFragmentSize | read-create | current | The maximum size of each fragment when the fragment type 'fwlIfFragments' is large. |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.6 | ColumnfwlIfICMPType | read-create | current | The ICMP type to be checked against the packet. If the ICMP Type matches with the packet, then the packet will be dropped. The default value is 'noICMPType' (2… |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.7 | ColumnfwlIfICMPCode | read-create | deprecated | **************** THIS OBJECT IS DEPRECATED **************** The ICMP Code to be checked against the packet. If the packet matches with the ICMP Code, then the … |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.8 | ColumnfwlIfICMPv6MsgType | read-create | current | The ICMPv6 type to be checked against the packet. If the ICMP Type matches with the packet, then the packet will be dropped. The default value is 'noICMPv6Type… |
| 1.3.6.1.4.1.10876.101.1.16.2.6.1.9 | ColumnfwlIfRowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.2.7 | TablefwlDefnDmzTable | not-accessible | current | This table is used for defining the De-Militarized Zone (DMZ). The host/hosts in this zone will have unrestricted access from the public/external network (Inte… |
| 1.3.6.1.4.1.10876.101.1.16.2.7.1 | RowfwlDefnDmzEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.7.1.1 | ColumnfwlDmzIpIndex | not-accessible | current | The IP Address which the DMZ is to be configured. |
| 1.3.6.1.4.1.10876.101.1.16.2.7.1.2 | ColumnfwlDmzRowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.2.8 | TablefwlUrlFilterTable | not-accessible | current | This table is used for defining URL filters. Any http request that matches the URL string will be filtered |
| 1.3.6.1.4.1.10876.101.1.16.2.8.1 | RowfwlUrlFilterEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.8.1.1 | ColumnfwlUrlString | not-accessible | current | The object specifies the URL string to be filtered |
| 1.3.6.1.4.1.10876.101.1.16.2.8.1.2 | ColumnfwlUrlHitCount | read-only | current | The number of times this URL Filter is matched while processing the packet |
| 1.3.6.1.4.1.10876.101.1.16.2.8.1.3 | ColumnfwlUrlFilterRowStatus | read-create | current | This object allows entries to be created or deleted in this table |
| 1.3.6.1.4.1.10876.101.1.16.2.9 | TablefwlDefnBlkListTable | not-accessible | current | This table is a user configurable table. It is used for listing the IP Addresses that are black listed. The traffic from or to a blacklisted IP Address shall b… |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1 | RowfwlDefnBlkListEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.1 | ColumnfwlBlkListIpAddressType | not-accessible | current | The address type of fwlBlkListIpAddress (IPv4/Ipv6) |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.2 | ColumnfwlBlkListIpAddress | not-accessible | current | The IP Address is to be listed as Blacklist. |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.3 | ColumnfwlBlkListIpMask | not-accessible | current | The IP Subnet mask for the IP address to be blacklisted. |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.4 | ColumnfwlBlkListHitsCount | read-only | current | The number of times BlackList is matched while processing the packet. |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.5 | ColumnfwlBlkListEntryType | read-only | current | This object is used to display whether the entry is created by administrator or the entry is created dynamically through snort module. static(0) - BlkListEntry… |
| 1.3.6.1.4.1.10876.101.1.16.2.9.1.6 | ColumnfwlBlkListRowStatus | read-write | current | This object allows entries to be created or deleted in this Table. The row status values are CREATE_AND_GO and DESTROY |
| 1.3.6.1.4.1.10876.101.1.16.2.10 | TablefwlDefnWhiteListTable | not-accessible | current | This is a user configurable table. This table is used for listing the IP Addresses that are to be listed as White list. The traffic from or to the IP Address i… |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1 | RowfwlDefnWhiteListEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1.1 | ColumnfwlWhiteListIpAddressType | not-accessible | current | The address type of fwlDefnWhiteListEntry (IPv4/Ipv6) |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1.2 | ColumnfwlWhiteListIpAddress | not-accessible | current | The IP Address is to be listed as White List. |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1.3 | ColumnfwlWhiteListIpMask | not-accessible | current | The IP Subnet mask for the IP address to be added in White List. |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1.4 | ColumnfwlWhiteListHitsCount | read-only | current | The number of times WhiteList is matched while processing the packet. |
| 1.3.6.1.4.1.10876.101.1.16.2.10.1.5 | ColumnfwlWhiteListRowStatus | read-write | current | This object allows entries to be created or deleted in this Table. The row status values are CREATE_AND_GO and DESTROY. |
| 1.3.6.1.4.1.10876.101.1.16.2.11 | TablefwlDefnIPv6DmzTable | not-accessible | current | This table is used for defining the De-Militarized Zone (DMZ)for IPv6. The host/hosts in this zone will have unrestricted access from the public/external netwo… |
| 1.3.6.1.4.1.10876.101.1.16.2.11.1 | RowfwlDefnIPv6DmzEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.2.11.1.1 | ColumnfwlDmzAddressType | read-create | current | The Address type of the ipv6 DMZ Host. This object is limited to IPv6 addresses. |
| 1.3.6.1.4.1.10876.101.1.16.2.11.1.2 | ColumnfwlDmzIpv6Index | not-accessible | current | The IPv6 Address which the DMZ is to be configured. |
| 1.3.6.1.4.1.10876.101.1.16.2.11.1.3 | ColumnfwlDmzIpv6RowStatus | read-create | current | This object allows entries to be created or deleted in this table. |
| 1.3.6.1.4.1.10876.101.1.16.3 | NodefwlStatistics | |||
| 1.3.6.1.4.1.10876.101.1.16.3.1 | ScalarfwlStatInspectedPacketsCount | read-only | current | The number of packets inspected by the Firewall module. It includes the number of packets rejected and accepted. |
| 1.3.6.1.4.1.10876.101.1.16.3.2 | ScalarfwlStatTotalPacketsDenied | read-only | current | The number of packets dropped by the Firewall module. This includes all fragmented packets, non-fragmented packets, packets with IP Options, without IP options… |
| 1.3.6.1.4.1.10876.101.1.16.3.3 | ScalarfwlStatTotalPacketsAccepted | read-only | current | The number of packets accepted by the Firewall module. This includes all fragmented packets, non-fragmented packets, packets with IP Options and packets withou… |
| 1.3.6.1.4.1.10876.101.1.16.3.4 | ScalarfwlStatTotalIcmpPacketsDenied | read-only | current | The number of ICMP packets rejected by the Firewall module. |
| 1.3.6.1.4.1.10876.101.1.16.3.5 | ScalarfwlStatTotalSynPacketsDenied | read-only | current | The number of SYN packets denied over the external interfaces. |
| 1.3.6.1.4.1.10876.101.1.16.3.6 | ScalarfwlStatTotalIpSpoofedPacketsDenied | read-only | current | The number of packets rejected by the Firewall due to IP Spoofing attack on the external interfaces. |
| 1.3.6.1.4.1.10876.101.1.16.3.7 | ScalarfwlStatTotalSrcRoutePacketsDenied | read-only | current | The number of packets rejected by the Firewall due to Source Routing attack on the external interfaces. |
| 1.3.6.1.4.1.10876.101.1.16.3.8 | ScalarfwlStatTotalTinyFragmentPacketsDenied | read-only | current | The number of packets rejected by the Firewall due to Tiny Fragment attack on the external interfaces. |
| 1.3.6.1.4.1.10876.101.1.16.3.9 | ScalarfwlStatTotalFragmentedPacketsDenied | read-only | current | The number of fragmented packets rejected by Firewall. |
| 1.3.6.1.4.1.10876.101.1.16.3.10 | ScalarfwlStatTotalLargeFragmentPacketsDenied | read-only | current | The number of packets rejected by Firewall due to large fragment attack on the external interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.11 | ScalarfwlStatTotalIpOptionPacketsDenied | read-only | current | The number of packets with IP options (source routing, record routing, timestamp) rejected by the Firewall. |
| 1.3.6.1.4.1.10876.101.1.16.3.12 | ScalarfwlStatTotalAttacksPacketsDenied | read-only | current | The number of packets rejected by firewall due to suspicious attacks. |
| 1.3.6.1.4.1.10876.101.1.16.3.13 | ScalarfwlStatMemoryAllocationFailCount | read-only | current | The number of times dynamic memory allocation failure (malloc) has occurred. |
| 1.3.6.1.4.1.10876.101.1.16.3.14 | ScalarfwlStatIPv6InspectedPacketsCount | read-only | current | The number of IPv6 packets inspected by the Firewall module. It includes the number of packets rejected and accepted. |
| 1.3.6.1.4.1.10876.101.1.16.3.15 | ScalarfwlStatIPv6TotalPacketsDenied | read-only | current | The number of IPv6 packets dropped by the Firewall module. |
| 1.3.6.1.4.1.10876.101.1.16.3.16 | ScalarfwlStatIPv6TotalPacketsAccepted | read-only | current | The number of IPv6 packets accepted by the Firewall module. |
| 1.3.6.1.4.1.10876.101.1.16.3.17 | ScalarfwlStatIPv6TotalIcmpPacketsDenied | read-only | current | The number of ICMPv6 packets rejected by the Firewall module. |
| 1.3.6.1.4.1.10876.101.1.16.3.18 | ScalarfwlStatIPv6TotalSpoofedPacketsDenied | read-only | current | The number of IPv6 packets rejected by the Firewall due to IP Spoofing attack on the external interfaces. |
| 1.3.6.1.4.1.10876.101.1.16.3.19 | ScalarfwlStatIPv6TotalAttacksPacketsDenied | read-only | current | The number of IPv6 packets rejected by firewall due to suspicious attacks. |
| 1.3.6.1.4.1.10876.101.1.16.3.20 | TablefwlStatIfTable | not-accessible | current | This table is used to maintain the statistics of packets per interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1 | RowfwlStatIfEntry | not-accessible | current | The individual entry in the above table . |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.1 | ColumnfwlStatIfIfIndex | not-accessible | current | The interface number that uniquely identifies an entry in this table. The value ranges from 1 to 1000. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.2 | ColumnfwlStatIfFilterCount | read-only | current | The number of filters configured on an interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.3 | ColumnfwlStatIfPacketsDenied | read-only | current | The number of packets dropped by the Firewall on a particular interface. This includes all fragmented packets, non-fragmented packets, packets with IP Options … |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.4 | ColumnfwlStatIfPacketsAccepted | read-only | current | The number of packets accepted by the Firewall on a particular interface. This includes all fragmented packets, non-fragmented packets, packets with IP Options… |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.5 | ColumnfwlStatIfSynPacketsDenied | read-only | current | The number of SYN packets denied on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.6 | ColumnfwlStatIfIcmpPacketsDenied | read-only | current | The number of ICMP packets rejected by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.7 | ColumnfwlStatIfIpSpoofedPacketsDenied | read-only | current | The number of packets rejected by the Firewall on a particular interface due to IP spoofing attack. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.8 | ColumnfwlStatIfSrcRoutePacketsDenied | read-only | current | The number of packets rejected by the Firewall on a particular interface due to Source Routing attack. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.9 | ColumnfwlStatIfTinyFragmentPacketsDenied | read-only | current | The number of packets rejected by the Firewall on a particular interface due to Tiny Fragment attack. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.10 | ColumnfwlStatIfFragmentPacketsDenied | read-only | current | The number of fragmented packets rejected by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.11 | ColumnfwlStatIfIpOptionPacketsDenied | read-only | current | The number of packets with IP options (source routing, record routing, timestamp) rejected or dropped by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.12 | ColumnfwlStatIfClear | read-write | current | This field is used to clear the statistics of packets per interface. The default value is 'false'. When this object is set to true , the statistics of packets … |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.13 | ColumnfwlIfTrapThreshold | read-write | current | This Object sets the Interface threshold value such that traps will be generated when the number of packets denied exceed the given threshold |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.14 | ColumnfwlStatIfIPv6PacketsDenied | read-only | current | The number of IPv6 packets dropped by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.15 | ColumnfwlStatIfIPv6PacketsAccepted | read-only | current | The number of IPv6 packets accepted by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.16 | ColumnfwlStatIfIPv6IcmpPacketsDenied | read-only | current | The number of ICMPv6 packets rejected by the Firewall on a particular interface. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.17 | ColumnfwlStatIfIPv6SpoofedPacketsDenied | read-only | current | The number of IPv6 spoofed packets rejected by the Firewall on a particular interface due to spoofing attack. |
| 1.3.6.1.4.1.10876.101.1.16.3.20.1.18 | ColumnfwlStatIfClearIPv6 | read-write | current | This field is used to clear the statistics of IPv6 packets per interface.The default value is 'false'. When this object is set to true , the statictics for IPv… |
| 1.3.6.1.4.1.10876.101.1.16.3.21 | ScalarfwlStatClear | read-write | current | This Object clears the global statistics. The default value is 'false'. When this object is set to true , the global statistics is cleared and the value is res… |
| 1.3.6.1.4.1.10876.101.1.16.3.22 | ScalarfwlStatClearIPv6 | read-write | current | This object clears the global ipv6 statistics. The default value is 'false'. When this object is set to true , the global ipv6 statistics is cleared and the va… |
| 1.3.6.1.4.1.10876.101.1.16.3.23 | ScalarfwlTrapThreshold | read-write | current | This Object sets the global threshold value such that traps will be generated when the number of packets denied exceed the given threshold |
| 1.3.6.1.4.1.10876.101.1.16.4 | NodefwlTraps | |||
| 1.3.6.1.4.1.10876.101.1.16.4.0 | NodefwlTrapTypes | |||
| 1.3.6.1.4.1.10876.101.1.16.4.0.1 | NotificationfwlTrapMemoryFailure | current | Trap which is send for memory initialization failure or when Dynamic Allocation fails. | |
| 1.3.6.1.4.1.10876.101.1.16.4.0.2 | NotificationfwlTrapAttackSummary | current | Trap which is send when the number of attacks exceeds the limit value. The limit value is configurable. | |
| 1.3.6.1.4.1.10876.101.1.16.4.0.3 | NotificationfwlTrapThresholdExceeded | current | This Object specifies the Interface index in which the number of packets denied exceeds the threshold configured. | |
| 1.3.6.1.4.1.10876.101.1.16.4.0.4 | NotificationfwlTrapMessage | current | This trap notifies the errors in Firewall Log file. | |
| 1.3.6.1.4.1.10876.101.1.16.4.0.5 | NotificationfwlIdsTrapLogging | current | This trap notifies the errors in IDS logging. | |
| 1.3.6.1.4.1.10876.101.1.16.4.0.6 | NotificationfwlIdsTrapAttackPktFromIds | current | This trap notifies the attack packet identified in IDS. | |
| 1.3.6.1.4.1.10876.101.1.16.4.1 | NodefwlTrapControl | |||
| 1.3.6.1.4.1.10876.101.1.16.4.1.1 | ScalarfwlTrapMemFailMessage | read-write | current | The string to display where the memory failure has occurred. It may happen during allocation of Memory pool or when dynamic allocation fails. This string is al… |
| 1.3.6.1.4.1.10876.101.1.16.4.1.2 | ScalarfwlTrapAttackMessage | read-write | current | This string is also used to display message about the number of attacks occurred. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.3 | ScalarfwlIfIndex | accessible-for-notify | current | fwlIfIfIndex is of type not-accessible and it cannot be used as object for notifications. So this object is defined to use for notifications.The value of this … |
| 1.3.6.1.4.1.10876.101.1.16.4.1.4 | ScalarfwlTrapEvent | accessible-for-notify | current | sizeexceeded - Firewall Log Size Exceeded. sizethreshold hit - Firewall Log Size hit the threshold value. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.5 | ScalarfwlTrapEventTime | accessible-for-notify | current | This object specifies the date and time at which fwlTrapEvent was performed. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.6 | ScalarfwlTrapFileName | read-only | current | Firewall Log filename in the trap message. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.7 | ScalarfwlIdsTrapEvent | accessible-for-notify | current | sizeexceeded - Firewall Log Size Exceeded. sizethreshold hit - Firewall Log Size hit the threshold value. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.8 | ScalarfwlIdsTrapEventTime | accessible-for-notify | current | This object specifies the date and time at which fwlTrapEvent was performed. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.9 | ScalarfwlIdsTrapFileName | read-only | current | Firewall Log filename in the trap message. |
| 1.3.6.1.4.1.10876.101.1.16.4.1.10 | ScalarfwlIdsAttackPktIp | accessible-for-notify | current | This object specifies the IP address of the attack-packet identified by IDS. |
| 1.3.6.1.4.1.10876.101.1.16.5 | NodefwlState | |||
| 1.3.6.1.4.1.10876.101.1.16.5.1 | TablefwlStateTable | not-accessible | current | This table contains the entries maintained by Firewall during state full inspection of the connections passing through the DUT from LAN to WAN or WAN to LAN. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1 | RowfwlStateEntry | not-accessible | current | The individual entry in the above table. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.1 | ColumnfwlStateType | not-accessible | current | This indicates the type of the the entry present in this table. There can be state full entries or init flow entries maintained for TCP connections or partial … |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.2 | ColumnfwlStateLocalIpAddrType | not-accessible | current | Address Family Identifier of the Local address |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.3 | ColumnfwlStateLocalIpAddress | not-accessible | current | The Local Ip Address of the session. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.4 | ColumnfwlStateRemoteIpAddrType | not-accessible | current | Address Family Identifier of the remote address |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.5 | ColumnfwlStateRemoteIpAddress | not-accessible | current | The Remote Ip Address of the session. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.6 | ColumnfwlStateLocalPort | not-accessible | current | This object identifies the Local Port information of the session |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.7 | ColumnfwlStateRemotePort | not-accessible | current | This object identifies the remote Port information of the session |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.8 | ColumnfwlStateProtocol | not-accessible | current | The type of the protocol of the session. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.9 | ColumnfwlStateDirection | not-accessible | current | The direction of the firewall state session. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.10 | ColumnfwlStateEstablishedTime | read-only | current | The time at which the firewall session has been established. |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.11 | ColumnfwlStateLocalState | read-only | current | The state information of the local host. The states new, established and related are used in stateful table. The other states are used in TCP init flow table. … |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.12 | ColumnfwlStateRemoteState | read-only | current | The state information of the remote host. The states new, established and related are used in stateful table. The other states are used in TCP init flow table.… |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.13 | ColumnfwlStateLogLevel | read-only | current | The logging details of the session. Definition of Log level (0-3) with 3 being the highest level |
| 1.3.6.1.4.1.10876.101.1.16.5.1.1.14 | ColumnfwlStateCallStatus | read-only | current | This object is effective when SIP is enabled. This indicates the status of the firewall session. The values hold and unhold are effective only for SIP calls. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| ProtocolType | INTEGER { icmp(1), igmp(2), ggp(3), ip(4), tcp(6), egp(8), igp(9), nvp(11), udp(17), irtp(28), idpr(35), rsvp(46), mhrp(48), igrp(88), ospfigp(89), any(255) } | current | Enumeration of protocols that are commonly used on Firewall AccessList. |
| Status | INTEGER { enabled(1), disabled(2) } | current | The status of the Firewall AccessList control switches. |