MIB Viewer

FIREWALL-MIB

184 objects
The MIB module to describe the Firewall .
OIDNameAccessStatusDescription
1.3.6.1.4.1.10876.101.1.16IdentityfirewallThe MIB module to describe the Firewall .
1.3.6.1.4.1.10876.101.1.16.1NodefwlGlobal
1.3.6.1.4.1.10876.101.1.16.1.1ScalarfwlGlobalMasterControlSwitchread-writecurrentThis switch is used to enable or disable the entire firewall service. The default value for this switch is 'enabled' (1).
1.3.6.1.4.1.10876.101.1.16.1.2ScalarfwlGlobalICMPControlSwitchread-writecurrentThis switch is used to generate or suppress the ICMP generation when a packet is rejected by the firewall. The default value for this switch is 'suppress'(2).
1.3.6.1.4.1.10876.101.1.16.1.3ScalarfwlGlobalIpSpoofFilteringread-writecurrentThis switch is used to determine whether the inbound packets (packets arriving on the external interface or the interface connected to the Internet)are to be e…
1.3.6.1.4.1.10876.101.1.16.1.4ScalarfwlGlobalSrcRouteFilteringread-writedeprecated**************** THIS OBJECT IS DEPRECATED **************** This switch is used to determine whether the inbound packets (packets arriving on the external inte…
1.3.6.1.4.1.10876.101.1.16.1.5ScalarfwlGlobalTinyFragmentFilteringread-writedeprecated**************** THIS OBJECT IS DEPRECATED **************** This switch is used to determine whether the inbound packets (packets arriving on the external inte…
1.3.6.1.4.1.10876.101.1.16.1.6ScalarfwlGlobalTcpInterceptread-writecurrentThis switch is used to determine whether packets are to be examined for a potential Denial of service attack (TCP SYN Flooding attack). The default value for t…
1.3.6.1.4.1.10876.101.1.16.1.7ScalarfwlGlobalTrapread-writecurrentThis switch is used to control the different types of Trap sent to the administrator in case of memory failure or any attacks has occurred. If this switch is e…
1.3.6.1.4.1.10876.101.1.16.1.8ScalarfwlGlobalTraceread-writecurrentThis is used to enable trace statements in Firewall Module. A four byte integer value is specified for enabling the level of tracing. Each Bit in the four byte…
1.3.6.1.4.1.10876.101.1.16.1.9ScalarfwlGlobalDebugread-writecurrentThis is used to enable/disable Debug Statements in Firewall Module.
1.3.6.1.4.1.10876.101.1.16.1.10ScalarfwlGlobalMaxFiltersread-onlycurrentThis specifies the maximum number of memory blocks that can be allocated for filters.
1.3.6.1.4.1.10876.101.1.16.1.11ScalarfwlGlobalMaxRulesread-onlycurrentThis specifies the maximum number of memory blocks that can be allocated for rules.
1.3.6.1.4.1.10876.101.1.16.1.12ScalarfwlGlobalUrlFilteringread-writecurrentThis enables or disables URL filtering. The default value for this switch is 'disable'(2).
1.3.6.1.4.1.10876.101.1.16.1.13ScalarfwlGlobalNetBiosFilteringread-writecurrentThis enables or disables NETBIOS filtering. The default value for this switch is 'disable'(2).
1.3.6.1.4.1.10876.101.1.16.1.14ScalarfwlGlobalNetBiosLan2Wanread-writecurrentThis enables or disables NETBIOS LAN to WAN control switch. The default value for this switch is 'disable'(2).
1.3.6.1.4.1.10876.101.1.16.1.15ScalarfwlGlobalICMPv6ControlSwitchread-writecurrentThis switch is used to generate or suppress the ICMPv6 generation when a packet is rejected by the firewall. When this is enabled, ICMPv6 error message is gene…
1.3.6.1.4.1.10876.101.1.16.1.16ScalarfwlGlobalIpv6SpoofFilteringread-writecurrentThis switch is used to determine whether the inbound packets (packets arriving on the external interface or the interface connected to the Internet)are to be e…
1.3.6.1.4.1.10876.101.1.16.1.17ScalarfwlGlobalLogFileSizeread-writecurrentThis is the maximum file size in bytes of the firewall log file.
1.3.6.1.4.1.10876.101.1.16.1.18ScalarfwlGlobalLogSizeThresholdread-writecurrentThis is the threshold value of the Log storage space with respect to the maximum Log Storage Space. It is entered as a percentage value.
1.3.6.1.4.1.10876.101.1.16.1.19ScalarfwlGlobalIdsLogSizeread-writecurrentThis is the maximum file size in bytes of the IDS log file.
1.3.6.1.4.1.10876.101.1.16.1.20ScalarfwlGlobalIdsLogThresholdread-writecurrentThis is the threshold value of the Log storage space with respect to the maximum Log Storage Space. It is entered as a percentage value.
1.3.6.1.4.1.10876.101.1.16.1.21ScalarfwlGlobalIdsVersionInforead-onlycurrentThis Object shows the Current version of IDS (Intrusion Detection System)
1.3.6.1.4.1.10876.101.1.16.1.22ScalarfwlGlobalReloadIdsread-writecurrentThis Object reload IDS process (Intrusion Detection System) with the new set of rules/configurations.
1.3.6.1.4.1.10876.101.1.16.1.23ScalarfwlGlobalIdsStatusread-writecurrentThis Object is used to enable or disable IDS (Intrusion Detection System) service in the system. By default IDS is enabled.
1.3.6.1.4.1.10876.101.1.16.1.24ScalarfwlGlobalLoadIdsRulesread-writecurrentThis Object loads the existing regular expressions of rules to Pattern Matching Engine (PME) if exists. Also reloads IDS process (Intrusion Detection System). …
1.3.6.1.4.1.10876.101.1.16.2NodefwlDefinition
1.3.6.1.4.1.10876.101.1.16.2.1ScalarfwlDefnTcpInterceptThresholdread-writecurrentThe number of TCP Connection requests (TCP SYN packets) entering into the firewall module within a timeout period. The default value is 50 connections.
1.3.6.1.4.1.10876.101.1.16.2.2ScalarfwlDefnInterceptTimeoutread-writecurrentThe interval after which the Connection requests exceeding the threshold will be discarded. The default value is 1 second. This timeout value applies for TCP,U…
1.3.6.1.4.1.10876.101.1.16.2.3TablefwlDefnFilterTablenot-accessiblecurrentThis table is used to configure the Filters in the Firewall. The Filters can be configured as 'Filter1 10.0.0.0/24 108.0.4.1/32 6'. It means that in Filter1, t…
1.3.6.1.4.1.10876.101.1.16.2.3.1RowfwlDefnFilterEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.3.1.1ColumnfwlFilterFilterNamenot-accessiblecurrentThis Filter name uniquely identifies the particular Filter configured.
1.3.6.1.4.1.10876.101.1.16.2.3.1.2ColumnfwlFilterSrcAddressread-createcurrentThe source IP address and the source mask to be checked against the packet. The default value is 0.0.0.0/0. The address value should not be specified without t…
1.3.6.1.4.1.10876.101.1.16.2.3.1.3ColumnfwlFilterDestAddressread-createcurrentThe destination IP address and the destination mask to be checked against the packet. The default value is 0.0.0.0/0. The address value should not be specified…
1.3.6.1.4.1.10876.101.1.16.2.3.1.4ColumnfwlFilterProtocolread-createcurrentThe type of protocol to be checked against the packet. The default value is 'any' (255). If the value is 'any' (255), it means that the protocol type can be an…
1.3.6.1.4.1.10876.101.1.16.2.3.1.5ColumnfwlFilterSrcPortread-createcurrentThe source port to be checked against the packet. The range of port can be specified by using the symbols like '>', '<', '!=', '=', '<=', '>='. For example the…
1.3.6.1.4.1.10876.101.1.16.2.3.1.6ColumnfwlFilterDestPortread-createcurrentThe destination port to be checked against the packet. The range of port can be specified by using the symbols like '>', '<', '!=', '=', '<=', '>='. For exampl…
1.3.6.1.4.1.10876.101.1.16.2.3.1.7ColumnfwlFilterAckBitread-createdeprecated**************** THIS OBJECT IS DEPRECATED **************** The TCP ACK bit to be checked against the packet. The default value is 'any'(3). It means that ACK …
1.3.6.1.4.1.10876.101.1.16.2.3.1.8ColumnfwlFilterRstBitread-createdeprecated**************** THIS OBJECT IS DEPRECATED **************** The TCP RST bit to be checked against the packet. The default value is 'any'(3). It means that RST …
1.3.6.1.4.1.10876.101.1.16.2.3.1.9ColumnfwlFilterTosread-createcurrentThe IP TOS bit to be checked against the packet. This is a single byte integer of which the last three bits (least significant bits) indicate Delay, Throughput…
1.3.6.1.4.1.10876.101.1.16.2.3.1.10ColumnfwlFilterAccountingread-writecurrentThis object is used to enable or disable the filter accounting of this filter. If this object is enabled then the Hit count of this filter will be incremented …
1.3.6.1.4.1.10876.101.1.16.2.3.1.11ColumnfwlFilterHitClearread-writecurrentThis object is used to clear the hit count of this filter. The default value is 'false'. When this object is true, the Hit count for the respective filter will…
1.3.6.1.4.1.10876.101.1.16.2.3.1.12ColumnfwlFilterHitsCountread-onlycurrentThe number of times this Filter is matched while processing the packet.
1.3.6.1.4.1.10876.101.1.16.2.3.1.13ColumnfwlFilterAddrTyperead-createcurrentThe address type of the source and destination address. This object is limited to IPv4 and IPv6 addresses.
1.3.6.1.4.1.10876.101.1.16.2.3.1.14ColumnfwlFilterFlowIdread-createcurrentThe flow label identifier is specific to an IPv6 header as its to classify the same flow of packets between a source and destination in IPv6
1.3.6.1.4.1.10876.101.1.16.2.3.1.15ColumnfwlFilterDscpread-createcurrentThe IP DSCP value is applicable for both IPv4 and IPv6, but when DSCP is specified TOS value(fwlFilterTos) should not be configured. Also TOS value (fwlFilterT…
1.3.6.1.4.1.10876.101.1.16.2.3.1.16ColumnfwlFilterRowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.2.4TablefwlDefnRuleTablenot-accessiblecurrentThe table used to configure the Rules by assigning a set of Filters.(Rule1 = Filter1 & Filter2; Rule2 = Filter1 , Filter2; etc.).
1.3.6.1.4.1.10876.101.1.16.2.4.1RowfwlDefnRuleEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.4.1.1ColumnfwlRuleRuleNamenot-accessiblecurrentThe name that identifies the particular Rule configured in the Firewall .
1.3.6.1.4.1.10876.101.1.16.2.4.1.2ColumnfwlRuleFilterSetread-createcurrentA set of Filters combined to form a Rule and this Rule is configured globally or on a particular interface.
1.3.6.1.4.1.10876.101.1.16.2.4.1.3ColumnfwlRuleRowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.2.5TablefwlDefnAclTablenot-accessiblecurrentThe ACL table will associate the filter or a combination of filters to a specific Action. The ACL name should map with the rule name
1.3.6.1.4.1.10876.101.1.16.2.5.1RowfwlDefnAclEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.5.1.1ColumnfwlAclIfIndexnot-accessiblecurrentThe interface number in which the filters are to be configured. The value ranges from 0 to 1000. If the value specified is 0, it means that the filters will be…
1.3.6.1.4.1.10876.101.1.16.2.5.1.2ColumnfwlAclAclNamenot-accessiblecurrentThe name that uniquely identifies the particular Filter or Rule configured in the Firewall .
1.3.6.1.4.1.10876.101.1.16.2.5.1.3ColumnfwlAclDirectionnot-accessiblecurrentThis specifies in which direction the Filters or Rules are to be applied on the packets, either to incoming or outgoing packets.
1.3.6.1.4.1.10876.101.1.16.2.5.1.4ColumnfwlAclActionread-createcurrentThis specifies the action to be taken against the packet. If the action value is 'permit', then the packet will be permitted if the filter or rule matches. If …
1.3.6.1.4.1.10876.101.1.16.2.5.1.5ColumnfwlAclSequenceNumberread-createcurrentThis specifies the order in which the Filters are to be matched against the packets from a particular interface. The sequence number should not be zero. The se…
1.3.6.1.4.1.10876.101.1.16.2.5.1.6ColumnfwlAclAclTyperead-onlydeprecated**************** THIS OBJECT IS DEPRECATED **************** This specifies whether the access list configured on a particular interface is a Filter or a Rule (…
1.3.6.1.4.1.10876.101.1.16.2.5.1.7ColumnfwlAclLogTriggerread-createcurrentThis specifies whether the log details should be in brief or detail or none .The default value is 'brief(1)'.
1.3.6.1.4.1.10876.101.1.16.2.5.1.8ColumnfwlAclFragActionread-createcurrentThis specifies whether the fragmentation has to permitted or denied.
1.3.6.1.4.1.10876.101.1.16.2.5.1.9ColumnfwlAclRowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.2.6TablefwlDefnIfTablenot-accessiblecurrentThis table is used for interface specific filtering like filtering based on IP options, Fragments, ICMP Type and Code, etc.
1.3.6.1.4.1.10876.101.1.16.2.6.1RowfwlDefnIfEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.6.1.1ColumnfwlIfIfIndexnot-accessiblecurrentThe interface number in which the filters or rules are to be configured.
1.3.6.1.4.1.10876.101.1.16.2.6.1.2ColumnfwlIfIfTyperead-createcurrentThis specifies whether the interface is an external interface (interface connected to the internet) or internal interface. The default value is 'external'(2).
1.3.6.1.4.1.10876.101.1.16.2.6.1.3ColumnfwlIfIpOptionsread-createcurrentThe IP options to be checked against the packet. If the packet matches with the IP option specified, then the packet will be dropped. The default value is 'any…
1.3.6.1.4.1.10876.101.1.16.2.6.1.4ColumnfwlIfFragmentsread-createcurrentThe Fragment type to be checked against the packet. If the packet matches with the fragment type, then the packet will be dropped. The default value is anyFrag…
1.3.6.1.4.1.10876.101.1.16.2.6.1.5ColumnfwlIfFragmentSizeread-createcurrentThe maximum size of each fragment when the fragment type 'fwlIfFragments' is large.
1.3.6.1.4.1.10876.101.1.16.2.6.1.6ColumnfwlIfICMPTyperead-createcurrentThe ICMP type to be checked against the packet. If the ICMP Type matches with the packet, then the packet will be dropped. The default value is 'noICMPType' (2…
1.3.6.1.4.1.10876.101.1.16.2.6.1.7ColumnfwlIfICMPCoderead-createdeprecated**************** THIS OBJECT IS DEPRECATED **************** The ICMP Code to be checked against the packet. If the packet matches with the ICMP Code, then the …
1.3.6.1.4.1.10876.101.1.16.2.6.1.8ColumnfwlIfICMPv6MsgTyperead-createcurrentThe ICMPv6 type to be checked against the packet. If the ICMP Type matches with the packet, then the packet will be dropped. The default value is 'noICMPv6Type…
1.3.6.1.4.1.10876.101.1.16.2.6.1.9ColumnfwlIfRowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.2.7TablefwlDefnDmzTablenot-accessiblecurrentThis table is used for defining the De-Militarized Zone (DMZ). The host/hosts in this zone will have unrestricted access from the public/external network (Inte…
1.3.6.1.4.1.10876.101.1.16.2.7.1RowfwlDefnDmzEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.7.1.1ColumnfwlDmzIpIndexnot-accessiblecurrentThe IP Address which the DMZ is to be configured.
1.3.6.1.4.1.10876.101.1.16.2.7.1.2ColumnfwlDmzRowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.2.8TablefwlUrlFilterTablenot-accessiblecurrentThis table is used for defining URL filters. Any http request that matches the URL string will be filtered
1.3.6.1.4.1.10876.101.1.16.2.8.1RowfwlUrlFilterEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.8.1.1ColumnfwlUrlStringnot-accessiblecurrentThe object specifies the URL string to be filtered
1.3.6.1.4.1.10876.101.1.16.2.8.1.2ColumnfwlUrlHitCountread-onlycurrentThe number of times this URL Filter is matched while processing the packet
1.3.6.1.4.1.10876.101.1.16.2.8.1.3ColumnfwlUrlFilterRowStatusread-createcurrentThis object allows entries to be created or deleted in this table
1.3.6.1.4.1.10876.101.1.16.2.9TablefwlDefnBlkListTablenot-accessiblecurrentThis table is a user configurable table. It is used for listing the IP Addresses that are black listed. The traffic from or to a blacklisted IP Address shall b…
1.3.6.1.4.1.10876.101.1.16.2.9.1RowfwlDefnBlkListEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.9.1.1ColumnfwlBlkListIpAddressTypenot-accessiblecurrentThe address type of fwlBlkListIpAddress (IPv4/Ipv6)
1.3.6.1.4.1.10876.101.1.16.2.9.1.2ColumnfwlBlkListIpAddressnot-accessiblecurrentThe IP Address is to be listed as Blacklist.
1.3.6.1.4.1.10876.101.1.16.2.9.1.3ColumnfwlBlkListIpMasknot-accessiblecurrentThe IP Subnet mask for the IP address to be blacklisted.
1.3.6.1.4.1.10876.101.1.16.2.9.1.4ColumnfwlBlkListHitsCountread-onlycurrentThe number of times BlackList is matched while processing the packet.
1.3.6.1.4.1.10876.101.1.16.2.9.1.5ColumnfwlBlkListEntryTyperead-onlycurrentThis object is used to display whether the entry is created by administrator or the entry is created dynamically through snort module. static(0) - BlkListEntry…
1.3.6.1.4.1.10876.101.1.16.2.9.1.6ColumnfwlBlkListRowStatusread-writecurrentThis object allows entries to be created or deleted in this Table. The row status values are CREATE_AND_GO and DESTROY
1.3.6.1.4.1.10876.101.1.16.2.10TablefwlDefnWhiteListTablenot-accessiblecurrentThis is a user configurable table. This table is used for listing the IP Addresses that are to be listed as White list. The traffic from or to the IP Address i…
1.3.6.1.4.1.10876.101.1.16.2.10.1RowfwlDefnWhiteListEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.10.1.1ColumnfwlWhiteListIpAddressTypenot-accessiblecurrentThe address type of fwlDefnWhiteListEntry (IPv4/Ipv6)
1.3.6.1.4.1.10876.101.1.16.2.10.1.2ColumnfwlWhiteListIpAddressnot-accessiblecurrentThe IP Address is to be listed as White List.
1.3.6.1.4.1.10876.101.1.16.2.10.1.3ColumnfwlWhiteListIpMasknot-accessiblecurrentThe IP Subnet mask for the IP address to be added in White List.
1.3.6.1.4.1.10876.101.1.16.2.10.1.4ColumnfwlWhiteListHitsCountread-onlycurrentThe number of times WhiteList is matched while processing the packet.
1.3.6.1.4.1.10876.101.1.16.2.10.1.5ColumnfwlWhiteListRowStatusread-writecurrentThis object allows entries to be created or deleted in this Table. The row status values are CREATE_AND_GO and DESTROY.
1.3.6.1.4.1.10876.101.1.16.2.11TablefwlDefnIPv6DmzTablenot-accessiblecurrentThis table is used for defining the De-Militarized Zone (DMZ)for IPv6. The host/hosts in this zone will have unrestricted access from the public/external netwo…
1.3.6.1.4.1.10876.101.1.16.2.11.1RowfwlDefnIPv6DmzEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.2.11.1.1ColumnfwlDmzAddressTyperead-createcurrentThe Address type of the ipv6 DMZ Host. This object is limited to IPv6 addresses.
1.3.6.1.4.1.10876.101.1.16.2.11.1.2ColumnfwlDmzIpv6Indexnot-accessiblecurrentThe IPv6 Address which the DMZ is to be configured.
1.3.6.1.4.1.10876.101.1.16.2.11.1.3ColumnfwlDmzIpv6RowStatusread-createcurrentThis object allows entries to be created or deleted in this table.
1.3.6.1.4.1.10876.101.1.16.3NodefwlStatistics
1.3.6.1.4.1.10876.101.1.16.3.1ScalarfwlStatInspectedPacketsCountread-onlycurrentThe number of packets inspected by the Firewall module. It includes the number of packets rejected and accepted.
1.3.6.1.4.1.10876.101.1.16.3.2ScalarfwlStatTotalPacketsDeniedread-onlycurrentThe number of packets dropped by the Firewall module. This includes all fragmented packets, non-fragmented packets, packets with IP Options, without IP options…
1.3.6.1.4.1.10876.101.1.16.3.3ScalarfwlStatTotalPacketsAcceptedread-onlycurrentThe number of packets accepted by the Firewall module. This includes all fragmented packets, non-fragmented packets, packets with IP Options and packets withou…
1.3.6.1.4.1.10876.101.1.16.3.4ScalarfwlStatTotalIcmpPacketsDeniedread-onlycurrentThe number of ICMP packets rejected by the Firewall module.
1.3.6.1.4.1.10876.101.1.16.3.5ScalarfwlStatTotalSynPacketsDeniedread-onlycurrentThe number of SYN packets denied over the external interfaces.
1.3.6.1.4.1.10876.101.1.16.3.6ScalarfwlStatTotalIpSpoofedPacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall due to IP Spoofing attack on the external interfaces.
1.3.6.1.4.1.10876.101.1.16.3.7ScalarfwlStatTotalSrcRoutePacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall due to Source Routing attack on the external interfaces.
1.3.6.1.4.1.10876.101.1.16.3.8ScalarfwlStatTotalTinyFragmentPacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall due to Tiny Fragment attack on the external interfaces.
1.3.6.1.4.1.10876.101.1.16.3.9ScalarfwlStatTotalFragmentedPacketsDeniedread-onlycurrentThe number of fragmented packets rejected by Firewall.
1.3.6.1.4.1.10876.101.1.16.3.10ScalarfwlStatTotalLargeFragmentPacketsDeniedread-onlycurrentThe number of packets rejected by Firewall due to large fragment attack on the external interface.
1.3.6.1.4.1.10876.101.1.16.3.11ScalarfwlStatTotalIpOptionPacketsDeniedread-onlycurrentThe number of packets with IP options (source routing, record routing, timestamp) rejected by the Firewall.
1.3.6.1.4.1.10876.101.1.16.3.12ScalarfwlStatTotalAttacksPacketsDeniedread-onlycurrentThe number of packets rejected by firewall due to suspicious attacks.
1.3.6.1.4.1.10876.101.1.16.3.13ScalarfwlStatMemoryAllocationFailCountread-onlycurrentThe number of times dynamic memory allocation failure (malloc) has occurred.
1.3.6.1.4.1.10876.101.1.16.3.14ScalarfwlStatIPv6InspectedPacketsCountread-onlycurrentThe number of IPv6 packets inspected by the Firewall module. It includes the number of packets rejected and accepted.
1.3.6.1.4.1.10876.101.1.16.3.15ScalarfwlStatIPv6TotalPacketsDeniedread-onlycurrentThe number of IPv6 packets dropped by the Firewall module.
1.3.6.1.4.1.10876.101.1.16.3.16ScalarfwlStatIPv6TotalPacketsAcceptedread-onlycurrentThe number of IPv6 packets accepted by the Firewall module.
1.3.6.1.4.1.10876.101.1.16.3.17ScalarfwlStatIPv6TotalIcmpPacketsDeniedread-onlycurrentThe number of ICMPv6 packets rejected by the Firewall module.
1.3.6.1.4.1.10876.101.1.16.3.18ScalarfwlStatIPv6TotalSpoofedPacketsDeniedread-onlycurrentThe number of IPv6 packets rejected by the Firewall due to IP Spoofing attack on the external interfaces.
1.3.6.1.4.1.10876.101.1.16.3.19ScalarfwlStatIPv6TotalAttacksPacketsDeniedread-onlycurrentThe number of IPv6 packets rejected by firewall due to suspicious attacks.
1.3.6.1.4.1.10876.101.1.16.3.20TablefwlStatIfTablenot-accessiblecurrentThis table is used to maintain the statistics of packets per interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1RowfwlStatIfEntrynot-accessiblecurrentThe individual entry in the above table .
1.3.6.1.4.1.10876.101.1.16.3.20.1.1ColumnfwlStatIfIfIndexnot-accessiblecurrentThe interface number that uniquely identifies an entry in this table. The value ranges from 1 to 1000.
1.3.6.1.4.1.10876.101.1.16.3.20.1.2ColumnfwlStatIfFilterCountread-onlycurrentThe number of filters configured on an interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.3ColumnfwlStatIfPacketsDeniedread-onlycurrentThe number of packets dropped by the Firewall on a particular interface. This includes all fragmented packets, non-fragmented packets, packets with IP Options …
1.3.6.1.4.1.10876.101.1.16.3.20.1.4ColumnfwlStatIfPacketsAcceptedread-onlycurrentThe number of packets accepted by the Firewall on a particular interface. This includes all fragmented packets, non-fragmented packets, packets with IP Options…
1.3.6.1.4.1.10876.101.1.16.3.20.1.5ColumnfwlStatIfSynPacketsDeniedread-onlycurrentThe number of SYN packets denied on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.6ColumnfwlStatIfIcmpPacketsDeniedread-onlycurrentThe number of ICMP packets rejected by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.7ColumnfwlStatIfIpSpoofedPacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall on a particular interface due to IP spoofing attack.
1.3.6.1.4.1.10876.101.1.16.3.20.1.8ColumnfwlStatIfSrcRoutePacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall on a particular interface due to Source Routing attack.
1.3.6.1.4.1.10876.101.1.16.3.20.1.9ColumnfwlStatIfTinyFragmentPacketsDeniedread-onlycurrentThe number of packets rejected by the Firewall on a particular interface due to Tiny Fragment attack.
1.3.6.1.4.1.10876.101.1.16.3.20.1.10ColumnfwlStatIfFragmentPacketsDeniedread-onlycurrentThe number of fragmented packets rejected by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.11ColumnfwlStatIfIpOptionPacketsDeniedread-onlycurrentThe number of packets with IP options (source routing, record routing, timestamp) rejected or dropped by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.12ColumnfwlStatIfClearread-writecurrentThis field is used to clear the statistics of packets per interface. The default value is 'false'. When this object is set to true , the statistics of packets …
1.3.6.1.4.1.10876.101.1.16.3.20.1.13ColumnfwlIfTrapThresholdread-writecurrentThis Object sets the Interface threshold value such that traps will be generated when the number of packets denied exceed the given threshold
1.3.6.1.4.1.10876.101.1.16.3.20.1.14ColumnfwlStatIfIPv6PacketsDeniedread-onlycurrentThe number of IPv6 packets dropped by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.15ColumnfwlStatIfIPv6PacketsAcceptedread-onlycurrentThe number of IPv6 packets accepted by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.16ColumnfwlStatIfIPv6IcmpPacketsDeniedread-onlycurrentThe number of ICMPv6 packets rejected by the Firewall on a particular interface.
1.3.6.1.4.1.10876.101.1.16.3.20.1.17ColumnfwlStatIfIPv6SpoofedPacketsDeniedread-onlycurrentThe number of IPv6 spoofed packets rejected by the Firewall on a particular interface due to spoofing attack.
1.3.6.1.4.1.10876.101.1.16.3.20.1.18ColumnfwlStatIfClearIPv6read-writecurrentThis field is used to clear the statistics of IPv6 packets per interface.The default value is 'false'. When this object is set to true , the statictics for IPv…
1.3.6.1.4.1.10876.101.1.16.3.21ScalarfwlStatClearread-writecurrentThis Object clears the global statistics. The default value is 'false'. When this object is set to true , the global statistics is cleared and the value is res…
1.3.6.1.4.1.10876.101.1.16.3.22ScalarfwlStatClearIPv6read-writecurrentThis object clears the global ipv6 statistics. The default value is 'false'. When this object is set to true , the global ipv6 statistics is cleared and the va…
1.3.6.1.4.1.10876.101.1.16.3.23ScalarfwlTrapThresholdread-writecurrentThis Object sets the global threshold value such that traps will be generated when the number of packets denied exceed the given threshold
1.3.6.1.4.1.10876.101.1.16.4NodefwlTraps
1.3.6.1.4.1.10876.101.1.16.4.0NodefwlTrapTypes
1.3.6.1.4.1.10876.101.1.16.4.0.1NotificationfwlTrapMemoryFailurecurrentTrap which is send for memory initialization failure or when Dynamic Allocation fails.
1.3.6.1.4.1.10876.101.1.16.4.0.2NotificationfwlTrapAttackSummarycurrentTrap which is send when the number of attacks exceeds the limit value. The limit value is configurable.
1.3.6.1.4.1.10876.101.1.16.4.0.3NotificationfwlTrapThresholdExceededcurrentThis Object specifies the Interface index in which the number of packets denied exceeds the threshold configured.
1.3.6.1.4.1.10876.101.1.16.4.0.4NotificationfwlTrapMessagecurrentThis trap notifies the errors in Firewall Log file.
1.3.6.1.4.1.10876.101.1.16.4.0.5NotificationfwlIdsTrapLoggingcurrentThis trap notifies the errors in IDS logging.
1.3.6.1.4.1.10876.101.1.16.4.0.6NotificationfwlIdsTrapAttackPktFromIdscurrentThis trap notifies the attack packet identified in IDS.
1.3.6.1.4.1.10876.101.1.16.4.1NodefwlTrapControl
1.3.6.1.4.1.10876.101.1.16.4.1.1ScalarfwlTrapMemFailMessageread-writecurrentThe string to display where the memory failure has occurred. It may happen during allocation of Memory pool or when dynamic allocation fails. This string is al…
1.3.6.1.4.1.10876.101.1.16.4.1.2ScalarfwlTrapAttackMessageread-writecurrentThis string is also used to display message about the number of attacks occurred.
1.3.6.1.4.1.10876.101.1.16.4.1.3ScalarfwlIfIndexaccessible-for-notifycurrentfwlIfIfIndex is of type not-accessible and it cannot be used as object for notifications. So this object is defined to use for notifications.The value of this …
1.3.6.1.4.1.10876.101.1.16.4.1.4ScalarfwlTrapEventaccessible-for-notifycurrentsizeexceeded - Firewall Log Size Exceeded. sizethreshold hit - Firewall Log Size hit the threshold value.
1.3.6.1.4.1.10876.101.1.16.4.1.5ScalarfwlTrapEventTimeaccessible-for-notifycurrentThis object specifies the date and time at which fwlTrapEvent was performed.
1.3.6.1.4.1.10876.101.1.16.4.1.6ScalarfwlTrapFileNameread-onlycurrentFirewall Log filename in the trap message.
1.3.6.1.4.1.10876.101.1.16.4.1.7ScalarfwlIdsTrapEventaccessible-for-notifycurrentsizeexceeded - Firewall Log Size Exceeded. sizethreshold hit - Firewall Log Size hit the threshold value.
1.3.6.1.4.1.10876.101.1.16.4.1.8ScalarfwlIdsTrapEventTimeaccessible-for-notifycurrentThis object specifies the date and time at which fwlTrapEvent was performed.
1.3.6.1.4.1.10876.101.1.16.4.1.9ScalarfwlIdsTrapFileNameread-onlycurrentFirewall Log filename in the trap message.
1.3.6.1.4.1.10876.101.1.16.4.1.10ScalarfwlIdsAttackPktIpaccessible-for-notifycurrentThis object specifies the IP address of the attack-packet identified by IDS.
1.3.6.1.4.1.10876.101.1.16.5NodefwlState
1.3.6.1.4.1.10876.101.1.16.5.1TablefwlStateTablenot-accessiblecurrentThis table contains the entries maintained by Firewall during state full inspection of the connections passing through the DUT from LAN to WAN or WAN to LAN.
1.3.6.1.4.1.10876.101.1.16.5.1.1RowfwlStateEntrynot-accessiblecurrentThe individual entry in the above table.
1.3.6.1.4.1.10876.101.1.16.5.1.1.1ColumnfwlStateTypenot-accessiblecurrentThis indicates the type of the the entry present in this table. There can be state full entries or init flow entries maintained for TCP connections or partial …
1.3.6.1.4.1.10876.101.1.16.5.1.1.2ColumnfwlStateLocalIpAddrTypenot-accessiblecurrentAddress Family Identifier of the Local address
1.3.6.1.4.1.10876.101.1.16.5.1.1.3ColumnfwlStateLocalIpAddressnot-accessiblecurrentThe Local Ip Address of the session.
1.3.6.1.4.1.10876.101.1.16.5.1.1.4ColumnfwlStateRemoteIpAddrTypenot-accessiblecurrentAddress Family Identifier of the remote address
1.3.6.1.4.1.10876.101.1.16.5.1.1.5ColumnfwlStateRemoteIpAddressnot-accessiblecurrentThe Remote Ip Address of the session.
1.3.6.1.4.1.10876.101.1.16.5.1.1.6ColumnfwlStateLocalPortnot-accessiblecurrentThis object identifies the Local Port information of the session
1.3.6.1.4.1.10876.101.1.16.5.1.1.7ColumnfwlStateRemotePortnot-accessiblecurrentThis object identifies the remote Port information of the session
1.3.6.1.4.1.10876.101.1.16.5.1.1.8ColumnfwlStateProtocolnot-accessiblecurrentThe type of the protocol of the session.
1.3.6.1.4.1.10876.101.1.16.5.1.1.9ColumnfwlStateDirectionnot-accessiblecurrentThe direction of the firewall state session.
1.3.6.1.4.1.10876.101.1.16.5.1.1.10ColumnfwlStateEstablishedTimeread-onlycurrentThe time at which the firewall session has been established.
1.3.6.1.4.1.10876.101.1.16.5.1.1.11ColumnfwlStateLocalStateread-onlycurrentThe state information of the local host. The states new, established and related are used in stateful table. The other states are used in TCP init flow table. …
1.3.6.1.4.1.10876.101.1.16.5.1.1.12ColumnfwlStateRemoteStateread-onlycurrentThe state information of the remote host. The states new, established and related are used in stateful table. The other states are used in TCP init flow table.…
1.3.6.1.4.1.10876.101.1.16.5.1.1.13ColumnfwlStateLogLevelread-onlycurrentThe logging details of the session. Definition of Log level (0-3) with 3 being the highest level
1.3.6.1.4.1.10876.101.1.16.5.1.1.14ColumnfwlStateCallStatusread-onlycurrentThis object is effective when SIP is enabled. This indicates the status of the firewall session. The values hold and unhold are effective only for SIP calls.
Type Definitions
NameSyntaxStatusDescription
ProtocolTypeINTEGER { icmp(1), igmp(2), ggp(3), ip(4), tcp(6), egp(8), igp(9), nvp(11), udp(17), irtp(28), idpr(35), rsvp(46), mhrp(48), igrp(88), ospfigp(89), any(255) }currentEnumeration of protocols that are commonly used on Firewall AccessList.
StatusINTEGER { enabled(1), disabled(2) }currentThe status of the Firewall AccessList control switches.