HM2-FW-MIB
468 objects
SNMP interface for Hirschmann Firewall modules. Copyright (C)
Imported Objects
| HM2-PLATFORM-QOS-ACL-MIB | AclBurstSize EtypeValue |
| HM2-TC-MIB | hm2ConfigurationMibs HmActionValue HmEnabledStatus HmExtraLargeDisplayString HmLargeDisplayString HmTimeSeconds1970 |
| IF-MIB | InterfaceIndex |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE NOTIFICATION-GROUP OBJECT-GROUP |
| SNMPv2-SMI | Counter64 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-IDENTITY OBJECT-TYPE Unsigned32 |
| SNMPv2-TC | DisplayString MacAddress RowStatus TruthValue |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.248.11.79 | Identityhm2FwMib | SNMP interface for Hirschmann Firewall modules. Copyright (C) | ||
| 1.3.6.1.4.1.248.11.79.0 | Nodehm2FwNotifications | |||
| 1.3.6.1.4.1.248.11.79.0.1 | Notificationhm2DynFwRuleAppliedTrap | current | A rule of the dynamic firewall was applied. The rule is identified by the given rule index of the rule table. | |
| 1.3.6.1.4.1.248.11.79.0.2 | Notificationhm2DynFwRuleAppliedAndLoggedTrap | current | A rule of the dynamic firewall was applied and logged according to the current logging mechanism. The rule is identified by the given rule index of the rule ta… | |
| 1.3.6.1.4.1.248.11.79.0.3 | Notificationhm2L3RuleAppliedTrap | current | A rule of the L3 firewall was applied. The rule is identified by the given rule index of the rule table. | |
| 1.3.6.1.4.1.248.11.79.0.4 | Notificationhm2L3RuleAppliedAndLoggedTrap | current | A rule of the L3 firewall was applied and logged according the current logging mechanism. The rule is identified by the given rule index of the rule table. | |
| 1.3.6.1.4.1.248.11.79.0.5 | Notificationhm2L2RuleAppliedTrap | current | A rule of the L2 firewall was applied. The rule is identified by the given rule index of the rule table. | |
| 1.3.6.1.4.1.248.11.79.0.6 | Notificationhm2L2RuleAppliedAndLoggedTrap | current | A rule of the L2 firewall was applied and logged according the current logging mechanism. The rule is identified by the given rule index of the rule table. | |
| 1.3.6.1.4.1.248.11.79.1 | Nodehm2FwObjects | |||
| 1.3.6.1.4.1.248.11.79.1.1 | Nodehm2FwGeneralSettings | |||
| 1.3.6.1.4.1.248.11.79.1.1.1 | Scalarhm2DynFwMaxRules | read-only | current | Maximum number of allowed rules for dynamic firewalling. |
| 1.3.6.1.4.1.248.11.79.1.1.2 | Scalarhm2L3MaxRules | read-only | current | Maximum number of allowed rules for L3 firewalling. |
| 1.3.6.1.4.1.248.11.79.1.1.3 | Scalarhm2ResetStatistics | read-write | current | Setting this value to action(2) will reset the statistics of the whole firewall module. It will be set to noop(1) automatically after reset. |
| 1.3.6.1.4.1.248.11.79.1.1.4 | Scalarhm2FlushTables | read-write | current | Setting this value to action(2) will flush all connection tracking states. It will be set to noop(1) automatically after table flush. |
| 1.3.6.1.4.1.248.11.79.1.1.5 | Scalarhm2DefaultPolicy | read-write | current | The default policy for forwarding packets: o accept(1): Packets matching this rule are accepted and will be forwarded o drop(2): Packets matching this rule wil… |
| 1.3.6.1.4.1.248.11.79.1.1.6 | Scalarhm2ConnTrackValidateCheckSum | read-write | current | This value describes, whether the Firewall connection tracking in the Linux kernel shall validate the protocol checksums. Disable this validation (false) impro… |
| 1.3.6.1.4.1.248.11.79.1.2 | Nodehm2DynFw | |||
| 1.3.6.1.4.1.248.11.79.1.2.1 | Nodehm2DynFwRuleObjects | |||
| 1.3.6.1.4.1.248.11.79.1.2.1.1 | Scalarhm2DynFwRuleCount | read-only | current | Number of current dynamic firewalls rules |
| 1.3.6.1.4.1.248.11.79.1.2.1.2 | Scalarhm2DynFwIfMappingRuleCount | read-only | current | Number of current DynFw IF mapping entries. |
| 1.3.6.1.4.1.248.11.79.1.2.1.3 | Scalarhm2DynFwRulePendingActions | read-only | current | This value describes, whether the DynFW rule table was modified but not yet written to the firewall implementation (set to true). After writing all modificatio… |
| 1.3.6.1.4.1.248.11.79.1.2.1.4 | Scalarhm2DynFwCommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the firewall (DynFW and Interface Mapping Table). After writing all modifications, the valu… |
| 1.3.6.1.4.1.248.11.79.1.2.2 | Nodehm2DynFwRuleTables | |||
| 1.3.6.1.4.1.248.11.79.1.2.2.1 | Tablehm2DynFwRuleTable | not-accessible | current | The list of rules for this dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1 | Rowhm2DynFwRuleEntry | not-accessible | current | Dynamic firewall rule entry. |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.1 | Columnhm2DynFwRuleIndex | accessible-for-notify | current | Rule index of this dynamic firewall rule |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.2 | Columnhm2DynFwSourceAddress | read-create | current | The source address of the packet to filter. Allowed formats are: - keyword 'any' - single address ('10.0.0.1') - CIDR address range ('10.0.0.0/8') - netobject … |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.3 | Columnhm2DynFwSourcePort | read-create | current | The source port of the packet to filter. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyphen ('… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.4 | Columnhm2DynFwTargetAddress | read-create | current | The destination address of the packet to filter. Allowed formats are: - keyword 'any' - single address ('10.0.0.1') - CIDR address range ('10.0.0.0/8') - netob… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.5 | Columnhm2DynFwTargetPort | read-create | current | The destination port of the packet to filter. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyph… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.6 | Columnhm2DynFwProto | read-create | current | The IP protocol (RFC 791) for protocol-independent filtering. The following values are currently supported: o icmp(1): internet control message protocol (RFC 7… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.7 | Columnhm2DynFwRuleParams | read-create | current | Additional parameters to this rule as string. A parameter has the syntax: <param>=<val> Parameters are separated by a comma. If more than one value is given fo… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.8 | Columnhm2DynFwAction | read-create | current | The action of the corresponding rule: o accept(1): Packets matching this rule are accepted and will be forwarded o drop(2): Packets matching this rule will be … |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.9 | Columnhm2DynFwLog | read-create | current | Set to true if application of this rule shall be logged |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.10 | Columnhm2DynFwTrap | read-create | current | Set to true if application of this rule shall send a trap. |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.11 | Columnhm2DynFwRowStatus | read-create | current | This is a standard row status value: - active(1): The rule is active. Note that until committed, the rule will not be applied. - notInService(2): The rule is i… |
| 1.3.6.1.4.1.248.11.79.1.2.2.1.1.12 | Columnhm2DynFwDescription | read-create | current | User defined textual description related to this rule. |
| 1.3.6.1.4.1.248.11.79.1.2.2.2 | Tablehm2DynFwRuleIfMappingTable | not-accessible | current | Table for mapping L3 rules to interfaces |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1 | Rowhm2DynFwRuleIfMappingEntry | not-accessible | current | Entry in rule interface mapping table |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1.1 | Columnhm2DynFwIfmRuleIndex | not-accessible | current | The index of the DynFw rule this mapping entry is assigned to. The DynFw rule must exist before creation of mapping entry. |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1.2 | Columnhm2DynFwIfmDirection | not-accessible | current | Meanings: - ingress(1): Apply this rule to packets arriving on this interface - egress(2): Apply this rule to packets leaving from this interface - both(3): Ap… |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1.3 | Columnhm2DynFwIfmPriority | read-create | current | The priority is the sorting key for rules in to this interface. They don't need to be unique, but no clear order can be assumed among rules with the same prior… |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1.4 | Columnhm2DynFwIfmInterface | not-accessible | current | The interface this mapping entry is applied to. This has to be either an hm2AgentSwitchIpInterfaceIfIndex or an hm2AgentSwitchIpVlanIfIndex. Note that for phys… |
| 1.3.6.1.4.1.248.11.79.1.2.2.2.1.5 | Columnhm2DynFwIfmRowStatus | read-create | current | The RowStatus value for this entry with the usual meanings: - active(1): The interface mapping is in place - notInService(2): The interface mapping is not in p… |
| 1.3.6.1.4.1.248.11.79.1.2.4 | Nodehm2DynFwStats | |||
| 1.3.6.1.4.1.248.11.79.1.2.4.1 | Nodehm2DynFwGeneralStats | |||
| 1.3.6.1.4.1.248.11.79.1.2.4.1.1 | Scalarhm2DynFwStatsTtPck | read-only | current | Total number of packets processed by the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.1.2 | Scalarhm2DynFwStatsTtPckSize | read-only | current | Total number of bytes processed by the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.1.3 | Scalarhm2DynFwStatsTtPckDenDrop | read-only | current | Total number of packets dropped or denied by the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.1.4 | Scalarhm2DynFwStatsTtPckAccepted | read-only | current | Total number of packets accepted by the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.2 | Nodehm2DynFwStatsTables | |||
| 1.3.6.1.4.1.248.11.79.1.2.4.2.1 | Tablehm2DynFwStatsRuleTable | not-accessible | current | Table of per-rule statistics of the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.2.1.1 | Rowhm2DynFwStatsRuleEntry | not-accessible | current | Statistics table entry for the dynamic firewall |
| 1.3.6.1.4.1.248.11.79.1.2.4.2.1.1.1 | Columnhm2DynFwStatsPacketCount | read-only | current | Number of packets matched by this rule |
| 1.3.6.1.4.1.248.11.79.1.2.4.2.1.1.2 | Columnhm2DynFwStatsPacketSize | read-only | current | Number of bytes processed by this rule |
| 1.3.6.1.4.1.248.11.79.1.2.4.2.1.1.3 | Columnhm2DynFwStatsLastApplied | read-only | current | Local system time (hm2SystemLocalTime) when the rule was applied the last time |
| 1.3.6.1.4.1.248.11.79.1.3 | Nodehm2L3Fw | |||
| 1.3.6.1.4.1.248.11.79.1.3.1 | Nodehm2L3RuleObjects | |||
| 1.3.6.1.4.1.248.11.79.1.3.1.1 | Scalarhm2L3RuleCount | read-only | current | Number of current L3 rules |
| 1.3.6.1.4.1.248.11.79.1.3.1.2 | Scalarhm2L3IfMappingRuleCount | read-only | current | Number of current L3 IF mapping entries. |
| 1.3.6.1.4.1.248.11.79.1.3.1.3 | Scalarhm2L3RulePendingActions | read-only | current | This value describes, whether the L3 rule table was modified but not yet written to the firewall implementation (set to true). After writing all modifications … |
| 1.3.6.1.4.1.248.11.79.1.3.1.4 | Scalarhm2L3CommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the firewall (L3 and Interface Mapping Table). After writing all modifications, the value s… |
| 1.3.6.1.4.1.248.11.79.1.3.2 | Nodehm2L3RuleTables | |||
| 1.3.6.1.4.1.248.11.79.1.3.2.1 | Tablehm2L3RuleTable | not-accessible | current | The list of L3 rules for this firewall |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1 | Rowhm2L3RuleEntry | not-accessible | current | L3 rule entry. |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.1 | Columnhm2L3RuleIndex | accessible-for-notify | current | Rule index of this L3 rule |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.2 | Columnhm2L3SourceAddress | read-create | current | The source address of the packet to filter. Allowed formats are: - keyword 'any' - single address ('10.0.0.1') - CIDR address range ('10.0.0.0/8') - Asset name… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.3 | Columnhm2L3SourcePort | read-create | current | The source port of the packet to reroute. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyphen (… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.4 | Columnhm2L3TargetAddress | read-create | current | The destination address of the packet to filter. Allowed formats are: - keyword 'any' - single address ('10.0.0.1') - CIDR address range ('10.0.0.0/8') - Asset… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.5 | Columnhm2L3TargetPort | read-create | current | The destination port of the packet to. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyphen ('10… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.6 | Columnhm2L3Proto | read-create | current | The IP protocol (RFC 791) for protocol-independent filtering. The following values are currently supported: o icmp(1): internet control message protocol (RFC 7… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.7 | Columnhm2L3RuleParams | read-create | current | Additional parameters to this rule as string. A parameter has the syntax: <param>=<val> Parameters are separated by a comma. If more than one value is given fo… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.8 | Columnhm2L3Action | read-create | current | The action of the corresponding rule: o accept(1): Packets matching this rule are accepted and will be forwarded o drop(2): Packets matching this rule will be … |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.9 | Columnhm2L3Log | read-create | current | Set to true if application of this rule shall be logged |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.10 | Columnhm2L3Trap | read-create | current | Set to true if application of this rule shall send a trap. |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.11 | Columnhm2L3RowStatus | read-create | current | This is a standard row status value: - active(1): The rule is active. Note that until committed, the rule will not be applied. You cannot activate the rule if … |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.12 | Columnhm2L3Description | read-create | current | User defined textual description related to this rule. |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.13 | Columnhm2DPIProfileIndex | read-create | current | The index of the DPI profile this rule is assigned to depending on enforcer action. Value 0 no DPI profile this rule is assigned to. You cannot assign the rule… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.14 | Columnhm2L3ProtoName | read-create | current | Following values are supported: - Protocol name from hm2ProtocolTable - icmp: internet control message protocol (RFC 792) - igmp: internet group management pro… |
| 1.3.6.1.4.1.248.11.79.1.3.2.1.1.15 | Columnhm2L3AppRuleName | read-create | current | Application rule name from hm2AppRuleTable |
| 1.3.6.1.4.1.248.11.79.1.3.2.2 | Tablehm2L3RuleIfMappingTable | not-accessible | current | Table for mapping L3 rules to interfaces |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1 | Rowhm2L3RuleIfMappingEntry | not-accessible | current | Entry in rule interface mapping table |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1.1 | Columnhm2L3IfmRuleIndex | not-accessible | current | The index of the L3 rule this mapping entry is assigned to. The rule must exist before the mapping entry can be created. |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1.2 | Columnhm2L3IfmDirection | not-accessible | current | Meanings: - ingress(1): Apply this rule to packets arriving on this interface - egress(2): Apply this rule to packets leaving from this interface - both(3): Ap… |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1.3 | Columnhm2L3IfmPriority | read-create | current | The priority is the sorting key for rules in to this interface. They don't need to be unique, but no clear order can be assumed among rules with the same prior… |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1.4 | Columnhm2L3IfmInterface | not-accessible | current | The interface this mapping entry is assigned to. This has to be either an hm2AgentSwitchIpInterfaceIfIndex or an hm2AgentSwitchIpVlanIfIndex. Note that for phy… |
| 1.3.6.1.4.1.248.11.79.1.3.2.2.1.5 | Columnhm2L3IfmRowStatus | read-create | current | The RowStatus value for this entry with the usual meanings: - active(1): The interface mapping is in place - notInService(2): The interface mapping is not in p… |
| 1.3.6.1.4.1.248.11.79.1.3.4 | Nodehm2L3Stats | |||
| 1.3.6.1.4.1.248.11.79.1.3.4.1 | Nodehm2L3GeneralStats | |||
| 1.3.6.1.4.1.248.11.79.1.3.4.1.1 | Scalarhm2L3StatsTotalPck | read-only | current | Total number of packets processed by the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.1.2 | Scalarhm2L3StatsTotalPckSize | read-only | current | Total number of bytes processed by the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.1.3 | Scalarhm2L3StatsTotalPckDenDrop | read-only | current | Total number of packets dropped or denied by the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.1.4 | Scalarhm2L3StatsTotalPckAccepted | read-only | current | Total number of packets accepted by the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.2 | Nodehm2L3StatsTables | |||
| 1.3.6.1.4.1.248.11.79.1.3.4.2.1 | Tablehm2L3StatsRuleTable | not-accessible | current | Table of per-rule statistics of the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.2.1.1 | Rowhm2L3StatsRuleEntry | not-accessible | current | Statistics table entry for the L3 firewall |
| 1.3.6.1.4.1.248.11.79.1.3.4.2.1.1.1 | Columnhm2L3StatsPacketCount | read-only | current | Number of packets matched by this rule |
| 1.3.6.1.4.1.248.11.79.1.3.4.2.1.1.2 | Columnhm2L3StatsPacketSize | read-only | current | Number of bytes processed by this rule |
| 1.3.6.1.4.1.248.11.79.1.3.4.2.1.1.3 | Columnhm2L3StatsLastApplied | read-only | current | Time of last application of the rule in seconds since the Unix epoch. |
| 1.3.6.1.4.1.248.11.79.1.3.11 | Nodehm2DPIProfileModbusObjects | |||
| 1.3.6.1.4.1.248.11.79.1.3.11.1 | Scalarhm2DPIProfileModbusPendingActions | read-only | current | This value describes, whether the DPI MODBUS profile table was modified but not yet written to the enforcer implementation (set to true). After writing all mod… |
| 1.3.6.1.4.1.248.11.79.1.3.11.2 | Scalarhm2DPIProfileModbusCommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI MODBUS Profile Table). After writing all modifications, the value switche… |
| 1.3.6.1.4.1.248.11.79.1.3.12 | Nodehm2DPIProfileOpcObjects | |||
| 1.3.6.1.4.1.248.11.79.1.3.12.1 | Scalarhm2DPIProfileOpcPendingActions | read-only | current | This value describes, whether the L3 OPC profile table was modified but not yet written to the enforcer implementation (set to true). After writing all modific… |
| 1.3.6.1.4.1.248.11.79.1.3.12.2 | Scalarhm2DPIProfileOpcCommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI OPC Profile Table). After writing all modifications, the value switches a… |
| 1.3.6.1.4.1.248.11.79.1.3.13 | Nodehm2DPIProfileIEC104Objects | |||
| 1.3.6.1.4.1.248.11.79.1.3.13.1 | Scalarhm2DPIProfileIEC104PendingActions | read-only | current | This value describes, whether the DPI IEC104 profile table was modified but not yet written to the enforcer implementation (set to true). After writing all mod… |
| 1.3.6.1.4.1.248.11.79.1.3.13.2 | Scalarhm2DPIProfileIEC104CommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI IEC104 Profile Table). After writing all modifications, the value switche… |
| 1.3.6.1.4.1.248.11.79.1.3.14 | Nodehm2DPIProfileEnipObjects | |||
| 1.3.6.1.4.1.248.11.79.1.3.14.1 | Scalarhm2DPIProfileEnipPendingActions | read-only | current | This value describes, whether the DPI EtherNet/IP profile table was modified but not yet written to the enforcer implementation (set to true). After writing al… |
| 1.3.6.1.4.1.248.11.79.1.3.14.2 | Scalarhm2DPIProfileEnipCommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI EtherNet/IP Profile Table). After writing all modifications, the value sw… |
| 1.3.6.1.4.1.248.11.79.1.3.16 | Nodehm2DPIProfileDnp3Objects | |||
| 1.3.6.1.4.1.248.11.79.1.3.16.1 | Scalarhm2DPIProfileDnp3PendingActions | read-only | current | This value describes, whether the DPI DNP3 profile table was modified but not yet written to the enforcer implementation (set to true). After writing all modif… |
| 1.3.6.1.4.1.248.11.79.1.3.16.2 | Scalarhm2DPIProfileDnp3CommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI DNP3 Profile Table). After writing all modifications, the value switches … |
| 1.3.6.1.4.1.248.11.79.1.3.17 | Nodehm2DPIProfileAmpGeneralSetting | |||
| 1.3.6.1.4.1.248.11.79.1.3.17.1 | Scalarhm2DPIAmpDI | read-write | current | To activate/de-activate the DI (Digital Input), so that 'configuration, program & mode protect' can be enable/disable with key-switch wired to the DI of the DP… |
| 1.3.6.1.4.1.248.11.79.1.3.17.2 | Scalarhm2DPIAmpProtectMode | read-write | current | To enable or disable 'configuration, program & mode protect'. |
| 1.3.6.1.4.1.248.11.79.1.3.18 | Nodehm2DPIProfileAmpObjects | |||
| 1.3.6.1.4.1.248.11.79.1.3.18.1 | Scalarhm2DPIProfileAmpPendingActions | read-only | current | This value describes, whether the DPI AMP profile table was modified but not yet written to the enforcer implementation (set to true). After writing all modifi… |
| 1.3.6.1.4.1.248.11.79.1.3.18.2 | Scalarhm2DPIProfileAmpCommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the enforcer (DPI AMP Profile Table). After writing all modifications, the value switches a… |
| 1.3.6.1.4.1.248.11.79.1.3.21 | Nodehm2DPIProfileTables | |||
| 1.3.6.1.4.1.248.11.79.1.3.21.1 | Tablehm2DPIProfileModbusTable | not-accessible | current | The list of DPI MODBUS profiles for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1 | Rowhm2DPIProfileModbusEntry | not-accessible | current | DPI MODBUS profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.1 | Columnhm2DPIProfileModbusIndex | accessible-for-notify | current | Profile index of this DPI MODBUS profile |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.2 | Columnhm2DPIProfileModbusDescription | read-create | current | User defined textual description related to this profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.3 | Columnhm2DPIProfileModbusFunctionType | read-create | current | The function types of the corresponding function codes: o readonly(1): Selects read only function codes for the function code list. o readwrite(2): Selects rea… |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.4 | Columnhm2DPIProfileModbusFunctionCodeList | read-create | current | The function codes for this enforcer as string. A function code has the syntax: <val> Function codes are separated by a comma. If more than one value is given … |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.5 | Columnhm2DPIProfileModbusUnitIdentifierList | read-create | current | Unit identifiers for this enforcer as string. A unit identifier has the syntax: <val> To specify no options, the value 'none' must be given. Unit identifiers a… |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.6 | Columnhm2DPIProfileModbusSanityCheck | read-create | current | Set to true if apply to packets for which a sanity check including format and specification shall be done |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.7 | Columnhm2DPIProfileModbusException | read-create | current | Set to true if apply to packets for which a device exception message shall be sent |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.8 | Columnhm2DPIProfileModbusReset | read-create | current | Set to true if apply to packets for which a reset connection message shall be sent |
| 1.3.6.1.4.1.248.11.79.1.3.21.1.1.9 | Columnhm2DPIProfileModbusRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.2 | Tablehm2DPIProfileOpcTable | not-accessible | current | The list of DPI OPC profiles for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1 | Rowhm2DPIProfileOpcEntry | not-accessible | current | DPI OPC profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.1 | Columnhm2DPIProfileOpcIndex | accessible-for-notify | current | Profile index of this DPI OPC profile |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.2 | Columnhm2DPIProfileOpcDescription | read-create | current | User defined textual description related to this profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.3 | Columnhm2DPIProfileOpcSanityCheck | read-create | current | Set to true if apply to packets for which a sanity check including format and specification shall be done |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.4 | Columnhm2DPIProfileOpcFragmentCheck | read-create | current | Set to true if apply to packets for which a fragment check shall be done |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.5 | Columnhm2DPIProfileOpcTimeoutConnect | read-create | current | Set to nonzero if apply to packets for which a timeout at connect in seconds shall be done. Value 0 disables this match criteria. |
| 1.3.6.1.4.1.248.11.79.1.3.21.2.1.6 | Columnhm2DPIProfileOpcRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3 | Tablehm2DPIProfileIEC104Table | not-accessible | current | The list of DPI IEC104 profiles for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1 | Rowhm2DPIProfileIEC104Entry | not-accessible | current | DPI IEC104 profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.1 | Columnhm2DPIProfileIEC104Index | accessible-for-notify | current | Profile index of this DPI IEC104 profile |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.2 | Columnhm2DPIProfileIEC104Description | read-create | current | User defined textual description related to this profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.3 | Columnhm2DPIProfileIEC104FunctionType | read-create | current | The function types of the corresponding type IDs: o readonly(1): Selects read only type IDs for the type ID list. o readwrite(2): Selects read write type IDs f… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.4 | Columnhm2DPIProfileIEC104TypeIDList | read-create | obsolete | **NOTE: This object is obsolete in favour of hm2DPIProfileIEC104AdvancedTypeIDList.** The type IDs for this enforcer as bit string. Each type ID bit can either… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.5 | Columnhm2DPIProfileIEC104OriginatorAddressList | read-create | obsolete | **NOTE: This object is obsolete in favour of hm2DPIProfileIEC104OriginatorAddrList.** Allowed Originator addresses for this enforcer as bit string. Each bit co… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.6 | Columnhm2DPIProfileIEC104CommonAddressList | read-create | current | Allowed Common addresses for this enforcer as string. Allowed format for common address list: - index range with first and last index separated by hyphen ('10-… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.7 | Columnhm2DPIProfileIEC104SanityCheck | read-create | current | Set to 'enable' if a sanity check including format and specification for all packets shall be done |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.8 | Columnhm2DPIProfileIEC104Reset | read-create | current | Set to 'enable' if reset connection message shall be sent in case a packet is dropped |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.9 | Columnhm2DPIProfileIEC104Debug | read-create | current | Set to 'enable' if reset connection message shall contain debug information |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.10 | Columnhm2DPIProfileIEC104RowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.11 | Columnhm2DPIProfileIEC104AdvancedTypeIDList | read-create | current | The type IDs for this enforcer as string. A type ID list has the syntax: <val> If more than one value is given for type ID list, values are separated by a , si… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.12 | Columnhm2DPIProfileIEC104OriginatorAddrList | read-create | current | Allowed Originator addresses for this enforcer as string. Allowed format for originator address list: - index range with first and last index separated by hyph… |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.13 | Columnhm2DPIProfileIEC104CauseOfTransmissionSize | read-create | current | Set to default value 2 for the latest protocol, set to 1 for legacy protocol |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.14 | Columnhm2DPIProfileIEC104CommonAddressSize | read-create | current | Set to default value 2 for the latest protocol, set to 1 for legacy protocol |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.15 | Columnhm2DPIProfileIEC104IOAddressSize | read-create | current | Set to default value 3 for the latest protocol, set to 2 or 1 for legacy protocol |
| 1.3.6.1.4.1.248.11.79.1.3.21.3.1.16 | Columnhm2DPIProfileIEC104AllowIEC101 | read-create | current | Set to 'enable' if Type IDs that are defined for the old IEC 101 standard have to be allowed |
| 1.3.6.1.4.1.248.11.79.1.3.21.4 | Tablehm2DPIProfileEnipTable | not-accessible | current | The list of DPI EtherNet/IP profiles for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1 | Rowhm2DPIProfileEnipEntry | not-accessible | current | DPI EtherNet/IP profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.1 | Columnhm2DPIProfileEnipIndex | accessible-for-notify | current | Profile index of this DPI EtherNet/IP profile |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.2 | Columnhm2DPIProfileEnipDescription | read-create | current | User defined textual description related to this profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.3 | Columnhm2DPIProfileEnipFunctionType | read-create | current | The function types of the corresponding commands: o readonly(1): Selects read only commands for the command list. o readwrite(2): Selects read write commands f… |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.4 | Columnhm2DPIProfileEnipSanityCheck | read-create | current | If a sanity check including format and specification for all packets shall be done, then it must be enabled. |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.5 | Columnhm2DPIProfileEnipDebug | read-create | current | Enables or disables the debug information in a reset connection message. If a reset connection message shall contain debug information, then it must be enabled. |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.6 | Columnhm2DPIProfileEnipRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.7 | Columnhm2DPIProfileEnipDefaultObjectList | read-create | current | Index of entries to be included from default object list as per ENIP standard. Allowed formats are: (Index range <1-347>) - keyword 'none' for excluding and 'a… |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.8 | Columnhm2DPIProfileEnipWildCardServices | read-create | current | Multiple service codes can be listed separated by a comma (',') - single service code (eg: 0x10) - comma separated list of service codes (eg: 0x12,0x31,0x5F) -… |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.9 | Columnhm2DPIProfileEnipAllowEmbPCCC | read-create | current | Enables or disables the DPI on PCCC messages. If DPI is required on PCCC messages that are encapsulated within CIP objects, then Allow embedded PCCC must be en… |
| 1.3.6.1.4.1.248.11.79.1.3.21.4.1.10 | Columnhm2DPIProfileEnipTcpReset | read-create | current | Enables or disables the resetting of TCP connection. The reset connection message shall be sent in case a packet is dropped, if TCP reset is enabled. |
| 1.3.6.1.4.1.248.11.79.1.3.21.5 | Tablehm2DPIObjectEnipTable | not-accessible | current | The list of DPI EtherNet/IP objects and services for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.5.1 | Rowhm2DPIObjectEnipEntry | not-accessible | current | DPI EtherNet/IP object entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.5.1.1 | Columnhm2DPIObjectEnipClassId | not-accessible | current | The object class ID values used in the class ID and service combination. Values ranging from 0x00 to 0xFFFFFFFF (0 to 4294967295) are interpreted as the Enip C… |
| 1.3.6.1.4.1.248.11.79.1.3.21.5.1.2 | Columnhm2DPIObjectEnipServices | read-create | current | The services codes are allowed as string. A service has the syntax: <0xval> - Services are separated by a comma and are formated in hex (e.g. 0x00 to 0x7F). - … |
| 1.3.6.1.4.1.248.11.79.1.3.21.5.1.3 | Columnhm2DPIObjectEnipDescription | read-create | current | User defined textual description related to the ENIP object class ID and services. |
| 1.3.6.1.4.1.248.11.79.1.3.21.5.1.4 | Columnhm2DPIObjectEnipRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.6 | Tablehm2DPIProfileDnp3Table | not-accessible | current | The list of DPI DNP3 profiles for this enforcer |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1 | Rowhm2DPIProfileDnp3Entry | not-accessible | current | DPI DNP3 profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.1 | Columnhm2DPIProfileDnp3Index | accessible-for-notify | current | Profile index of this DPI DNP3 profile |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.2 | Columnhm2DPIProfileDnp3Description | read-create | current | User defined textual description related to this profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.3 | Columnhm2DPIProfileDnp3FunctionCodeList | read-create | current | The function codes for this enforcer as string. A function code has the syntax: <val> If more than one value is given for a function code, values are separated… |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.4 | Columnhm2DPIProfileDnp3DefaultWhiteList | read-create | current | Index of entries to be included from Default White list of objects as per DNP3 standard IEEE 1815-2012. Allowed formats are: (Index range <1-317>) - keyword 'n… |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.5 | Columnhm2DPIProfileDnp3CrcCheck | read-create | current | This option makes DNP3 enforcer validate the checksum contained in dnp3 link-layer frames. Frames with invalid checksums will be ignored |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.6 | Columnhm2DPIProfileDnp3SanityCheck | read-create | current | Set to true for which all sanity checks shall be done |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.7 | Columnhm2DPIProfileDnp3CheckOutstationTraffic | read-create | current | Set to true to make dnp3 enforcer check packets originating at an outstation |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.8 | Columnhm2DPIProfileDnp3TcpReset | read-create | current | Set to true if apply to packets for which a reset connection message shall be sent on ingress and egress ports |
| 1.3.6.1.4.1.248.11.79.1.3.21.6.1.9 | Columnhm2DPIProfileDnp3RowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.7 | Tablehm2DPIProfileDnp3ObjectTable | not-accessible | current | The list of DPI DNP3 object codes |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1 | Rowhm2DPIProfileDnp3ObjectEntry | not-accessible | current | DPI DNP3 object code entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.1 | Columnhm2DPIProfileDnp3ObjectIndex | accessible-for-notify | current | An index that (together with the DPI index hm2DPIProfileDnp3Index) identifies the entry in the object code list table. This index can be choosen freely, but mu… |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.2 | Columnhm2DPIProfileDnp3ObjectType | read-write | current | Set the object type for DNP3 object code list. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.3 | Columnhm2DPIProfileDnp3ObjectGroupno | read-create | current | Group number for object code list. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.4 | Columnhm2DPIProfileDnp3ObjectVariation | read-create | current | Variation number for object code list |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.5 | Columnhm2DPIProfileDnp3ObjectFunction | read-create | current | Function code number for object code list. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.6 | Columnhm2DPIProfileDnp3ObjectQualifier | read-create | current | Qualifier codes for Object codes. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.7 | Columnhm2DPIProfileDnp3ObjectLength | read-create | current | Object length defined for corresponding object codes. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.8 | Columnhm2DPIProfileDnp3ObjectFuncName | read-create | current | Corresponding function name for function no in Object code. |
| 1.3.6.1.4.1.248.11.79.1.3.21.7.1.9 | Columnhm2DPIProfileDnp3ObjectRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8 | Tablehm2DPIProfileAmpTable | not-accessible | current | The list of DPI AMP profiles for this enforcer. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1 | Rowhm2DPIProfileAmpEntry | not-accessible | current | DPI AMP profile entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.1 | Columnhm2DPIProfileAmpIndex | accessible-for-notify | current | Profile index for the DPI AMP profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.2 | Columnhm2DPIProfileAmpDescription | read-create | current | Textual description related to the DPI AMP profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.3 | Columnhm2DPIProfileAmpProtocol | read-create | current | Specify the AMP protocol for the DPI AMP profile. The following values are currently supported: o camp(1): Common ASCII Message Protocol. o nitp(2): Non-Intell… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.4 | Columnhm2DPIProfileAmpMsgType | read-create | current | Specify the message type for the DPI AMP profile. This field specifies the type of data contained in the message data area and also specifies if the message is… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.5 | Columnhm2DPIProfileAmpAddrClass | read-create | current | Specify the particular type of the memory to be accessed. Allowed formats are: - keyword 'any' - Address class range with first and last class seperated by hyp… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.6 | Columnhm2DPIProfileAmpDevClass | read-create | current | Specify the device class. Allowed formats are: - keyword 'any' - Device class range with first and last class seperated by hyphen (0004-000A). - Comma seperate… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.7 | Columnhm2DPIProfileAmpAddress | read-create | current | Specify the beginning address of the memory to be read or written. Allowed formats are: - Keyword 'any' - Memory address range with first and last address sepe… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.8 | Columnhm2DPIProfileAmpDataword | read-create | current | Specify the address from which the data will be read. It will only be used for the CAMP packets with the memory exchange command or response. Allowed formats a… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.9 | Columnhm2DPIProfileAmpTaskcode | read-create | current | Specify the task code for the DPI AMP profile. Allowed formats are: - Comma seperated task code (00,03,FF). |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.10 | Columnhm2DPIProfileAmpTaskcodedata | read-create | current | Specify the task code data for the DPI AMP profile. Allowed formats are: - Range with first and last task code seperated by hyphen (0004-000A). - Comma seprate… |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.11 | Columnhm2DPIProfileAmpProtectmode | read-create | current | Forcefully enable/disable the protect mode for the particular task code in the DPI AMP profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.12 | Columnhm2DPIProfileAmpEcc | read-create | current | Enable/disable the checking for the NITP Error Check Characters (ECC) of the packets in the DPI AMP profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.13 | Columnhm2DPIProfileAmpBcc | read-create | current | Enable/disable the checking for the CAMP Block Check Characters (BCC) of the AMP packets in the DPI AMP profile. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.14 | Columnhm2DPIProfileAmpDebug | read-create | current | Enable/disable the debugging in the DPI AMP profile. If it is enabled then the reset connection message will contain the debug information. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.15 | Columnhm2DPIProfileAmpTcpReset | read-create | current | Enable/disable the reseting of the TCP connection. If it is enabled then the TCP reset connection message will be sent in case a packet is dropped |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.16 | Columnhm2DPIProfileAmpSanityCheck | read-create | current | Enable/disable the sanity check including format and specification of all the AMP packets. |
| 1.3.6.1.4.1.248.11.79.1.3.21.8.1.17 | Columnhm2DPIProfileAmpRowStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.3.21.9 | Tablehm2DPIAmpTaskCodeTable | not-accessible | current | The list of task code table. |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1 | Rowhm2DPIAmpTaskCodeEntry | not-accessible | current | Task code table entry. |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1.1 | Columnhm2DPIAmpTaskCode | not-accessible | current | Task code value for the new custom task codes The value can be between 00 to FF. |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1.2 | Columnhm2DPIAmpTaskCodeDescription | read-create | current | Description related to the task code. |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1.3 | Columnhm2DPIAmpTaskCodeType | read-only | current | Specify the type of task code in the task code table if it is default(i.e. default) or user defined(i.e. custom). |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1.4 | Columnhm2DPIAmpTaskCodeMode | read-create | current | Specify the mode of the task code if it is config or nonconfig. |
| 1.3.6.1.4.1.248.11.79.1.3.21.9.1.5 | Columnhm2DPIAmpTaskCodeStatus | read-create | current | This is a standard row status value: - active(1): The profile is active. You cannot modify it. - notInService(2): The profile is inactive because of user actio… |
| 1.3.6.1.4.1.248.11.79.1.4 | Nodehm2FwLearningMode | |||
| 1.3.6.1.4.1.248.11.79.1.4.1 | Nodehm2FLMObjects | |||
| 1.3.6.1.4.1.248.11.79.1.4.1.1 | Scalarhm2FLMAdminState | read-write | current | Enable or disable the Firewall Learning Mode. |
| 1.3.6.1.4.1.248.11.79.1.4.1.2 | Scalarhm2FLMAction | read-write | current | Actions to control the Firewall Learning Mode. |
| 1.3.6.1.4.1.248.11.79.1.4.1.3 | Scalarhm2FLMAppState | read-only | current | State of running FLM Application. |
| 1.3.6.1.4.1.248.11.79.1.4.1.4 | Scalarhm2FLMAppInfoEnum | read-only | current | Memory status of FLM Application. |
| 1.3.6.1.4.1.248.11.79.1.4.1.5 | Scalarhm2FLMAppInfoString | read-only | current | Special status message. |
| 1.3.6.1.4.1.248.11.79.1.4.1.6 | Scalarhm2FLML3Entries | read-only | current | Number of Layer 3 entries in the connection table. |
| 1.3.6.1.4.1.248.11.79.1.4.1.7 | Scalarhm2FLMFreeMem | read-only | current | Free memory(%) for learning data. |
| 1.3.6.1.4.1.248.11.79.1.4.1.8 | Scalarhm2FLMMaxEntries | read-only | current | Number of maximum interface entries that can be selected. |
| 1.3.6.1.4.1.248.11.79.1.4.2 | Nodehm2FLMTables | |||
| 1.3.6.1.4.1.248.11.79.1.4.2.1 | Tablehm2FLMInterfaceTable | not-accessible | current | The list of interfaces selected for Firewall Learning Mode. |
| 1.3.6.1.4.1.248.11.79.1.4.2.1.1 | Rowhm2FLMInterfaceEntry | not-accessible | current | Interface selected for Firewall Learning Mode. |
| 1.3.6.1.4.1.248.11.79.1.4.2.1.1.1 | Columnhm2FLMInterfaceIndex | read-write | current | Interface index of the entry. |
| 1.3.6.1.4.1.248.11.79.1.4.2.1.1.2 | Columnhm2FLMInterfaceRowStatus | read-create | current | This is a standard row status value: - active(1): The interface is active. - notInService(2): The interface is inactive because routing was disabled. - notRead… |
| 1.3.6.1.4.1.248.11.79.1.5 | Nodehm2FwIdsGroup | |||
| 1.3.6.1.4.1.248.11.79.1.5.1 | Nodehm2IDSObjects | |||
| 1.3.6.1.4.1.248.11.79.1.5.1.1 | Scalarhm2IDSUserName | read-write | current | IDS Agent user name is an administrator privilege user from the user database . |
| 1.3.6.1.4.1.248.11.79.1.5.1.2 | Scalarhm2IDSIsRunning | read-only | current | This value describes whether the IDS feature is running or not |
| 1.3.6.1.4.1.248.11.79.1.5.1.3 | Scalarhm2IDSAdminState | read-write | current | Enable/Disable This value describes, whether the operator has enabled IDS feature on the device or not |
| 1.3.6.1.4.1.248.11.79.1.6 | Nodehm2L2FwGroup | |||
| 1.3.6.1.4.1.248.11.79.1.6.1 | Nodehm2L2FwGeneralSettings | |||
| 1.3.6.1.4.1.248.11.79.1.6.1.1 | Scalarhm2L2MaxRules | read-only | current | Maximum number of allowed rules for L2 filtering. |
| 1.3.6.1.4.1.248.11.79.1.6.1.2 | Scalarhm2L2DefaultPolicy | read-write | current | The default policy for forwarding packets: o accept(1): Packets matching this rule are accepted and will be forwarded o drop(2): Packets matching this rule wil… |
| 1.3.6.1.4.1.248.11.79.1.6.1.3 | Scalarhm2L2ValidateFCS | read-write | current | Activate/Deactivate the validation of FCS. |
| 1.3.6.1.4.1.248.11.79.1.6.2 | Nodehm2L2RuleObjects | |||
| 1.3.6.1.4.1.248.11.79.1.6.2.1 | Scalarhm2L2RuleCount | read-only | current | Number of current L2 rules |
| 1.3.6.1.4.1.248.11.79.1.6.2.2 | Scalarhm2L2IfMappingRuleCount | read-only | current | Number of current L2 IF mapping entries. |
| 1.3.6.1.4.1.248.11.79.1.6.2.3 | Scalarhm2L2RulePendingActions | read-only | current | This value describes, whether the L2 rule table was modified but not yet written to the firewall implementation (set to true). After writing all modifications … |
| 1.3.6.1.4.1.248.11.79.1.6.2.4 | Scalarhm2L2CommitPendingActions | read-write | current | Setting this value to action(2) writes not yet committed changes to the firewall (L2 and Interface Mapping Table). After writing all modifications, the value s… |
| 1.3.6.1.4.1.248.11.79.1.6.3 | Nodehm2L2RuleTables | |||
| 1.3.6.1.4.1.248.11.79.1.6.3.1 | Tablehm2L2RuleTable | not-accessible | current | A table of layer 2 Filter rule instances. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1 | Rowhm2L2RuleEntry | not-accessible | current | A table of layer 2 Filter classification rules. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.1 | Columnhm2L2RuleIndex | not-accessible | current | The index of this rule instance within an Filter. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.2 | Columnhm2L2RuleHitCount | read-only | current | Number of packets that matched the L2 rule. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.3 | Columnhm2L2RuleAction | read-create | current | The action of the corresponding rule: o accept(1): Packets matching this rule are accepted and will be forwarded o drop(2): Packets matching this rule will be … |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.4 | Columnhm2L2RuleDestMacAddr | read-create | current | The destination MAC address used in the Filter classification or Asset name from hm2AssetTable. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.5 | Columnhm2L2RuleSrcMacAddr | read-create | current | The source MAC address used in the Filter classification or Asset name from hm2AssetTable. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.6 | Columnhm2L2RuleEtypeKey | read-create | current | The Ethertype keyword used in the Filter classification. A keyword of custom(1) requires that the hm2L2RuleEtypeValue object also be set. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.7 | Columnhm2L2RuleEtypeValue | read-create | current | The Ethertype custom value used in the Filter classification. This object is only valid if the hm2L2RuleEtypeKey is set to custom(1). Values ranging from 0x060… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.8 | Columnhm2L2RuleVlanId | read-create | current | The VLAN ID value used in the Filter classification. The VLAN ID field is defined as the 12-bit VLAN identifier in the 802.1Q tag header of a tagged Ethernet f… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.9 | Columnhm2L2RuleSrcIpAddr | read-create | current | The source IP address in cidr or Asset name from hm2AssetTable. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.10 | Columnhm2L2RuleDestIpAddr | read-create | current | The Destination IP address in cidr or Asset name from hm2AssetTable. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.11 | Columnhm2L2RuleProtocol | read-create | current | The IP protocol (RFC 791) for protocol-independent filtering. The following values are currently supported: o icmp(1): internet control message protocol (RFC 7… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.12 | Columnhm2L2RuleIpTosBits | read-create | current | The type of service (TOS) bits value. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.13 | Columnhm2L2RuleSrcPort | read-create | current | The Source port number |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.14 | Columnhm2L2RuleDestPort | read-create | current | The Destination port number |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.15 | Columnhm2L2RuleAssignQueueId | read-create | current | Queue identifier to which all inbound packets matching L2 packet filter rule. This object defaults to the standard queue assignment for user priority 0 traffic… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.16 | Columnhm2L2RuleRateLimitCrate | read-create | current | Committed rate attribute statement value, specified in kbps. Value 0 disables this match criteria. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.17 | Columnhm2L2RuleRateLimitCburst | read-create | current | Committed burst size attribute statement value, specified in kbytes. Value 0 disables this match criteria. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.18 | Columnhm2L2RuleRateLimitCrateUnit | read-create | current | The unit of the L2RuleRateLimitCrate. Can be either packets per second (pps) or kilobits per second (kbps). |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.19 | Columnhm2L2FwTrap | read-create | current | Set to true if application of this rule shall send a trap. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.20 | Columnhm2L2RuleDescription | read-create | current | User defined textual description related to this rule. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.21 | Columnhm2L2RuleLog | read-create | current | Set to true if application of this rule shall be logged |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.22 | Columnhm2L2RuleStatsAction | read-create | current | Setting the object to 'flushRuleHitCount(2)' will reset hit counter statistics. Reading the object always returns 'other'. |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.23 | Columnhm2L2RowStatus | read-create | current | This is a standard row status value - active(1): The rule is active. Note that until committed, the rule will not be applied. You cannot activate the rule if a… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.24 | Columnhm2L2DPIProfileIndex | read-create | current | The index of the DPI profile, to which this rule is assigned, depending on enforcer action. Value 0 : This rule is not assigned to any DPI Profile. You cannot … |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.25 | Columnhm2L2RuleProtoName | read-create | current | Following values are supported: - Protocol name from hm2ProtocolTable - icmp: internet control message protocol (RFC 792) - igmp: internet group management pro… |
| 1.3.6.1.4.1.248.11.79.1.6.3.1.1.26 | Columnhm2L2AppRuleName | read-create | current | Application rule name from hm2AppRuleTable |
| 1.3.6.1.4.1.248.11.79.1.6.3.2 | Tablehm2L2RuleIfMappingTable | not-accessible | current | Table for mapping L2 rules to interfaces |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1 | Rowhm2L2RuleIfMappingEntry | not-accessible | current | Entry in rule interface mapping table |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.1 | Columnhm2L2IfmType | not-accessible | current | Meanings: - port(1): Apply this rule to packets arriving on non-routing physical interface. - vlan(2): Apply this rule to packets arriving on non-routing vlan … |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.2 | Columnhm2L2IfmInterface | not-accessible | current | The interface this mapping entry is assigned to. This has to be either an hm2AgentSwitchIpInterfaceIfIndex or an hm2AgentSwitchIpVlanIfIndex. Note : Routing sh… |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.3 | Columnhm2L2IfmDirection | not-accessible | current | Meanings: - ingress(1): Apply this rule to packets arriving on this interface - egress(2): Apply this rule to packets leaving from this interface |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.4 | Columnhm2L2IfmRuleIndex | not-accessible | current | The index of the L2 rule this mapping entry is assigned to. The rule must exist before the mapping entry can be created. |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.5 | Columnhm2L2IfmPriority | read-create | current | The priority is the sorting key for rules in to this interface. They don't need to be unique, but no clear order can be assumed among rules with the same prior… |
| 1.3.6.1.4.1.248.11.79.1.6.3.2.1.6 | Columnhm2L2IfmRowStatus | read-create | current | The RowStatus value for this entry with the usual meanings: - active(1): The interface mapping is in place - notInService(2): The interface mapping is not in p… |
| 1.3.6.1.4.1.248.11.79.1.7 | Nodehm2FwAssetMgmtGroup | |||
| 1.3.6.1.4.1.248.11.79.1.7.1 | Tablehm2AssetTable | not-accessible | current | A list of the Assets representing real world devices/systems |
| 1.3.6.1.4.1.248.11.79.1.7.1.1 | Rowhm2AssetEntry | not-accessible | current | Asset Entries |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.1 | Columnhm2AssetIndex | accessible-for-notify | current | Index number of this Asset table |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.2 | Columnhm2AssetName | read-create | current | Descriptive name for the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.3 | Columnhm2AssetDescription | read-create | current | Logical description of the function of Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.4 | Columnhm2AssetType | read-create | current | Specifies type of the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.5 | Columnhm2AssetManufacturer | read-create | current | Make or company that manufacturerd the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.6 | Columnhm2AssetModel | read-create | current | Model version of the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.7 | Columnhm2AssetGeneralLocation | read-create | current | General location of the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.8 | Columnhm2AssetSpecificLocation | read-create | current | Specific location of the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.9 | Columnhm2AssetTag | read-create | current | User defined field for corporate asset tags |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.10 | Columnhm2AssetIpAddress | read-create | current | The IP address associated to the Asset, allowed formats are: - keyword 'any' - single address ('10.0.0.1') - CIDR address range ('10.0.0.0/8') - a prepending '… |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.11 | Columnhm2AssetMacAddress | read-create | current | Physical address associated with the Asset |
| 1.3.6.1.4.1.248.11.79.1.7.1.1.12 | Columnhm2AssetStatus | read-create | current | active(1) - This template is active. notInService(2) - Row has been suspended. notReady(3) - Row has incomplete values. createAndGo(4) - Accept row values and … |
| 1.3.6.1.4.1.248.11.79.1.7.2 | Tablehm2AppRuleTable | not-accessible | current | Application rules |
| 1.3.6.1.4.1.248.11.79.1.7.2.1 | Rowhm2AppRuleEntry | not-accessible | current | Application rule entry |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.1 | Columnhm2AppRuleIndex | not-accessible | current | Index number of the Application rule |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.2 | Columnhm2AppRuleName | read-create | current | Logical description of the Application rule |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.3 | Columnhm2AppRuleProtocol | read-create | current | Following values are supported: - Protocol name from hm2ProtocolTable - icmp: internet control message protocol (RFC 792) - igmp: internet group management pro… |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.4 | Columnhm2AppRulePort | read-create | current | The ports used by the selected protocol. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyphen ('… |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.5 | Columnhm2AppRuleDirection | read-create | current | - ingress(1): Apply this rule to packets arriving on this interface - egress(2): Apply this rule to packets leaving from this interface - both(3): Apply this r… |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.6 | Columnhm2AppRuleIsDefault | read-create | current | Set to true if this is a factory initialized rule |
| 1.3.6.1.4.1.248.11.79.1.7.2.1.7 | Columnhm2AppRuleStatus | read-create | current | This is a standard row status value: - active(1): The rule is active. Note that until committed, the rule will not be applied. You cannot activate the rule if … |
| 1.3.6.1.4.1.248.11.79.1.7.3 | Tablehm2ProtocolTable | not-accessible | current | A list of user defined Protocols for Packet Filter rules |
| 1.3.6.1.4.1.248.11.79.1.7.3.1 | Rowhm2ProtocolEntry | not-accessible | current | Protocol table entries |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.1 | Columnhm2ProtocolIndex | not-accessible | current | Index number of the Protocol entry |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.2 | Columnhm2ProtocolName | read-create | current | The descriptive name for this protocol |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.3 | Columnhm2ProtocolDescription | read-create | current | User defined textual description related to this protocol |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.4 | Columnhm2ProtocolType | read-create | current | Specify the type used in the protocol |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.5 | Columnhm2ProtocolEtypeKey | read-create | current | The Ethertype keyword to be used in the L2 filter. A keyword of custom(1) requires that the hm2ProtocolEtherType object also be set. |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.6 | Columnhm2ProtocolEtherType | read-create | current | The Ethertype custom value to be used in the L2 filter. This object is only valid if the hm2ProtocolEtypeKey is set to custom(1). Values ranging from 0x0600 to… |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.7 | Columnhm2ProtocolIPProtoNumber | read-create | current | IP Protocol number for user defined protocols - (-1) represents that no ip protocol is selected |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.8 | Columnhm2ProtocolPort | read-create | current | The ports used by this protocol. Allowed formats are: - keyword 'any' - single port ('10') - port range with first and last port separated by hyphen ('10-15') … |
| 1.3.6.1.4.1.248.11.79.1.7.3.1.9 | Columnhm2ProtocolStatus | read-create | current | active(1) - This template is active. notInService(2) - Row has been suspended. notReady(3) - Row has incomplete values. createAndGo(4) - Accept row values and … |
| 1.3.6.1.4.1.248.11.79.2 | Nodehm2FwConformance | |||
| 1.3.6.1.4.1.248.11.79.2.1 | Nodehm2FwCompliances | |||
| 1.3.6.1.4.1.248.11.79.2.1.1 | Compliancehm2FwCompliance | current | The compliance statement for an SNMP entity which implements the Hirschmann firewall MIB. | |
| 1.3.6.1.4.1.248.11.79.2.2 | Nodehm2FwGroups | |||
| 1.3.6.1.4.1.248.11.79.2.2.1 | Grouphm2FwGeneralGroup | current | A collection of all Hirschmann objects provided by the firewall module. | |
| 1.3.6.1.4.1.248.11.79.2.2.2 | Grouphm2FwNotificationsGroup | current | A collection of all Hirschmann notifications provided by the firewall module. | |
| 1.3.6.1.4.1.248.11.79.3 | Nodehm2FwSNMPExtensionGroup | |||
| 1.3.6.1.4.1.248.11.79.3.11 | Nodehm2FwSNMPExtensionDPISESGroup | |||
| 1.3.6.1.4.1.248.11.79.3.11.1 | Identityhm2FwSNMPExtensionDPIEntryInvalid | current | Indicates that the DPI profile contains the index value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.11.2 | Identityhm2FwSNMPExtensionDPIDescriptionInvalid | current | Indicates that the DPI profile contains the description which has invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.11.3 | Identityhm2FwSNMPExtensionDPISanityCheckInvalid | current | Indicates that the DPI profile contains an invalid value for sanity check that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.11.4 | Identityhm2FwSNMPExtensionDPITCPResetInvalid | current | Indicates that the DPI profile contains an invalid value for TCP reset that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.11.5 | Identityhm2FwSNMPExtensionDPIProfileInUse | current | Indicates that the DPI profile cannot be deleted or deactivated since it is currently used by atleast one L3 firewall rule. | |
| 1.3.6.1.4.1.248.11.79.3.11.6 | Identityhm2FwSNMPExtensionDPIProfileActive | current | Indicates that the DPI profile cannot be deleted since it is active. | |
| 1.3.6.1.4.1.248.11.79.3.11.7 | Identityhm2FwSNMPExtensionDPIProfileUpdateError | current | Indicates that the DPI profile cannot be modified since it is active. | |
| 1.3.6.1.4.1.248.11.79.3.11.8 | Identityhm2FwSNMPExtensionDPIFunctionCodeInvalid | current | Indicates that the DPI entry contains an invalid value for function code that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.11.9 | Identityhm2FwSNMPExtensionDPIProfileNotPresent | current | Indicates that the DPI profile does not exist. | |
| 1.3.6.1.4.1.248.11.79.3.11.10 | Identityhm2FwSNMPExtensionDPIProfileNotActive | current | Indicates that the DPI profile is not active. | |
| 1.3.6.1.4.1.248.11.79.3.12 | Nodehm2FwSNMPExtensionIEC104SESGroup | |||
| 1.3.6.1.4.1.248.11.79.3.12.1 | Identityhm2FwSNMPExtensionIEC104FunctionTypeInvalid | current | Indicates that the IEC104 entry contains an invalid value for function type that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.2 | Identityhm2FwSNMPExtensionIEC104CommonAddListInvalid | current | Indicates that the IEC104 entry contains an invalid value for common address list that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.3 | Identityhm2FwSNMPExtensionIEC104DebugInvalid | current | Indicates that the IEC104 entry contains an invalid value for debug that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.4 | Identityhm2FwSNMPExtensionIEC104AdvTypeIDListInvalid | current | Indicates that the IEC104 entry contains an invalid value for advance type ID list that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.5 | Identityhm2FwSNMPExtensionIEC104OriginAddListInvalid | current | Indicates that the IEC104 entry contains an invalid value for originator address list that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.6 | Identityhm2FwSNMPExtensionIEC104TransSizeInvalid | current | Indicates that the IEC104 entry contains an invalid value for cause of transmission size that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.7 | Identityhm2FwSNMPExtensionIEC104CommAddrSizeInvalid | current | Indicates that the IEC104 entry contains an invalid value for common address size that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.8 | Identityhm2FwSNMPExtensionIEC104IOAddrSizeInvalid | current | Indicates that the IEC104 entry contains an invalid value for IO address size that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.12.9 | Identityhm2FwSNMPExtensionIEC104AllowIEC101Invalid | current | Indicates that the IEC104 entry contains an invalid value for allow IEC_60870_5_101 that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13 | Nodehm2FwSNMPExtensionDNP3Group | |||
| 1.3.6.1.4.1.248.11.79.3.13.1 | Identityhm2FwSNMPExtensionDNP3CRCInvalid | current | Indicates that the DNP3 entry contains an invalid value for CRC check that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.2 | Identityhm2FwSNMPExtensionDNP3DefWhiteListInvalid | current | Indicates that the DNP3 entry contains an invalid value for default object list that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.3 | Identityhm2FwSNMPExtensionDNP3FunctionCodeListInvalid | current | Indicates that the DNP3 entry contains an invalid value for function code list that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.4 | Identityhm2FwSNMPExtensionDNP3OutTrafficInvalid | current | Indicates that the DNP3 entry contains an invalid value for outstation traffic check that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.5 | Identityhm2FwSNMPExtensionDNP3GroupNumInvalid | current | Indicates that the DNP3 entry contains an invalid value for group number that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.6 | Identityhm2FwSNMPExtensionDNP3FunctionLengthInvalid | current | Indicates that the DNP3 entry contains an invalid value for function length that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.7 | Identityhm2FwSNMPExtensionDNP3FunctionNameInvalid | current | Indicates that the DNP3 entry contains an invalid value for function name that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.8 | Identityhm2FwSNMPExtensionDNP3ObjectCreateError | current | Indicates that the DNP3 object list cannot be created. | |
| 1.3.6.1.4.1.248.11.79.3.13.9 | Identityhm2FwSNMPExtensionDNP3ObjectIndexInvalid | current | Indicates that the DNP3 object index contains invalid characters or is out of range. | |
| 1.3.6.1.4.1.248.11.79.3.13.10 | Identityhm2FwSNMPExtensionDNP3ObjectProfileActive | current | Indicates that the DNP3 object list cannot be modified since the DNP3 profile corresponding to it is active. | |
| 1.3.6.1.4.1.248.11.79.3.13.11 | Identityhm2FwSNMPExtensionDNP3ObjectProfileNotExist | current | Indicates that the DNP3 object list cannot be modified since the DNP3 profile does not exist. | |
| 1.3.6.1.4.1.248.11.79.3.13.12 | Identityhm2FwSNMPExtensionDNP3ObjectTypeInvalid | current | Indicates that the object type contains an invalid value that cannot be be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.13 | Identityhm2FwSNMPExtensionDNP3QualifierCodeInvalid | current | Indicates that the qualifier code contains an invalid value that cannot be be processed. | |
| 1.3.6.1.4.1.248.11.79.3.13.14 | Identityhm2FwSNMPExtensionDNP3VariationNumInvalid | current | Indicates that the variation number contains an invalid value that cannot be be processed. | |
| 1.3.6.1.4.1.248.11.79.3.14 | Nodehm2FwSNMPExtensionOPCGroup | |||
| 1.3.6.1.4.1.248.11.79.3.14.1 | Identityhm2FwSNMPExtensionOPCFragmentCheckInvalid | current | Indicates that the OPC entry contains an invalid value for fragment check that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.14.2 | Identityhm2FwSNMPExtensionOPCTimeoutInvalid | current | Indicates that the OPC entry contains an invalid value for OPC data connection timeout that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.15 | Nodehm2FwSNMPExtensionModbusGroup | |||
| 1.3.6.1.4.1.248.11.79.3.15.1 | Identityhm2FwSNMPExtensionModbusExceptionInvalid | current | Indicates that the modbus entry contains an invalid value for exception response that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.15.2 | Identityhm2FwSNMPExtensionModbusUnitIdentifierInvalid | current | Indicates that the modbus entry contains an invalid value for unit identifier that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.15.3 | Identityhm2FwSNMPExtensionModbusStatefullCheckInvalid | current | Indicates that the modbus entry contains an invalid value for statefull check that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17 | Nodehm2FwSNMPExtensionAMPGroup | |||
| 1.3.6.1.4.1.248.11.79.3.17.1 | Identityhm2FwSNMPExtensionAMPMessageTypeInvalid | current | Indicates that the message type contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.2 | Identityhm2FwSNMPExtensionAMPAddressClassInvalid | current | Indicates that the address class contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.3 | Identityhm2FwSNMPExtensionAMPDeviceClassInvalid | current | Indicates that the device class contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.4 | Identityhm2FwSNMPExtensionAMPMemoryAddressInvalid | current | Indicates that the memory address contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.5 | Identityhm2FwSNMPExtensionAMPDataWordInvalid | current | Indicates that the data word contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.6 | Identityhm2FwSNMPExtensionAMPTaskCodeInvalid | current | Indicates that the task code contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.7 | Identityhm2FwSNMPExtensionAMPTaskCodeDataInvalid | current | Indicates that the task code data contains invalid characters or has a wrong length. | |
| 1.3.6.1.4.1.248.11.79.3.17.8 | Identityhm2FwSNMPExtensionAMPProtocolInvalid | current | Indicates that the protocol contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.9 | Identityhm2FwSNMPExtensionAMPECCInvalid | current | Indicates that the error check characters contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.10 | Identityhm2FwSNMPExtensionAMPBCCInvalid | current | Indicates that the block check characters contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.11 | Identityhm2FwSNMPExtensionAMPDebugInvalid | current | Indicates that the debug contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.12 | Identityhm2FwSNMPExtensionAMPDigitalInputInvalid | current | Indicates that the digital input contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.13 | Identityhm2FwSNMPExtensionAMPProtectModeInvalid | current | Indicates that the protect mode contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.14 | Identityhm2FwSNMPExtensionAMPTaskCodeModeInvalid | current | Indicates that the task code mode contains an invalid value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.17.15 | Identityhm2FwSNMPExtensionAMPAddressClassRangeInvalid | current | Indicates that the address class is exceeding the maximum permissable range i.e. 0000-FFFF. | |
| 1.3.6.1.4.1.248.11.79.3.17.16 | Identityhm2FwSNMPExtensionAMPDeviceClassRangeInvalid | current | Indicates that the device class is exceeding the maximum permissable range i.e. 0000-FFFF. | |
| 1.3.6.1.4.1.248.11.79.3.17.17 | Identityhm2FwSNMPExtensionAMPMemoryAddressRangeInvalid | current | Indicates that the memory address is exceeding the maximum permissable range i.e. 0000-FFFF. | |
| 1.3.6.1.4.1.248.11.79.3.17.18 | Identityhm2FwSNMPExtensionAMPDataWordRangeInvalid | current | Indicates that the data word is exceeding the maximum permissable range i.e. 0000-FFFF. | |
| 1.3.6.1.4.1.248.11.79.3.17.19 | Identityhm2FwSNMPExtensionAMPTaskCodeRangeInvalid | current | Indicates that the task code is exceeding the maximum permissable range i.e. 00-FF. | |
| 1.3.6.1.4.1.248.11.79.3.17.20 | Identityhm2FwSNMPExtensionAMPTaskCodeDataRangeInvalid | current | Indicates that the task code data is exceeding the maximum permissable length i.e. 72 bytes. | |
| 1.3.6.1.4.1.248.11.79.3.17.21 | Identityhm2FwSNMPExtensionAMPProtocolNITPMessageTypeInvalid | current | Indicates that the message type is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.22 | Identityhm2FwSNMPExtensionAMPProtocolNITPAddressClassInvalid | current | Indicates that the address class is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.23 | Identityhm2FwSNMPExtensionAMPProtocolNITPDeviceClassInvalid | current | Indicates that the device class is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.24 | Identityhm2FwSNMPExtensionAMPProtocolNITPMemoryAddressInvalid | current | Indicates that the memory address is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.25 | Identityhm2FwSNMPExtensionAMPProtocolNITPDataWordInvalid | current | Indicates that the data word is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.26 | Identityhm2FwSNMPExtensionAMPProtocolNITPBCCInvalid | current | Indicates that the block check characters is not available when the protocol is NITP. | |
| 1.3.6.1.4.1.248.11.79.3.17.27 | Identityhm2FwSNMPExtensionAMPProtocolCAMPAddressClassInvalid | current | Indicates that the address class is not available if the protocol is CAMP and the message type includes hexadecimal values 02 and/or 03. | |
| 1.3.6.1.4.1.248.11.79.3.17.28 | Identityhm2FwSNMPExtensionAMPProtocolCAMPDataWordInvalid | current | Indicates that the data word is not available if the protocol is CAMP and the message type includes hexadecimal values between 02..07. | |
| 1.3.6.1.4.1.248.11.79.3.17.29 | Identityhm2FwSNMPExtensionAMPProtocolCAMPDeviceClassInvalid | current | Indicates that the device class is not available if the protocol is CAMP and the message type includes hexadecimal values between 04..09. | |
| 1.3.6.1.4.1.248.11.79.3.17.30 | Identityhm2FwSNMPExtensionAMPProtocolCAMPMemoryAddressInvalid | current | Indicates that the memory address is not available if the protocol is CAMP and the message type includes hexadecimal values between 04..09. | |
| 1.3.6.1.4.1.248.11.79.3.17.31 | Identityhm2FwSNMPExtensionAMPProtocolCAMPTaskCodeInvalid | current | Indicates that the task code is not available if the protocol is CAMP and the message type includes hexadecimal values between 04..09. | |
| 1.3.6.1.4.1.248.11.79.3.17.32 | Identityhm2FwSNMPExtensionAMPProtocolCAMPTaskCodeDataInvalid | current | Indicates that the task code data is not available if the protocol is CAMP and the message type includes hexadecimal values between 04..09. | |
| 1.3.6.1.4.1.248.11.79.3.17.33 | Identityhm2FwSNMPExtensionAMPProtocolCAMPECCInvalid | current | Indicates that the error check characters is not available if the protocol is CAMP and the message type includes hexadecimal values between 04..09. | |
| 1.3.6.1.4.1.248.11.79.3.17.34 | Identityhm2FwSNMPExtensionAMPProtectModeDigitalInputInvalid | current | Indicates that protect mode is not available if the digital input is enabled. | |
| 1.3.6.1.4.1.248.11.79.3.17.35 | Identityhm2FwSNMPExtensionAMPMessageTypeInputInvalid | current | Indicates that the message type contains an invalid value that cannot be processed. Allowed message types are 02,03,04,05,06,07,08,09,FF. | |
| 1.3.6.1.4.1.248.11.79.3.17.36 | Identityhm2FwSNMPExtensionAMPMessageTypeBothTogetherInvalid | current | Indicates that the message type can have either the value 'Packed Task Code Message' or the value 'Memory Transfer Command'. Both together are not allowed. | |
| 1.3.6.1.4.1.248.11.79.3.17.37 | Identityhm2FwSNMPExtensionAMPTaskCodeDataMultipleInvalid | current | Indicates that the task code data is only available if a single task code is configured in the AMP profile. | |
| 1.3.6.1.4.1.248.11.79.3.17.38 | Identityhm2FwSNMPExtensionAMPTaskCodeConfigureInvalid | current | Indicates that the AMP profile cannot be configured for the AMP profile. Task code is not present in the task code table. | |
| 1.3.6.1.4.1.248.11.79.3.17.39 | Identityhm2FwSNMPExtensionAMPProfileDeleteInvalid | current | Indicates that the profile cannot be deleted or deactivated if the profile is associated with at least one L2 firewall rule. | |
| 1.3.6.1.4.1.248.11.79.3.17.40 | Identityhm2FwSNMPExtensionAMPProfileEnableInvalid | current | Indicates that the profile cannot be activated if not all required parameters are set. | |
| 1.3.6.1.4.1.248.11.79.3.17.41 | Identityhm2FwSNMPExtensionAMPTaskCodeTableInvalid | current | Indicates that the task code cannot be deleted or modified if it is associated with an AMP profile. | |
| 1.3.6.1.4.1.248.11.79.3.17.42 | Identityhm2FwSNMPExtensionAMPDefaultTaskCode | current | Indicates that the default task codes connot be deleted or modified. | |
| 1.3.6.1.4.1.248.11.79.3.17.43 | Identityhm2FwSNMPExtensionAMPMessageTypeTogetherInvalid | current | Indicates that the message type can have either the value 'Memory Exchange Command' or the value 'Memory Exchange Message'. Both together are not allowed. | |
| 1.3.6.1.4.1.248.11.79.3.18 | Nodehm2FwSNMPExtensionENIPGroup | |||
| 1.3.6.1.4.1.248.11.79.3.18.1 | Identityhm2FwSNMPExtensionENIPAllowPCCCInvalid | current | Indicates that the Allow embedded PCCC field contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.18.2 | Identityhm2FwSNMPExtensionENIPDefObjectListInvalid | current | Indicates that the default object list contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.18.3 | Identityhm2FwSNMPExtensionENIPDescriptionInvalid | current | Indicates that description for object contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.18.4 | Identityhm2FwSNMPExtensionENIPFunctionTypeError | current | Indicates that function type is 'any' thus the wildcard service code list and default object list cannot be added or modified. | |
| 1.3.6.1.4.1.248.11.79.3.18.5 | Identityhm2FwSNMPExtensionENIPObjectClassIdInvalid | current | Indicates that the class ID contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.18.6 | Identityhm2FwSNMPExtensionENIPObjectCreateError | current | Indicates that the object cannot be created due to general error. | |
| 1.3.6.1.4.1.248.11.79.3.18.7 | Identityhm2FwSNMPExtensionENIPObjectFunctionTypeInvalid | current | Indicates that the object cannot be created since the function type is 'any'. | |
| 1.3.6.1.4.1.248.11.79.3.18.8 | Identityhm2FwSNMPExtensionENIPObjectCreateProfileActiveError | current | Indicates that the object cannot be created when the profile is active. | |
| 1.3.6.1.4.1.248.11.79.3.18.9 | Identityhm2FwSNMPExtensionENIPObjectCreateProfileNotExistError | current | Indicates that the object cannot be created when the profile does not exist. | |
| 1.3.6.1.4.1.248.11.79.3.18.10 | Identityhm2FwSNMPExtensionENIPObjectModifyProfileActiveError | current | Indicates that the object cannot be modified when the profile is active. | |
| 1.3.6.1.4.1.248.11.79.3.18.11 | Identityhm2FwSNMPExtensionENIPObjectModifyProfileNotExistError | current | Indicates that the object cannot be modified when the profile does not exist. | |
| 1.3.6.1.4.1.248.11.79.3.18.12 | Identityhm2FwSNMPExtensionENIPObjectServiceCodeInvalid | current | Indicates that the service code list contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.18.13 | Identityhm2FwSNMPExtensionENIPProfileActive | current | Indicates that the default object list or wildcard service code list cannot be modified when the profile is active. | |
| 1.3.6.1.4.1.248.11.79.3.18.14 | Identityhm2FwSNMPExtensionENIPProfileNotExist | current | Indicates that the default object list or wildcard service code list cannot be modified since the profile does not exist. | |
| 1.3.6.1.4.1.248.11.79.3.18.15 | Identityhm2FwSNMPExtensionENIPWildcardServiceListInvalid | current | Indicates that the Wild card service list contains a value which is out of range or contains invalid characters. | |
| 1.3.6.1.4.1.248.11.79.3.20 | Nodehm2FwSNMPExtensionIPGroup | |||
| 1.3.6.1.4.1.248.11.79.3.20.1 | Identityhm2FwSNMPExtensionIPQueueIDInvalid | current | Indicates that the packet filter rule entry contains an invalid value for assigned queue ID that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.2 | Identityhm2FwSNMPExtensionIPBurstSizeInvalid | current | Indicates that the packet filter rule entry contains an invalid value for burst size that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.3 | Identityhm2FwSNMPExtensionIPDirectionInvalid | current | Indicates that the packet filter assignment entry contains an invalid value for direction that cannot be processed. It can only be ingress or egress. | |
| 1.3.6.1.4.1.248.11.79.3.20.4 | Identityhm2FwSNMPExtensionIPEthertypeInvalid | current | Indicates that the packet filter rule entry contains an invalid value for ethertype that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.5 | Identityhm2FwSNMPExtensionIPEthertypeValueInvalid | current | Indicates that the packet filter rule entry contains an invalid value for ethertype custom value that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.6 | Identityhm2FwSNMPExtensionIPLogInvalid | current | Indicates that the packet filter rule entry contains an invalid value for log that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.7 | Identityhm2FwSNMPExtensionIPParameterInvalid | current | Indicates that the packet filter rule entry contains an invalid value for parameters that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.8 | Identityhm2FwSNMPExtensionIPPriorityInvalid | current | Indicates that the packet filter assignment entry contains an invalid value for priority that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.9 | Identityhm2FwSNMPExtensionIPProfileIndexInvalid | current | Indicates that the packet filter rule entry contains an invalid value for dpi profile index that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.10 | Identityhm2FwSNMPExtensionIPRateLimitInvalid | current | Indicates that the packet filter rule entry contains an invalid value for rate limit that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.11 | Identityhm2FwSNMPExtensionIPRuleInUse | current | Indicates that the rule cannot be deleted as it is associated with interface. | |
| 1.3.6.1.4.1.248.11.79.3.20.12 | Identityhm2FwSNMPExtensionIPTOSPriorityInvalid | current | Indicates that the packet filter rule entry contains an invalid value for TOS priority that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.13 | Identityhm2FwSNMPExtensionIPProtocolInvalid | current | Indicates that the assigned protocol for an entry is invalid. | |
| 1.3.6.1.4.1.248.11.79.3.20.14 | Identityhm2FwSNMPExtensionIPTrapInvalid | current | Indicates that the packet filter rule entry contains an invalid value for trap that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.20.15 | Identityhm2FwSNMPExtensionIPUnitInvalid | current | Indicates that the packet filter rule entry contains an invalid value for unit that cannot be processed. It can only has value 'pps' or 'kbps'. | |
| 1.3.6.1.4.1.248.11.79.3.20.16 | Identityhm2FwSNMPExtensionIPUnsupportedDPIL4Protocol | current | Indicates that the packet filter rule {0} specifies {1} DPI with an unsupported L4 protocol. Only {2} is allowed. | |
| 1.3.6.1.4.1.248.11.79.3.20.17 | Identityhm2FwSNMPExtensionIPActionInvalid | current | Indicates that the assigned action for an entry is invalid. | |
| 1.3.6.1.4.1.248.11.79.3.20.18 | Identityhm2FwSNMPExtensionIPEntryActiveErrorReturn | current | Indicates that the radius authentication server entry cannot be activated as an active entry with same IP address and same UDP port already exists. | |
| 1.3.6.1.4.1.248.11.79.3.20.19 | Identityhm2FwSNMPExtensionIPDestPortAny | current | Indicates that the destination port 'any' is invalid for the selected action in the packet filter rule. | |
| 1.3.6.1.4.1.248.11.79.3.20.20 | Identityhm2FwSNMPExtensionIPPortProtoInvalid | current | Indicates that the source port and destination port can be assigned values between 1 to 65535 only when protocol is tcp or udp. | |
| 1.3.6.1.4.1.248.11.79.3.20.21 | Identityhm2FwSNMPExtensionIPAppRuleNameInvalid | current | Indicates that the packet filter entry contains an invalid value for application rule name that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21 | Nodehm2FwTemplateSNMPExtensionGroup | |||
| 1.3.6.1.4.1.248.11.79.3.21.1 | Identityhm2FwTemplateSNMPExtAssetTagInvalid | current | Indicates that the asset entry conatins an invalid value for asset tag that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21.2 | Identityhm2FwTemplateSNMPExtCannotDeleteDefaultRule | current | Indicates that the application rule cannot be deleted as it is designated as 'default'. | |
| 1.3.6.1.4.1.248.11.79.3.21.3 | Identityhm2FwTemplateSNMPExtGenLocInvalid | current | Indicates that the asset entry contains an invalid value for general location that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21.4 | Identityhm2FwTemplateSNMPExtIPProtoNumberInvalid | current | Indicates that the protocol entry contains IP protocol number value which is out of range. Permissable range is -1..255. | |
| 1.3.6.1.4.1.248.11.79.3.21.5 | Identityhm2FwTemplateSNMPExtManufacturerInvalid | current | Indicates that the asset entry contains an invalid value for manufacturer that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21.6 | Identityhm2FwTemplateSNMPExtModelInvalid | current | Indicates that the asset entry contains an invalid value for model that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21.7 | Identityhm2FwTemplateSNMPExtSpecLocInvalid | current | Indicates that the asset entry contains an invalid value for specific location that cannot be processed. | |
| 1.3.6.1.4.1.248.11.79.3.21.8 | Identityhm2FwTemplateSNMPExtDeleteInvalid | current | Indicates that the entry cannot be deleted or modified beacuse it is associated with at least one application rule or L2/L3 firewall rule. |
Type Definitions
| Name | Syntax | Status | Description |
|---|---|---|---|
| EnipClassId | Unsigned32 | current | Class ID value of an ENIP Class Object. The allowed value is 0x00 to 0xFFFFFFFF. |