CISCO-IP-PROTOCOL-FILTER-MIB
The MIB module is for management of information
to support packet filtering on IP protocols.
The cippfIpProfileTable allows users to create
delete, and get information about filter profiles.
Filter profiles are uniquely identified by the
profile names. Filter profiles can either be of
Simple or Extended usage types, and the usage type
cannot be changed once it has been created.
The cippfIfIpProfileTable applies the filtering
profiles to device interfaces running IP. A filter
profile can be applied to multiple interfaces.
The cippfIpFilterTable contains ordered lists of
IP filters for all the filtering profiles.
Filters and profiles are related if they are of
the same filter profile name. Filters can only
be created if their associated filter profiles
already exist in the cippfIpProfileTable.
Filters of the same profile name belongs to a
common profile.
The cippfIfIpProfileTable can be configured with
information independent from the other. However,
if the name of a profile in the cippfIfIpProfileTable
matches that of any profile in the
cippfIpProfileTable and the profile name of any
filter entry in the cippfIpFilterTable, the profile
is 'active' and the filter entry is being applied
to IP traffic passing through the attached device
interfaces. Therefore, any change to the filters
in the cippfIpFilterTable or the profile itself in
the cippfIpProfileTable will affect all the
attached interfaces.
- Source file
CISCO-IP-PROTOCOL-FILTER-MIB- Last revised
- Identity
ciscoIpProtocolMIB- Base OID
1.3.6.1.4.1.9.9.278
Imported Objects
| CISCO-FILTER-GROUP-MIB | CfgFilterGroupName |
| CISCO-SMI | ciscoMgmt |
| CISCO-SYSLOG-MIB | SyslogSeverity |
| IF-MIB | ifIndex |
| INET-ADDRESS-MIB | InetAddress InetAddressType InetPortNumber |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter64 Integer32 MODULE-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | RowStatus TEXTUAL-CONVENTION (no object page) TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IP-PROTOCOL-FILTER-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IP-PROTOCOL-FILTER-MIB::ciscoIpProtocolMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IP-PROTOCOL-FILTER-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IP-PROTOCOL-FILTER-MIB::ciscoIpProtocolMIB'
Objects (56)
Showing 56 of 56 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.278 |
||
.1.3.6.1.4.1.9.9.278.0 |
||
.1.3.6.1.4.1.9.9.278.1 |
||
.1.3.6.1.4.1.9.9.278.1.1 |
||
.1.3.6.1.4.1.9.9.278.1.1.1 |
||
.1.3.6.1.4.1.9.9.278.1.1.1.1 |
||
.1.3.6.1.4.1.9.9.278.1.1.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.278.1.1.1.1.2 |
|
|
Unsigned32
|
.1.3.6.1.4.1.9.9.278.1.1.1.1.3 |
|
.1.3.6.1.4.1.9.9.278.1.1.1.1.4 |
||
.1.3.6.1.4.1.9.9.278.1.1.2 |
||
.1.3.6.1.4.1.9.9.278.1.1.2.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.278.1.1.2.1.1 |
|
.1.3.6.1.4.1.9.9.278.1.1.2.1.2 |
||
.1.3.6.1.4.1.9.9.278.1.1.2.1.3 |
||
.1.3.6.1.4.1.9.9.278.1.1.3 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.1 |
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.10 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.11 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.12 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.13 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.14 |
|
|
|
Integer32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.15 |
.1.3.6.1.4.1.9.9.278.1.1.3.1.16 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.17 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.18 |
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.19 |
||
|
Unsigned32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.2 |
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.20 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.21 |
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.22 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.23 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.24 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.25 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.26 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.27 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.3 |
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.4 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.5 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.6 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.7 |
||
.1.3.6.1.4.1.9.9.278.1.1.3.1.8 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.278.1.1.3.1.9 |
|
.1.3.6.1.4.1.9.9.278.1.1.4 |
||
.1.3.6.1.4.1.9.9.278.1.1.4.1 |
||
.1.3.6.1.4.1.9.9.278.1.1.4.1.1 |
||
.1.3.6.1.4.1.9.9.278.1.1.4.1.2 |
||
|
secondsSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.9.9.278.1.1.4.1.3 |
|
.1.3.6.1.4.1.9.9.278.1.2 |
||
.1.3.6.1.4.1.9.9.278.1.2.1 |
||
.1.3.6.1.4.1.9.9.278.1.2.1.1 |
||
.1.3.6.1.4.1.9.9.278.1.2.1.1.1 |
||
.1.3.6.1.4.1.9.9.278.2 |
||
.1.3.6.1.4.1.9.9.278.2.1 |
||
.1.3.6.1.4.1.9.9.278.2.2 |
Dependencies (12) 9 direct · 3 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- CISCO-TCcisco
- INET-ADDRESS-MIBrfc
- SNMPv2-CONFrfc
- SNMP-FRAMEWORK-MIBrfc
- CISCO-FILTER-GROUP-MIBcisco
- CISCO-SYSLOG-MIBcisco
- IANAifType-MIBrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- CISCO-IP-PROTOCOL-FILTER-MIBciscoselected
Type Definitions (1)
| OctetString |
range: 1..64 |
Conformance Groups (5)
Compliance Statements (3)
OID
.1.3.6.1.4.1.9.9.278.2.1.1The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.
OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
the Cisco IP Protocol Filter MIB.
OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
Required groups
| mandatory | ciscoIpProtocolFilteringGroup |
OID
.1.3.6.1.4.1.9.9.278.2.1.2The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.
OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterOrderPosition
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.
OBJECT cippfIpProfileType
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.
the Cisco IP Protocol Filter MIB.
OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
OBJECT cippfIpFilterOrderPosition
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.
OBJECT cippfIpProfileType
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.
Required groups
| mandatory | ciscoIpProtocolFilteringGroup | |
| optional | ciscoIpProtocolFilterGroup2 | Implementation of this group is optional. |
OID
.1.3.6.1.4.1.9.9.278.2.1.3The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.
the Cisco IP Protocol Filter MIB.
Required groups
| mandatory | ciscoIpProtocolFilteringGroup | |
| mandatory | ciscoIpProtocolFilterStatsGroup | |
| optional | ciscoIpProtocolFilterGroup2 | Implementation of this group is optional. |
| optional | ciscoIpProtocolFilterExtGroup |
Implementation of this group is mandatory for those systems where additional objects supported for each filter. |
| optional | ciscoIpProtocolFilterObjectGroup |
Implementation of this group is mandatory for those systems where filter groups are supported in IP filters. |
Object refinements
| Object | Access | Syntax | Description |
|---|---|---|---|
| cippfIpFilterAddressType |
ipv4(1)
|
An implementation is only required to support IPv4 addresses. |
|
| cippfIpFilterSrcAddress | An implementation is only required to support IPv4 addresses. |
||
| cippfIpFilterDestAddress | An implementation is only required to support IPv4 addresses. |
||
| cippfIpFilterOrderPosition | readonly | Write access is not required. | |
| cippfIpProfileType | readonly | Write access is not required. | |
| cippfIpFilterSrcIPGroupName | noaccess | This object is not required to be implemented if filter group is not supported. |
|
| cippfIpFilterDstIPGroupName | noaccess | This object is not required to be implemented if filter group is not supported. |
|
| cippfIpFilterSrcServiceGroupName | noaccess | This object is not required to be implemented if filter group is not supported. |
|
| cippfIpFilterDstServiceGroupName | noaccess | This object is not required to be implemented if filter group is not supported. |
|
| cippfIpFilterICMPGroupName | noaccess | This object is not required to be implemented if filter group is not supported. |