CISCO-IP-PROTOCOL-FILTER-MIB

        The MIB module is for management of information 
to support packet filtering on IP protocols.
        
The cippfIpProfileTable allows users to create
delete, and get information about filter profiles.
Filter profiles are uniquely identified by the 
profile names.  Filter profiles can either be of
Simple or Extended usage types, and the usage type
cannot be changed once it has been created. 
        
The cippfIfIpProfileTable applies the filtering
profiles to device interfaces running IP.  A filter
profile can be applied to multiple interfaces.
        
The cippfIpFilterTable contains ordered lists of
IP filters for all the filtering profiles.  
Filters and profiles are related if they are of 
the same filter profile name.  Filters can only 
be created if their associated filter profiles
already exist in the cippfIpProfileTable. 
Filters of the same profile name belongs to a 
common profile.  
        
The cippfIfIpProfileTable can be configured with
information independent from the other.  However, 
if the name of a profile in the cippfIfIpProfileTable
matches that of any profile in the 
cippfIpProfileTable and the profile name of any 
filter entry in the cippfIpFilterTable, the profile 
is 'active' and the filter entry is being applied 
to IP traffic passing through the attached device 
interfaces.  Therefore, any change to the filters 
in the cippfIpFilterTable or the profile itself in 
the cippfIpProfileTable will affect all the 
attached interfaces.
    
Source file
CISCO-IP-PROTOCOL-FILTER-MIB
Last revised
Identity
ciscoIpProtocolMIB
Base OID
1.3.6.1.4.1.9.9.278
Imported Objects
CISCO-FILTER-GROUP-MIB CfgFilterGroupName
CISCO-SMI ciscoMgmt
CISCO-SYSLOG-MIB SyslogSeverity
IF-MIB ifIndex
INET-ADDRESS-MIB InetAddress InetAddressType InetPortNumber
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter64 Integer32 MODULE-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowStatus TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IP-PROTOCOL-FILTER-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IP-PROTOCOL-FILTER-MIB::ciscoIpProtocolMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IP-PROTOCOL-FILTER-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IP-PROTOCOL-FILTER-MIB::ciscoIpProtocolMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (56)
.1.3.6.1.4.1.9.9.278
.1.3.6.1.4.1.9.9.278.0
.1.3.6.1.4.1.9.9.278.1
.1.3.6.1.4.1.9.9.278.1.1
.1.3.6.1.4.1.9.9.278.1.1.1
.1.3.6.1.4.1.9.9.278.1.1.1.1
.1.3.6.1.4.1.9.9.278.1.1.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.278.1.1.1.1.2
Unsigned32
.1.3.6.1.4.1.9.9.278.1.1.1.1.3
.1.3.6.1.4.1.9.9.278.1.1.1.1.4
.1.3.6.1.4.1.9.9.278.1.1.2
.1.3.6.1.4.1.9.9.278.1.1.2.1
Enumeration
.1.3.6.1.4.1.9.9.278.1.1.2.1.1
.1.3.6.1.4.1.9.9.278.1.1.2.1.2
.1.3.6.1.4.1.9.9.278.1.1.2.1.3
.1.3.6.1.4.1.9.9.278.1.1.3
.1.3.6.1.4.1.9.9.278.1.1.3.1
Unsigned32
.1.3.6.1.4.1.9.9.278.1.1.3.1.1
.1.3.6.1.4.1.9.9.278.1.1.3.1.10
.1.3.6.1.4.1.9.9.278.1.1.3.1.11
.1.3.6.1.4.1.9.9.278.1.1.3.1.12
.1.3.6.1.4.1.9.9.278.1.1.3.1.13
Enumeration
.1.3.6.1.4.1.9.9.278.1.1.3.1.14
Integer32
.1.3.6.1.4.1.9.9.278.1.1.3.1.15
.1.3.6.1.4.1.9.9.278.1.1.3.1.16
.1.3.6.1.4.1.9.9.278.1.1.3.1.17
Integer32
.1.3.6.1.4.1.9.9.278.1.1.3.1.18
.1.3.6.1.4.1.9.9.278.1.1.3.1.19
Unsigned32
.1.3.6.1.4.1.9.9.278.1.1.3.1.2
.1.3.6.1.4.1.9.9.278.1.1.3.1.20
Integer32
.1.3.6.1.4.1.9.9.278.1.1.3.1.21
.1.3.6.1.4.1.9.9.278.1.1.3.1.22
.1.3.6.1.4.1.9.9.278.1.1.3.1.23
.1.3.6.1.4.1.9.9.278.1.1.3.1.24
.1.3.6.1.4.1.9.9.278.1.1.3.1.25
.1.3.6.1.4.1.9.9.278.1.1.3.1.26
.1.3.6.1.4.1.9.9.278.1.1.3.1.27
Enumeration
.1.3.6.1.4.1.9.9.278.1.1.3.1.3
.1.3.6.1.4.1.9.9.278.1.1.3.1.4
.1.3.6.1.4.1.9.9.278.1.1.3.1.5
.1.3.6.1.4.1.9.9.278.1.1.3.1.6
.1.3.6.1.4.1.9.9.278.1.1.3.1.7
.1.3.6.1.4.1.9.9.278.1.1.3.1.8
Integer32
.1.3.6.1.4.1.9.9.278.1.1.3.1.9
.1.3.6.1.4.1.9.9.278.1.1.4
.1.3.6.1.4.1.9.9.278.1.1.4.1
.1.3.6.1.4.1.9.9.278.1.1.4.1.1
.1.3.6.1.4.1.9.9.278.1.1.4.1.2
.1.3.6.1.4.1.9.9.278.1.1.4.1.3
.1.3.6.1.4.1.9.9.278.1.2
.1.3.6.1.4.1.9.9.278.1.2.1
.1.3.6.1.4.1.9.9.278.1.2.1.1
.1.3.6.1.4.1.9.9.278.1.2.1.1.1
.1.3.6.1.4.1.9.9.278.2
.1.3.6.1.4.1.9.9.278.2.1
.1.3.6.1.4.1.9.9.278.2.2
Dependencies (12) 9 direct · 3 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (1)
OctetString range: 1..64
Compliance Statements (3)

OID .1.3.6.1.4.1.9.9.278.2.1.1
The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.

OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.

OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.

OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.
Required groups

OID .1.3.6.1.4.1.9.9.278.2.1.2
The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.

OBJECT cippfIpFilterAddressType
SYNTAX InetAddressType { ipv4(1) }
DESCRIPTION
An implementation is only required to
support IPv4 addresses.

OBJECT cippfIpFilterSrcAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.

OBJECT cippfIpFilterDestAddress
SYNTAX InetAddress (SIZE(4))
DESCRIPTION
An implementation is only required to
support IPv4 addresses.

OBJECT cippfIpFilterOrderPosition
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.

OBJECT cippfIpProfileType
MIN-ACCESS read-only
DESCRIPTION
Write access is not required.
Required groups
mandatory ciscoIpProtocolFilteringGroup
optional ciscoIpProtocolFilterGroup2 Implementation of this group is optional.

OID .1.3.6.1.4.1.9.9.278.2.1.3
The compliance statement for entities implementing
the Cisco IP Protocol Filter MIB.
Required groups
mandatory ciscoIpProtocolFilteringGroup
mandatory ciscoIpProtocolFilterStatsGroup
optional ciscoIpProtocolFilterGroup2 Implementation of this group is optional.
optional ciscoIpProtocolFilterExtGroup Implementation of this group is mandatory
for those systems where additional objects
supported for each filter.
optional ciscoIpProtocolFilterObjectGroup Implementation of this group is mandatory
for those systems where filter groups
are supported in IP filters.
Object refinements
ObjectAccessSyntaxDescription
cippfIpFilterAddressType
ipv4(1)
An implementation is only required to
support IPv4 addresses.
cippfIpFilterSrcAddress An implementation is only required to
support IPv4 addresses.
cippfIpFilterDestAddress An implementation is only required to
support IPv4 addresses.
cippfIpFilterOrderPosition readonly
Write access is not required.
cippfIpProfileType readonly
Write access is not required.
cippfIpFilterSrcIPGroupName noaccess
This object is not required to be implemented
if filter group is not supported.
cippfIpFilterDstIPGroupName noaccess
This object is not required to be implemented
if filter group is not supported.
cippfIpFilterSrcServiceGroupName noaccess
This object is not required to be implemented
if filter group is not supported.
cippfIpFilterDstServiceGroupName noaccess
This object is not required to be implemented
if filter group is not supported.
cippfIpFilterICMPGroupName noaccess
This object is not required to be implemented
if filter group is not supported.