CISCO-IP-URPF-MIB

        Unicast Reverse Path Forwarding (URPF) is a function that
checks the validity of the source address of IP packets
received on an interface. This in an attempt to prevent
Denial of Service attacks based on IP address spoofing.
        
URPF checks validity of a source address by determining
whether the packet would be successfully routed as a
destination address. 
Based on configuration, the check made
can be for existence of any route for the address, or more
strictly for a route out the interface on which the packet
was received by the device. When a violating packet is
detected, it can be dropped. 
This MIB allows detection of
spoofingevents.
    
Source file
CISCO-IP-URPF-MIB
Last revised
Identity
ciscoIpUrpfMIB
Base OID
1.3.6.1.4.1.9.9.451
Imported Objects
CISCO-SMI ciscoMgmt
IF-MIB ifIndex
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC TEXTUAL-CONVENTION (no object page) TimeStamp TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-IP-URPF-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-IP-URPF-MIB::ciscoIpUrpfMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-IP-URPF-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-IP-URPF-MIB::ciscoIpUrpfMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (40)
.1.3.6.1.4.1.9.9.451
.1.3.6.1.4.1.9.9.451.0
.1.3.6.1.4.1.9.9.451.1
.1.3.6.1.4.1.9.9.451.1.1
secondsInteger32
.1.3.6.1.4.1.9.9.451.1.1.1
secondsInteger32
.1.3.6.1.4.1.9.9.451.1.1.2
secondsInteger32
.1.3.6.1.4.1.9.9.451.1.1.3
.1.3.6.1.4.1.9.9.451.1.2
.1.3.6.1.4.1.9.9.451.1.2.1
.1.3.6.1.4.1.9.9.451.1.2.1.1
Enumeration
.1.3.6.1.4.1.9.9.451.1.2.1.1.1
.1.3.6.1.4.1.9.9.451.1.2.1.1.2
packets per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.451.1.2.1.1.3
.1.3.6.1.4.1.9.9.451.1.2.2
.1.3.6.1.4.1.9.9.451.1.2.2.1
Enumeration
.1.3.6.1.4.1.9.9.451.1.2.2.1.1
.1.3.6.1.4.1.9.9.451.1.2.2.1.2
.1.3.6.1.4.1.9.9.451.1.2.2.1.3
packets/secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.451.1.2.2.1.4
.1.3.6.1.4.1.9.9.451.1.2.2.1.5
.1.3.6.1.4.1.9.9.451.1.2.3
.1.3.6.1.4.1.9.9.451.1.2.3.1
.1.3.6.1.4.1.9.9.451.1.2.3.1.2
.1.3.6.1.4.1.9.9.451.1.2.3.1.3
.1.3.6.1.4.1.9.9.451.1.3
.1.3.6.1.4.1.9.9.451.1.3.1
.1.3.6.1.4.1.9.9.451.1.3.1.1
.1.3.6.1.4.1.9.9.451.1.3.1.1.1
packets/secondSNMPv2-SMIUnsigned32
.1.3.6.1.4.1.9.9.451.1.3.1.1.2
.1.3.6.1.4.1.9.9.451.1.3.1.1.3
Enumeration
.1.3.6.1.4.1.9.9.451.1.3.1.1.4
Enumeration
.1.3.6.1.4.1.9.9.451.1.3.1.1.5
OctetString
.1.3.6.1.4.1.9.9.451.1.3.1.1.6
.1.3.6.1.4.1.9.9.451.1.4
.1.3.6.1.4.1.9.9.451.1.4.1
.1.3.6.1.4.1.9.9.451.1.4.1.1
OctetString
.1.3.6.1.4.1.9.9.451.1.4.1.1.1
.1.3.6.1.4.1.9.9.451.2
.1.3.6.1.4.1.9.9.451.2.1
.1.3.6.1.4.1.9.9.451.2.2
Dependencies (8) 6 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Dependency-first compile order
  1. SNMPv2-SMIrfc
  2. CISCO-SMIcisco
  3. SNMPv2-TCrfc
  4. IANAifType-MIBrfc
  5. SNMPv2-CONFrfc
  6. SNMPv2-MIBrfc
  7. IF-MIBrfc
  8. SNMP-FRAMEWORK-MIBrfc
  9. CISCO-IP-URPF-MIBciscoselected
Type Definitions (2)
Bits
allowDefault(0)
allowSelfPing(1)
Enumeration
strict(1)
loose(2)
disabled(3)
Conformance Groups (3)
Compliance Statements (1)

OID .1.3.6.1.4.1.9.9.451.2.1.1
An SNMP entity can implement this module to
provide URPF problem diagnosis information.
Required groups
mandatory ciscoIpUrpfMIBMainObjectGroup
mandatory ciscoIpUrpfMIBNotifyGroup
optional ciscoIpUrpfMIBVrfObjectGroup This group is mandatory for all implementations
that need to index URPF statistics by VRF interfaces.
Notifications / Traps (1)
NameOIDDescription
.1.3.6.1.4.1.9.9.451.0.1
This notification is generated when
cipUrpfIfDropRateNotifyEnable is set to true and
the calculated URPF drop rate (cipUrpfIfDropRate)
exceeds the notification threshold drop rate
(cipUrpfIfNotifyDropRateThreshold). Note the
exceptional value of 0 for threshold allows notification
generation if any drop events occur in an interval.

After generating this notification, another such
notification will not be sent out for a minimum of five
minutes (note the exception to this provided by
cipUrpfIfNotifyDrHoldDownReset).

The object value present in the notification is the
the drop rate that exceeded the threshold.