CISCO-UNIFIED-FIREWALL-MIB

        Overview of Cisco Firewall MIB
==============================
This MIB Module models status and performance
statistics pertaining to the common features supported
by Cisco firewall implementations. For each firewall 
feature, capability (if applicable) and statistics are
defined. Supporting the configuration of firewall 
features is outside the scope of this MIB.
        
Following are the major firewall features:
        
1) 'Stateful Packet Filtering'
     Creating and maintaining the state of authorized 
     traffic flows dynamically to permit only
     flows authorized by the policy is a mandatory 
     function of a firewall.  
     This MIB instruments the activity and memory
     usage by this function.
        
2) 'Application Inspection'
     This refers to the function of inspecting the
     headers of layer 3 and layer 4 protocols and
     creating dynamic entries in the connection
     table for traffic flows spawned by an already
     established traffic flow.
        
     This MIB reflects the protocols that are being 
     inspected.
        
3) 'URL Filtering'
     This refers to the function of facilitating
     or restricting URL access requests through
     the firewall by consulting either local policy
     or that configured on a dedicated URL filtering
     server.
        
     This MIB instruments the URL filtering activity,
     the status and activity of distinct URL filtering
     servers configured on the firewall and the
     impact of the performance of the URL filtering
     servers on the latency and throughput of the
     firewall.
        
4) 'Proxy Authentication'
     This refers to the function of authenticating
     and/or authorizing users on behalf of servers
     on the secure side of the firewall. This operation
     could affect the throughput of the firewall.
        
     The MIB objects pertaining to Proxy Authentication
     will be defined in a subsequent revision of this
     MIB. 
        
        
5) 'Transparent Mode Operation'
     A firewall could operate as a bridge and yet
     filter traffic based on layer 3-layer 7 control
     and payload information. Operating in this mode
     makes it easy to implement a firewall without
     fragmenting existing subnets. Another advantage
     of this mode of operation is enhanced security.
        
     This MIB instruments the status, activity, 
     and performance of the firewall in this mode.
     Please note that to fully manage a firewall
     operating in this mode, the firewall must also
     support the bridge MIB (BRIDGE-MIB).
        
        
6) 'Advanced Application Inspection and Control'
     This function is also termed 'Application
     Firewall' and pertains to inspecting payload and
     headers of application traffic to make sure the
     traffic flows conform to the configured security
     policy.
        
     Monitoring this function entails identifying the
     security alerts generated by this function and 
     measuring the impact on firewall performance by
     this task. Application Firewall will be 
     instrumented in a separate MIB dedicated for the
     function.
        
7) 'Failover' or 'Redundancy'
     Redundancy configuration is essential for business
     critical firewalls.
        
     Instrumenting this function entails reflecting
     the configuration of redundancy and identifying
     failover events.
        
     The MIB objects pertaining to Proxy Authentication
     will be defined in a subsequent revision of this
     MIB. 
        
        
The management information for each firewall feature
is defined in a distinct module compliance unit. The 
compliance units corresponding to basic features of 
firewalls are defined as mandatory.
        
Acronyms
========
Following are definitions of some terms used in this
module. Please refer to the module conformance for a
glossary of feature-specific terms.
        
 `Firewall'
    A firewall is a set of related programs, 
    implemented on a host or a network device, that
    protects the resources of a private network from
    users from other networks. Common firewalling
    functions include stateful packet filtering,
    proxy authentication of users on behalf of 
    applications on the secure side of the firewall,
    URL access control, inspection of payload of 
    traffic streams to determine security threats.
        
 `Layer2 Firewall' or 'Transparent Firewall'
    A firewall device that operates as a bridge
    while performing firewalling function.
        
 `Connection'
    The record in the firewall of a traffic strean
    that has been authorized to flow through the 
    firewall.
        
 `Half Open Connection'
    For a connection oriented protocol: a connection
    that has not reached the established on both the
    sides of the connection.
    For a connection-less protocol: the connection
    corresponding to a traffic stream where traffic
    flow has occurred (since the establishment of the
    connection entry) only on one direction.
        
 `Embryonic Connection'
    The connection entry corresponding to an 
    application layer protocol in which the signaling
    channel has been established while the setup of
    the data channel is underway.
        
 `Policy'
    An element of firewall configuration that
    identifies the access rights to a resource by a
    traffic source. An example of a policy is an 
    Access Control Rule.
        
 `Policy Target'
    An entity to which a policy is applied so that 
    the action corresponding to the policy is taken
    only on traffic streams associated with the
    entity. An example of a policy target is an 
    interface.
        
 `URL Filtering Server'
    A server which is employed by the firewall to 
    enforce URL access policies.
        
 `Protocol Data Unit' or PDU
    An instance of the unit of information using which
    a protocol operates is called the Protocol Data
    Unit or the PDU of the protocol.
        
 `Deep Packet Inspection'
    The task of examining the contents of the payloads
    of one or more layer 7 application protocols 
    with a view to enforcing the local security
    policies termed 'Deep Packet Inspection'.
        
 `Advanced Application Inspection and Control'
    An entity that performs deep packet inspection
    of layer 7 application protocol data units is
    termed an 'Application Firewall'.
    
Source file
CISCO-UNIFIED-FIREWALL-MIB
Last revised
Identity
ciscoUnifiedFirewallMIB
Base OID
1.3.6.1.4.1.9.9.491
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-UNIFIED-FIREWALL-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-UNIFIED-FIREWALL-MIB::ciscoUnifiedFirewallMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-UNIFIED-FIREWALL-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-UNIFIED-FIREWALL-MIB::ciscoUnifiedFirewallMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (280)
.1.3.6.1.4.1.9.9.491
.1.3.6.1.4.1.9.9.491.0
.1.3.6.1.4.1.9.9.491.1
.1.3.6.1.4.1.9.9.491.1.1
.1.3.6.1.4.1.9.9.491.1.1.1
.1.3.6.1.4.1.9.9.491.1.1.1.1
Connections per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.1.10
Connections per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.1.11
.1.3.6.1.4.1.9.9.491.1.1.1.12
.1.3.6.1.4.1.9.9.491.1.1.1.2
.1.3.6.1.4.1.9.9.491.1.1.1.3
.1.3.6.1.4.1.9.9.491.1.1.1.4
.1.3.6.1.4.1.9.9.491.1.1.1.5
.1.3.6.1.4.1.9.9.491.1.1.1.6
.1.3.6.1.4.1.9.9.491.1.1.1.7
.1.3.6.1.4.1.9.9.491.1.1.1.8
.1.3.6.1.4.1.9.9.491.1.1.1.9
.1.3.6.1.4.1.9.9.491.1.1.2
.1.3.6.1.4.1.9.9.491.1.1.2.1
.1.3.6.1.4.1.9.9.491.1.1.2.2
.1.3.6.1.4.1.9.9.491.1.1.2.3
.1.3.6.1.4.1.9.9.491.1.1.2.4
.1.3.6.1.4.1.9.9.491.1.1.3
.1.3.6.1.4.1.9.9.491.1.1.3.1
.1.3.6.1.4.1.9.9.491.1.1.3.2
.1.3.6.1.4.1.9.9.491.1.1.4
.1.3.6.1.4.1.9.9.491.1.1.4.1
.1.3.6.1.4.1.9.9.491.1.1.4.1.1
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.1
Connections Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.10
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.2
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.3
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.4
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.5
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.6
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.7
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.8
Connections Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.4.1.1.9
.1.3.6.1.4.1.9.9.491.1.1.4.2
.1.3.6.1.4.1.9.9.491.1.1.4.2.1
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.1
Connections Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.10
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.2
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.3
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.4
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.5
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.6
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.7
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.8
Connections Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.1.4.2.1.9
.1.3.6.1.4.1.9.9.491.1.1.4.3
.1.3.6.1.4.1.9.9.491.1.1.4.3.1
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.1
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.10
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.11
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.2
OctetString
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.3
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.4
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.5
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.6
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.7
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.8
.1.3.6.1.4.1.9.9.491.1.1.4.3.1.9
.1.3.6.1.4.1.9.9.491.1.1.4.4
.1.3.6.1.4.1.9.9.491.1.1.4.4.1
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.1
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.10
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.11
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.2
OctetString
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.3
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.4
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.5
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.6
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.7
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.8
.1.3.6.1.4.1.9.9.491.1.1.4.4.1.9
.1.3.6.1.4.1.9.9.491.1.2
.1.3.6.1.4.1.9.9.491.1.2.1
.1.3.6.1.4.1.9.9.491.1.2.2
.1.3.6.1.4.1.9.9.491.1.2.3
.1.3.6.1.4.1.9.9.491.1.2.3.1
OctetString
.1.3.6.1.4.1.9.9.491.1.2.3.1.1
.1.3.6.1.4.1.9.9.491.1.2.3.1.2
.1.3.6.1.4.1.9.9.491.1.2.3.1.3
.1.3.6.1.4.1.9.9.491.1.3
.1.3.6.1.4.1.9.9.491.1.3.1
.1.3.6.1.4.1.9.9.491.1.3.1.1
.1.3.6.1.4.1.9.9.491.1.3.1.10
.1.3.6.1.4.1.9.9.491.1.3.1.11
.1.3.6.1.4.1.9.9.491.1.3.1.12
.1.3.6.1.4.1.9.9.491.1.3.1.13
Requests Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.14
Requests Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.15
.1.3.6.1.4.1.9.9.491.1.3.1.16
.1.3.6.1.4.1.9.9.491.1.3.1.17
.1.3.6.1.4.1.9.9.491.1.3.1.18
.1.3.6.1.4.1.9.9.491.1.3.1.19
.1.3.6.1.4.1.9.9.491.1.3.1.2
Requests per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.3
Requests per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.4
.1.3.6.1.4.1.9.9.491.1.3.1.5
.1.3.6.1.4.1.9.9.491.1.3.1.6
Requests per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.7
Requests Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.3.1.8
.1.3.6.1.4.1.9.9.491.1.3.1.9
.1.3.6.1.4.1.9.9.491.1.3.2
.1.3.6.1.4.1.9.9.491.1.3.2.1
.1.3.6.1.4.1.9.9.491.1.3.2.2
.1.3.6.1.4.1.9.9.491.1.3.3
.1.3.6.1.4.1.9.9.491.1.3.3.1
.1.3.6.1.4.1.9.9.491.1.3.3.1.1
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.1
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.10
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.11
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.12
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.13
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.14
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.2
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.3
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.4
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.5
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.6
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.7
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.8
.1.3.6.1.4.1.9.9.491.1.3.3.1.1.9
.1.3.6.1.4.1.9.9.491.1.4
.1.3.6.1.4.1.9.9.491.1.4.1
.1.3.6.1.4.1.9.9.491.1.4.1.1
.1.3.6.1.4.1.9.9.491.1.4.1.10
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.4.1.11
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.4.1.12
.1.3.6.1.4.1.9.9.491.1.4.1.13
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.4.1.14
Integer32
.1.3.6.1.4.1.9.9.491.1.4.1.15
.1.3.6.1.4.1.9.9.491.1.4.1.16
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.4.1.17
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.4.1.18
.1.3.6.1.4.1.9.9.491.1.4.1.19
.1.3.6.1.4.1.9.9.491.1.4.1.2
Connections Per SecondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.4.1.20
.1.3.6.1.4.1.9.9.491.1.4.1.3
.1.3.6.1.4.1.9.9.491.1.4.1.4
.1.3.6.1.4.1.9.9.491.1.4.1.5
Integer32
.1.3.6.1.4.1.9.9.491.1.4.1.6
.1.3.6.1.4.1.9.9.491.1.4.1.7
.1.3.6.1.4.1.9.9.491.1.4.1.8
.1.3.6.1.4.1.9.9.491.1.4.1.9
.1.3.6.1.4.1.9.9.491.1.4.2
.1.3.6.1.4.1.9.9.491.1.4.2.1
.1.3.6.1.4.1.9.9.491.1.4.2.1.1
.1.3.6.1.4.1.9.9.491.1.4.2.1.1.1
.1.3.6.1.4.1.9.9.491.1.4.2.1.1.2
.1.3.6.1.4.1.9.9.491.1.4.2.1.1.3
.1.3.6.1.4.1.9.9.491.1.4.2.1.1.4
.1.3.6.1.4.1.9.9.491.1.4.2.1.1.5
.1.3.6.1.4.1.9.9.491.1.4.2.2
.1.3.6.1.4.1.9.9.491.1.4.2.2.1
.1.3.6.1.4.1.9.9.491.1.4.2.2.1.1
Integer32
.1.3.6.1.4.1.9.9.491.1.4.2.2.1.2
.1.3.6.1.4.1.9.9.491.1.4.2.2.1.3
.1.3.6.1.4.1.9.9.491.1.4.2.2.1.4
.1.3.6.1.4.1.9.9.491.1.4.2.2.1.5
.1.3.6.1.4.1.9.9.491.1.4.3
.1.3.6.1.4.1.9.9.491.1.4.3.1
.1.3.6.1.4.1.9.9.491.1.4.3.2
.1.3.6.1.4.1.9.9.491.1.4.3.2.1
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.1
Integer32
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.2
OctetString
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.3
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.4
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.5
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.6
.1.3.6.1.4.1.9.9.491.1.4.3.2.1.7
.1.3.6.1.4.1.9.9.491.1.4.4
.1.3.6.1.4.1.9.9.491.1.4.4.1
.1.3.6.1.4.1.9.9.491.1.4.4.3
.1.3.6.1.4.1.9.9.491.1.4.4.3.1
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.1
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.2
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.3
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.4
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.5
.1.3.6.1.4.1.9.9.491.1.4.4.3.1.6
.1.3.6.1.4.1.9.9.491.1.5
.1.3.6.1.4.1.9.9.491.1.5.1
Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.1.1
Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.1.2
Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.1.3
.1.3.6.1.4.1.9.9.491.1.5.2
.1.3.6.1.4.1.9.9.491.1.5.2.1
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.1
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.2
.1.3.6.1.4.1.9.9.491.1.5.2.1.3
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.4
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.5
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.6
HTTP Protocol Data UnitsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.5.2.1.7
.1.3.6.1.4.1.9.9.491.1.5.3
.1.3.6.1.4.1.9.9.491.1.5.3.1
.1.3.6.1.4.1.9.9.491.1.5.3.1.1
.1.3.6.1.4.1.9.9.491.1.5.3.1.10
.1.3.6.1.4.1.9.9.491.1.5.3.1.11
.1.3.6.1.4.1.9.9.491.1.5.3.1.12
.1.3.6.1.4.1.9.9.491.1.5.3.1.2
.1.3.6.1.4.1.9.9.491.1.5.3.1.3
.1.3.6.1.4.1.9.9.491.1.5.3.1.4
.1.3.6.1.4.1.9.9.491.1.5.3.1.5
.1.3.6.1.4.1.9.9.491.1.5.3.1.6
.1.3.6.1.4.1.9.9.491.1.5.3.1.7
.1.3.6.1.4.1.9.9.491.1.5.3.1.8
.1.3.6.1.4.1.9.9.491.1.5.3.1.9
.1.3.6.1.4.1.9.9.491.1.5.3.2
Events per secondSNMPv2-SMIGauge32
.1.3.6.1.4.1.9.9.491.1.5.3.2.1
.1.3.6.1.4.1.9.9.491.1.5.3.3
.1.3.6.1.4.1.9.9.491.1.5.3.3.1
.1.3.6.1.4.1.9.9.491.1.5.3.3.1.1
.1.3.6.1.4.1.9.9.491.1.5.3.3.1.2
.1.3.6.1.4.1.9.9.491.1.5.3.3.1.3
.1.3.6.1.4.1.9.9.491.1.5.3.3.1.4
.1.3.6.1.4.1.9.9.491.1.5.3.4
.1.3.6.1.4.1.9.9.491.1.5.3.4.1
.1.3.6.1.4.1.9.9.491.1.5.3.4.1.1
.1.3.6.1.4.1.9.9.491.1.5.3.4.1.2
.1.3.6.1.4.1.9.9.491.1.5.3.4.1.3
.1.3.6.1.4.1.9.9.491.1.5.3.4.1.4
.1.3.6.1.4.1.9.9.491.1.6
.1.3.6.1.4.1.9.9.491.1.6.1
.1.3.6.1.4.1.9.9.491.1.6.1.1
ARP ResponsesSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.6.1.10
ARP ResponsesSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.6.1.11
ARP entriesInteger32
.1.3.6.1.4.1.9.9.491.1.6.1.2
.1.3.6.1.4.1.9.9.491.1.6.1.3
.1.3.6.1.4.1.9.9.491.1.6.1.5
ICMP Traceroute RequestsSNMPv2-SMICounter64
.1.3.6.1.4.1.9.9.491.1.6.1.6
.1.3.6.1.4.1.9.9.491.1.6.1.7
.1.3.6.1.4.1.9.9.491.1.6.1.8
.1.3.6.1.4.1.9.9.491.1.6.1.9
.1.3.6.1.4.1.9.9.491.1.7
.1.3.6.1.4.1.9.9.491.1.7.1
.1.3.6.1.4.1.9.9.491.1.7.2
.1.3.6.1.4.1.9.9.491.1.7.3
.1.3.6.1.4.1.9.9.491.1.7.4
.1.3.6.1.4.1.9.9.491.1.8
.1.3.6.1.4.1.9.9.491.1.8.1
.1.3.6.1.4.1.9.9.491.1.8.1.1
.1.3.6.1.4.1.9.9.491.1.8.1.10
.1.3.6.1.4.1.9.9.491.1.8.1.11
.1.3.6.1.4.1.9.9.491.1.8.1.12
.1.3.6.1.4.1.9.9.491.1.8.1.13
millisecInteger32
.1.3.6.1.4.1.9.9.491.1.8.1.14
.1.3.6.1.4.1.9.9.491.1.8.1.15
.1.3.6.1.4.1.9.9.491.1.8.1.16
Integer32
.1.3.6.1.4.1.9.9.491.1.8.1.2
.1.3.6.1.4.1.9.9.491.1.8.1.3
.1.3.6.1.4.1.9.9.491.1.8.1.4
.1.3.6.1.4.1.9.9.491.1.8.1.5
.1.3.6.1.4.1.9.9.491.1.8.1.6
.1.3.6.1.4.1.9.9.491.1.8.1.7
Integer32
.1.3.6.1.4.1.9.9.491.1.8.1.8
Integer32
.1.3.6.1.4.1.9.9.491.1.8.1.9
.1.3.6.1.4.1.9.9.491.1.8.2
.1.3.6.1.4.1.9.9.491.1.8.2.1
.1.3.6.1.4.1.9.9.491.1.8.2.2
.1.3.6.1.4.1.9.9.491.1.8.2.3
.1.3.6.1.4.1.9.9.491.1.8.2.3.1
.1.3.6.1.4.1.9.9.491.1.8.2.3.1.1
.1.3.6.1.4.1.9.9.491.1.8.2.3.1.2
.1.3.6.1.4.1.9.9.491.1.8.2.3.1.3
.1.3.6.1.4.1.9.9.491.1.8.3
.1.3.6.1.4.1.9.9.491.1.8.3.1
.1.3.6.1.4.1.9.9.491.1.8.3.2
.1.3.6.1.4.1.9.9.491.1.8.3.2.1
.1.3.6.1.4.1.9.9.491.1.8.3.2.1.1
.1.3.6.1.4.1.9.9.491.1.8.3.2.1.2
.1.3.6.1.4.1.9.9.491.1.8.3.2.1.3
.1.3.6.1.4.1.9.9.491.1.8.3.2.1.4
.1.3.6.1.4.1.9.9.491.1.8.3.2.1.5
.1.3.6.1.4.1.9.9.491.2
.1.3.6.1.4.1.9.9.491.2.1
.1.3.6.1.4.1.9.9.491.2.2
Dependencies (12) 10 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (6)
Enumeration
init(0)
up(1)
down(2)
goingDown(3)
goingUp(4)
noLicense(5)
none(6)
Enumeration
disabled(0)
election(1)
onCall(2)
slaveCold(3)
slaveAppSync(4)
slaveConfig(5)
slaveFilesys(6)
slaveBulkSync(7)
slave(8)
slavePending(9)
deputyBulkSync(10)
deputy(11)
masterFast(12)
masterDrain(13)
masterConfig(14)
masterPostConfig(15)
master(16)
masterDefer(17)
Enumeration
default(0)
group1(1)
group2(2)
Enumeration
init(0)
disabled(1)
failed(2)
negotiation(3)
standbyCold(4)
standbyConfig(5)
standbyFilesys(6)
standbyBulk(7)
standby(8)
activeFast(9)
activeDrain(10)
activePreConf(11)
activePostConf(12)
active(13)
invalid(14)
Enumeration
unknown(0)
normal(1)
testing(2)
linkDown(3)
failed(4)
noLink(5)
Enumeration
unknown(0)
monitored(1)
notMonitored(2)
waiting(3)
autostateDown(4)
shutdown(5)
Conformance Groups (13)
This group contains the MIB objects required to
instrument the firewall stateful connection activity.
.1.3.6.1.4.1.9.9.491.2.2.1
This group contains the MIB objects required to
instrument the resource usage of the stateful packet
filtering feature of the managed firewall.
.1.3.6.1.4.1.9.9.491.2.2.2
This group contains the MIB objects required to
instrument policy based summary of firewall connection
activity.
.1.3.6.1.4.1.9.9.491.2.2.3
This group contains the MIB objects required to
instrument the firewall Application Inspection
function.
.1.3.6.1.4.1.9.9.491.2.2.4
This group contains the MIB objects required to
instrument the firewall URL filtering function.
.1.3.6.1.4.1.9.9.491.2.2.5
This group contains the MIB objects required to
instrument the resource usage of the URL filtering
feature of the managed firewall.
.1.3.6.1.4.1.9.9.491.2.2.6
This group contains the MIB objects required to
instrument the transparent mode (or layer 2) operation
of a firewall.
.1.3.6.1.4.1.9.9.491.2.2.7
This group contains notifications defined
in the Cisco Firewall MIB pertaining to
basic firewall operations.

Presently, the list include a notification
pertaining to URL filtering alone.
.1.3.6.1.4.1.9.9.491.2.2.8
This group contains the notifications that signal
security critical events pertaining to the
transparent mode operation of the firewall.
.1.3.6.1.4.1.9.9.491.2.2.9
This group contains the MIB objects required to
instrument the basic elements of Advanced Application
Inspection and Control (AAIC).
.1.3.6.1.4.1.9.9.491.2.2.10
This group defines statistics pertaining to deep
packet inspection of HTTP payloads.

A firewall that implements this group must implement
the group 'ciscoFwBasicAaicGroup'.
.1.3.6.1.4.1.9.9.491.2.2.11
This group contains the MIB objects that allow
the administrator to control the granularity of
objects reported by the agent.
.1.3.6.1.4.1.9.9.491.2.2.12
This group contains the MIB objects that allow
the administrator to control the granularity of
objects reported by the agent.
.1.3.6.1.4.1.9.9.491.2.2.13
Compliance Statements (1)

OID .1.3.6.1.4.1.9.9.491.2.1.1
The compliance statement for SNMP entities
the Cisco Firewall MIB.
Required groups
mandatory ciscoFwConnectionGroup
mandatory ciscoFwMibReportingControlGroup
optional ciscoFwApplInspectionGroup This group is mandatory for a firewall
implementation which implements application
inspection of L7 protocols
optional ciscoFwConnResourceUsageGroup This group is optional.
optional ciscoFwFailoverGroup This group is optional.
optional ciscoFwPolicyConnectionGroup This group is mandatory for a firewall
implementation which implements the
instrumentation of policy based connection
statistics.
optional ciscoFwUrlFilterGroup This group is mandatory only if the
firewall implements URL Filtering
functionality.
optional ciscoFwUrlFilterResourceGroup This group is optional.
optional ciscoFwTransparentFwGroup This group is mandatory only if the
firewall implements transparent or layer 2
mode of operation.
optional ciscoFwTransparentNotifGroup This group is mandatory only if the
firewall implements transparent or layer 2
mode of operation.
optional ciscoFwBasicAaicGroup This group is mandatory only if the
firewall implements the group
'ciscoFwAaicHttpGroup'.
optional ciscoFwAaicHttpGroup This group is mandatory only for a
firewall implementation which implements
Advanced Application Inspection and
Control (deep packet inspection) of HTTP
traffic.

Further, any implementation that supports
thsi group MUST implement group
ciscoFwBasicAaicGroup.
Notifications / Traps (4)
NameOIDDescription
.1.3.6.1.4.1.9.9.491.0.1
This notification is generated when the firewall
elects a new primary URL filtering server from
the existing set of configured servers.

Such a change could occur either as a result of
the current primary server becoming unavailable or
as a result of explicit management action in
nominating a filtering server the primary server.

The notification is issued just before the change
occurs. Consequently, the varbinds identify the
attributes corresponding to the old primary server.

This notification is issued if and only if the
object 'cufwCntlUrlfServerStatusChange' has been
set to 'true'.
.1.3.6.1.4.1.9.9.491.0.2
This notification is generated when the firewall
detects the move of a static MAC address to a new
port.

Such a change could occur either as a result of
physical move of the device with the MAC Address
to the new port, due to management action of
relocating the MAC address at the new location or
due to MAC address spoofing.

The varbinds identify the new location (port) of
the MAC Address and its status at the new location.

This notification is issued if and only if the
object 'cufwCntlL2StaticMacAddressMoved' has been
set to 'true'.
.1.3.6.1.4.1.9.9.491.0.3
This notification is generated when the firewall
detects a state change in either units of an HA pair.

This notification is issued if and only if the
object 'cufwCntlFOstateChange' has been
set to 'true'.
.1.3.6.1.4.1.9.9.491.0.4
This notification is generated when the firewall
detects a new master has been elected.

This notification is issued if and only if the
object 'cufwCntlCluStateChange' has been
set to 'true'.