FS-URPF-MIB
Unicast Reverse Path Forwarding (URPF) is a function
that checks the validity of the source address of IP
packets received on an interface. This in an attempt
to prevent Denial of Service attacks based on IP address
spoofing.
URPF checks validity of a source address by determining
whether the packet would be successfully routed as a
destination address.
Based on configuration, the check made can be for existence
of any route for the address, or more strictly for a route
out the interface on which the packet was received by the
device. When a violating packet is detected, it can be dropped.
This MIB allows detection of spoofing events.
- Source file
FS-URPF-MIB- Last revised
- Identity
fsUrpfMIB- Base OID
1.3.6.1.4.1.52642.1.1.10.2.46
Imported Objects
| FS-SMI | fsMgmt |
| IF-MIB | ifIndex |
| SNMP-FRAMEWORK-MIB | SnmpAdminString |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | TruthValue |
Net-SNMP examples using the fscom MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'FS-URPF-MIB' -M '/opt/observium/mibs/fscom:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'FS-URPF-MIB::fsUrpfMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'FS-URPF-MIB' -M '/opt/observium/mibs/fscom:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'FS-URPF-MIB::fsUrpfMIB'
Objects (30)
Showing 30 of 30 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.52642.1.1.10.2.46 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.1 |
||
|
secondsInteger32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.1.1 |
|
|
secondsInteger32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.1.2 |
|
|
secondsInteger32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.1.3 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.1 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.1.1.1 |
|
|
packetsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.1.1.2 |
|
|
packets per secondSNMPv2-SMIGauge32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.1.1.3 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.2 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.2.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.2.1.1 |
|
|
packetsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.2.1.2 |
|
|
packets/secondSNMPv2-SMIGauge32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.2.2.1.3 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.1 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.2 |
||
|
packets/secondSNMPv2-SMIUnsigned32
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.3 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.4 |
||
|
Enumeration
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.5 |
|
|
OctetString
|
.1.3.6.1.4.1.52642.1.1.10.2.46.0.3.1.1.6 |
|
.1.3.6.1.4.1.52642.1.1.10.2.46.1 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.2 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.2.1 |
||
.1.3.6.1.4.1.52642.1.1.10.2.46.2.2 |
Dependencies (8) 6 direct · 2 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- FS-SMIfscom
- SNMPv2-TCrfc
- IANAifType-MIBrfc
- SNMPv2-CONFrfc
- SNMPv2-MIBrfc
- IF-MIBrfc
- SNMP-FRAMEWORK-MIBrfc
- FS-URPF-MIBfscomselected
Conformance Groups (3)
|
fsUrpfComputeInterval fsUrpfDropRateWindow fsUrpfDropNotifyHoldDownTime fsUrpfDrops fsUrpfDropRate fsUrpfIfDrops fsUrpfIfDropRate fsUrpfIfCheckStrict fsUrpfIfDropRateNotifyEnable fsUrpfIfNotifyDropRateThreshold fsUrpfIfNotifyDrHoldDownReset
The collection of common counter objects, those
needed by other objects, and the common interface table. |
.1.3.6.1.4.1.52642.1.1.10.2.46.2.2.1
|
|
|
The collection of objects needed to index by
VRF. |
.1.3.6.1.4.1.52642.1.1.10.2.46.2.2.2
|
|
|
The collection of objects which are used to specify
notifications for URPF. |
.1.3.6.1.4.1.52642.1.1.10.2.46.2.2.3
|
Compliance Statements (1)
OID
.1.3.6.1.4.1.52642.1.1.10.2.46.2.1.1An SNMP entity can implement this module to
provide URPF problem diagnosis information.
provide URPF problem diagnosis information.
Required groups
| mandatory | fsUrpfMIBMainObjectGroup | |
| mandatory | fsUrpfMIBNotifyGroup | |
| optional | fsUrpfMIBVrfObjectGroup |
This group is mandatory for all implementations that need to index URPF statistics by VRF interfaces. |
Notifications / Traps (1)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.52642.1.1.10.2.46.1.1 |
This notification is generated when
fsUrpfIfDropRateNotifyEnable is set to true and the calculated URPF drop rate (fsUrpfIfDropRate) exceeds the notification threshold drop rate (fsUrpfIfNotifyDropRateThreshold). Note the exceptional value of 0 for threshold allows notification generation if any drop events occur in an interval. After generating this notification, another such notification will not be sent out for a minimum of five minutes (note the exception to this provided by fsUrpfIfNotifyDrHoldDownReset). The object value present in the notification is the the drop rate that exceeded the threshold. |