MIDCOM-MIB

        This MIB module defines a set of basic objects for
configuring middleboxes, such as firewalls and network
        
address translators, in order to enable communication
across these devices.
        
Managed objects defined in this MIB module are structured
in three kinds of objects:
  - transaction objects required according to the MIDCOM
    protocol requirements defined in RFC 3304 and according
    to the MIDCOM protocol semantics defined in RFC 3989,
  - configuration objects that can be used for retrieving or
    setting parameters of the implementation of transaction
    objects,
  - optional monitoring objects that provide information
    about used resource and statistics
        
The transaction objects are organized in two subtrees:
  - objects modeling MIDCOM policy rules in the
    midcomRuleTable
  - objects modeling MIDCOM policy rule groups in the
    midcomGroupTable
        
Note that typically, configuration objects are not intended
to be written by MIDCOM clients.  In general, write access
to these objects needs to be restricted more strictly than
write access to objects in the transaction subtrees.
        
Copyright (C) The Internet Society (2008).  This version
of this MIB module is part of RFC 5190;  see the RFC
itself for full legal notices.
    
Source file
MIDCOM-MIB
Last revised
Identity
midcomMIB
Base OID
1.3.6.1.2.1.171
Imported Objects
IF-MIB InterfaceIndexOrZero
INET-ADDRESS-MIB InetAddress InetAddressPrefixLength InetAddressType InetPortNumber
NAT-MIB NatBindIdOrZero
SNMP-FRAMEWORK-MIB SnmpAdminString
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Gauge32 mib-2 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC RowStatus StorageType TEXTUAL-CONVENTION (no object page) TruthValue
Net-SNMP examples using the rfc MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'MIDCOM-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'MIDCOM-MIB::midcomMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'MIDCOM-MIB' -M '/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'MIDCOM-MIB::midcomMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (78)
.1.3.6.1.2.1.171
.1.3.6.1.2.1.171.0
.1.3.6.1.2.1.171.1
.1.3.6.1.2.1.171.1.1
.1.3.6.1.2.1.171.1.1.3
.1.3.6.1.2.1.171.1.1.3.1
OctetString
.1.3.6.1.2.1.171.1.1.3.1.1
Enumeration
.1.3.6.1.2.1.171.1.1.3.1.10
.1.3.6.1.2.1.171.1.1.3.1.11
Unsigned32
.1.3.6.1.2.1.171.1.1.3.1.12
Enumeration
.1.3.6.1.2.1.171.1.1.3.1.13
.1.3.6.1.2.1.171.1.1.3.1.14
.1.3.6.1.2.1.171.1.1.3.1.15
.1.3.6.1.2.1.171.1.1.3.1.16
.1.3.6.1.2.1.171.1.1.3.1.17
.1.3.6.1.2.1.171.1.1.3.1.18
.1.3.6.1.2.1.171.1.1.3.1.19
.1.3.6.1.2.1.171.1.1.3.1.20
.1.3.6.1.2.1.171.1.1.3.1.21
.1.3.6.1.2.1.171.1.1.3.1.22
.1.3.6.1.2.1.171.1.1.3.1.23
.1.3.6.1.2.1.171.1.1.3.1.24
.1.3.6.1.2.1.171.1.1.3.1.25
.1.3.6.1.2.1.171.1.1.3.1.26
.1.3.6.1.2.1.171.1.1.3.1.27
Unsigned32
.1.3.6.1.2.1.171.1.1.3.1.3
Enumeration
.1.3.6.1.2.1.171.1.1.3.1.4
Enumeration
.1.3.6.1.2.1.171.1.1.3.1.5
.1.3.6.1.2.1.171.1.1.3.1.6
.1.3.6.1.2.1.171.1.1.3.1.7
.1.3.6.1.2.1.171.1.1.3.1.8
.1.3.6.1.2.1.171.1.1.3.1.9
.1.3.6.1.2.1.171.1.1.4
.1.3.6.1.2.1.171.1.1.4.1
Unsigned32
.1.3.6.1.2.1.171.1.1.4.1.2
.1.3.6.1.2.1.171.1.1.4.1.3
.1.3.6.1.2.1.171.1.2
.1.3.6.1.2.1.171.1.2.1
.1.3.6.1.2.1.171.1.2.2
.1.3.6.1.2.1.171.1.2.3
.1.3.6.1.2.1.171.1.2.3.1
.1.3.6.1.2.1.171.1.2.3.1.1
Bits
.1.3.6.1.2.1.171.1.2.3.1.2
.1.3.6.1.2.1.171.1.2.3.1.3
.1.3.6.1.2.1.171.1.2.4
.1.3.6.1.2.1.171.1.2.4.1
.1.3.6.1.2.1.171.1.2.4.1.1
.1.3.6.1.2.1.171.1.2.4.1.2
.1.3.6.1.2.1.171.1.2.4.1.3
.1.3.6.1.2.1.171.1.3
.1.3.6.1.2.1.171.1.3.1
.1.3.6.1.2.1.171.1.3.1.1
.1.3.6.1.2.1.171.1.3.1.1.10
.1.3.6.1.2.1.171.1.3.1.1.4
.1.3.6.1.2.1.171.1.3.1.1.5
.1.3.6.1.2.1.171.1.3.1.1.6
.1.3.6.1.2.1.171.1.3.1.1.7
.1.3.6.1.2.1.171.1.3.1.1.8
.1.3.6.1.2.1.171.1.3.1.1.9
.1.3.6.1.2.1.171.1.3.2
.1.3.6.1.2.1.171.1.3.2.1
.1.3.6.1.2.1.171.1.3.2.10
.1.3.6.1.2.1.171.1.3.2.11
.1.3.6.1.2.1.171.1.3.2.12
.1.3.6.1.2.1.171.1.3.2.13
.1.3.6.1.2.1.171.1.3.2.14
.1.3.6.1.2.1.171.1.3.2.15
.1.3.6.1.2.1.171.1.3.2.2
.1.3.6.1.2.1.171.1.3.2.3
.1.3.6.1.2.1.171.1.3.2.4
.1.3.6.1.2.1.171.1.3.2.5
.1.3.6.1.2.1.171.1.3.2.6
.1.3.6.1.2.1.171.1.3.2.7
.1.3.6.1.2.1.171.1.3.2.8
.1.3.6.1.2.1.171.1.3.2.9
.1.3.6.1.2.1.171.2
.1.3.6.1.2.1.171.2.1
.1.3.6.1.2.1.171.2.2
Dependencies (9) 7 direct · 2 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (2)
Enumeration
addressBind(1)
addressPortBind(2)
none(3)
Unsigned32
Conformance Groups (6)
A collection of objects providing information about
policy rules and policy rule groups.
.1.3.6.1.2.1.171.2.2.1
A collection of objects providing information about
the capabilities of a middlebox.
.1.3.6.1.2.1.171.2.2.2
A collection of objects providing information about
the firewall rule group and firewall rule priority to
be used by firewalls loaded through MIDCOM.
.1.3.6.1.2.1.171.2.2.3
A collection of objects providing information about
the used NAT and firewall resources.
.1.3.6.1.2.1.171.2.2.4
A collection of objects providing statistical
information about the MIDCOM server.
.1.3.6.1.2.1.171.2.2.5
The notifications emitted by the midcomMIB.
.1.3.6.1.2.1.171.2.2.6
Compliance Statements (1)

OID .1.3.6.1.2.1.171.2.1.1
The compliance statement for implementations of the
MIDCOM-MIB module.

Note that compliance with this compliance
statement requires compliance with the
ifCompliance3 MODULE-COMPLIANCE statement of the
IF-MIB [RFC2863].
Required groups
mandatory midcomRuleGroup
mandatory midcomNotificationsGroup
mandatory midcomCapabilitiesGroup
mandatory midcomStatisticsGroup
optional midcomConfigFirewallGroup A compliant implementation does not have to implement
the midcomConfigFirewallGroup.
optional midcomResourceGroup A compliant implementation does not have to implement
the midcomResourceGroup.
Object refinements
ObjectAccessSyntaxDescription
midcomRuleInternalIpPrefixLength readonly
Write access is not required. When write access is
not supported, return 128 as the value of this object.
A value of 128 means that the function represented by
this option is not supported.
midcomRuleExternalIpPrefixLength readonly
Write access is not required. When write access is
not supported, return 128 as the value of this object.

A value of 128 means that the function represented by
this option is not supported.
midcomRuleMaxIdleTime readonly
Write access is not required. When write access is
not supported, return 0 as the value of this object.
A value of 0 means that the function represented by
this option is not supported.
midcomRuleInterface readonly
Write access is not required.
midcomConfigMaxLifetime readonly
Write access is not required.
midcomConfigPersistentRules readonly
Write access is not required.
midcomConfigIfEnabled readonly
Write access is not required.
midcomConfigFirewallGroupId readonly
Write access is not required.
midcomConfigFirewallPriority readonly
Write access is not required.
Notifications / Traps (3)
NameOIDDescription
.1.3.6.1.2.1.171.0.1
This notification is generated whenever the value of
midcomRuleOperStatus enters any error state or any
termination state without an explicit trigger by a
MIDCOM client.
.1.3.6.1.2.1.171.0.2
This notification is generated whenever the value
of midcomRuleOperStatus enters one of the states
{reserved, enabled, any error state, any termination state}
as a result of a MIDCOM agent writing successfully to
object midcomRuleAdminStatus.

In addition, it is generated when the lifetime of
a rule was changed by successfully writing to object
midcomRuleLifetime.
.1.3.6.1.2.1.171.0.3
This notification is generated for indicating that the
lifetime of all member rules of the group was changed by
successfully writing to object midcomGroupLifetime.

Note that this notification is only sent if the lifetime
of a group was changed by successfully writing to object
midcomGroupLifetime. No notification is sent
- if a group's lifetime is changed by writing to object
midcomRuleLifetime of any of its member policies,
- if a group's lifetime expires (in this case,
notifications are sent for all member policies), or
- if the group is terminated by terminating the last
of its member policies without writing to object
midcomGroupLifetime.