EZ5 MIB Catalog

CISCO-FIREWALL-MIB

2020-10-01

MIB module for monitoring Cisco Firewalls.

Download CISCO-FIREWALL-MIB.txt Open CISCO-FIREWALL-MIB.txt in a new tab

SCALARS (4) · TABLES (5) · TRAPS (6)

Scalars (4)

NameOID
cfwBasicEventsTableLastRow1.3.6.1.4.1.9.9.147.1.1.1.1
cfwNetEventsTableLastRow1.3.6.1.4.1.9.9.147.1.1.2.1
cfwConnectionPerSecond1.3.6.1.4.1.9.9.147.1.2.2.3
cfwConnectionPerSecondPeak1.3.6.1.4.1.9.9.147.1.2.2.4

Tables (5)

NameOID
cfwBasicEventsTable1.3.6.1.4.1.9.9.147.1.1.1.2
cfwNetEventsTable1.3.6.1.4.1.9.9.147.1.1.2.2
cfwHardwareStatusTable1.3.6.1.4.1.9.9.147.1.2.1.1
cfwBufferStatsTable1.3.6.1.4.1.9.9.147.1.2.2.1
cfwConnectionStatTable1.3.6.1.4.1.9.9.147.1.2.2.2

Traps (6)

NameOID
cfwSecurityNotification1.3.6.1.4.1.9.9.147.2.0.2
cfwContentInspectNotification1.3.6.1.4.1.9.9.147.2.0.3
cfwConnNotification1.3.6.1.4.1.9.9.147.2.0.4
cfwAccessNotification1.3.6.1.4.1.9.9.147.2.0.5
cfwAuthNotification1.3.6.1.4.1.9.9.147.2.0.6
cfwGenericNotification1.3.6.1.4.1.9.9.147.2.0.7

END OF TOC

Scalar details

cfwBasicEventsTableLastRow

1.3.6.1.4.1.9.9.147.1.1.1.1

Unsigned32

The index value of the most recently created row in the cfwBasicEventsTable. This number starts at 1 and increase by one with each new log entry. When this number wraps, all events are deleted.

cfwNetEventsTableLastRow

1.3.6.1.4.1.9.9.147.1.1.2.1

Unsigned32

The index value of the last row in the cfwNetEventsTable. This number starts at 1 and increase by one with each new log entry. When this number wraps, all events are deleted.

cfwConnectionPerSecond

1.3.6.1.4.1.9.9.147.1.2.2.3

Gauge32 · Connections per second

The current cps rate on the firewall.

cfwConnectionPerSecondPeak

1.3.6.1.4.1.9.9.147.1.2.2.4

Gauge32 · Connections per second

The peak cps rate hit on the firewall.

Table details

cfwBasicEventsTable

1.3.6.1.4.1.9.9.147.1.1.1.2

Index: cfwBasicEventIndex

Table of basic data for firewall events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. The oldest Events will be selected first for deletion.

cfwBasicEventIndex

1.3.6.1.4.1.9.9.147.1.1.1.2.1.1

Unsigned32

An index that uniquely identifies an entry in the log table. These indices are assigned beginning with 1 and increase by one with each new event logged.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicSecurityEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.3

SecurityEvent1 = other2 = none3 = dos4 = recon5 = pakFwd6 = addrSpoof7 = svcSpoof8 = thirdParty9 = complete10 = invalPak11 = illegCom12 = policyThis textual convention is used to describe various security-related events and statistics on a firewall. other : Generic attack event. none : No attack is occurring, an informational event. dos : A denial of service attack has been detected. recon : A pattern of reconnaissance activity has been detected. pakFwd : A packet forwarding attack has been detected. addrSpoof : A spoofed address has been detected. svcSpoof : A spoofed service (eg., DNS) has been detected. thirdParty : This site is being used as a third-party for an attack on another network. For example, the 'smurf' attack or email spamming. complete : An attack has terminated invlPak : An invalid packet with attack characteristics has been detected. illegCmd : An illegal command has been found. policy : An attempt has reen made to violate a security policy. · Integer32

The type of security-related event that this row contains. If the event is not security-related this object will not be instantiated.

cfwBasicContentInspEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.4

ContentInspectionEvent1 = other2 = okay3 = error4 = found5 = clean6 = reject7 = savedContent inspection events, these events report that something was found in the application payload. The details entry in the event can report on what was found (eg., virus, company private info., etc), what it was found in (eg., html, win32 executable, e-mail), and what was done with it (eg., the quarantine location). other : A content inspection event. Used to indicate that some content inspection has occurred that is not covered by the other content inspection enumerations. okay : The check of the content was okay, nothing 'bad' was found. error : There was an error while checking the content. found : Something was found that the content inspection engine has determined merits attention. clean : The content inspection engine has found something that violates the security policy and has neutralized the content in the data flow. reject : The content inspection engine has found something that violates the security policy and has discarded the content. saved : The content inspection engine has found something that violates the security policy and has stored it in a quarentine storage area. · Integer32

The type of content inspection-related event that this row contains. If the event is not content inspection-related this object will not be instantiated.

cfwBasicConnectionEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.5

ConnectionEvent1 = other2 = accept3 = error4 = drop5 = close6 = timeout7 = refused8 = reset9 = noRespThis textual convention is used to describe various events and statistics that are related to the connections that occur on a firewall. other : A generic connection event. accept : A connection has been acccepted. error : An error has occurred for a connection. drop : The connection has been dropped. close : A connection has been closed. timeout : A connection has been timed out. refused : A connection has been refused. reset : A connection has been reset. noResp : A connection has received no response. · Integer32

The type of connection-related event that this row contains. If the event is not connection-related this object will not be instantiated.

cfwBasicAccessEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.6

AccessEvent1 = other2 = grant3 = deny4 = denyMult5 = errorThis textual convention is used to describe various events and statistics that are related to the access control on a firewall. other : Miscellaneous access event. grant : A service has allowed access based on all of its access checks. deny : a client was denied use of a service. denyMult : A client was denied use of a service multiple times. error : An error has ocurred during the access control process. · Integer32

The type of access-related event that this row contains. If the event is not access-related this object will not be instantiated.

cfwBasicAuthenticationEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.7

AuthenticationEvent1 = other2 = succ3 = error4 = fail5 = succPriv6 = failPriv7 = failMultThis textual convention is used to describe various events and statistics that are related to authorization. other : Miscellaneous authentication event. succ : A client successfuly authenticated. error : Error while authenticating. fail : A client failed an authenticating. succPriv : A client accessed a service with special privileges. failPriv : A client failed to access a service with special privileges. failMult : Multiple failed authentication attempts by a client. · Integer32

The type of authentication-related event that this row contains. If the event is not authentication-related this object will not be instantiated.

cfwBasicGenericEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.8

GenericEvent1 = abnormal2 = okay3 = errorGeneric Events - events for which there is no more specific enumeration abnormal : An abnormal event has occurred that is neither 'okay' nor an 'error'. okay : A normal event occurred or the system has changed from an abnormal state to a normal state error : An error event occurred · Integer32

The type of generic event that this row contains. If the event does not fall into one of the other categories this object will be populated. Otherwise, this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwNetEventsTable

1.3.6.1.4.1.9.9.147.1.1.2.2

Index: cfwNetEventIndex

Table of detailed data for network events. The agent may choose to delete the instances of cfwBasicEventsEntry as required because of lack of memory. It is an implementation-specific matter as to when this deletion may occur. It is recommended that the oldest log instances are deleted first.

cfwNetEventIndex

1.3.6.1.4.1.9.9.147.1.1.2.2.1.1

Unsigned32

An index that uniquely identifies an entry in the log table. These indices are assigned beginning with one and increase by one with each new log entry. When this number wraps, all events are deleted in order to allow the NMS to differentiate between old and new events.

cfwNetEventInterface

1.3.6.1.4.1.9.9.147.1.1.2.2.1.2

InterfaceIndexOrZeroThis textual convention is an extension of the InterfaceIndex convention. The latter defines a greater than zero value used to identify an interface or interface sub-layer in the managed system. This extension permits the additional value of zero. the value zero is object-specific and must therefore be defined as part of the description of any object which uses this syntax. Examples of the usage of zero might include situations where interface was unknown, or when none or all interfaces need to be referenced. (0..2147483647) · Integer32 · hint d

The interface most closely associated with this event. For example, for an event that relates to the receipt of a packet, this object identifies the interface on which the packet was received. If there are multiple interfaces associated with an event, the interface most closely associated with the cause of the event will be used. For example, for an event for the setup of a TCP connection, the interface on the initiator's side of the connection would be preferred. If there is no associated interface, then this object has the value zero.

cfwNetEventSrcIpAddress

1.3.6.1.4.1.9.9.147.1.1.2.2.1.3

IpAddress SIZE (4)

Source IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is the result of multiple packets with different source addresses, this value may be zero or an address taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventInsideSrcIpAddress

1.3.6.1.4.1.9.9.147.1.1.2.2.1.4

IpAddress SIZE (4)

Source IP address after Network Address Translation has been applied. If NAT has not been applied to the source address in this packet this object will not be instantiated, resulting in a sparse table. If the event is the result of multiple packets with different source addresses, this value may be zero or an address taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventDstIpAddress

1.3.6.1.4.1.9.9.147.1.1.2.2.1.5

IpAddress SIZE (4)

Destination IP address in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is the result of multiple packets with different destination addresses, this value may be zero or an address taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventInsideDstIpAddress

1.3.6.1.4.1.9.9.147.1.1.2.2.1.6

IpAddress SIZE (4)

Destination IP address after Network Address Translation has been applied. If NAT has not been applied to the destination address in this packet this object will not be instantiated, resulting in a sparse table. If the event is the result of multiple packets with different destination addresses, this value may be zero or an address taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventSrcIpPort

1.3.6.1.4.1.9.9.147.1.1.2.2.1.7

INTEGER (0..65535) · Integer32

Source UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is the result of multiple packets with different source ports, this value may be zero or a port taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventInsideSrcIpPort

1.3.6.1.4.1.9.9.147.1.1.2.2.1.8

INTEGER (0..65535) · Integer32

Source UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the source port in this packet this object will not be instantiated, resulting in a sparse table. If the event is the result of multiple packets with different source ports, this value may be zero or a port taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventDstIpPort

1.3.6.1.4.1.9.9.147.1.1.2.2.1.9

INTEGER (0..65535) · Integer32

Destination UDP/TCP port in the IP packet that caused the event. If there is no packet associated with the event this object has the value of zero. If the event is the result of multiple packets with different destination ports, this value may be zero or a port taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventInsideDstIpPort

1.3.6.1.4.1.9.9.147.1.1.2.2.1.10

INTEGER (0..65535) · Integer32

Destination UDP/TCP port after Port Address Translation has been applied. If PAT has not been applied to the Destination port in this packet this object will not be instantiated, resulting in a sparse table. If the event is the result of multiple packets with different destination ports, this value may be zero or a port taken from an arbitrarily chosen packet in the sequence of packets causing the event.

cfwNetEventService

1.3.6.1.4.1.9.9.147.1.1.2.2.1.11

Services1 = otherFWService2 = fileXferFtp3 = fileXferTftp4 = fileXferFtps5 = loginTelnet6 = loginRlogin7 = loginTelnets8 = remoteExecSunRPC9 = remoteExecMSRPC10 = remoteExecRsh11 = remoteExecXserver12 = webHttp13 = webHttps14 = mailSmtp15 = multimediaStreamworks16 = multimediaH32317 = multimediaNetShow18 = multimediaVDOLive19 = multimediaRealAV20 = multimediaRTSP21 = dbOracle22 = dbMSsql23 = contInspProgLang24 = contInspUrl25 = directoryNis26 = directoryDns27 = directoryNetbiosns28 = directoryNetbiosdgm29 = directoryNetbiosssn30 = directoryWins31 = qryWhois32 = qryFinger33 = qryIdent34 = fsNfsStatus35 = fsNfs36 = fsCifs37 = protoIcmp38 = protoTcp39 = protoUdp40 = protoIp41 = protoSnmpThis textual convention is used to describe various services that are monitored by the firewall. otherFWService - a service that does not fit into any other category. fileXferFtp - identifies FTP, File Transfer Protocol. fileXferTftp - identifies TFTP, Trivial File Transfer Protocol fileXferFtps - identifies FTP, File Transfer Protocol running over Secure Sockets Layer. loginTelnet - identifies telnet loginRlogin - identifies rlogin. loginTelnets - identifies telnet over Secure Sockets Layer(SSL). remoteExecSunRPC - identifies Sun Remote Procedure Call Protocol. remoteExecMSRPC - identifies Microsoft Remote Procedure Call Protocol. remoteExecRsh - identifies the remote shell. remoteExecXserver - identifies the Xwindows server. webHttp - identifies Hyper Text Transfer Protocol. webHttps - identifies the secure HTTP protocol. mailSmtp - identifies SMTP, Simple Mail Transfer Protocol. mailSmtps - identifies SMTP, Simple Mail Transfer Protocol running over Secure Sockets Layer (SSL). multimediaStreamworks - identifies streamworks. multimediaH323 - identifies H323. multimediaNetShow - identifies NetShow. multimediaVDOLive - identifies vDOLive. multimediaRealAV - identifies RealAV. multimediaRTSP - identifies Real Time Streaming Protocol dbOracle - identifies Oracle's SQL*Net. dbMSsql - identifies MicroSoft SQL. contInspProgLang - identifies a payload as a programming language such as Java or ActiveX. contInspUrl - identifies a payload as a URL. directoryNis - identifies NIS, Network Information Service. directoryDns - identifies DNS, Domain Name Service. directoryNetbiosns - identifies NetBIOSNS - NetBIOS Name Service. directoryNetbiosdgm - identifies NetBIOSNS - NetBIOS datagram Service. directoryNetbiosssn - identifies NetBIOSNS - NetBIOS Session Service. directoryWins - identifies Windows Internet Naming Service (WINS). qryWhois - identifies WhoIs service. qryFinger - identifies finger. qryIdent - identifies Ident. fsNfsStatus - identifies Network File System (NFS) Status. fsNfs - identifies Network File System (NFS). fsCifs - identifies CIFS, Common Internet File Service. protoIcmp - identifies ICMP, Internet Control Message Protocol. protoTcp - identifies TCP, Transmission Control Protocol. protoUdp - identifies UDP, User Datagram Protocol. protoIp - identifies IP, Internet Protocol. protoSnmp - identifies SNMP, Simple Network Management Protocol. · Integer32

The identification of the type of service involved with this event.

cfwNetEventServiceInformation

1.3.6.1.4.1.9.9.147.1.1.2.2.1.12

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Specific service information. This can be used to describe the particular service indentified by cfwNetEventService and can reflect whether the service is a local service or a gateway service. For example, if the value for cfwNetEventService is loginTelnet then the string provided might be 'local telnet'.

cfwNetEventIdentity

1.3.6.1.4.1.9.9.147.1.1.2.2.1.13

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

This object will contain a description of the entity that caused the event. The entity could be a userid, username, processid or other identifier for the entity using the service. If there is no such information then this object will contain a zero-length string.

cfwNetEventDescription

1.3.6.1.4.1.9.9.147.1.1.2.2.1.14

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A detailed description of the event.

cfwHardwareStatusTable

1.3.6.1.4.1.9.9.147.1.2.1.1

Index: cfwHardwareType

Table of firewall cfwHardwareStatusEntry entries.

cfwHardwareType

1.3.6.1.4.1.9.9.147.1.2.1.1.1.1

Hardware1 = memory2 = disk3 = power4 = netInterface5 = cpu6 = primaryUnit7 = secondaryUnit8 = otherThis textual convention is used to describe various hardware resouces that can be monitored by the firewall. memory - identifies memory. disk - identifies disk. power - identifies power. netInterface - identifies a network interface. tape - identifies a tape drive. controller - identifies hardware controller. cpu - identifies CPU. primaryUnit - identifies the primary unit of the two identical firewalls configured redundancy. secondaryUnit - identifies the secondary unit of the two identical firewalls configured redundancy. other - identifies other hardware. · Integer32

The hardware type for which this row provides status information.

cfwHardwareInformation

1.3.6.1.4.1.9.9.147.1.2.1.1.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A detailed textual description of the resource identified by cfwHardwareType.

cfwHardwareStatusValue

1.3.6.1.4.1.9.9.147.1.2.1.1.1.3

HardwareStatus1 = other2 = up3 = down4 = error5 = overTemp6 = busy7 = noMedia8 = backup9 = active10 = standbyThis textual convention is used to describe various events that are related to the resources on a firewall. other : Generic resource event. up : The resource is in service. down : The resource is not in service. error : There has been an error for this resource. overTemp : The resource is overheating. busy : The resource is busy. noMedia : A device doesn't have its needed media. backup : Processing has switched to the backup. active : This is the active unit. standby : This is the standby unit. · Integer32

This object contains the current status of the resource.

cfwHardwareStatusDetail

1.3.6.1.4.1.9.9.147.1.2.1.1.1.4

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A detailed textual description of the current status of the resource which may provide a more specific description than cfwHardwareStatusValue.

cfwBufferStatsTable

1.3.6.1.4.1.9.9.147.1.2.2.1

Index: cfwBufferStatSize · cfwBufferStatType

A table conatining status information about a firewall's buffers.

cfwBufferStatSize

1.3.6.1.4.1.9.9.147.1.2.2.1.1.1

Unsigned32

This object contains the size of the set of buffers for which this row contains the statistics given by cfwBufferStatType.

cfwBufferStatType

1.3.6.1.4.1.9.9.147.1.2.2.1.1.2

ResourceStatistics1 = highUse2 = highLoad3 = maximum4 = minimum5 = low6 = high7 = average8 = free9 = inUseThis textual convention is used to identify various statistics that are related to the resources on a firewall. highUse : The highest load the resource has had for a time period. The time period will be implementation dependent. highLoad : The highest load the resource has had since startup. maximum : The maximum amount of the resource that is available. minimum : The minimum amount of the resource that is available. low : The lowest amount of the resource that has been available since startup. high : The highest amount of the resource that has been available since startup. average : The average amount of the resource that has been available since startup. free : The amount of the resource that is currently available since startup. inUse : The amount of the resource that is currently in use, eg. CPU usage, memory usage. · Integer32

This object identifies the type of statistic given by this row for the particular set of buffers identified by cfwBufferStatSize.

cfwBufferStatInformation

1.3.6.1.4.1.9.9.147.1.2.2.1.1.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A detailed textual description of the statistic identified by cfwBufferStatType.

cfwBufferStatValue

1.3.6.1.4.1.9.9.147.1.2.2.1.1.4

Gauge32

The value of the buffer statistic.

cfwConnectionStatTable

1.3.6.1.4.1.9.9.147.1.2.2.2

Index: cfwConnectionStatService · cfwConnectionStatType

Table of firewall statistic instances.

cfwConnectionStatService

1.3.6.1.4.1.9.9.147.1.2.2.2.1.1

Services1 = otherFWService2 = fileXferFtp3 = fileXferTftp4 = fileXferFtps5 = loginTelnet6 = loginRlogin7 = loginTelnets8 = remoteExecSunRPC9 = remoteExecMSRPC10 = remoteExecRsh11 = remoteExecXserver12 = webHttp13 = webHttps14 = mailSmtp15 = multimediaStreamworks16 = multimediaH32317 = multimediaNetShow18 = multimediaVDOLive19 = multimediaRealAV20 = multimediaRTSP21 = dbOracle22 = dbMSsql23 = contInspProgLang24 = contInspUrl25 = directoryNis26 = directoryDns27 = directoryNetbiosns28 = directoryNetbiosdgm29 = directoryNetbiosssn30 = directoryWins31 = qryWhois32 = qryFinger33 = qryIdent34 = fsNfsStatus35 = fsNfs36 = fsCifs37 = protoIcmp38 = protoTcp39 = protoUdp40 = protoIp41 = protoSnmpThis textual convention is used to describe various services that are monitored by the firewall. otherFWService - a service that does not fit into any other category. fileXferFtp - identifies FTP, File Transfer Protocol. fileXferTftp - identifies TFTP, Trivial File Transfer Protocol fileXferFtps - identifies FTP, File Transfer Protocol running over Secure Sockets Layer. loginTelnet - identifies telnet loginRlogin - identifies rlogin. loginTelnets - identifies telnet over Secure Sockets Layer(SSL). remoteExecSunRPC - identifies Sun Remote Procedure Call Protocol. remoteExecMSRPC - identifies Microsoft Remote Procedure Call Protocol. remoteExecRsh - identifies the remote shell. remoteExecXserver - identifies the Xwindows server. webHttp - identifies Hyper Text Transfer Protocol. webHttps - identifies the secure HTTP protocol. mailSmtp - identifies SMTP, Simple Mail Transfer Protocol. mailSmtps - identifies SMTP, Simple Mail Transfer Protocol running over Secure Sockets Layer (SSL). multimediaStreamworks - identifies streamworks. multimediaH323 - identifies H323. multimediaNetShow - identifies NetShow. multimediaVDOLive - identifies vDOLive. multimediaRealAV - identifies RealAV. multimediaRTSP - identifies Real Time Streaming Protocol dbOracle - identifies Oracle's SQL*Net. dbMSsql - identifies MicroSoft SQL. contInspProgLang - identifies a payload as a programming language such as Java or ActiveX. contInspUrl - identifies a payload as a URL. directoryNis - identifies NIS, Network Information Service. directoryDns - identifies DNS, Domain Name Service. directoryNetbiosns - identifies NetBIOSNS - NetBIOS Name Service. directoryNetbiosdgm - identifies NetBIOSNS - NetBIOS datagram Service. directoryNetbiosssn - identifies NetBIOSNS - NetBIOS Session Service. directoryWins - identifies Windows Internet Naming Service (WINS). qryWhois - identifies WhoIs service. qryFinger - identifies finger. qryIdent - identifies Ident. fsNfsStatus - identifies Network File System (NFS) Status. fsNfs - identifies Network File System (NFS). fsCifs - identifies CIFS, Common Internet File Service. protoIcmp - identifies ICMP, Internet Control Message Protocol. protoTcp - identifies TCP, Transmission Control Protocol. protoUdp - identifies UDP, User Datagram Protocol. protoIp - identifies IP, Internet Protocol. protoSnmp - identifies SNMP, Simple Network Management Protocol. · Integer32

The identification of the type of connection providing statistics.

cfwConnectionStatType

1.3.6.1.4.1.9.9.147.1.2.2.2.1.2

ConnectionStat1 = other2 = totalOpen3 = currentOpen4 = currentClosing5 = currentHalfOpen6 = currentInUse7 = highThis textual convention is used to describe various connections statistics. other : A generic connection event. totalOpen : Total open connections since reboot. currentOpen : The number of connections currently open. currentClosing : The number of connections currently closing. currentHalfOpen : The number of connections currently half-open. currentInUse : The number of connections currently in use. high : The highest number of connections in use at any one time since system startup. · Integer32

The state of the connections that this row contains statistics for.

cfwConnectionStatDescription

1.3.6.1.4.1.9.9.147.1.2.2.2.1.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A detailed textual description of this statistic.

cfwConnectionStatCount

1.3.6.1.4.1.9.9.147.1.2.2.2.1.4

Counter32

This is an integer that contains the value of the resource statistic. If a type of 'gauge' is more appropriate this object will be omitted resulting in a sparse table.

cfwConnectionStatValue

1.3.6.1.4.1.9.9.147.1.2.2.2.1.5

Gauge32

This is an integer that contains the value of the resource statistic. If a type of 'counter' is more appropriate this object will be omitted resulting in a sparse table.

Trap details

cfwSecurityNotification

1.3.6.1.4.1.9.9.147.2.0.2

This notification is used for events involving security events. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicSecurityEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.3

SecurityEvent1 = other2 = none3 = dos4 = recon5 = pakFwd6 = addrSpoof7 = svcSpoof8 = thirdParty9 = complete10 = invalPak11 = illegCom12 = policyThis textual convention is used to describe various security-related events and statistics on a firewall. other : Generic attack event. none : No attack is occurring, an informational event. dos : A denial of service attack has been detected. recon : A pattern of reconnaissance activity has been detected. pakFwd : A packet forwarding attack has been detected. addrSpoof : A spoofed address has been detected. svcSpoof : A spoofed service (eg., DNS) has been detected. thirdParty : This site is being used as a third-party for an attack on another network. For example, the 'smurf' attack or email spamming. complete : An attack has terminated invlPak : An invalid packet with attack characteristics has been detected. illegCmd : An illegal command has been found. policy : An attempt has reen made to violate a security policy. · Integer32

The type of security-related event that this row contains. If the event is not security-related this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwContentInspectNotification

1.3.6.1.4.1.9.9.147.2.0.3

This notification is used to notify the NMS of content inspection events. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicContentInspEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.4

ContentInspectionEvent1 = other2 = okay3 = error4 = found5 = clean6 = reject7 = savedContent inspection events, these events report that something was found in the application payload. The details entry in the event can report on what was found (eg., virus, company private info., etc), what it was found in (eg., html, win32 executable, e-mail), and what was done with it (eg., the quarantine location). other : A content inspection event. Used to indicate that some content inspection has occurred that is not covered by the other content inspection enumerations. okay : The check of the content was okay, nothing 'bad' was found. error : There was an error while checking the content. found : Something was found that the content inspection engine has determined merits attention. clean : The content inspection engine has found something that violates the security policy and has neutralized the content in the data flow. reject : The content inspection engine has found something that violates the security policy and has discarded the content. saved : The content inspection engine has found something that violates the security policy and has stored it in a quarentine storage area. · Integer32

The type of content inspection-related event that this row contains. If the event is not content inspection-related this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwConnNotification

1.3.6.1.4.1.9.9.147.2.0.4

This notification is used to notify the NMS of connection-oriented events. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicConnectionEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.5

ConnectionEvent1 = other2 = accept3 = error4 = drop5 = close6 = timeout7 = refused8 = reset9 = noRespThis textual convention is used to describe various events and statistics that are related to the connections that occur on a firewall. other : A generic connection event. accept : A connection has been acccepted. error : An error has occurred for a connection. drop : The connection has been dropped. close : A connection has been closed. timeout : A connection has been timed out. refused : A connection has been refused. reset : A connection has been reset. noResp : A connection has received no response. · Integer32

The type of connection-related event that this row contains. If the event is not connection-related this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwAccessNotification

1.3.6.1.4.1.9.9.147.2.0.5

This notification is used to notify the NMS of access events. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicAccessEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.6

AccessEvent1 = other2 = grant3 = deny4 = denyMult5 = errorThis textual convention is used to describe various events and statistics that are related to the access control on a firewall. other : Miscellaneous access event. grant : A service has allowed access based on all of its access checks. deny : a client was denied use of a service. denyMult : A client was denied use of a service multiple times. error : An error has ocurred during the access control process. · Integer32

The type of access-related event that this row contains. If the event is not access-related this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwAuthNotification

1.3.6.1.4.1.9.9.147.2.0.6

This notification is used to notify the NMS of authentication events. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicAuthenticationEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.7

AuthenticationEvent1 = other2 = succ3 = error4 = fail5 = succPriv6 = failPriv7 = failMultThis textual convention is used to describe various events and statistics that are related to authorization. other : Miscellaneous authentication event. succ : A client successfuly authenticated. error : Error while authenticating. fail : A client failed an authenticating. succPriv : A client accessed a service with special privileges. failPriv : A client failed to access a service with special privileges. failMult : Multiple failed authentication attempts by a client. · Integer32

The type of authentication-related event that this row contains. If the event is not authentication-related this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

cfwGenericNotification

1.3.6.1.4.1.9.9.147.2.0.7

This notification is used to notify the NMS of events that do not fall into the other categories. The included objects provide more detailed information about the event.

cfwBasicEventTime

1.3.6.1.4.1.9.9.147.1.1.1.2.1.2

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The time that the event occurred.

cfwBasicGenericEventType

1.3.6.1.4.1.9.9.147.1.1.1.2.1.8

GenericEvent1 = abnormal2 = okay3 = errorGeneric Events - events for which there is no more specific enumeration abnormal : An abnormal event has occurred that is neither 'okay' nor an 'error'. okay : A normal event occurred or the system has changed from an abnormal state to a normal state error : An error event occurred · Integer32

The type of generic event that this row contains. If the event does not fall into one of the other categories this object will be populated. Otherwise, this object will not be instantiated.

cfwBasicEventDescription

1.3.6.1.4.1.9.9.147.1.1.1.2.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

A description of the event. The value of the object may be a zero-length string.

cfwBasicEventDetailsTableRow

1.3.6.1.4.1.9.9.147.1.1.1.2.1.10

RowPointerRepresents a pointer to a conceptual row. The value is the name of the instance of the first accessible columnar object in the conceptual row. For example, ifIndex.3 would point to the 3rd row in the ifTable (note that if ifIndex were not-accessible, then ifDescr.3 would be used instead). · OBJECT IDENTIFIER

A pointer to a row in the table containing details about this event. Generally, the table will be the cfwNetEventsTable but a Cisco-defined table may also appear here. If there there is no more detailed information for this event the value of this object will have the value {0 0}.

↑ To TOC