EZ5 MIB Catalog

CISCO-UNIFIED-FIREWALL-MIB

2021-03-18

Overview of Cisco Firewall MIB ============================== This MIB Module models status and performance statistics pertaining to the common features supported by Cisco firewall implementations. For each firewall feature, capability (if applicable) and statistics are defined. Supporting the configuration of firewall features is outside the scope of this MIB. Following are the major firewall features: 1) 'Stateful Packet Filtering' Creating and maintaining the state of authorized traffic flows dynamically to permit only flows authorized by the policy is a mandatory function of a firewall. This MIB instruments the activity and memory usage by this function. 2) 'Application Inspection' This refers to the function of inspecting the headers of layer 3 and layer 4 protocols and creating dynamic entries in the connection table for traffic flows spawned by an already established traffic flow. This MIB reflects the protocols that are being inspected. 3) 'URL Filtering' This refers to the function of facilitating or restricting URL access requests through the firewall by consulting either local policy or that configured on a dedicated URL filtering server. This MIB instruments the URL filtering activity, the status and activity of distinct URL filtering servers configured on the firewall and the impact of the performance of the URL filtering servers on the latency and throughput of the firewall. 4) 'Proxy Authentication' This refers to the function of authenticating and/or authorizing users on behalf of servers on the secure side of the firewall. This operation could affect the throughput of the firewall. The MIB objects pertaining to Proxy Authentication will be defined in a subsequent revision of this MIB. 5) 'Transparent Mode Operation' A firewall could operate as a bridge and yet filter traffic based on layer 3-layer 7 control and payload information. Operating in this mode makes it easy to implement a firewall without fragmenting existing subnets. Another advantage of this mode of operation is enhanced security. This MIB instruments the status, activity, and performance of the firewall in this mode. Please note that to fully manage a firewall operating in this mode, the firewall must also support the bridge MIB (BRIDGE-MIB). 6) 'Advanced Application Inspection and Control' This function is also termed 'Application Firewall' and pertains to inspecting payload and headers of application traffic to make sure the traffic flows conform to the configured security policy. Monitoring this function entails identifying the security alerts generated by this function and measuring the impact on firewall performance by this task. Application Firewall will be instrumented in a separate MIB dedicated for the function. 7) 'Failover' or 'Redundancy' Redundancy configuration is essential for business critical firewalls. Instrumenting this function entails reflecting the configuration of redundancy and identifying failover events. The MIB objects pertaining to Proxy Authentication will be defined in a subsequent revision of this MIB. The management information for each firewall feature is defined in a distinct module compliance unit. The compliance units corresponding to basic features of firewalls are defined as mandatory. Acronyms ======== Following are definitions of some terms used in this module. Please refer to the module conformance for a glossary of feature-specific terms. `Firewall' A firewall is a set of related programs, implemented on a host or a network device, that protects the resources of a private network from users from other networks. Common firewalling functions include stateful packet filtering, proxy authentication of users on behalf of applications on the secure side of the firewall, URL access control, inspection of payload of traffic streams to determine security threats. `Layer2 Firewall' or 'Transparent Firewall' A firewall device that operates as a bridge while performing firewalling function. `Connection' The record in the firewall of a traffic strean that has been authorized to flow through the firewall. `Half Open Connection' For a connection oriented protocol: a connection that has not reached the established on both the sides of the connection. For a connection-less protocol: the connection corresponding to a traffic stream where traffic flow has occurred (since the establishment of the connection entry) only on one direction. `Embryonic Connection' The connection entry corresponding to an application layer protocol in which the signaling channel has been established while the setup of the data channel is underway. `Policy' An element of firewall configuration that identifies the access rights to a resource by a traffic source. An example of a policy is an Access Control Rule. `Policy Target' An entity to which a policy is applied so that the action corresponding to the policy is taken only on traffic streams associated with the entity. An example of a policy target is an interface. `URL Filtering Server' A server which is employed by the firewall to enforce URL access policies. `Protocol Data Unit' or PDU An instance of the unit of information using which a protocol operates is called the Protocol Data Unit or the PDU of the protocol. `Deep Packet Inspection' The task of examining the contents of the payloads of one or more layer 7 application protocols with a view to enforcing the local security policies termed 'Deep Packet Inspection'. `Advanced Application Inspection and Control' An entity that performs deep packet inspection of layer 7 application protocol data units is termed an 'Application Firewall'.

Download CISCO-UNIFIED-FIREWALL-MIB.txt Open CISCO-UNIFIED-FIREWALL-MIB.txt in a new tab

SCALARS (119) · TABLES (14) · TRAPS (4)

Scalars (119)

NameOID
cufwConnGlobalNumAttempted1.3.6.1.4.1.9.9.491.1.1.1.1
cufwConnGlobalNumSetupsAborted1.3.6.1.4.1.9.9.491.1.1.1.2
cufwConnGlobalNumPolicyDeclined1.3.6.1.4.1.9.9.491.1.1.1.3
cufwConnGlobalNumResDeclined1.3.6.1.4.1.9.9.491.1.1.1.4
cufwConnGlobalNumHalfOpen1.3.6.1.4.1.9.9.491.1.1.1.5
cufwConnGlobalNumActive1.3.6.1.4.1.9.9.491.1.1.1.6
cufwConnGlobalNumExpired1.3.6.1.4.1.9.9.491.1.1.1.7
cufwConnGlobalNumAborted1.3.6.1.4.1.9.9.491.1.1.1.8
cufwConnGlobalNumEmbryonic1.3.6.1.4.1.9.9.491.1.1.1.9
cufwConnGlobalConnSetupRate11.3.6.1.4.1.9.9.491.1.1.1.10
cufwConnGlobalConnSetupRate51.3.6.1.4.1.9.9.491.1.1.1.11
cufwConnGlobalNumRemoteAccess1.3.6.1.4.1.9.9.491.1.1.1.12
cufwConnResMemoryUsage1.3.6.1.4.1.9.9.491.1.1.2.1
cufwConnResActiveConnMemoryUsage1.3.6.1.4.1.9.9.491.1.1.2.2
cufwConnResHOConnMemoryUsage1.3.6.1.4.1.9.9.491.1.1.2.3
cufwConnResEmbrConnMemoryUsage1.3.6.1.4.1.9.9.491.1.1.2.4
cufwConnReptAppStats1.3.6.1.4.1.9.9.491.1.1.3.1
cufwConnReptAppStatsLastChanged1.3.6.1.4.1.9.9.491.1.1.3.2
cufwAIAuditTrailEnabled1.3.6.1.4.1.9.9.491.1.2.1
cufwAIAlertEnabled1.3.6.1.4.1.9.9.491.1.2.2
cufwUrlfFunctionEnabled1.3.6.1.4.1.9.9.491.1.3.1.1
cufwUrlfRequestsNumProcessed1.3.6.1.4.1.9.9.491.1.3.1.2
cufwUrlfRequestsProcRate11.3.6.1.4.1.9.9.491.1.3.1.3
cufwUrlfRequestsProcRate51.3.6.1.4.1.9.9.491.1.3.1.4
cufwUrlfRequestsNumAllowed1.3.6.1.4.1.9.9.491.1.3.1.5
cufwUrlfRequestsNumDenied1.3.6.1.4.1.9.9.491.1.3.1.6
cufwUrlfRequestsDeniedRate11.3.6.1.4.1.9.9.491.1.3.1.7
cufwUrlfRequestsDeniedRate51.3.6.1.4.1.9.9.491.1.3.1.8
cufwUrlfRequestsNumCacheAllowed1.3.6.1.4.1.9.9.491.1.3.1.9
cufwUrlfRequestsNumCacheDenied1.3.6.1.4.1.9.9.491.1.3.1.10
cufwUrlfAllowModeReqNumAllowed1.3.6.1.4.1.9.9.491.1.3.1.11
cufwUrlfAllowModeReqNumDenied1.3.6.1.4.1.9.9.491.1.3.1.12
cufwUrlfRequestsNumResDropped1.3.6.1.4.1.9.9.491.1.3.1.13
cufwUrlfRequestsResDropRate11.3.6.1.4.1.9.9.491.1.3.1.14
cufwUrlfRequestsResDropRate51.3.6.1.4.1.9.9.491.1.3.1.15
cufwUrlfNumServerTimeouts1.3.6.1.4.1.9.9.491.1.3.1.16
cufwUrlfNumServerRetries1.3.6.1.4.1.9.9.491.1.3.1.17
cufwUrlfResponsesNumLate1.3.6.1.4.1.9.9.491.1.3.1.18
cufwUrlfUrlAccRespsNumResDropped1.3.6.1.4.1.9.9.491.1.3.1.19
cufwUrlfResTotalRequestCacheSize1.3.6.1.4.1.9.9.491.1.3.2.1
cufwUrlfResTotalRespCacheSize1.3.6.1.4.1.9.9.491.1.3.2.2
cufwFOEnabled1.3.6.1.4.1.9.9.491.1.4.1.1
cufwFOUnitDesignation1.3.6.1.4.1.9.9.491.1.4.1.2
cufwFOLink1.3.6.1.4.1.9.9.491.1.4.1.3
cufwFOStateLink1.3.6.1.4.1.9.9.491.1.4.1.4
cufwFOStdbyConfigLocked1.3.6.1.4.1.9.9.491.1.4.1.5
cufwFOEncryption1.3.6.1.4.1.9.9.491.1.4.1.6
cufwFOSerialNumOurs1.3.6.1.4.1.9.9.491.1.4.1.7
cufwFOSerialNumMate1.3.6.1.4.1.9.9.491.1.4.1.8
cufwFOSwVersionOurs1.3.6.1.4.1.9.9.491.1.4.1.9
cufwFOSwVersionMate1.3.6.1.4.1.9.9.491.1.4.1.10
cufwFOUnitPolltime1.3.6.1.4.1.9.9.491.1.4.1.11
cufwFOUnitHoldtime1.3.6.1.4.1.9.9.491.1.4.1.12
cufwFOUnitBfdEnabled1.3.6.1.4.1.9.9.491.1.4.1.13
cufwFOLinkStatePolltime1.3.6.1.4.1.9.9.491.1.4.1.14
cufwFOInterfacePolicy1.3.6.1.4.1.9.9.491.1.4.1.15
cufwFOMonitoredInterfaces1.3.6.1.4.1.9.9.491.1.4.1.16
cufwFOInterfacePolltime1.3.6.1.4.1.9.9.491.1.4.1.17
cufwFOInterfaceHoldtime1.3.6.1.4.1.9.9.491.1.4.1.18
cufwFOReplicationHttp1.3.6.1.4.1.9.9.491.1.4.1.19
cufwFOReplicationRate1.3.6.1.4.1.9.9.491.1.4.1.20
cufwFOStatefulUpdateEnabled1.3.6.1.4.1.9.9.491.1.4.3.1
cuFwFOMaxStateEvents1.3.6.1.4.1.9.9.491.1.4.4.1
cufwAaicGlobalNumBadProtocolOps1.3.6.1.4.1.9.9.491.1.5.1.1
cufwAaicGlobalNumBadPDUSize1.3.6.1.4.1.9.9.491.1.5.1.2
cufwAaicGlobalNumBadPortRange1.3.6.1.4.1.9.9.491.1.5.1.3
cufwAaicHttpNumBadProtocolOps1.3.6.1.4.1.9.9.491.1.5.2.1.1
cufwAaicHttpNumBadPDUSize1.3.6.1.4.1.9.9.491.1.5.2.1.2
cufwAaicHttpNumTunneledConns1.3.6.1.4.1.9.9.491.1.5.2.1.3
cufwAaicHttpNumLargeURIs1.3.6.1.4.1.9.9.491.1.5.2.1.4
cufwAaicHttpNumBadContent1.3.6.1.4.1.9.9.491.1.5.2.1.5
cufwAaicHttpNumMismatchContent1.3.6.1.4.1.9.9.491.1.5.2.1.6
cufwAaicHttpNumDoubleEncodedPkts1.3.6.1.4.1.9.9.491.1.5.2.1.7
cufwAaicPassedSnortCount1.3.6.1.4.1.9.9.491.1.5.3.1.1
cufwAaicBlockedSnortCount1.3.6.1.4.1.9.9.491.1.5.3.1.2
cufwAaicInjbySnortCount1.3.6.1.4.1.9.9.491.1.5.3.1.3
cufwAaicBypassSnortDownCount1.3.6.1.4.1.9.9.491.1.5.3.1.4
cufwAaicBypassSnortBusyCount1.3.6.1.4.1.9.9.491.1.5.3.1.5
cufwAaicFastfwdFlowsCount1.3.6.1.4.1.9.9.491.1.5.3.1.6
cufwAaicBlacklistedFlowsCount1.3.6.1.4.1.9.9.491.1.5.3.1.7
cufwAaicStartofFlowEvCount1.3.6.1.4.1.9.9.491.1.5.3.1.8
cufwAaicEndofFlowEvCount1.3.6.1.4.1.9.9.491.1.5.3.1.9
cufwAaicDeniedFlowEvCount1.3.6.1.4.1.9.9.491.1.5.3.1.10
cufwAaicFwdbeforeDropCount1.3.6.1.4.1.9.9.491.1.5.3.1.11
cufwAaicInjDropCount1.3.6.1.4.1.9.9.491.1.5.3.1.12
cufwAaicIntrusionEvtRate1.3.6.1.4.1.9.9.491.1.5.3.2.1
cufwL2GlobalEnableStealthMode1.3.6.1.4.1.9.9.491.1.6.1.1
cufwL2GlobalArpCacheSize1.3.6.1.4.1.9.9.491.1.6.1.2
cufwL2GlobalEnableArpInspection1.3.6.1.4.1.9.9.491.1.6.1.3
cufwL2GlobalNumArpRequests1.3.6.1.4.1.9.9.491.1.6.1.5
cufwL2GlobalNumIcmpRequests1.3.6.1.4.1.9.9.491.1.6.1.6
cufwL2GlobalNumFloods1.3.6.1.4.1.9.9.491.1.6.1.7
cufwL2GlobalNumDrops1.3.6.1.4.1.9.9.491.1.6.1.8
cufwL2GlobalArpOverflowRate51.3.6.1.4.1.9.9.491.1.6.1.9
cufwL2GlobalNumBadArpResponses1.3.6.1.4.1.9.9.491.1.6.1.10
cufwL2GlobalNumSpoofedArpResps1.3.6.1.4.1.9.9.491.1.6.1.11
cufwCntlUrlfServerStatusChange1.3.6.1.4.1.9.9.491.1.7.1
cufwCntlL2StaticMacAddressMoved1.3.6.1.4.1.9.9.491.1.7.2
cufwCntlFOstateChange1.3.6.1.4.1.9.9.491.1.7.3
cufwCntlCluStateChange1.3.6.1.4.1.9.9.491.1.7.4
cufwCluEnabled1.3.6.1.4.1.9.9.491.1.8.1.1
cufwCluInterfaceMode1.3.6.1.4.1.9.9.491.1.8.1.2
cufwCluUnitState1.3.6.1.4.1.9.9.491.1.8.1.3
cufwCCLink1.3.6.1.4.1.9.9.491.1.8.1.4
cufwCluGroupName1.3.6.1.4.1.9.9.491.1.8.1.5
cufwCluUnitName1.3.6.1.4.1.9.9.491.1.8.1.6
cufwCluConsoleReplicate1.3.6.1.4.1.9.9.491.1.8.1.7
cufwCluSiteID1.3.6.1.4.1.9.9.491.1.8.1.8
cufwCluPriority1.3.6.1.4.1.9.9.491.1.8.1.9
cufwCluSerialNum1.3.6.1.4.1.9.9.491.1.8.1.10
cufwCCLipAddr1.3.6.1.4.1.9.9.491.1.8.1.11
cufwCCLmacAddr1.3.6.1.4.1.9.9.491.1.8.1.12
cufwCluSwVersion1.3.6.1.4.1.9.9.491.1.8.1.13
cufwCluUnitHoldtime1.3.6.1.4.1.9.9.491.1.8.1.14
cufwCluLastJoinAt1.3.6.1.4.1.9.9.491.1.8.1.15
cufwCluLastLeaveAt1.3.6.1.4.1.9.9.491.1.8.1.16
cuFwCluUnitHealth1.3.6.1.4.1.9.9.491.1.8.2.1
cufwCluOverallHealth1.3.6.1.4.1.9.9.491.1.8.2.2
cuFwCluMaxStateEvents1.3.6.1.4.1.9.9.491.1.8.3.1

Tables (14)

NameOID
cufwConnSummaryTable1.3.6.1.4.1.9.9.491.1.1.4.1
cufwAppConnSummaryTable1.3.6.1.4.1.9.9.491.1.1.4.2
cufwPolicyConnSummaryTable1.3.6.1.4.1.9.9.491.1.1.4.3
cufwPolicyAppConnSummaryTable1.3.6.1.4.1.9.9.491.1.1.4.4
cufwInspectionTable1.3.6.1.4.1.9.9.491.1.2.3
cufwUrlfServerTable1.3.6.1.4.1.9.9.491.1.3.3.1
cufwFOGrpStatusTable1.3.6.1.4.1.9.9.491.1.4.2.1
cufwFOInterfaceTable1.3.6.1.4.1.9.9.491.1.4.2.2
cufwFOLogicalUpdatesTable1.3.6.1.4.1.9.9.491.1.4.3.2
cufwFOHistoryEvTable1.3.6.1.4.1.9.9.491.1.4.4.3
cufwAspFrameDropsTable1.3.6.1.4.1.9.9.491.1.5.3.3
cufwAspFlowDropsTable1.3.6.1.4.1.9.9.491.1.5.3.4
cufwCluInterfaceTable1.3.6.1.4.1.9.9.491.1.8.2.3
cufwCluHistEvTable1.3.6.1.4.1.9.9.491.1.8.3.2

Traps (4)

NameOID
ciscoUFwUrlfServerStateChange1.3.6.1.4.1.9.9.491.0.1
ciscoUFwL2StaticMacAddressMoved1.3.6.1.4.1.9.9.491.0.2
cufwFailoverStateChanged1.3.6.1.4.1.9.9.491.0.3
cufwClusterStateChanged1.3.6.1.4.1.9.9.491.0.4

END OF TOC

Scalar details

cufwConnGlobalNumAttempted

1.3.6.1.4.1.9.9.491.1.1.1.1

Counter64 (0..18446744073709551615) · Connections

Connection Statistics Aggregation Connection 1 +-----------+ ------------->| |-------> Global Connection Summary Connection 2 | | ------------->| | Connection 3 | | ------------->| First |------------> ConnSummary | Level | (i.e, L-3/4 Protocol Connection 4 |Aggregation| Connection Summary) ------------->| | . | | . | |---------------> PolicyConnSummary Connection N | | (i.e, L-3/4 Policy Target based ------------->| | Protocol Connection Summary) +-----------+ +-----------+ L-3/4 Protocol | | Connection Summary | | ------------------>| |---------> AppConnSummary | | (i.e, L-7 Protocol | Second | Connection Summary) |---Level---| L-3/4 Policy Target |Aggregation| based Protocol | | Connection Summary | | ------------------>| |---------------> PolicyAppConnSummary | | (i.e, L-7 Policy Target based | | Protocol Connection Summary) +-----------+ Specifically, the object 'cufwConnGlobalNumAttempted' models the number of connections which are attempted to be set up through the firewall. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumSetupsAborted

1.3.6.1.4.1.9.9.491.1.1.1.2

Counter64 (0..18446744073709551615) · Connections

The number of connection setup attempts that were aborted before the connection could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt. Consequently, this value subsumes the values of objects 'cufwConnGlobalNumPolicyDeclined' and 'cufwConnGlobalNumResDeclined'. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumPolicyDeclined

1.3.6.1.4.1.9.9.491.1.1.1.3

Counter64 (0..18446744073709551615) · Connections

The number of connections which were attempted to be setup but which were declined due to reasons of security policy. This includes the connections that failed authentication. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumResDeclined

1.3.6.1.4.1.9.9.491.1.1.1.4

Counter64 (0..18446744073709551615) · Connections

The number of connections which were attempted to be setup but which were declined due to non-availability of required resources. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumHalfOpen

1.3.6.1.4.1.9.9.491.1.1.1.5

Gauge32 · Connections

The number of connections which are in the process of being setup but which have not yet reached the established state in the connection table.

cufwConnGlobalNumActive

1.3.6.1.4.1.9.9.491.1.1.1.6

Gauge32 · Connections

The number of connections which are currently active.

cufwConnGlobalNumExpired

1.3.6.1.4.1.9.9.491.1.1.1.7

Counter64 (0..18446744073709551615) · Connections

The number of connections which were active but which were since normally terminated. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumAborted

1.3.6.1.4.1.9.9.491.1.1.1.8

Counter64 (0..18446744073709551615) · Connections

The number of connections which were active but which were aborted by the firewall due to reasons of policy or resource rationing. This value is accumulated from the last reboot of the firewall.

cufwConnGlobalNumEmbryonic

1.3.6.1.4.1.9.9.491.1.1.1.9

Gauge32 · Connections

The number of embryonic application layer connections (that is, connections in which the signaling channel has been established while the data channel is awaiting setup). This value is accumulated from the last reboot of the firewall.

cufwConnGlobalConnSetupRate1

1.3.6.1.4.1.9.9.491.1.1.1.10

Gauge32 · Connections per second

The averaged number of connections which the firewall establishing per second, averaged over the last 60 seconds.

cufwConnGlobalConnSetupRate5

1.3.6.1.4.1.9.9.491.1.1.1.11

Gauge32 · Connections per second

The averaged number of connections which the firewall establishing per second, averaged over the last 300 seconds.

cufwConnGlobalNumRemoteAccess

1.3.6.1.4.1.9.9.491.1.1.1.12

Gauge32 · Connections

The number of active connections which correspond to remote access applications. Specifically, the protocol for which the connection is established must be one of PPP, PPTP, L2TP or remote access IPsec (IPsec connections employing extended authentication). This value is accumulated from the last reboot of the firewall.

cufwConnResMemoryUsage

1.3.6.1.4.1.9.9.491.1.1.2.1

Gauge32 · KBytes

The amount of memory occupied by all structures required to maintain the state of all connections which are either being established or are active.

cufwConnResActiveConnMemoryUsage

1.3.6.1.4.1.9.9.491.1.1.2.2

Gauge32 · KBytes

The amount of memory occupied by all structures required to maintain the state of all active connections.

cufwConnResHOConnMemoryUsage

1.3.6.1.4.1.9.9.491.1.1.2.3

Gauge32 · KBytes

The amount of memory occupied by all structures required to maintain the state of all half open connections.

cufwConnResEmbrConnMemoryUsage

1.3.6.1.4.1.9.9.491.1.1.2.4

Gauge32 · KBytes

The amount of memory occupied by all structures required to maintain the state of all embryonic connections.

cufwConnReptAppStats

1.3.6.1.4.1.9.9.491.1.1.3.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

Setting this object to 'true' enables the MIB to report connection activity statistics pertaining to application protocols. If this object is set to 'false', the agent should stop updating the objects defined in this module pertaining to application protocols. Application monitoring could be a resource intensive operation. It is expected that the administrators would use this control to disable application monitoring when the performance of the firewall is degrading.

cufwConnReptAppStatsLastChanged

1.3.6.1.4.1.9.9.491.1.1.3.2

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

The time at which the value of cufwConnReptAppStats was last changed.

cufwAIAuditTrailEnabled

1.3.6.1.4.1.9.9.491.1.2.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The value identifies if audit trail in application inspection has been globally enabled or disabled.

cufwAIAlertEnabled

1.3.6.1.4.1.9.9.491.1.2.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The value identifies if application inspection alerts have been globally enabled or disabled.

cufwUrlfFunctionEnabled

1.3.6.1.4.1.9.9.491.1.3.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

URL Filtering Operation _________ 2.2 Request | | |---------->| Server | | | | _________ __|_ |_________| | |<--(5. Response )---| | 3. Response | | | | |<-------------| | Client |---(1. Request )--->|FW | |_________| |____|<--------------| | 4. URLF Resp ____|______ | | | |------------>|URLF Server| 2.1 URLF Req |___________| 1) Client sends a Request containing a URL to the Server 2.1) FW extracts the URL from the Request and sends it to URL Filtering Server (or Verifies the URL locally) 2.2) FW also forwards the original Request from the Client to the Server 3) Any Responses from the Server received before receiving a response from URLF Server are cached by the FW 4) URLF Response indicates whether the URL access should be allowed or denied 5) If the URLF Response allows the URL, FW forwards the URL Access responses from the Server to the Client 6) If the URLF Response indicates that the URL access should be denied, FW drops all the cached URL responses and forces the connection between the Client and the Server to be terminated Specifically, the object cufwUrlfFunctionEnabled indicates if the URL filtering function is enabled. When this MIB object contains the value 'false', the firewall device will not perform URL filtering function, even if it contains configuration pertaining to other aspects of URL filtering.

cufwUrlfRequestsNumProcessed

1.3.6.1.4.1.9.9.491.1.3.1.2

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests processed by this firewall. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsProcRate1

1.3.6.1.4.1.9.9.491.1.3.1.3

Gauge32 · Requests per second

The number of URL access requests processed per seconds by this firewall averaged over the last 60 seconds.

cufwUrlfRequestsProcRate5

1.3.6.1.4.1.9.9.491.1.3.1.4

Gauge32 · Requests per second

The number of URL access requests processed per second by this firewall averaged over the last 300 seconds.

cufwUrlfRequestsNumAllowed

1.3.6.1.4.1.9.9.491.1.3.1.5

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests allowed by this firewall, due to a directive from a URL filtering server or a static policy configured on the firewall. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsNumDenied

1.3.6.1.4.1.9.9.491.1.3.1.6

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests declined by this firewall, due to a directive from a URL filtering server, a static policy configured on the firewall, due to resource constraints or any other reason. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsDeniedRate1

1.3.6.1.4.1.9.9.491.1.3.1.7

Gauge32 · Requests per second

The rate at which URL access requests were denied by this firewall, due to a directive from a URL filtering server, a static policy configured on the firewall, due to resource constraints or any other reason, averaged over the last 60 seconds.

cufwUrlfRequestsDeniedRate5

1.3.6.1.4.1.9.9.491.1.3.1.8

Gauge32 · Requests Per Second

The rate at which URL access requests were denied by this firewall, due to a directive from a URL filtering server, a static policy configured on the firewall, due to resource constraints or any other reason, averaged over the last 300 seconds.

cufwUrlfRequestsNumCacheAllowed

1.3.6.1.4.1.9.9.491.1.3.1.9

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests allowed by the firewall because of a cached entry holding the result from a previous URL access request that was handled either by a URLF Server or exclusive domain configuration. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsNumCacheDenied

1.3.6.1.4.1.9.9.491.1.3.1.10

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests denied by the firewall because of a cached entry holding the result from a previous URL access request that was handled either by a URLF Server or exclusive domain configuration. This value is accumulated from the last reboot of the firewall.

cufwUrlfAllowModeReqNumAllowed

1.3.6.1.4.1.9.9.491.1.3.1.11

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests that were allowed by the firewall when the URL filtering server was not available. This value is accumulated from the last reboot of the firewall.

cufwUrlfAllowModeReqNumDenied

1.3.6.1.4.1.9.9.491.1.3.1.12

Counter64 (0..18446744073709551615) · Requests

The number of URL access requests that were declined by the firewall when the URL filtering server was not available. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsNumResDropped

1.3.6.1.4.1.9.9.491.1.3.1.13

Counter64 (0..18446744073709551615) · Requests

The number of incoming URL access requests that were dropped by the firewall because of resource constraints. This value is accumulated from the last reboot of the firewall.

cufwUrlfRequestsResDropRate1

1.3.6.1.4.1.9.9.491.1.3.1.14

Gauge32 · Requests Per Second

The rate at which incoming URL access requests were dropped by the firewall because of resource constraints, averaged over the last 60 seconds.

cufwUrlfRequestsResDropRate5

1.3.6.1.4.1.9.9.491.1.3.1.15

Gauge32 · Requests Per Second

The rate at which incoming URL access requests were dropped by the firewall because of resource constraints, averaged over the last 300 seconds.

cufwUrlfNumServerTimeouts

1.3.6.1.4.1.9.9.491.1.3.1.16

Counter64 (0..18446744073709551615)

The number of times the firewall failed to receive a response from the configured URL filtering servers for a request to authorize a URL access request. This is equal to the number of times a firewall removed a URL access request from the queue of pending requests because no response was received from the URL filtering server(s). This value is accumulated from the last reboot of the firewall.

cufwUrlfNumServerRetries

1.3.6.1.4.1.9.9.491.1.3.1.17

Counter64 (0..18446744073709551615)

The number of URL access authorization requests re-sent by the firewall to the URL Filtering Servers because a response was not received within the configured time interval. This value is accumulated from the last reboot of the firewall.

cufwUrlfResponsesNumLate

1.3.6.1.4.1.9.9.491.1.3.1.18

Counter64 (0..18446744073709551615) · Responses

The number of responses from URL filtering servers which were received after the original URL access request was removed from the queue of pending requests. This value is accumulated from the last reboot of the firewall.

cufwUrlfUrlAccRespsNumResDropped

1.3.6.1.4.1.9.9.491.1.3.1.19

Counter64 (0..18446744073709551615) · Responses

The number of transport packets constituting responses to URL access requests that were dropped by the firewall due to resource constraints waiting for a response from the filtering server. This value is accumulated from the last reboot of the firewall.

cufwUrlfResTotalRequestCacheSize

1.3.6.1.4.1.9.9.491.1.3.2.1

Gauge32 · KBytes

The amount of memory occupied by all the caches used in the firewall to cache pending URL access requests.

cufwUrlfResTotalRespCacheSize

1.3.6.1.4.1.9.9.491.1.3.2.2

Gauge32 · KBytes

The amount of memory occupied by all the caches used in the firewall to cache responses for URL requests received from servers while awaiting a response from URL filter server.

cufwFOEnabled

1.3.6.1.4.1.9.9.491.1.4.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This value depicts if failover is enabled or not on the device.

cufwFOUnitDesignation

1.3.6.1.4.1.9.9.491.1.4.1.2

Hardware1 = memory2 = disk3 = power4 = netInterface5 = cpu6 = primaryUnit7 = secondaryUnit8 = otherThis textual convention is used to describe various hardware resouces that can be monitored by the firewall. memory - identifies memory. disk - identifies disk. power - identifies power. netInterface - identifies a network interface. tape - identifies a tape drive. controller - identifies hardware controller. cpu - identifies CPU. primaryUnit - identifies the primary unit of the two identical firewalls configured redundancy. secondaryUnit - identifies the secondary unit of the two identical firewalls configured redundancy. other - identifies other hardware. · Integer32

The hardware type that points to designation as primary or secondary unit.

1.3.6.1.4.1.9.9.491.1.4.1.3

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The ifIndex of the interface used for failover communication between the two units.

1.3.6.1.4.1.9.9.491.1.4.1.4

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The ifIndex of the interface used for failover communication to pass connection state information.

cufwFOStdbyConfigLocked

1.3.6.1.4.1.9.9.491.1.4.1.5

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object depicts if the the ability to make any configuration changes directly on the standby unit or context is enabled.

cufwFOEncryption

1.3.6.1.4.1.9.9.491.1.4.1.6

Integer32 (0..2)

The type of encryption enabled on the failover links between the units to encrypt all failover communications. Value Type 0 none 1 IPSec LAN-to-LAN tunnels 2 Key Passphrase

cufwFOSerialNumOurs

1.3.6.1.4.1.9.9.491.1.4.1.7

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific serial number string for the current unit in pair.

cufwFOSerialNumMate

1.3.6.1.4.1.9.9.491.1.4.1.8

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific serial number string for the peer unit in pair.

cufwFOSwVersionOurs

1.3.6.1.4.1.9.9.491.1.4.1.9

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific software revision string for the current unit in pair.

cufwFOSwVersionMate

1.3.6.1.4.1.9.9.491.1.4.1.10

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific software revision string for the peer unit in pair.

cufwFOUnitPolltime

1.3.6.1.4.1.9.9.491.1.4.1.11

Integer32 (200..15000) · millisec

The polling frequency of the Hello packets between the units in HA pair.

cufwFOUnitHoldtime

1.3.6.1.4.1.9.9.491.1.4.1.12

Integer32 (800..45000) · millisec

The hold time that each unit will wait before declaring the peer unit as dead. If the failed unit is the active unit, the standby unit takes over as the active unit.

cufwFOUnitBfdEnabled

1.3.6.1.4.1.9.9.491.1.4.1.13

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object depicts if BFD protocol is enabled between the units for health monitoring.

cufwFOLinkStatePolltime

1.3.6.1.4.1.9.9.491.1.4.1.14

Integer32 (300..799) · millisec

The frequency at which the link-state of a unit's interfaces are polled to detect link failures.

cufwFOInterfacePolicy

1.3.6.1.4.1.9.9.491.1.4.1.15

Integer32 (1..1025)

The count of interface failures set as threshold to trigger switchover when interfaces are declared as health-check failed.

cufwFOMonitoredInterfaces

1.3.6.1.4.1.9.9.491.1.4.1.16

Gauge32

The count of interfaces monitored on the HA units for interface health.

cufwFOInterfacePolltime

1.3.6.1.4.1.9.9.491.1.4.1.17

Integer32 (500..15000) · millisec

The polling frequency of the Hello packets on each interface between the units in HA pair.

cufwFOInterfaceHoldtime

1.3.6.1.4.1.9.9.491.1.4.1.18

Integer32 (5000..75000) · millisec

The hold time that each unit will wait before declaring the peer unit as dead due to interface check failure.

cufwFOReplicationHttp

1.3.6.1.4.1.9.9.491.1.4.1.19

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object depicts if the stateful replication of HTTP sessions is enabled in a Stateful Failover environment.

cufwFOReplicationRate

1.3.6.1.4.1.9.9.491.1.4.1.20

Gauge32 · Connections Per Second

The bulk-sync connection replication rate between the HA units.

cufwFOStatefulUpdateEnabled

1.3.6.1.4.1.9.9.491.1.4.3.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This value depicts if failover has enabled stateful updates for all HA clients on the device.

cuFwFOMaxStateEvents

1.3.6.1.4.1.9.9.491.1.4.4.1

Integer32

The max count of history logs for FO state transitions that can be saved on the device.

cufwAaicGlobalNumBadProtocolOps

1.3.6.1.4.1.9.9.491.1.5.1.1

Counter64 (0..18446744073709551615) · Protocol Data Units

'Protocol Operation' is the application protocol specific operation that the PDU is intended to perform. An example of 'protocol operation' is the HELO command of SMTP protocol. This MIB object records the number of application protocol data units that contained a protocol operation which was disallowed by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of application traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicGlobalNumBadPDUSize

1.3.6.1.4.1.9.9.491.1.5.1.2

Counter64 (0..18446744073709551615) · Protocol Data Units

This MIB object records the number of application protocol data units (PDU) that had either an invalid header size or an invalid payload size, as determined by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of application traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicGlobalNumBadPortRange

1.3.6.1.4.1.9.9.491.1.5.1.3

Counter64 (0..18446744073709551615) · Protocol Data Units

Number of application protocol units that attempted to advertise illegal port ranges for secondary connections. An example of such an occurrence would be a passive FTP connection, where the server advertises a disallowed port range for data connection. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of application traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumBadProtocolOps

1.3.6.1.4.1.9.9.491.1.5.2.1.1

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol which were detected to be containing HTTP protocol methods which are disallowed by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumBadPDUSize

1.3.6.1.4.1.9.9.491.1.5.2.1.2

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol that had either an invalid header size or an invalid payload size, as determined by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumTunneledConns

1.3.6.1.4.1.9.9.491.1.5.2.1.3

Counter64 (0..18446744073709551615) · Connections

The number of connections corresponding to HTTP protocol which were detected to be tunneling other application traffic streams. An instance of this would be InstantMessenger traffic running on HTTP. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumLargeURIs

1.3.6.1.4.1.9.9.491.1.5.2.1.4

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol which were detected to be containing a URI of size not permitted by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumBadContent

1.3.6.1.4.1.9.9.491.1.5.2.1.5

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol which were detected to be containing content whose type disallowed by the local security policy. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumMismatchContent

1.3.6.1.4.1.9.9.491.1.5.2.1.6

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol which were detected to be containing content whose type was different from the content type specified in the header of the PDU. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicHttpNumDoubleEncodedPkts

1.3.6.1.4.1.9.9.491.1.5.2.1.7

Counter64 (0..18446744073709551615) · HTTP Protocol Data Units

The number of PDUs corresponding to HTTP protocol which were detected to be containing double encoding. Double encoding is a mechanism to obfuscate content in which a encoded data is re-encoded so as to evade deep packet inspections. For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads. This value is accumulated from the last reboot of the firewall.

cufwAaicPassedSnortCount

1.3.6.1.4.1.9.9.491.1.5.3.1.1

Counter64 (0..18446744073709551615) · Packets

The number of packets sent to Snort from Lina. These are packets with pass verdict.

cufwAaicBlockedSnortCount

1.3.6.1.4.1.9.9.491.1.5.3.1.2

Counter64 (0..18446744073709551615) · Packets

The number of packets blocked in Snort.

cufwAaicInjbySnortCount

1.3.6.1.4.1.9.9.491.1.5.3.1.3

Counter64 (0..18446744073709551615) · Packets

The number of packets Snort created and added to the traffic stream.

cufwAaicBypassSnortDownCount

1.3.6.1.4.1.9.9.491.1.5.3.1.4

Counter64 (0..18446744073709551615) · Packets

The number of packets that bypassed inspection when Snort was Down.

cufwAaicBypassSnortBusyCount

1.3.6.1.4.1.9.9.491.1.5.3.1.5

Counter64 (0..18446744073709551615) · Packets

The number of packets that bypassed inspection when Snort was too busy to handle the packets.

cufwAaicFastfwdFlowsCount

1.3.6.1.4.1.9.9.491.1.5.3.1.6

Counter64 (0..18446744073709551615) · Flow

The number of flows that were fast forwarded both by policy, and as result of initial inspection due to say Whitelisting.

cufwAaicBlacklistedFlowsCount

1.3.6.1.4.1.9.9.491.1.5.3.1.7

Counter64 (0..18446744073709551615) · Flow

The number of flows from policy configuration that were black-listed by Snort after inspection.

cufwAaicStartofFlowEvCount

1.3.6.1.4.1.9.9.491.1.5.3.1.8

Counter64 (0..18446744073709551615) · Event

The Lina process sends start-of-flow events to Snort when it fast paths a flow without sending it to Snort. These events help Snort keep track of the connections and report the connection events.

cufwAaicEndofFlowEvCount

1.3.6.1.4.1.9.9.491.1.5.3.1.9

Counter64 (0..18446744073709551615) · Event

The Lina process sends end-of-flow events to Snort when a fast path flow ends.

cufwAaicDeniedFlowEvCount

1.3.6.1.4.1.9.9.491.1.5.3.1.10

Counter64 (0..18446744073709551615) · Event

The Lina process sends denied flow events to Snort when it decides to drop a flow before sending it to Snort.

cufwAaicFwdbeforeDropCount

1.3.6.1.4.1.9.9.491.1.5.3.1.11

Counter64 (0..18446744073709551615) · Packet

Valid for NGIPS interfaces only. This is the number of to-be-dropped packets forwarded to Snort. When the Lina process decides to drop the frame for some reason such as (Invalid TCP header length, Invalid UDP length or Invalid IP length), the frames are also sent to Snort for visibility.

cufwAaicInjDropCount

1.3.6.1.4.1.9.9.491.1.5.3.1.12

Counter64 (0..18446744073709551615) · Packet

The number of packets that Snort added to the traffic stream that were dropped.

cufwAaicIntrusionEvtRate

1.3.6.1.4.1.9.9.491.1.5.3.2.1

Gauge32 · Events per second

The rate at which intrusion events were recorded by Snort on this firewall averaged over the last 300 seconds.

cufwL2GlobalEnableStealthMode

1.3.6.1.4.1.9.9.491.1.6.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The value indicates if the firewall is operating in transparent (layer 2) mode or not. When operating in transparent mode, the firewall operates as a bridge while performing firewalling functions.

cufwL2GlobalArpCacheSize

1.3.6.1.4.1.9.9.491.1.6.1.2

Integer32 (1..2147483647) · ARP entries

The value indicates the configured maximum size of the ARP cache used for management traffic.

cufwL2GlobalEnableArpInspection

1.3.6.1.4.1.9.9.491.1.6.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The value indicates if ARP inspection, which is a security feature, is enabled globally on the managed firewall.

cufwL2GlobalNumArpRequests

1.3.6.1.4.1.9.9.491.1.6.1.5

Counter64 (0..18446744073709551615) · ARP Requests

The number of ARP requests issued by the transparent firewall to resolve a destination IP address. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalNumIcmpRequests

1.3.6.1.4.1.9.9.491.1.6.1.6

Counter64 (0..18446744073709551615) · ICMP Traceroute Requests

The number of ICMP traceroute requests issued by the transparent firewall to resolve a destination IP address. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalNumFloods

1.3.6.1.4.1.9.9.491.1.6.1.7

Counter64 (0..18446744073709551615)

The number of times the firewall floods a frame to be forwarded to the egress interfaces because the destination MAC address is missing in the bridge table. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalNumDrops

1.3.6.1.4.1.9.9.491.1.6.1.8

Counter64 (0..18446744073709551615)

The number of times the firewall dropped an incoming frame because the destination MAC address is missing in the bridge table. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalArpOverflowRate5

1.3.6.1.4.1.9.9.491.1.6.1.9

Gauge32

The number of times an existing entry from the ARP cache had to be ejected in order to insert a new entry in the last 300 seconds. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalNumBadArpResponses

1.3.6.1.4.1.9.9.491.1.6.1.10

Counter64 (0..18446744073709551615) · ARP Responses

The number of malformed ARP responses received by the firewall in trying to resolve the MAC address of the destination IP address in an incoming frame. This counter is accumulated since the last reboot of the firewall.

cufwL2GlobalNumSpoofedArpResps

1.3.6.1.4.1.9.9.491.1.6.1.11

Counter64 (0..18446744073709551615) · ARP Responses

The number of spoofed ARP responses received by the firewall. Such an event would occur when the firewall encounters an ARP response mapping an IP address to a different MAC Address from the one present in the local ARP cache. This counter is accumulated since the last reboot of the firewall.

cufwCntlUrlfServerStatusChange

1.3.6.1.4.1.9.9.491.1.7.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the SNMP notification to signal the election of a new primary URL filtering server by this firewall. Such a change could occur either as a result of the current primary server becoming unavailable or as a result of explicit management action in nominating a filtering server the primary server.

cufwCntlL2StaticMacAddressMoved

1.3.6.1.4.1.9.9.491.1.7.2

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the SNMP notification to signal the move of a statically configured MAC address to a new port. Such a change could occur either as a result of physical move of the device with the MAC Address to the new port or due to MAC address spoofing.

cufwCntlFOstateChange

1.3.6.1.4.1.9.9.491.1.7.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the SNMP notification to signal the election of a new active or standby in an HA pair.

cufwCntlCluStateChange

1.3.6.1.4.1.9.9.491.1.7.4

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object defines the administrative state of sending the SNMP notification to signal the election of a new master in a cluster unit.

cufwCluEnabled

1.3.6.1.4.1.9.9.491.1.8.1.1

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This value depicts if clustering is enabled or not on the device.

cufwCluInterfaceMode

1.3.6.1.4.1.9.9.491.1.8.1.2

INTEGER (0..3) · Integer32

Mode of interface in clustering. Value Type 0 none 1 Spanned ether-channel 2 Individual 3 invalid

cufwCluUnitState

1.3.6.1.4.1.9.9.491.1.8.1.3

CUfwCluState0 = disabled1 = election2 = onCall3 = slaveCold4 = slaveAppSync5 = slaveConfig6 = slaveFilesys7 = slaveBulkSync8 = slave9 = slavePending10 = deputyBulkSync11 = deputy12 = masterFast13 = masterDrain14 = masterConfig15 = masterPostConfig16 = master17 = masterDeferThis type denotes possible cluster unit states. · Integer32

The current state of the unit in cluster.

1.3.6.1.4.1.9.9.491.1.8.1.4

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The ifIndex of the interface used for cluster communication between the units.

cufwCluGroupName

1.3.6.1.4.1.9.9.491.1.8.1.5

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The group name uniquely identifying this cluster.

cufwCluUnitName

1.3.6.1.4.1.9.9.491.1.8.1.6

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The name uniquely identifying this cluster member.

cufwCluConsoleReplicate

1.3.6.1.4.1.9.9.491.1.8.1.7

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

The console replication feature is enabled on this slave. Slave units send the console messages to the master unit so that you only need to monitor one console port for the cluster.

cufwCluSiteID

1.3.6.1.4.1.9.9.491.1.8.1.8

INTEGER (0..8) · Integer32

The site ID for this unit used in inter-site clustering.

cufwCluPriority

1.3.6.1.4.1.9.9.491.1.8.1.9

INTEGER (1..100) · Integer32

The priority of this unit for master unit elections (1 being highest).

cufwCluSerialNum

1.3.6.1.4.1.9.9.491.1.8.1.10

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific serial number string for the current unit in cluster.

cufwCCLipAddr

1.3.6.1.4.1.9.9.491.1.8.1.11

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The ip address used on the interface for CCL communication.

cufwCCLmacAddr

1.3.6.1.4.1.9.9.491.1.8.1.12

PhysAddressRepresents media- or physical-level addresses. · OCTET STRING · hint 1x:

The MAC address on the CCL link.

cufwCluSwVersion

1.3.6.1.4.1.9.9.491.1.8.1.13

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The vendor-specific software revision string for the current unit in cluster.

cufwCluUnitHoldtime

1.3.6.1.4.1.9.9.491.1.8.1.14

INTEGER (800..45000) · Integer32 · millisec

To determine unit health, the ASA cluster units send keepalive messages on the cluster control link to other units. The hold time that each unit will wait before declaring a peer unit as dead.

cufwCluLastJoinAt

1.3.6.1.4.1.9.9.491.1.8.1.15

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The date&time at which this unit last joined the cluster.

cufwCluLastLeaveAt

1.3.6.1.4.1.9.9.491.1.8.1.16

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The date&time at which this unit last left the cluster.

cuFwCluUnitHealth

1.3.6.1.4.1.9.9.491.1.8.2.1

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The string would show either healthy or un-healthy.

cufwCluOverallHealth

1.3.6.1.4.1.9.9.491.1.8.2.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The string would show either healthy or un-healthy.

cuFwCluMaxStateEvents

1.3.6.1.4.1.9.9.491.1.8.3.1

INTEGER · Integer32

The max count of history logs for cluster state transitions that can be saved on the device.

Table details

cufwConnSummaryTable

1.3.6.1.4.1.9.9.491.1.1.4.1

Index: cufwConnProtocol

This table summarizes the connection activity on the firewall per layer3-layer 4 protocol instance. Each entry in the table lists the connection summary of a distinct network protocol. For instance, the conceptual row corresponding to the index cufwConnProtocol = fwpTcp yields the summary of TCP connection activity on the firewall since its reboot.

cufwConnProtocol

1.3.6.1.4.1.9.9.491.1.1.4.1.1.1

CFWNetworkProtocol1 = none2 = other3 = ip4 = icmp5 = gre6 = udp7 = tcpThis type denotes protocols operating at layers 3 or 4 of Open System Interconnection (OSI) model. The following values are defined: 'none' Denotes the semantics of 'not applicable'. 'other' Denotes any protocol not listed. 'ip' Denotes Internet Protocol (IP). 'icmp' Denotes Internet Control Message Protocol. 'gre' Denotes Generic Route Encapsulation protocol. 'udp' Denotes User Datagram Protocol. 'tcp' Denotes Transmission Control Protocol. · Integer32

The (L3-L4) protocol for which this conceptual row summarizes the connection activity on the managed entity.

cufwConnNumAttempted

1.3.6.1.4.1.9.9.491.1.1.4.1.1.2

Counter64 (0..18446744073709551615) · Connections

The number of connections attempted since the last reboot of the firewall, corresponding to the protocol denoted by 'cufwConnProtocol'. This value is accumulated from the last reboot of the firewall.

cufwConnNumSetupsAborted

1.3.6.1.4.1.9.9.491.1.1.4.1.1.3

Counter64 (0..18446744073709551615) · Connections

The number of connection setup attempts, corresponding to the protocol denoted by 'cufwConnProtocol', that were aborted before the connection could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt. Consequently, this value subsumes the values of objects 'cufwConnNumPolicyDeclined' and 'cufwConnNumResDeclined'. This value is accumulated from the last reboot of the firewall.

cufwConnNumPolicyDeclined

1.3.6.1.4.1.9.9.491.1.1.4.1.1.4

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwConnProtocol'. This value is accumulated from the last reboot of the firewall.

cufwConnNumResDeclined

1.3.6.1.4.1.9.9.491.1.1.4.1.1.5

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwConnProtocol'. This value is accumulated from the last reboot of the firewall.

cufwConnNumHalfOpen

1.3.6.1.4.1.9.9.491.1.1.4.1.1.6

Gauge32 · Connections

The number of connections that are currently in the process of being established, corresponding to the protocol denoted by 'cufwConnProtocol'.

cufwConnNumActive

1.3.6.1.4.1.9.9.491.1.1.4.1.1.7

Gauge32 · Connections

The number of connections that are currently active, corresponding to the protocol denoted by 'cufwConnProtocol'.

cufwConnNumAborted

1.3.6.1.4.1.9.9.491.1.1.4.1.1.8

Counter64 (0..18446744073709551615) · Connections

The number of connections that were abnormally terminated after successful establishment, corresponding to the protocol denoted by 'cufwConnProtocol'. This value is accumulated from the last reboot of the firewall.

cufwConnSetupRate1

1.3.6.1.4.1.9.9.491.1.1.4.1.1.9

Gauge32 · Connections Per Second

The connection setup rate averaged over the last 60 seconds corresponding to the protocol denoted by 'cufwConnProtocol'.

cufwConnSetupRate5

1.3.6.1.4.1.9.9.491.1.1.4.1.1.10

Gauge32 · Connections Per Second

The connection setup rate averaged over the last 300 seconds corresponding to the protocol denoted by 'cufwConnProtocol'.

cufwAppConnSummaryTable

1.3.6.1.4.1.9.9.491.1.1.4.2

Index: cufwAppConnProtocol

This table lists the summary of firewall connections pertaining to Layer 7 protocols, catalogued by distinct application protocols. Each entry in the table lists the connection summary corresponding to a distinct application protocol. For instance, to obtain the connection summary for SMTP on the firewall since the last reboot of the device, use the conceptual row corresponding to cufwAppConnProtocol = fwApSmtp

cufwAppConnProtocol

1.3.6.1.4.1.9.9.491.1.1.4.2.1.1

CFWApplicationProtocol1 = none2 = other3 = ftp4 = telnet5 = smtp6 = http7 = tacacs8 = dns9 = sqlnet10 = https11 = tftp12 = gopher13 = finger14 = kerberos15 = pop216 = pop317 = sunRpc18 = msRpc19 = nntp20 = snmp21 = imap22 = ldap23 = exec24 = login25 = shell26 = msSql27 = sybaseSql28 = nfs29 = lotusnote30 = h32331 = cuseeme32 = realmedia33 = netshow34 = streamworks35 = vdolive36 = sap37 = sip38 = mgcp39 = rtsp40 = skinny41 = gtpV042 = gtpV143 = echo44 = discard45 = daytime46 = netstat47 = ssh48 = time49 = tacacsDs50 = bootps51 = bootpc52 = dnsix53 = rtelnet54 = ident55 = sqlServ56 = ntp57 = pwdgen58 = ciscoFna59 = ciscoTna60 = ciscoSys61 = netbiosNs62 = netbiosDgm63 = netbiosSsn64 = sqlSrv65 = snmpTrap66 = rsvd67 = send68 = xdmcp69 = bgp70 = irc71 = qmtp72 = ipx73 = dbase74 = imap375 = rsvpTunnel76 = hpCollector77 = hpManagedNode78 = hpAlarmMgr79 = microsoftDs80 = creativeServer81 = creativePartnr82 = appleQtc83 = igmpV3Lite84 = isakmp85 = biff86 = who87 = syslog88 = router89 = ncp90 = timed91 = ircServ92 = uucp93 = syslogConn94 = sshell95 = ldaps96 = dhcpFailover97 = msexchRouting98 = entrustSvcs99 = entrustSvcHandler100 = ciscoTdp101 = webster102 = gdoi103 = iscsi104 = cddbp105 = ftps106 = telnets107 = imaps108 = ircs109 = pop3s110 = socks111 = kazaa112 = msSqlM113 = msSna114 = wins115 = ica116 = orasrv117 = rdbDbsDisp118 = vqp119 = icabrowser120 = kermit121 = rsvpEncap122 = l2tp123 = pptp124 = h323Gatestat125 = rWinsock126 = radius127 = hsrp128 = net8Cman129 = oracleEmVp130 = oracleNames131 = oracle132 = ciscoSvcs133 = ciscoNetMgmt134 = stun135 = trRsrb136 = ddnsV3137 = aceSvr138 = giop139 = ttc140 = ipass141 = clp142 = citrixImaClient143 = sms144 = citrix145 = realSecure146 = lotusMtap147 = cifs148 = msDotnetster149 = tarantella150 = fcipPort151 = ssp152 = iscsiTarget153 = mySql154 = msClusterNet155 = ldapAdmin156 = ieee80211Iapp157 = oemAgent158 = rtcPmPort159 = dbControlAgent160 = ipsecMsft161 = sipTls162 = aim163 = pcAnyWhereData164 = pcAnyWhereStat165 = x11166 = ircu167 = n2h2Server168 = h323CallSigAlt169 = yahooMsgr170 = msnMsgrThis type denotes the application (OSI Layer 7) protocol/service corresponding to a firewall session or a connection. Description of constants of this type 'none' Denotes the semantics of 'not applicable'. 'other' Denotes any protocol not listed.Reference: The protocols enumerated in this textual convention may be correlated with the information on protocols/ services defined by Internet Assigned Numbers Authority (IANA) found at http://www.iana.com/assignments/port-numbers · Integer32

The layer7 protocol for which this conceptual row summarizes the connection activity for this firewall.

cufwAppConnNumAttempted

1.3.6.1.4.1.9.9.491.1.1.4.2.1.2

Counter64 (0..18446744073709551615) · Connections

The number of connections attempted since the last reboot of the firewall, corresponding to the protocol denoted by 'cufwAppConnProtocol'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwAppConnNumSetupsAborted

1.3.6.1.4.1.9.9.491.1.1.4.2.1.3

Counter64 (0..18446744073709551615) · Connections

The number of connection setup attempts, corresponding to the protocol denoted by 'cufwAppConnProtocol', that were aborted before the connection could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt. Consequently, this value subsumes the values of objects 'cufwAppConnNumPolicyDeclined' and 'cufwAppConnNumResDeclined'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwAppConnNumPolicyDeclined

1.3.6.1.4.1.9.9.491.1.1.4.2.1.4

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwAppConnProtocol'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwAppConnNumResDeclined

1.3.6.1.4.1.9.9.491.1.1.4.2.1.5

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwAppConnProtocol'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwAppConnNumHalfOpen

1.3.6.1.4.1.9.9.491.1.1.4.2.1.6

Gauge32 · Connections

The number of connections that are currently in the process of being established, corresponding to the protocol denoted by 'cufwAppConnProtocol'.

cufwAppConnNumActive

1.3.6.1.4.1.9.9.491.1.1.4.2.1.7

Gauge32 · Connections

The number of connections that are currently active, corresponding to the protocol denoted by 'cufwAppConnProtocol'.

cufwAppConnNumAborted

1.3.6.1.4.1.9.9.491.1.1.4.2.1.8

Counter64 (0..18446744073709551615) · Connections

The number of connections that were terminated by the firewall successful establishment, corresponding to the protocol denoted by 'cufwAppConnProtocol'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwAppConnSetupRate1

1.3.6.1.4.1.9.9.491.1.1.4.2.1.9

Gauge32 · Connections Per Second

The connection setup rate averaged over the last 60 seconds corresponding to the protocol denoted by 'cufwAppConnProtocol'.

cufwAppConnSetupRate5

1.3.6.1.4.1.9.9.491.1.1.4.2.1.10

Gauge32 · Connections Per Second

The connection setup rate averaged over the last 300 seconds corresponding to the protocol denoted by 'cufwAppConnProtocol'.

cufwPolicyConnSummaryTable

1.3.6.1.4.1.9.9.491.1.1.4.3

Index: cufwPolConnPolicy · cufwPolConnPolicyTargetType · cufwPolConnPolicyTarget · cufwPolConnProtocol

This table lists the summary of firewall connections for layer3-layer 4 protocols catalogued on a per policy basis. Each entry in the table lists the connection summary of a distinct network protocol, configured on the specified policy on the firewall, and pertaining to a specified target to which the policy is currently applied. If a policy is bound to a target, it would have one or more entries in this table. If the policy is detached from the target, all entries corresponding to the association between the policy and the target are elminated from this table. Although the information is indexed by policy targets as well, one may aggregate the connection summary for a specific policy across all the target to which the policy is currently applied by setting cufwConnPolicyTargetType = 'targetAll'

cufwPolConnPolicy

1.3.6.1.4.1.9.9.491.1.1.4.3.1.1

CFWPolicyThis type denotes the identity of a policy enforced by the firewall. In the context of firewalls, only security policies are relevant. Objects of this type must comprise printable, human readable ASCII characters. A zero length string is used to denote a 'null' policy. An example of a policy is the 'policy-map' entity configured using the Modular Policy Command framework. SIZE (0..128) · OCTET STRING

The identity of the firewall policy for which this conceptual row contains the connection activity summary.

cufwPolConnPolicyTargetType

1.3.6.1.4.1.9.9.491.1.1.4.3.1.2

CFWPolicyTargetType1 = all2 = other3 = interface4 = zone5 = zonepair6 = user7 = usergroup8 = contextThis type is used to represent the type of a policy target. The following values are defined: 'all' Certain firewall implementations allow policies to be applied on all applicable targets. (Such policies are termed 'global'). The target type 'all' denotes the set of all applicable targets. 'other' Denotes an entity type that has yet not been classified in one of the other types. This value is useful in accomodating new target types before the textual convention is revised to include them. 'interface' The policy target is an interface of the managed device. 'zone' The policy target is a zone, where a zone is is a collection of interfaces of the managed device. 'zonepair' The policy target is a pair of zones. 'user' Denotes the identity of a user who is authorized to access the firewall itself or the resources protected by the firewall. 'usergroup' Denotes the identity of a user group. User group denotes a collection of user identities, as defined above. 'context' Denotes a logical device defined in the managed device with a distinct management context. Examples of such logical devices include virtual contexts defined by Firewall Service Module, virtual sensors defined by Intrusion Detection Service Module and Virtual Routing and Forwarding (VRFs) defined by IOS. · Integer32

The type of the entity to which the firewall policy 'cufwPolConnPolicy' has been applied. This could be an interface type (most commonly), the type of another object or a group of objects defined in the firewall configuration. When this object is set to 'targetALL', the value of index object cufwConnPolicyTarget is ignored.

cufwPolConnPolicyTarget

1.3.6.1.4.1.9.9.491.1.1.4.3.1.3

CFWPolicyTargetIn the context of policy management, the term target refers to an entity on the managed device to which the policy is applied thereby enforcing the policy on the traffic stream(s) associated with the entity. The type 'CFWPolicyTarget' denotes the identity of a policy target. Examples of policy targets include interfaces, security zones, users, user groups and virtual contexts. Objects of this type must comprise printable, human readable ASCII characters. A zero length string is used to denote a 'null' target. SIZE (0..128) · OCTET STRING

The identity of the entity to which the firewall policy 'cufwPolConnPolicy' is applied. This could be an interface object (most commonly), another object or group of objects defined in the firewall configuration.

cufwPolConnProtocol

1.3.6.1.4.1.9.9.491.1.1.4.3.1.4

CFWNetworkProtocol1 = none2 = other3 = ip4 = icmp5 = gre6 = udp7 = tcpThis type denotes protocols operating at layers 3 or 4 of Open System Interconnection (OSI) model. The following values are defined: 'none' Denotes the semantics of 'not applicable'. 'other' Denotes any protocol not listed. 'ip' Denotes Internet Protocol (IP). 'icmp' Denotes Internet Control Message Protocol. 'gre' Denotes Generic Route Encapsulation protocol. 'udp' Denotes User Datagram Protocol. 'tcp' Denotes Transmission Control Protocol. · Integer32

The (L3-L4) protocol corresponding to which this conceptual row summarizes the connection activity on the firewall.

cufwPolConnNumAttempted

1.3.6.1.4.1.9.9.491.1.1.4.3.1.5

Counter64 (0..18446744073709551615) · Connections

The number of connections attempted since the last reboot of the firewall, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolConnNumSetupsAborted

1.3.6.1.4.1.9.9.491.1.1.4.3.1.6

Counter64 (0..18446744073709551615) · Connections

The number of connection setup attempts, corresponding to the protocol denoted by 'cufwPolConnProtocol', associated with the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget', that were aborted before the connection could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt. Consequently, this value subsumes the values of objects 'cufwPolConnNumPolicyDeclined' and 'cufwPolConnNumResDeclined'.

cufwPolConnNumPolicyDeclined

1.3.6.1.4.1.9.9.491.1.1.4.3.1.7

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolConnNumResDeclined

1.3.6.1.4.1.9.9.491.1.1.4.3.1.8

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolConnNumHalfOpen

1.3.6.1.4.1.9.9.491.1.1.4.3.1.9

Gauge32 · Connections

The number of connections that are currently in the process of being established, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolConnNumActive

1.3.6.1.4.1.9.9.491.1.1.4.3.1.10

Gauge32 · Connections

The number of connections that are currently active, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolConnNumAborted

1.3.6.1.4.1.9.9.491.1.1.4.3.1.11

Counter64 (0..18446744073709551615) · Connections

The number of connections that were abnormally terminated after successful establishment, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

cufwPolicyAppConnSummaryTable

1.3.6.1.4.1.9.9.491.1.1.4.4

Index: cufwPolAppConnPolicy · cufwPolAppConnPolicyTargetType · cufwPolAppConnPolicyTarget · cufwPolAppConnProtocol

This table lists the summary of firewall connections pertaining to Layer 7 protocols, catalogued on a per policy basis Each entry in the table lists the connection summary of a distinct application protocol, configured on the specified policy on the firewall, and pertaining to a specified target to which the policy has been applied. If a policy is bound to a target, it would have one or more entries in this table. If the policy is detached from the target, all entries corresponding to the association between the policy and the target are elminated from this table. Although the information is indexed by policy targets as well, one may aggregate the connection summary for a specific policy across all the target to which the policy is currently applied by setting cufwAppConnPolicyTargetType = 'targetALL'

cufwPolAppConnPolicy

1.3.6.1.4.1.9.9.491.1.1.4.4.1.1

CFWPolicyThis type denotes the identity of a policy enforced by the firewall. In the context of firewalls, only security policies are relevant. Objects of this type must comprise printable, human readable ASCII characters. A zero length string is used to denote a 'null' policy. An example of a policy is the 'policy-map' entity configured using the Modular Policy Command framework. SIZE (0..128) · OCTET STRING

The identity of the firewall policy for which this conceptual row contains the connection activity summary.

cufwPolAppConnPolicyTargetType

1.3.6.1.4.1.9.9.491.1.1.4.4.1.2

CFWPolicyTargetType1 = all2 = other3 = interface4 = zone5 = zonepair6 = user7 = usergroup8 = contextThis type is used to represent the type of a policy target. The following values are defined: 'all' Certain firewall implementations allow policies to be applied on all applicable targets. (Such policies are termed 'global'). The target type 'all' denotes the set of all applicable targets. 'other' Denotes an entity type that has yet not been classified in one of the other types. This value is useful in accomodating new target types before the textual convention is revised to include them. 'interface' The policy target is an interface of the managed device. 'zone' The policy target is a zone, where a zone is is a collection of interfaces of the managed device. 'zonepair' The policy target is a pair of zones. 'user' Denotes the identity of a user who is authorized to access the firewall itself or the resources protected by the firewall. 'usergroup' Denotes the identity of a user group. User group denotes a collection of user identities, as defined above. 'context' Denotes a logical device defined in the managed device with a distinct management context. Examples of such logical devices include virtual contexts defined by Firewall Service Module, virtual sensors defined by Intrusion Detection Service Module and Virtual Routing and Forwarding (VRFs) defined by IOS. · Integer32

The type of the entity to which the firewall policy 'cufwPolAppConnPolicy' has been applied. This could be an interface type (most commonly), the type of another object or a group of objects defined in the firewall configuration. When this object is set to 'targetALL', the value of index object cufwAppConnPolicyTarget is ignored.

cufwPolAppConnPolicyTarget

1.3.6.1.4.1.9.9.491.1.1.4.4.1.3

CFWPolicyTargetIn the context of policy management, the term target refers to an entity on the managed device to which the policy is applied thereby enforcing the policy on the traffic stream(s) associated with the entity. The type 'CFWPolicyTarget' denotes the identity of a policy target. Examples of policy targets include interfaces, security zones, users, user groups and virtual contexts. Objects of this type must comprise printable, human readable ASCII characters. A zero length string is used to denote a 'null' target. SIZE (0..128) · OCTET STRING

The identity of the entity to which the firewall policy 'cufwPolAppProtocol' refers. This could be an interface object (most commonly), another object or group of objects defined in the firewall configuration.

cufwPolAppConnProtocol

1.3.6.1.4.1.9.9.491.1.1.4.4.1.4

CFWApplicationProtocol1 = none2 = other3 = ftp4 = telnet5 = smtp6 = http7 = tacacs8 = dns9 = sqlnet10 = https11 = tftp12 = gopher13 = finger14 = kerberos15 = pop216 = pop317 = sunRpc18 = msRpc19 = nntp20 = snmp21 = imap22 = ldap23 = exec24 = login25 = shell26 = msSql27 = sybaseSql28 = nfs29 = lotusnote30 = h32331 = cuseeme32 = realmedia33 = netshow34 = streamworks35 = vdolive36 = sap37 = sip38 = mgcp39 = rtsp40 = skinny41 = gtpV042 = gtpV143 = echo44 = discard45 = daytime46 = netstat47 = ssh48 = time49 = tacacsDs50 = bootps51 = bootpc52 = dnsix53 = rtelnet54 = ident55 = sqlServ56 = ntp57 = pwdgen58 = ciscoFna59 = ciscoTna60 = ciscoSys61 = netbiosNs62 = netbiosDgm63 = netbiosSsn64 = sqlSrv65 = snmpTrap66 = rsvd67 = send68 = xdmcp69 = bgp70 = irc71 = qmtp72 = ipx73 = dbase74 = imap375 = rsvpTunnel76 = hpCollector77 = hpManagedNode78 = hpAlarmMgr79 = microsoftDs80 = creativeServer81 = creativePartnr82 = appleQtc83 = igmpV3Lite84 = isakmp85 = biff86 = who87 = syslog88 = router89 = ncp90 = timed91 = ircServ92 = uucp93 = syslogConn94 = sshell95 = ldaps96 = dhcpFailover97 = msexchRouting98 = entrustSvcs99 = entrustSvcHandler100 = ciscoTdp101 = webster102 = gdoi103 = iscsi104 = cddbp105 = ftps106 = telnets107 = imaps108 = ircs109 = pop3s110 = socks111 = kazaa112 = msSqlM113 = msSna114 = wins115 = ica116 = orasrv117 = rdbDbsDisp118 = vqp119 = icabrowser120 = kermit121 = rsvpEncap122 = l2tp123 = pptp124 = h323Gatestat125 = rWinsock126 = radius127 = hsrp128 = net8Cman129 = oracleEmVp130 = oracleNames131 = oracle132 = ciscoSvcs133 = ciscoNetMgmt134 = stun135 = trRsrb136 = ddnsV3137 = aceSvr138 = giop139 = ttc140 = ipass141 = clp142 = citrixImaClient143 = sms144 = citrix145 = realSecure146 = lotusMtap147 = cifs148 = msDotnetster149 = tarantella150 = fcipPort151 = ssp152 = iscsiTarget153 = mySql154 = msClusterNet155 = ldapAdmin156 = ieee80211Iapp157 = oemAgent158 = rtcPmPort159 = dbControlAgent160 = ipsecMsft161 = sipTls162 = aim163 = pcAnyWhereData164 = pcAnyWhereStat165 = x11166 = ircu167 = n2h2Server168 = h323CallSigAlt169 = yahooMsgr170 = msnMsgrThis type denotes the application (OSI Layer 7) protocol/service corresponding to a firewall session or a connection. Description of constants of this type 'none' Denotes the semantics of 'not applicable'. 'other' Denotes any protocol not listed.Reference: The protocols enumerated in this textual convention may be correlated with the information on protocols/ services defined by Internet Assigned Numbers Authority (IANA) found at http://www.iana.com/assignments/port-numbers · Integer32

The layer7 protocol for which this conceptual row summarizes the connection activity for this firewall.

cufwPolAppConnNumAttempted

1.3.6.1.4.1.9.9.491.1.1.4.4.1.5

Counter64 (0..18446744073709551615) · Connections

The number of connections attempted since the last reboot of the firewall, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwPolAppConnNumSetupsAborted

1.3.6.1.4.1.9.9.491.1.1.4.4.1.6

Counter64 (0..18446744073709551615) · Connections

The number of connection setup attempts, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', associated with the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget', that were aborted before the connections could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt. Consequently, this value subsumes the values of objects 'cufwPolAppConnNumPolicyDeclined' and 'cufwPolAppConnNumResDeclined'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwPolAppConnNumPolicyDeclined

1.3.6.1.4.1.9.9.491.1.1.4.4.1.7

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwPolAppConnNumResDeclined

1.3.6.1.4.1.9.9.491.1.1.4.4.1.8

Counter64 (0..18446744073709551615) · Connections

The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'. This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.

cufwPolAppConnNumHalfOpen

1.3.6.1.4.1.9.9.491.1.1.4.4.1.9

Gauge32 · Connections

The number of connections that are currently in the process of being established, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'.

cufwPolAppConnNumActive

1.3.6.1.4.1.9.9.491.1.1.4.4.1.10

Gauge32 · Connections

The number of connections that are currently active, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'.

cufwPolAppConnNumAborted

1.3.6.1.4.1.9.9.491.1.1.4.4.1.11

Counter64 (0..18446744073709551615) · Connections

The number of connections that were abnormally terminated after successful establishment, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'.

cufwInspectionTable

1.3.6.1.4.1.9.9.491.1.2.3

Index: cufwInspectionPolicyName · cufwInspectionProtocol

This table identifies if an application protocol has been configured for inspection and if so, the name of the firewall policy or the inspection configuration that configures the specified protocol for inspection. The table also identifies if the specified protocol is actively being inspected. This table may be used by an administrator to quickly identify if a protocol is being subjected to application inspection by the managed firewall.

cufwInspectionPolicyName

1.3.6.1.4.1.9.9.491.1.2.3.1.1

CFWPolicyThis type denotes the identity of a policy enforced by the firewall. In the context of firewalls, only security policies are relevant. Objects of this type must comprise printable, human readable ASCII characters. A zero length string is used to denote a 'null' policy. An example of a policy is the 'policy-map' entity configured using the Modular Policy Command framework. SIZE (0..128) · OCTET STRING

The name of the policy that configures the device inspect the protocol specified by 'cufwInspectionProtocol'.

cufwInspectionProtocol

1.3.6.1.4.1.9.9.491.1.2.3.1.2

CFWApplicationProtocol1 = none2 = other3 = ftp4 = telnet5 = smtp6 = http7 = tacacs8 = dns9 = sqlnet10 = https11 = tftp12 = gopher13 = finger14 = kerberos15 = pop216 = pop317 = sunRpc18 = msRpc19 = nntp20 = snmp21 = imap22 = ldap23 = exec24 = login25 = shell26 = msSql27 = sybaseSql28 = nfs29 = lotusnote30 = h32331 = cuseeme32 = realmedia33 = netshow34 = streamworks35 = vdolive36 = sap37 = sip38 = mgcp39 = rtsp40 = skinny41 = gtpV042 = gtpV143 = echo44 = discard45 = daytime46 = netstat47 = ssh48 = time49 = tacacsDs50 = bootps51 = bootpc52 = dnsix53 = rtelnet54 = ident55 = sqlServ56 = ntp57 = pwdgen58 = ciscoFna59 = ciscoTna60 = ciscoSys61 = netbiosNs62 = netbiosDgm63 = netbiosSsn64 = sqlSrv65 = snmpTrap66 = rsvd67 = send68 = xdmcp69 = bgp70 = irc71 = qmtp72 = ipx73 = dbase74 = imap375 = rsvpTunnel76 = hpCollector77 = hpManagedNode78 = hpAlarmMgr79 = microsoftDs80 = creativeServer81 = creativePartnr82 = appleQtc83 = igmpV3Lite84 = isakmp85 = biff86 = who87 = syslog88 = router89 = ncp90 = timed91 = ircServ92 = uucp93 = syslogConn94 = sshell95 = ldaps96 = dhcpFailover97 = msexchRouting98 = entrustSvcs99 = entrustSvcHandler100 = ciscoTdp101 = webster102 = gdoi103 = iscsi104 = cddbp105 = ftps106 = telnets107 = imaps108 = ircs109 = pop3s110 = socks111 = kazaa112 = msSqlM113 = msSna114 = wins115 = ica116 = orasrv117 = rdbDbsDisp118 = vqp119 = icabrowser120 = kermit121 = rsvpEncap122 = l2tp123 = pptp124 = h323Gatestat125 = rWinsock126 = radius127 = hsrp128 = net8Cman129 = oracleEmVp130 = oracleNames131 = oracle132 = ciscoSvcs133 = ciscoNetMgmt134 = stun135 = trRsrb136 = ddnsV3137 = aceSvr138 = giop139 = ttc140 = ipass141 = clp142 = citrixImaClient143 = sms144 = citrix145 = realSecure146 = lotusMtap147 = cifs148 = msDotnetster149 = tarantella150 = fcipPort151 = ssp152 = iscsiTarget153 = mySql154 = msClusterNet155 = ldapAdmin156 = ieee80211Iapp157 = oemAgent158 = rtcPmPort159 = dbControlAgent160 = ipsecMsft161 = sipTls162 = aim163 = pcAnyWhereData164 = pcAnyWhereStat165 = x11166 = ircu167 = n2h2Server168 = h323CallSigAlt169 = yahooMsgr170 = msnMsgrThis type denotes the application (OSI Layer 7) protocol/service corresponding to a firewall session or a connection. Description of constants of this type 'none' Denotes the semantics of 'not applicable'. 'other' Denotes any protocol not listed.Reference: The protocols enumerated in this textual convention may be correlated with the information on protocols/ services defined by Internet Assigned Numbers Authority (IANA) found at http://www.iana.com/assignments/port-numbers · Integer32

The application protocol that is configured for inspection.

cufwInspectionStatus

1.3.6.1.4.1.9.9.491.1.2.3.1.3

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This MIB object identifies if the directive to inspect the protocol specified by 'cufwInspectionProtocol' by the policy corresponding to this conceptual row is enabled or disabled.

cufwUrlfServerTable

1.3.6.1.4.1.9.9.491.1.3.3.1

Index: cufwUrlfServerAddrType · cufwUrlfServerAddress · cufwUrlfServerPort

This table lists the URL filtering servers configured on the managed device and their performance statistics. This table is not meant as a device to configure URL filtering servers.

cufwUrlfServerAddrType

1.3.6.1.4.1.9.9.491.1.3.3.1.1.1

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

The type of the IP address of the URL filtering server.

cufwUrlfServerAddress

1.3.6.1.4.1.9.9.491.1.3.3.1.1.2

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

The value of the IP address of the URL filtering server.

cufwUrlfServerPort

1.3.6.1.4.1.9.9.491.1.3.3.1.1.3

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

The value of the port at which the URL filtering server listens for incoming requests.

cufwUrlfServerVendor

1.3.6.1.4.1.9.9.491.1.3.3.1.1.4

CFWUrlfVendorId1 = other2 = websense3 = n2h2This type denotes the vendor of a URL filtering server which the firewall uses to implement URL filtering. A URL filtering server provides a database of URLs with appropriate access restrictions (e.g., deny or permit). Various security devices can make use of these filtering servers to provide URL filtering functionality to the users. The following values are defined: 'other' Other type of URL filtering servers than those specified below. 'websense' Websense URL filtering server. One of the products provided by Websense is a Web Filtering Server. More information about Websense Web Filtering product can be found at http://www.websense.com 'n2h2' N2H2 URL filtering server. More information about N2H2 Filtering product can be found at http://www.n2h2.com · Integer32

The vendor type of the URL filtering server.

cufwUrlfServerStatus

1.3.6.1.4.1.9.9.491.1.3.3.1.1.5

CFWUrlServerStatus1 = online2 = offline3 = indeterminateThis type denotes the status of the URL filtering server which the firewall uses to implement URL filtering. The following values are defined: 'online' Indicates that the Server is online 'offline' Indicates that the Server is offline 'indeterminate' Indicates that the Server status cannot be determined · Integer32

The status of the URL filtering server corresponding to this conceptual row.

cufwUrlfServerReqsNumProcessed

1.3.6.1.4.1.9.9.491.1.3.3.1.1.6

Counter64 (0..18446744073709551615)

The number of URL access requests forwarded by the managed firewall device to the URL filtering server corresponding to this conceptual row. This value is counted from the last reboot of the managed device.

cufwUrlfServerReqsNumAllowed

1.3.6.1.4.1.9.9.491.1.3.3.1.1.7

Counter64 (0..18446744073709551615)

The number of URL access requests allowed by the URL filtering server corresponding to this conceptual row. This counter does not include late responses. This value is counted from the last reboot of the managed device.

cufwUrlfServerReqsNumDenied

1.3.6.1.4.1.9.9.491.1.3.3.1.1.8

Counter64 (0..18446744073709551615)

The number of URL access requests denied by the URL filtering server corresponding to this conceptual row. This counter does not include late responses. This value is counted from the last reboot of the managed device.

cufwUrlfServerNumTimeouts

1.3.6.1.4.1.9.9.491.1.3.3.1.1.9

Counter64 (0..18446744073709551615)

The number of times the firewall failed to receive a response from the URL filtering server corresponding to this conceptual row, for a request to authorize a URL access request. This is equal to the number of times a firewall removed a URL access request from the queue of pending requests because no response was received from the URL filtering server. This value is accumulated from the last reboot of the firewall.

cufwUrlfServerNumRetries

1.3.6.1.4.1.9.9.491.1.3.3.1.1.10

Counter64 (0..18446744073709551615)

The number of URL access authorization requests re-sent by the firewall to the URL Filtering Server corresponding to this conceptual row, because a response was not received within the configured time interval from the server. This value is counted from the last reboot of the managed device.

cufwUrlfServerRespsNumReceived

1.3.6.1.4.1.9.9.491.1.3.3.1.1.11

Counter64 (0..18446744073709551615)

The number of URL access responses received by the firewall from the URL filtering server corresponding to this conceptual row. This counter does not include late responses. This value is counted from the last reboot of the managed device.

cufwUrlfServerRespsNumLate

1.3.6.1.4.1.9.9.491.1.3.3.1.1.12

Counter64 (0..18446744073709551615)

The number of URL access responses received by the managed firewall from the URL filtering server corresponding to this conceptual row after the original URL access request was removed from the queue of pending requests. This value is counted from the last reboot of the managed device.

cufwUrlfServerAvgRespTime1

1.3.6.1.4.1.9.9.491.1.3.3.1.1.13

Gauge32 · seconds

The average round-trip response time of the URL filtering server computed over the last 60 seconds. A value of zero indicates that there was insufficient data to compute this value over the last time interval.

cufwUrlfServerAvgRespTime5

1.3.6.1.4.1.9.9.491.1.3.3.1.1.14

Gauge32 · seconds

The average round-trip response time of the URL filtering server computed over the last 300 seconds. A value of zero indicates that there was insufficient data to compute this value over the last time interval.

cufwFOGrpStatusTable

1.3.6.1.4.1.9.9.491.1.4.2.1

Index: cufwFOGroupIndex

This table summarizes the failover state of a logical group of ASA contexts. The HA switchover happens at the group level.

cufwFOGroupIndex

1.3.6.1.4.1.9.9.491.1.4.2.1.1.1

CUfwFOGroupId0 = default1 = group12 = group2This type denotes possible HA group identifiers. A failover group is simply a logical group of one or more security contexts. One group is assigned to be active on the primary ASA, and the other group is assigned to be active on the secondary ASA. When a failover occurs, it occurs at the failover group level. Use value 0, if not applicable. · Integer32

A distinct HA group identifier for which this conceptual row summarizes critical failover data.

cufwFOGrpLastFailoverAt

1.3.6.1.4.1.9.9.491.1.4.2.1.1.2

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The date&time at which the last switchover was triggered for an HA group.

cufwFOGrpHAstate

1.3.6.1.4.1.9.9.491.1.4.2.1.1.3

HardwareStatus1 = other2 = up3 = down4 = error5 = overTemp6 = busy7 = noMedia8 = backup9 = active10 = standbyThis textual convention is used to describe various events that are related to the resources on a firewall. other : Generic resource event. up : The resource is in service. down : The resource is not in service. error : There has been an error for this resource. overTemp : The resource is overheating. busy : The resource is busy. noMedia : A device doesn't have its needed media. backup : Processing has switched to the backup. active : This is the active unit. standby : This is the standby unit. · Integer32

The current HA role of a group on the unit being polled. Allowed values are active or standby or unknown.

cufwFOGrpUpTime

1.3.6.1.4.1.9.9.491.1.4.2.1.1.4

Gauge32 · Seconds

The Uptime of a group in the current HA role on the unit being polled.

cufwFOGrpContextCount

1.3.6.1.4.1.9.9.491.1.4.2.1.1.5

Gauge32

The number of virtual contexts part of the group on the unit being polled.

cufwFOInterfaceTable

1.3.6.1.4.1.9.9.491.1.4.2.2

Index: cufwFOGroupIndex · cufwContextId · cufwContextifIndex

This table summarizes the interface health check status of each interface in a group per context.

cufwFOGrpId

1.3.6.1.4.1.9.9.491.1.4.2.2.1.1

CUfwFOGroupId0 = default1 = group12 = group2This type denotes possible HA group identifiers. A failover group is simply a logical group of one or more security contexts. One group is assigned to be active on the primary ASA, and the other group is assigned to be active on the secondary ASA. When a failover occurs, it occurs at the failover group level. Use value 0, if not applicable. · Integer32

A distinct HA group identifier for which this conceptual row summarizes the interface health.

cufwContextId

1.3.6.1.4.1.9.9.491.1.4.2.2.1.2

Integer32 (1..250)

The virtual context-id of the ASA context for which this conceptual row summarizes an interface's health within a logical HA group.

cufwContextifIndex

1.3.6.1.4.1.9.9.491.1.4.2.2.1.3

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The ifIndex from the IF-MIB for an interface in a context.

cufwFOInterfaceMonitoring

1.3.6.1.4.1.9.9.491.1.4.2.2.1.4

CUfwInterfaceMonitor0 = unknown1 = monitored2 = notMonitored3 = waiting4 = autostateDown5 = shutdownThis type denotes possible interface monitor states. monitored : interface monitoring is enabled. notMonitored : interface monitoring is not enabled. waiting : interface tests are going on and awaiting results. autostateDown: Applies only to ASASM interfaces. Supervisor informs when last physical interface of that vlan goes down. shutdown : interface is administratively down · Integer32

The monitoring state of the interface being addressed in a context.

cufwFOInterfaceStatus

1.3.6.1.4.1.9.9.491.1.4.2.2.1.5

CUfwInterfaceHealth0 = unknown1 = normal2 = testing3 = linkDown4 = failed5 = noLinkThis type denotes possible Interface health-check outcomes. normal : interface is monitored and in healthy state. testing : Ongoing testing. linkDown : interface link is administratively down. failed : interface link is physically up, but not able to pass the tests. Declared as failed. noLink : interface link is down. · Integer32

The health-check outcome of the interface being addressed in a context.

cufwFOLogicalUpdatesTable

1.3.6.1.4.1.9.9.491.1.4.3.2

Index: cufwFOGroupIdx · cufwFOCLientId

This table summarizes the statistics of every HA client's logical updates to and from its peer.

cufwFOGroupIdx

1.3.6.1.4.1.9.9.491.1.4.3.2.1.1

CUfwFOGroupId0 = default1 = group12 = group2This type denotes possible HA group identifiers. A failover group is simply a logical group of one or more security contexts. One group is assigned to be active on the primary ASA, and the other group is assigned to be active on the secondary ASA. When a failover occurs, it occurs at the failover group level. Use value 0, if not applicable. · Integer32

A distinct HA group identifier for which this conceptual row summarizes the sync statistics.

cufwFOCLientId

1.3.6.1.4.1.9.9.491.1.4.3.2.1.2

Integer32 (1..64)

A distinct HA client identifier for which this conceptual row summarizes the sync statistics.

cufwFOCLientName

1.3.6.1.4.1.9.9.491.1.4.3.2.1.3

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The HA client's name for which this conceptual row summarizes the sync statistics.

cufwFOLUTransmitCount

1.3.6.1.4.1.9.9.491.1.4.3.2.1.4

Counter32

The count of transmitted updates sent to peer for the HA client.

cufwFOLUTransmitErrors

1.3.6.1.4.1.9.9.491.1.4.3.2.1.5

Counter32

The count of transmit errors for updates sent to peer for the HA client.

cufwFOLUReceiveCount

1.3.6.1.4.1.9.9.491.1.4.3.2.1.6

Counter32

The count of received updates from peer for the HA client.

cufwFOLUReceiveErrors

1.3.6.1.4.1.9.9.491.1.4.3.2.1.7

Counter32

The count of receive errors for updates from peer for the HA client.

cufwFOHistoryEvTable

1.3.6.1.4.1.9.9.491.1.4.4.3

Index: cufwFOGrpIndex · cufwFOHistoryIndex

This table summarizes the failover state of a logical group of ASA contexts.

cufwFOGrpIndex

1.3.6.1.4.1.9.9.491.1.4.4.3.1.1

CUfwFOGroupId0 = default1 = group12 = group2This type denotes possible HA group identifiers. A failover group is simply a logical group of one or more security contexts. One group is assigned to be active on the primary ASA, and the other group is assigned to be active on the secondary ASA. When a failover occurs, it occurs at the failover group level. Use value 0, if not applicable. · Integer32

A distinct HA group identifier for which this conceptual row summarizes time-tale history of failover events.

cufwFOHistoryIndex

1.3.6.1.4.1.9.9.491.1.4.4.3.1.2

Integer32

A distinct index that points to an entry in the table for an HA group.

cufwFOGrpHAFromState

1.3.6.1.4.1.9.9.491.1.4.4.3.1.3

CUfwFOState0 = init1 = disabled2 = failed3 = negotiation4 = standbyCold5 = standbyConfig6 = standbyFilesys7 = standbyBulk8 = standby9 = activeFast10 = activeDrain11 = activePreConf12 = activePostConf13 = active14 = invalidThis type denotes possible HA states. init : Establishing any platform dependant capabilities required for redundancy disabled : Failover is disabled failed : Unit is disabled for some reason negotiation : Negotiating to identify the peer standbyCold : Verifing compatibility with the peer device standbyConfig : Config sync with Active standbyFilesys: Syncing its file system with Active standbyBulk : Executing a bulk sync for some HA clients standby : Unit progression to standby complete activeFast : HA clients are completing time critical platform dependent processing activeDrain : HA clients are notified to drain already queued messages activePreConf : HA clients are preparing for system configuration active : Unit is Active · Integer32

The log entry points to the HA state that this event transitioned from.

cufwFOGrpHAToState

1.3.6.1.4.1.9.9.491.1.4.4.3.1.4

CUfwFOState0 = init1 = disabled2 = failed3 = negotiation4 = standbyCold5 = standbyConfig6 = standbyFilesys7 = standbyBulk8 = standby9 = activeFast10 = activeDrain11 = activePreConf12 = activePostConf13 = active14 = invalidThis type denotes possible HA states. init : Establishing any platform dependant capabilities required for redundancy disabled : Failover is disabled failed : Unit is disabled for some reason negotiation : Negotiating to identify the peer standbyCold : Verifing compatibility with the peer device standbyConfig : Config sync with Active standbyFilesys: Syncing its file system with Active standbyBulk : Executing a bulk sync for some HA clients standby : Unit progression to standby complete activeFast : HA clients are completing time critical platform dependent processing activeDrain : HA clients are notified to drain already queued messages activePreConf : HA clients are preparing for system configuration active : Unit is Active · Integer32

The log entry points to the HA state that this event transitioned to.

cufwFOGrpTransitionAt

1.3.6.1.4.1.9.9.491.1.4.4.3.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The date&time at which this transition happened for an HA group.

cufwFOGrpTransitionReason

1.3.6.1.4.1.9.9.491.1.4.4.3.1.6

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The reason for this transition event for an HA group.

cufwAspFrameDropsTable

1.3.6.1.4.1.9.9.491.1.5.3.3

Index: cufwAspFrameDropIndex

This table lists all the ASP frame drops on this firewall device.

cufwAspFrameDropIndex

1.3.6.1.4.1.9.9.491.1.5.3.3.1.1

Integer32

Index within the data-plane frame drop list of supported counters.

cufwAspFrameDropName

1.3.6.1.4.1.9.9.491.1.5.3.3.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Name of the frame drop counter.

cufwAspFrameDropDescription

1.3.6.1.4.1.9.9.491.1.5.3.3.1.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Description of the frame drop counter.

cufwAspFrameDropValue

1.3.6.1.4.1.9.9.491.1.5.3.3.1.4

Counter32

Frame drop counter value.

cufwAspFlowDropsTable

1.3.6.1.4.1.9.9.491.1.5.3.4

Index: cufwAspFlowDropIndex

This table lists all the ASP flow drops on this firewall device.

cufwAspFlowDropIndex

1.3.6.1.4.1.9.9.491.1.5.3.4.1.1

Integer32

Index within the data-plane flow drop list of supported counters.

cufwAspFlowDropName

1.3.6.1.4.1.9.9.491.1.5.3.4.1.2

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Name of the flow drop counter.

cufwAspFlowDropDescription

1.3.6.1.4.1.9.9.491.1.5.3.4.1.3

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

Description of the flow drop counter.

cufwAspFlowDropValue

1.3.6.1.4.1.9.9.491.1.5.3.4.1.4

Counter32

Flow drop counter value.

cufwCluInterfaceTable

1.3.6.1.4.1.9.9.491.1.8.2.3

Index: cuCluIfcIndex

This table summarises the health of each interface in a cluster unit.

cuCluIfcIndex

1.3.6.1.4.1.9.9.491.1.8.2.3.1.1

InterfaceIndexA unique value, greater than zero, for each interface or interface sub-layer in the managed system. It is recommended that values are assigned contiguously starting from 1. The value for each interface sub-layer must remain constant at least from one re-initialization of the entity's network management system to the next re-initialization. (1..2147483647) · Integer32 · hint d

The ifIndex from the IF-MIB for an interface in a cluster unit.

cufwCluHealthStatus

1.3.6.1.4.1.9.9.491.1.8.2.3.1.2

CUfwCluHealth0 = init1 = up2 = down3 = goingDown4 = goingUp5 = noLicense6 = noneThis type denotes possible cluster interface/app health states. · Integer32

The health-check outcome of the interface being addressed in a cluster unit.

cufwCluHealthCheck

1.3.6.1.4.1.9.9.491.1.8.2.3.1.3

CUfwInterfaceMonitor0 = unknown1 = monitored2 = notMonitored3 = waiting4 = autostateDown5 = shutdownThis type denotes possible interface monitor states. monitored : interface monitoring is enabled. notMonitored : interface monitoring is not enabled. waiting : interface tests are going on and awaiting results. autostateDown: Applies only to ASASM interfaces. Supervisor informs when last physical interface of that vlan goes down. shutdown : interface is administratively down · Integer32

The monitoring state of the interface being addressed in a cluster unit.

cufwCluHistEvTable

1.3.6.1.4.1.9.9.491.1.8.3.2

Index: cufwCluHistIndex

This table summarises the cluster state transitions' history in a unit.

cufwCluHistIndex

1.3.6.1.4.1.9.9.491.1.8.3.2.1.1

INTEGER · Integer32

A distinct index that points to an entry in the cluster history table for this unit.

cufwCluFromState

1.3.6.1.4.1.9.9.491.1.8.3.2.1.2

CUfwCluState0 = disabled1 = election2 = onCall3 = slaveCold4 = slaveAppSync5 = slaveConfig6 = slaveFilesys7 = slaveBulkSync8 = slave9 = slavePending10 = deputyBulkSync11 = deputy12 = masterFast13 = masterDrain14 = masterConfig15 = masterPostConfig16 = master17 = masterDeferThis type denotes possible cluster unit states. · Integer32

The log entry points to the cluster state that this event transitioned from.

cufwCluToState

1.3.6.1.4.1.9.9.491.1.8.3.2.1.3

CUfwCluState0 = disabled1 = election2 = onCall3 = slaveCold4 = slaveAppSync5 = slaveConfig6 = slaveFilesys7 = slaveBulkSync8 = slave9 = slavePending10 = deputyBulkSync11 = deputy12 = masterFast13 = masterDrain14 = masterConfig15 = masterPostConfig16 = master17 = masterDeferThis type denotes possible cluster unit states. · Integer32

The log entry points to the cluster state that this event transitioned to.

cufwCluTransitionAt

1.3.6.1.4.1.9.9.491.1.8.3.2.1.4

DateAndTimeA date-time specification. field octets contents range ----- ------ -------- ----- 1 1-2 year* 0..65536 2 3 month 1..12 3 4 day 1..31 4 5 hour 0..23 5 6 minutes 0..59 6 7 seconds 0..60 (use 60 for leap-second) 7 8 deci-seconds 0..9 8 9 direction from UTC '+' / '-' 9 10 hours from UTC* 0..13 10 11 minutes from UTC 0..59 * Notes: - the value of year is in network-byte order - daylight saving time in New Zealand is +13 For example, Tuesday May 26, 1992 at 1:30:15 PM EDT would be displayed as: 1992-5-26,13:30:15.0,-4:0 Note that if only local time is known, then timezone information (fields 8-10) is not present. SIZE (8 | 11) · OCTET STRING · hint 2d-1d-1d,1d:1d:1d.1d,1a1d:1d

The date&time at which this transition happened for the cluster unit.

cufwCluTransitionReason

1.3.6.1.4.1.9.9.491.1.8.3.2.1.5

DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..255) · OCTET STRING · hint 255a

The reason for this transition for the cluster unit.

Trap details

ciscoUFwUrlfServerStateChange

1.3.6.1.4.1.9.9.491.0.1

This notification is generated when the firewall elects a new primary URL filtering server from the existing set of configured servers. Such a change could occur either as a result of the current primary server becoming unavailable or as a result of explicit management action in nominating a filtering server the primary server. The notification is issued just before the change occurs. Consequently, the varbinds identify the attributes corresponding to the old primary server. This notification is issued if and only if the object 'cufwCntlUrlfServerStatusChange' has been set to 'true'.

cufwUrlfServerStatus

1.3.6.1.4.1.9.9.491.1.3.3.1.1.5

CFWUrlServerStatus1 = online2 = offline3 = indeterminateThis type denotes the status of the URL filtering server which the firewall uses to implement URL filtering. The following values are defined: 'online' Indicates that the Server is online 'offline' Indicates that the Server is offline 'indeterminate' Indicates that the Server status cannot be determined · Integer32

The status of the URL filtering server corresponding to this conceptual row.

ciscoUFwL2StaticMacAddressMoved

1.3.6.1.4.1.9.9.491.0.2

This notification is generated when the firewall detects the move of a static MAC address to a new port. Such a change could occur either as a result of physical move of the device with the MAC Address to the new port, due to management action of relocating the MAC address at the new location or due to MAC address spoofing. The varbinds identify the new location (port) of the MAC Address and its status at the new location. This notification is issued if and only if the object 'cufwCntlL2StaticMacAddressMoved' has been set to 'true'.

dot1dTpFdbPort

1.3.6.1.2.1.17.4.3.1.2

Integer32

Either the value '0', or the port number of the port on which a frame having a source address equal to the value of the corresponding instance of dot1dTpFdbAddress has been seen. A value of '0' indicates that the port number has not been learned, but that the bridge does have some forwarding/filtering information about this address (e.g., in the dot1dStaticTable). Implementors are encouraged to assign the port value to this object whenever it is learned, even for addresses for which the corresponding value of dot1dTpFdbStatus is not learned(3).

dot1dTpFdbStatus

1.3.6.1.2.1.17.4.3.1.3

INTEGER1 = other2 = invalid3 = learned4 = self5 = mgmt · Integer32

The status of this entry. The meanings of the values are: other(1) - none of the following. This would include the case where some other MIB object (not the corresponding instance of dot1dTpFdbPort, nor an entry in the dot1dStaticTable) is being used to determine if and how frames addressed to the value of the corresponding instance of dot1dTpFdbAddress are being forwarded. invalid(2) - this entry is no longer valid (e.g., it was learned but has since aged out), but has not yet been flushed from the table. learned(3) - the value of the corresponding instance of dot1dTpFdbPort was learned, and is being used. self(4) - the value of the corresponding instance of dot1dTpFdbAddress represents one of the bridge's addresses. The corresponding instance of dot1dTpFdbPort indicates which of the bridge's ports has this address. mgmt(5) - the value of the corresponding instance of dot1dTpFdbAddress is also the value of an existing instance of dot1dStaticAddress.

cufwFailoverStateChanged

1.3.6.1.4.1.9.9.491.0.3

This notification is generated when the firewall detects a state change in either units of an HA pair. This notification is issued if and only if the object 'cufwCntlFOstateChange' has been set to 'true'.

cufwFOGroupIndex

1.3.6.1.4.1.9.9.491.1.4.2.1.1.1

CUfwFOGroupId0 = default1 = group12 = group2This type denotes possible HA group identifiers. A failover group is simply a logical group of one or more security contexts. One group is assigned to be active on the primary ASA, and the other group is assigned to be active on the secondary ASA. When a failover occurs, it occurs at the failover group level. Use value 0, if not applicable. · Integer32

A distinct HA group identifier for which this conceptual row summarizes critical failover data.

cufwFOGrpHAstate

1.3.6.1.4.1.9.9.491.1.4.2.1.1.3

HardwareStatus1 = other2 = up3 = down4 = error5 = overTemp6 = busy7 = noMedia8 = backup9 = active10 = standbyThis textual convention is used to describe various events that are related to the resources on a firewall. other : Generic resource event. up : The resource is in service. down : The resource is not in service. error : There has been an error for this resource. overTemp : The resource is overheating. busy : The resource is busy. noMedia : A device doesn't have its needed media. backup : Processing has switched to the backup. active : This is the active unit. standby : This is the standby unit. · Integer32

The current HA role of a group on the unit being polled. Allowed values are active or standby or unknown.

cufwClusterStateChanged

1.3.6.1.4.1.9.9.491.0.4

This notification is generated when the firewall detects a new master has been elected. This notification is issued if and only if the object 'cufwCntlCluStateChange' has been set to 'true'.

cufwCluUnitState

1.3.6.1.4.1.9.9.491.1.8.1.3

CUfwCluState0 = disabled1 = election2 = onCall3 = slaveCold4 = slaveAppSync5 = slaveConfig6 = slaveFilesys7 = slaveBulkSync8 = slave9 = slavePending10 = deputyBulkSync11 = deputy12 = masterFast13 = masterDrain14 = masterConfig15 = masterPostConfig16 = master17 = masterDeferThis type denotes possible cluster unit states. · Integer32

The current state of the unit in cluster.

↑ To TOC