A10-AX-MIB :: axSwitchStatAnomSYNFragDrop

MIB Reference — IPNetwork Monitor

All MIBsA10-AX-MIBaxSwitchStatAnomSYNFragDrop

axSwitchStatAnomSYNFragDrop

Module: A10-AX-MIB

OID (symbolic): A10-AX-MIB::axSwitchStatAnomSYNFragDrop

OID (numeric): 1.3.6.1.4.1.22610.2.4.3.16.31.1.29

Node type: OBJECT-TYPE

Type: Counter32

Access: read-only

Description:

Number of packets dropped by a tcp-syn-frag filter.

What is axSwitchStatAnomSYNFragDrop?

This Counter32 counts fragmented TCP SYN packets that are dropped because normal TCP handshakes never arrive as fragments. Blocking these prevents attackers from evading deep packet inspection or exhausting connection resources. An increase from 0 to 100000 drops signals a SYN fragmentation attack attempt is underway and being stopped.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.31.1.29
snmpwalk -v2c -c public <target> A10-AX-MIB::axSwitchStatAnomSYNFragDrop

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.31.1.29.1
snmpget -v2c -c public <target> A10-AX-MIB::axSwitchStatAnomSYNFragDrop.1

OID Breakdown

Numeric OIDNameModule
1isoLANART-AGENT
1.3orgBIANCA-BRICK-PPP-MIB
1.3.6dodBIANCA-BRICK-PPP-MIB
1.3.6.1internetBIANCA-BRICK-PPP-MIB
1.3.6.1.4privateBIANCA-BRICK-PPP-MIB
1.3.6.1.4.1enterprisesANIROOT-MIB
1.3.6.1.4.1.22610a10A10-COMMON-MIB
1.3.6.1.4.1.22610.2a10MgmtA10-COMMON-MIB
1.3.6.1.4.1.22610.2.4axMgmtA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3axAppA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16axSwitchStatsA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16.31axSwitchStatTableA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16.31.1axSwitchStatEntryA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16.31.1.29axSwitchStatAnomSYNFragDropA10-AX-MIB