All MIBs › A10-AX-MIB › axSwitchStatsAnomSYNFragDrop
axSwitchStatsAnomSYNFragDrop
Module: A10-AX-MIB
OID (symbolic): A10-AX-MIB::axSwitchStatsAnomSYNFragDrop
OID (numeric): 1.3.6.1.4.1.22610.2.4.3.16.28
Node type: OBJECT-TYPE
Type: INTEGER
Access: read-only
Description:
Number of packets dropped by a tcp-syn-frag filter.
What is axSwitchStatsAnomSYNFragDrop?
This OID tracks fragmented TCP SYN packets, which are suspicious because connection initiation should fit in one frame. This filter prevents SYN fragmentation attacks used to evade stateful inspection. A non-zero count, like 50 per hour during attack, confirms the device is blocking evasion attempts; zero in normal operation is expected.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.28 snmpwalk -v2c -c public <target> A10-AX-MIB::axSwitchStatsAnomSYNFragDrop
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.28.1 snmpget -v2c -c public <target> A10-AX-MIB::axSwitchStatsAnomSYNFragDrop.1
SNMPv3 example:
snmpget -v3 -l authPriv -u snmpv3-user -a SHA -A "AuthPassword1" -x AES -X "PrivPassword1" <target> axSwitchStatsAnomSYNFragDrop.1
OID Breakdown
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | BIANCA-BRICK-PPP-MIB |
| 1.3.6 | dod | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1 | internet | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1.4 | private | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1.4.1 | enterprises | ANIROOT-MIB |
| 1.3.6.1.4.1.22610 | a10 | A10-COMMON-MIB |
| 1.3.6.1.4.1.22610.2 | a10Mgmt | A10-COMMON-MIB |
| 1.3.6.1.4.1.22610.2.4 | axMgmt | A10-AX-MIB |
| 1.3.6.1.4.1.22610.2.4.3 | axApp | A10-AX-MIB |
| 1.3.6.1.4.1.22610.2.4.3.16 | axSwitchStats | A10-AX-MIB |
| 1.3.6.1.4.1.22610.2.4.3.16.28 | axSwitchStatsAnomSYNFragDrop | A10-AX-MIB |