A10-AX-MIB :: axSwitchStatsAnomSYNFragDrop

MIB Reference — IPNetwork Monitor

All MIBsA10-AX-MIBaxSwitchStatsAnomSYNFragDrop

axSwitchStatsAnomSYNFragDrop

Module: A10-AX-MIB

OID (symbolic): A10-AX-MIB::axSwitchStatsAnomSYNFragDrop

OID (numeric): 1.3.6.1.4.1.22610.2.4.3.16.28

Node type: OBJECT-TYPE

Type: INTEGER

Access: read-only

Description:

Number of packets dropped by a tcp-syn-frag filter.

What is axSwitchStatsAnomSYNFragDrop?

This OID tracks fragmented TCP SYN packets, which are suspicious because connection initiation should fit in one frame. This filter prevents SYN fragmentation attacks used to evade stateful inspection. A non-zero count, like 50 per hour during attack, confirms the device is blocking evasion attempts; zero in normal operation is expected.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.28
snmpwalk -v2c -c public <target> A10-AX-MIB::axSwitchStatsAnomSYNFragDrop

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.22610.2.4.3.16.28.1
snmpget -v2c -c public <target> A10-AX-MIB::axSwitchStatsAnomSYNFragDrop.1

SNMPv3 example:

snmpget -v3 -l authPriv -u snmpv3-user -a SHA -A "AuthPassword1" -x AES -X "PrivPassword1" <target> axSwitchStatsAnomSYNFragDrop.1

OID Breakdown

Numeric OIDNameModule
1isoLANART-AGENT
1.3orgBIANCA-BRICK-PPP-MIB
1.3.6dodBIANCA-BRICK-PPP-MIB
1.3.6.1internetBIANCA-BRICK-PPP-MIB
1.3.6.1.4privateBIANCA-BRICK-PPP-MIB
1.3.6.1.4.1enterprisesANIROOT-MIB
1.3.6.1.4.1.22610a10A10-COMMON-MIB
1.3.6.1.4.1.22610.2a10MgmtA10-COMMON-MIB
1.3.6.1.4.1.22610.2.4axMgmtA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3axAppA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16axSwitchStatsA10-AX-MIB
1.3.6.1.4.1.22610.2.4.3.16.28axSwitchStatsAnomSYNFragDropA10-AX-MIB