ACC-IPFILTER

MIB Reference — IPNetwork Monitor

All MIBsACC-IPFILTER

Category: IP and Core Protocols, Vendor: ACC/Ericsson

Description:

Handles IP packet filtering (access control list) configuration on ACC/Ericsson routers, supporting permit/deny rules based on address and protocol.

Imported Objects

From ACC-MIB

DisplayString
IfIndex
RowStatus
SmdsAddress
accBRGOBJECT-IDENTITY

From ACC-SYSTEM

accTrapLogSeqNumOBJECT-TYPE

From RFC1155-SMI

Counter
IpAddress
OBJECT-TYPE
TimeTicks

What Is ACC-IPFILTER?

This MIB manages IP packet-filtering (access control list) configuration on ACC/Ericsson routers, defining permit/deny rules based on source/destination address and protocol. It is purely a security/configuration MIB governing which traffic is allowed or blocked at the router. It doesn't expose hardware or software health telemetry itself; no sample objects were supplied to confirm whether it includes rule-hit counters, but if present such counters would let an operator verify filter rules are actively matching traffic as intended, useful for confirming a security policy is working or diagnosing unexpectedly blocked traffic. It parallels standard IP access-list concepts found in many vendor and IETF filtering MIBs. It's deployed on ACC/Ericsson routers used for perimeter or inter-network traffic filtering. Network engineers evaluating or troubleshooting this functionality can download the ACC-IPFILTER file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in ACC-IPFILTER. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • configured IP filter/ACL rules
  • permit/deny rule matches (if exposed)

Supported Devices

  • ACC/Ericsson routers

Monitoring Examples

No sample object names were provided for this module; typically, an admin would review the configured permit/deny rule set (source/destination address, protocol) applied to an interface, and if rule-hit or match counters are exposed, would poll them to confirm a specific filter rule is actively blocking or passing the expected traffic, or to detect a rule silently failing to match due to misconfiguration.

OIDs
OID symbolicOID numericTypeAccessDescription
accIpFilter1.3.6.1.4.1.5.1.1.18
INT accIpSrcRouting1.3.6.1.4.1.5.1.1.18.1INTEGERread-writeSource Routing mode
accIpFiltTable1.3.6.1.4.1.5.1.1.18.2not-accessibleList of IP filters Entries added/deleted by management action. Setting any object to NULL deletes the entry
accIpFiltEntry1.3.6.1.4.1.5.1.1.18.2.1not-accessibleSpecific IP filter
IP accIpFiltDAddr1.3.6.1.4.1.5.1.1.18.2.1.1IpAddressread-writeDestination Address
IP accIpFiltDNetMask1.3.6.1.4.1.5.1.1.18.2.1.2IpAddressread-writeDestination Network Mask
IP accIpFiltSAddr1.3.6.1.4.1.5.1.1.18.2.1.3IpAddressread-writeSource Address
IP accIpFiltSNetMask1.3.6.1.4.1.5.1.1.18.2.1.4IpAddressread-writeSource Network Mask
OCT accIpFiltParm1.3.6.1.4.1.5.1.1.18.2.1.5OCTET STRINGread-writeFilter parameters; Byte 0 is Operation 1 [0,1,2] = [None, !,=] Bytes 1,2 is Protocol Byte 3 is Operation 2 [0 = none [1,2,3,4] = both [!, , =] [5,6,7,8] = destination [!, , =] [9,10,11,12] = source [!, , =] Bytes 4,5 is UDP/TCP port number
INT accIpFiltDisp1.3.6.1.4.1.5.1.1.18.2.1.6INTEGERread-writeDisposition of packets meeting the filter criteria. Packets not discarded will be output with the selected relative transmission priority.
accIpSmdsAtTable1.3.6.1.4.1.5.1.1.18.3not-accessibleThe IP/SMDS address translation table. Contains the IP address, Local SNI, IP multicast address (E.164 format), and ARP multicast address (E.164 format).
accIpSmdsAtEntry1.3.6.1.4.1.5.1.1.18.3.1not-accessibleAn IP/SMDS address translation table entry. Each entry contains an IP address and necessary SMDS translation parameters.
IP accIpSmdsAtIpAddr1.3.6.1.4.1.5.1.1.18.3.1.1IpAddressread-onlyThe IP address associated with the Local SNI, IP Multicast and ARP Multicast SMDS addresses.
ADR accIpSmdsAtSmdsAddr1.3.6.1.4.1.5.1.1.18.3.1.2SmdsAddressread-writeThe local SNI SMDS address in E.164 address format (e.g., 0xC18005551212FFFF)
ADR accIpSmdsAtIpMcast1.3.6.1.4.1.5.1.1.18.3.1.3SmdsAddressread-writeThe IP Multicast SMDS Group address in E.164 address format (e.g.,0xE18005551111FFFF)
ADR accIpSmdsAtArpMcast1.3.6.1.4.1.5.1.1.18.3.1.4SmdsAddressread-onlyThe ARP Multicast SMDS Group address in E.164 address format (e.g.,0xE18005551111FFFF)
INT accIpSubDirBcast1.3.6.1.4.1.5.1.1.18.4INTEGERread-writePackets with an all-ones host portion of the destination IP address are called Subnet Directed Broadcast (or Limited Broadcast) packets. This object selects if these packets are to be broadcast onto the destination subnet.
accIpIfFiltDispTable1.3.6.1.4.1.5.1.1.18.5not-accessibleList of revised IP filters which add support for filtering by source or destination interface.
accIpIfFiltDispEntry1.3.6.1.4.1.5.1.1.18.5.1not-accessibleAn entry in the revised IP filter table.
INT accIpIfFiltDispIfIndex1.3.6.1.4.1.5.1.1.18.5.1.1INTEGERread-onlyInterface index to which this filter applies, or zero for global filters. This integer identifies the row of the system wide interfaces table associated with the particular interface.
INT accIpIfFiltDispPktDir1.3.6.1.4.1.5.1.1.18.5.1.2INTEGERread-onlyStream direction to which filter is applied. Input and Output require an interface to be specified. Global indicates all interfaces and both directions. Input and Global filters are applied prior to Output filters. NOTE: a packet originating in the router may not pass through the filter logic.
INT accIpIfFiltDispSeqNum1.3.6.1.4.1.5.1.1.18.5.1.3INTEGERread-onlyAn internally generated sequence number used to allow the Filter display table to be retruned in the order the filters are applied (most specific to least specific) without violating SNMP ordering rules. Sequence numbers for all filters may change with a single addition or modification of a filter. Sequence numbers, once assigned, are not assigned again. This number has no intrinsic meaning.
IP accIpIfFiltDispDAddr1.3.6.1.4.1.5.1.1.18.5.1.4IpAddressread-onlyDestination Address
IP accIpIfFiltDispDNetMask1.3.6.1.4.1.5.1.1.18.5.1.5IpAddressread-onlyDestination Network Mask
IP accIpIfFiltDispSAddr1.3.6.1.4.1.5.1.1.18.5.1.6IpAddressread-onlySource Address
IP accIpIfFiltDispSNetMask1.3.6.1.4.1.5.1.1.18.5.1.7IpAddressread-onlySource Network Mask
INT accIpIfFiltDispOp11.3.6.1.4.1.5.1.1.18.5.1.8INTEGERread-onlyLogical operation to be performed on the next object/parameter (protocol). If 'none', the filter will match any protocol.
INT accIpIfFiltDispProtocol1.3.6.1.4.1.5.1.1.18.5.1.9INTEGERread-onlyIp protocol on which to filter.
INT accIpIfFiltDispOp21.3.6.1.4.1.5.1.1.18.5.1.10INTEGERread-onlyLogical operation to be performed on the next object/parameter (port).
INT accIpIfFiltDispUDPTCPPort1.3.6.1.4.1.5.1.1.18.5.1.11INTEGERread-onlyThe UDP or TCP port number to which the previous logical operation is to apply.
INT accIpIfFiltDispDispos1.3.6.1.4.1.5.1.1.18.5.1.12INTEGERread-onlyDisposition of packets meeting the filter criteria. Packets not discarded will be output with the selected relative transmission priority. The log option causes a rate selected trap to be generated.
CTR accIpIfFiltDispMatches1.3.6.1.4.1.5.1.1.18.5.1.13Counterread-onlyThe number of times this filter criteria has been applied.
TIK accIpIfFiltDispLastMatchTime1.3.6.1.4.1.5.1.1.18.5.1.14TimeTicksread-onlyThe value of sysUpTime the last time this filter was applied.
OCT accIpIfFiltDispMatchPkt1.3.6.1.4.1.5.1.1.18.5.1.15OCTET STRINGread-onlyThis object is used exclusivley for returning information in a trap about the last packet that was filtered. A query of this object will return an octet string of length zero.
accIpIfFiltEditTable1.3.6.1.4.1.5.1.1.18.6not-accessibleA transient table which is used to create/delete /modify an entry in the IP filter database.
accIpIfFiltEditEntry1.3.6.1.4.1.5.1.1.18.6.1not-accessibleAn entry in the revised IP filter table.
INT accIpIfFiltEditIndex1.3.6.1.4.1.5.1.1.18.6.1.1INTEGERread-onlyAn arbitrary number assigned to the record that is currently being edited.
INT accIpIfFiltEditAction1.3.6.1.4.1.5.1.1.18.6.1.2INTEGERread-writeThe action to be performed with this record. In the future the field 'pending' may be added.
INT accIpIfFiltEditIfIndex1.3.6.1.4.1.5.1.1.18.6.1.3INTEGERread-writeInterface index to which this filter applies, or zero for global filters. This integer identifies the row of the system wide interfaces table associated with the particular interface.
INT accIpIfFiltEditPktDir1.3.6.1.4.1.5.1.1.18.6.1.4INTEGERread-writeStream direction to which filter is applied. Input and Output require an interface to be specified. Global indicates all interfaces and both directions. Input and Global filters are applied prior to Output filters. NOTE: a packet originating in the router may not pass through the filter logic.
IP accIpIfFiltEditDAddr1.3.6.1.4.1.5.1.1.18.6.1.5IpAddressread-writeDestination Address
IP accIpIfFiltEditDNetMask1.3.6.1.4.1.5.1.1.18.6.1.6IpAddressread-writeDestination Network Mask
IP accIpIfFiltEditSAddr1.3.6.1.4.1.5.1.1.18.6.1.7IpAddressread-writeSource Address
IP accIpIfFiltEditSNetMask1.3.6.1.4.1.5.1.1.18.6.1.8IpAddressread-writeSource Network Mask
INT accIpIfFiltEditOp11.3.6.1.4.1.5.1.1.18.6.1.9INTEGERread-writeLogical operation to be performed on the next object/parameter (protocol). If 'none', the filter will match any protocol.
INT accIpIfFiltEditProtocol1.3.6.1.4.1.5.1.1.18.6.1.10INTEGERread-writeIp protocol on which to filter.
INT accIpIfFiltEditOp21.3.6.1.4.1.5.1.1.18.6.1.11INTEGERread-writeLogical operation to be performed on the next object/parameter (port).
INT accIpIfFiltEditUDPTCPPort1.3.6.1.4.1.5.1.1.18.6.1.12INTEGERread-writeThe UDP or TCP port number to which the previous logical operation is to apply.
INT accIpIfFiltEditDispos1.3.6.1.4.1.5.1.1.18.6.1.13INTEGERread-writeDisposition of packets meeting the filter criteria. Packets not discarded will be output with the selected relative transmission priority. The log option causes a rate sensitive trap to be generated.
accIpNamedFiltTable1.3.6.1.4.1.5.1.1.18.7not-accessibleTable of port-independent named IP filters
accIpNamedFiltEntry1.3.6.1.4.1.5.1.1.18.7.1not-accessibleEntry for a single named port-independent named IP filter
OCT accIpNamedFiltName1.3.6.1.4.1.5.1.1.18.7.1.1OCTET STRINGread-writeThe name of the filter entry.
INT accIpNamedFiltAction1.3.6.1.4.1.5.1.1.18.7.1.2INTEGERread-writeAction to perform on filter entry: ADD or DELETE
INT accIpNamedFiltPktDir1.3.6.1.4.1.5.1.1.18.7.1.3INTEGERread-writeDirection filter is to be applied in. Filters which are applied globally ignore this parameter
IP accIpNamedFiltDAddr1.3.6.1.4.1.5.1.1.18.7.1.4IpAddressread-writeDestination address to apply in filter
IP accIpNamedFiltDNetMask1.3.6.1.4.1.5.1.1.18.7.1.5IpAddressread-writeDesintation network mask to apply in filter
IP accIpNamedFiltSAddr1.3.6.1.4.1.5.1.1.18.7.1.6IpAddressread-writeSource address to apply in filter
IP accIpNamedFiltSNetMask1.3.6.1.4.1.5.1.1.18.7.1.7IpAddressread-writeSource network mask to apply in filter
INT accIpNamedFiltOp11.3.6.1.4.1.5.1.1.18.7.1.8INTEGERread-writeFirst operator to apply in filter
INT accIpNamedFiltProtocol1.3.6.1.4.1.5.1.1.18.7.1.9INTEGERread-writeProtocol to apply in filter
INT accIpNamedFiltOp21.3.6.1.4.1.5.1.1.18.7.1.10INTEGERread-writeThe secondary operator to apply
INT accIpNamedFiltUDPTCPPort1.3.6.1.4.1.5.1.1.18.7.1.11INTEGERread-writeUDP/TCP port number to apply in filter
INT accIpNamedFiltDisp1.3.6.1.4.1.5.1.1.18.7.1.12INTEGERread-write
CTR accIpNamedFiltMatches1.3.6.1.4.1.5.1.1.18.7.1.13Counterread-onlyCount of times this filter has been matched
TIK accIpNamedFiltLastMatch1.3.6.1.4.1.5.1.1.18.7.1.14TimeTicksread-onlyTime/Date that filter was last matched
INT accIpNamedFiltApplId1.3.6.1.4.1.5.1.1.18.7.1.15INTEGERread-onlyUser defined identification number associated with an application. (i.e, telnet, ftp)
OCT accIpNamedFiltSAIndex1.3.6.1.4.1.5.1.1.18.7.1.16OCTET STRINGread-writePoints to a Security Association used for one communication flow
INT pysmiFakeCol3491.3.6.1.4.1.5.1.1.18.7.1.4294967295INTEGERnot-accessible
accIpFiltApplTable1.3.6.1.4.1.5.1.1.18.8not-accessibleTable showing the list of IP filters that will be applied on a given interface, shown in the order that they will be applied. This is essentially an expansion of the filter profile to filter entries on a per interface basis.
accIpFiltApplEntry1.3.6.1.4.1.5.1.1.18.8.1not-accessibleA single entry in the filter application table.
INT accIpFiltApplIfIndex1.3.6.1.4.1.5.1.1.18.8.1.1INTEGERread-onlyInterface index to which this filter applies, or zero for global filters. This integer identifies the row of the system wide interfaces table associated with the particular interface.
INT accIpFiltApplPktDir1.3.6.1.4.1.5.1.1.18.8.1.2INTEGERread-onlyStream direction to which filter is applied. Input and Output require an interface to be specified. Global indicates all interfaces and both directions. Input and Global filters are applied prior to Output filters. NOTE: a packet originating in the router may not pass through the filter logic.
INT accIpFiltApplSeqNum1.3.6.1.4.1.5.1.1.18.8.1.3INTEGERread-onlyAn internally generated sequence number used to allow the Filter display table to be returned in the order the filters are applied (most specific to least specific) without violating SNMP ordering rules. Sequence numbers for all filters may change with a single addition or modification of a filter. Sequence numbers, once assigned, are not assigned again. This number has no intrinsic meaning.
STR accIpFiltApplName1.3.6.1.4.1.5.1.1.18.8.1.4DisplayStringread-onlyThe name of the filter entry.
CTR accIpFiltApplMatches1.3.6.1.4.1.5.1.1.18.8.1.5Counterread-onlyCount of times this filter has been matched
TIK accIpFiltApplLastMatch1.3.6.1.4.1.5.1.1.18.8.1.6TimeTicksread-onlyTime/Date that filter was last matched

RFC description

Manages IP packet filtering (access control list) configuration on ACC/Ericsson routers, providing permit/deny rules based on address and protocol.

Start monitoring ACC/Ericsson WAN access routers (legacy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download ACC-IPFILTER