APSYSMGMT-MIB :: apSysMgmtInetAddrWithReasonDOSTrap

MIB Reference — IPNetwork Monitor

All MIBsAPSYSMGMT-MIBapSysMgmtInetAddrWithReasonDOSTrap

apSysMgmtInetAddrWithReasonDOSTrap

Module: APSYSMGMT-MIB

OID (symbolic): APSYSMGMT-MIB::apSysMgmtInetAddrWithReasonDOSTrap

OID (numeric): 1.3.6.1.4.1.9148.3.2.8.0.4

Node type: NOTIFICATION-TYPE

Description:

This trap is generated when an IP is placed on a deny list due to denial-of-service attempts, and provides the ip address that has been demoted, the realm-id of that IP, (if available) the URI portion of the SIP From header of the message that caused the demotion and the reason for demotion.

What is apSysMgmtInetAddrWithReasonDOSTrap?

This notification (trap) is generated when a system detects denial-of-service attacks and automatically blocks the offending IP address by adding it to a deny list. The trap provides the blocked IP, the affected realm/service context, the SIP message that triggered the block, and the specific reason for demotion. Security operators use this alert to respond to active attacks, review which traffic patterns are triggering DoS protections, and potentially whitelist legitimate traffic if false positives occur.

Examples

Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):

snmptrap -v2c -c public <manager> '' APSYSMGMT-MIB::apSysMgmtInetAddrWithReasonDOSTrap
snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.9148.3.2.8.0.4

Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):

snmptrapd -f -Lo -c /dev/null authCommunity log public

Example snmptrapd log entry:

zoo11-linux.zoo [UDP: [192.168.30.111]:58179->[192.168.30.10]:162]:
  DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (495104323) 57 days, 7:17:23.23
  SNMPv2-MIB::snmpTrapOID.0 = OID: APSYSMGMT-MIB::apSysMgmtInetAddrWithReasonDOSTrap

OID Breakdown

Numeric OIDNameModule
1isoLANART-AGENT
1.3orgBIANCA-BRICK-PPP-MIB
1.3.6dodBIANCA-BRICK-PPP-MIB
1.3.6.1internetBIANCA-BRICK-PPP-MIB
1.3.6.1.4privateBIANCA-BRICK-PPP-MIB
1.3.6.1.4.1enterprisesANIROOT-MIB
1.3.6.1.4.1.9148acmepacketACMEPACKET-SMI
1.3.6.1.4.1.9148.3acmepacketMgmtACMEPACKET-SMI
1.3.6.1.4.1.9148.3.2apSystemManagementModuleACMEPACKET2-ENVMON-MIB
1.3.6.1.4.1.9148.3.2.8apSysMgmtDOSNotificationPrefixACMEPACKET2-ENVMON-MIB
1.3.6.1.4.1.9148.3.2.8.0apSysMgmtDOSNotificationsACMEPACKET2-ENVMON-MIB
1.3.6.1.4.1.9148.3.2.8.0.4apSysMgmtInetAddrWithReasonDOSTrapAPSYSMGMT-MIB