BEGEMOT-PF-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsBEGEMOT-PF-MIB

Organization: NixSys BVBA

Last Updated: 2005-01-24

Category: Net-SNMP and Linux, VPN and Security

Description: Manages FreeBSD PF (Packet Filter) firewall rules, state tables, and traffic counters via bsnmpd.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is BEGEMOT-PF-MIB?

BEGEMOT-PF-MIB is the Begemot family MIB exposing FreeBSD's PF (Packet Filter) firewall through the bsnmpd SNMP agent. It provides overall firewall running/enabled status, runtime and debug-level scalars, a host identifier, packet-level error/drop counters (bad offset, fragment, short packet, normalization events, memory drops), and state-table size and search-rate statistics. This directly monitors firewall software health and performance: whether PF is active, how many stateful connections it is tracking, and whether it is dropping packets due to malformed traffic or memory pressure - key indicators of both correctness and resource strain under load. It is specific to the FreeBSD/bsnmpd implementation rather than tied to an IETF standard, though its state-table concepts parallel other firewall/NAT MIBs. It is deployed on FreeBSD-based firewalls and routers running pf, common in BSD-based network appliances and router distributions. Network engineers evaluating or troubleshooting this functionality can download the BEGEMOT-PF-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in BEGEMOT-PF-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • FreeBSD-based firewalls/routers running pf

Monitoring Examples

An administrator polls pfStatusRunning to confirm the firewall is active, watches pfStateTableCount against a configured limit to detect state-table exhaustion, and monitors pfCounterMemDrop and pfCounterFragment for rising values. A spike in pfCounterMemDrop combined with pfStateTableCount near its maximum indicates the firewall is dropping new connections due to memory or state exhaustion, likely from a connection flood or denial-of-service attack.

What Can Be Monitored

  • firewall running status
  • runtime/debug level
  • state table count
  • state table search rate
  • packet error counters (fragment, short, bad offset, normalize, memory drop)
Imported Objects

From BEGEMOT-MIB

begemotMODULE-IDENTITY

From SNMPv2-SMI

Counter64
Integer32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

TruthValue

How to Use in IPNetwork Monitor

Example using pfCounterMatch OID:

Select a FreeBSD hosts/appliances running the Begemot bsnmpd SNMP agent as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type pfCounterMatch into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of packets that matched a filter rule. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

BEGEMOT (BSD Embedded SNMP) MIB for packet filter (pf) firewall rule and state management on BSD systems.

Start monitoring FreeBSD hosts/appliances running the Begemot bsnmpd SNMP agent with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download BEGEMOT-PF-MIB