CISCO-FILTER-GROUP-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FILTER-GROUP-MIB

Category: Cisco Devices, VPN and Security

Description: Provides management objects for defining and managing named traffic filter groups applied to network interfaces on Cisco devices.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FILTER-GROUP-MIB?

CISCO-FILTER-GROUP-MIB lets a management station create and configure reusable 'filter groups' -- named collections of match criteria -- that Cisco IOS devices use to build access-control lists for packet filtering across IP and other protocols. Each group is typed as network (IP address plus wildcard-mask entries), IP protocol (protocol numbers such as TCP, UDP, GRE, OSPF, EIGRP), IP service (TCP/UDP port ranges), or ICMP (type/code pairs), and a group's type is fixed once it is created. A separate nested-group table lets one filter group reference another, so complex filtering policies can be built up from smaller, reusable building blocks rather than duplicated inline. Because the module defines no counters or traps of its own, it represents pure configuration state -- the actual packet-matching and permit/deny decisions happen in whatever ACL feature, not defined in this MIB, consumes these named groups. It is a supporting building-block MIB rather than a stand-alone monitoring tool, best explored via a CISCO-FILTER-GROUP-MIB MIB Browser when auditing or programmatically managing the reusable object groups behind a device's access-control policy.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FILTER-GROUP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco IOS routers/switches supporting object-group-based ACL configuration

Monitoring Examples

A network engineer could read cfgFilterGroupTable to enumerate every named filter group configured on a router and its type, then walk cfgFilterIpServiceGroupTable to confirm a 'web-ports' service group actually contains TCP 80 and 443 as intended. To build a policy that blocks a set of subnets except for HTTP/HTTPS, the engineer would populate a network-type group in cfgFilterNetworkGroupTable with the address/wildcard-mask pairs, then reference an existing service group inside it via cfgFilterNestedGroupTable rather than re-entering the port ranges. Comparing the actual group contents against an intended security policy this way is a straightforward SNMP-based configuration-audit check.

What Can Be Monitored

  • configured filter group names and types
  • IP network/wildcard-mask entries per group
  • IP protocol number entries per group
  • TCP/UDP port range entries per group
  • ICMP type/code entries per group
  • nested filter-group relationships
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoIpProtocol

From INET-ADDRESS-MIB

InetAddress
InetAddressType
InetPortNumber

From RFC-1212

OBJECT-TYPE

From RFC1155-SMI

Gauge

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-TC-v1

RowStatus
StorageType
OIDs

RFC description

Packet filtering and access control groups for IP protocols and services on Cisco devices.

Start monitoring Cisco IOS routers/switches (object-group-based ACLs) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FILTER-GROUP-MIB