CISCO-FIREPOWER-AAA-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsCISCO-FIREPOWER-AAA-MIB

Organization: Cisco Systems Inc.

Last Updated: 2022-08-25

Category: Cisco Devices, Hardware and Environment

Description: Provides management objects for authentication, authorization, and accounting (AAA) configuration and statistics on Cisco Firepower/UCS platforms.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FIREPOWER-AAA-MIB?

CISCO-FIREPOWER-AAA-MIB models the Authentication, Authorization, and Accounting (AAA) configuration of Cisco Firepower/UCS platforms, mirroring the underlying UCS Manager information model for authentication realms. It exposes tables describing configured authentication realms, their login defaults, role policies, and finite-state-machine (FSM) progress/status fields used internally for tracking configuration transitions. The MIB is oriented toward monitoring software configuration state and operational progress of AAA subsystem tasks rather than physical hardware, including FSM descriptors that reveal stuck or failed AAA configuration operations. It is closely tied to Cisco's UCS/Firepower management information model (MIT) and shares its DN/RN addressing conventions with sibling Firepower MIBs. It is deployed on Cisco Firepower/UCS fabric interconnects and chassis managers for identity and access management oversight. Engineers can download the CISCO-FIREPOWER-AAA-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREPOWER-AAA-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Firepower/UCS fabric interconnects and chassis managers

Monitoring Examples

An administrator would poll cfprAaaAuthRealmTable, identified by cfprAaaAuthRealmDn, reading cfprAaaAuthRealmConLogin and cfprAaaAuthRealmDefLogin to confirm the active authentication realm, and cfprAaaAuthRealmFsmProgr/cfprAaaAuthRealmFsmPrev to check whether a recent AAA configuration change completed successfully. A realm stuck in a non-final FSM state or a description in cfprAaaAuthRealmFsmDescr indicating failure would flag an AAA provisioning problem needing attention.

What Can Be Monitored

  • active authentication realm
  • default login realm
  • default role policy
  • FSM progress/status of AAA changes
  • realm description
Imported Objects

From CISCO-FIREPOWER-MIB

CfprManagedObjectDn
CfprManagedObjectId
ciscoFirepowerMIBObjectsOBJECT-IDENTITY

From CISCO-FIREPOWER-TC-MIB

CfprAaaAccess
CfprAaaAccountStatus
CfprAaaAuthRealmFsmCurrentFsm
CfprAaaAuthRealmFsmStageName
CfprAaaCimcSessionType
CfprAaaCipherMode
CfprAaaClear
CfprAaaConfigState
CfprAaaDomainAuthRealm
CfprAaaEpAccess
CfprAaaEpFsmCurrentFsm
CfprAaaEpFsmStageName
CfprAaaEpFsmTaskItem
CfprAaaExtMgmtAccess
CfprAaaFqdnEnforceType
CfprAaaIpmiOverLan
CfprAaaLdapEpFsmCurrentFsm
CfprAaaLdapEpFsmStageName
CfprAaaLdapGroupRuleAuthorization
CfprAaaLdapGroupRuleTraversal
CfprAaaLdapVendor
CfprAaaNoRolePolicy
CfprAaaPwdPolicy
CfprAaaRadiusEpFsmCurrentFsm
CfprAaaRadiusEpFsmStageName
CfprAaaRadiusService
CfprAaaRealm
CfprAaaRealmFsmCurrentFsm
CfprAaaRealmFsmStageName
CfprAaaRealmFsmTaskItem
CfprAaaRevokePolicy
CfprAaaSession
CfprAaaSessionState
CfprAaaSshStr
CfprAaaTacacsPlusEpFsmCurrentFsm
CfprAaaTacacsPlusEpFsmStageName
CfprAaaUserEpFsmCurrentFsm
CfprAaaUserEpFsmStageName
CfprAaaUserEpFsmTaskItem
CfprAaaUserInterface
CfprCommTlsVerType
CfprConditionActionIndicator
CfprConditionCause
CfprConditionCode
CfprConditionRemoteInvRslt
CfprConditionSeverity
CfprFsmCompletion
CfprFsmFlags
CfprFsmFsmStageStatus
CfprNetworkSwitchId
CfprPolicyPolicyOwner

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoAlarmSeverity
CiscoInetAddressMask
CiscoNetworkAddress
TimeIntervalSec
Unsigned64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
MacAddress
RowPointer
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue
OIDs

RFC description

Cisco Firepower AAA management information base for authentication, authorization, and accounting functions.

Start monitoring Cisco Firepower/UCS fabric interconnects and chassis managers with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREPOWER-AAA-MIB