CISCO-FIREPOWER-EXTPOL-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FIREPOWER-EXTPOL-MIB

Organization: Cisco Systems Inc.

Last Updated: 2022-08-25

Category: Cisco Devices, Hardware and Environment

Description: Provides management objects for external policy resolution and integration settings on Cisco UCS/Firepower management platforms.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FIREPOWER-EXTPOL-MIB?

CISCO-FIREPOWER-EXTPOL-MIB is a Cisco enterprise MIB that models the EXTPOL (external policy resolution) management information package used within Cisco UCS/Firepower management platforms to integrate with external policy-providing clients (such as directory or identity services). It exposes a client registration/connection table describing each external policy client's identity, connection protocol, capabilities, and connection state. Its primary monitoring value is software/integration status: confirming that external policy clients are connected, authenticated, and within their grace period, rather than exposing hardware sensors. It follows the broader Cisco UCS management-information-model MIB pattern (distinguished-name/relative-name based objects), implying dependency on the shared Cisco UCS MIB object-naming conventions. It is typically deployed on Cisco Firepower/UCS management appliances that integrate with external identity or policy services, and the CISCO-FIREPOWER-EXTPOL-MIB MIB Browser view lets administrators inspect this client registration state directly.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREPOWER-EXTPOL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Firepower/UCS management platform

Monitoring Examples

An administrator would poll cfprExtpolClientTable to see each registered client's cfprExtpolClientConnProtocol and cfprExtpolClientHost, confirming the client is reachable and using the expected protocol. The cfprExtpolClientGracePeriodUsed field reveals whether a client's connection is operating on a grace-period credential, which could indicate an authentication renewal problem. A client entry with an unexpected cfprExtpolClientCapability or missing cfprExtpolClientGuid would flag a misregistered or stale integration client.

What Can Be Monitored

  • external policy client connection status
  • client connection protocol
  • client capability/descriptor
  • grace-period credential usage
  • client host/identity
Imported Objects

From CISCO-FIREPOWER-MIB

CfprManagedObjectDn
CfprManagedObjectId
ciscoFirepowerMIBObjectsOBJECT-IDENTITY

From CISCO-FIREPOWER-TC-MIB

CfprConditionRemoteInvRslt
CfprExtpolAppCapability
CfprExtpolConnProtocol
CfprExtpolConnType
CfprExtpolConnectorOperState
CfprExtpolEpFsmCurrentFsm
CfprExtpolEpFsmStageName
CfprExtpolEpFsmTaskItem
CfprExtpolProviderFsmCurrentFsm
CfprExtpolProviderFsmStageName
CfprExtpolProviderFsmTaskItem
CfprExtpolRegistryFsmCurrentFsm
CfprExtpolRegistryFsmStageName
CfprExtpolRegistryFsmTaskItem
CfprExtpolState
CfprExtpolSuspendState
CfprFsmCompletion
CfprFsmFlags
CfprFsmFsmStageStatus

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoAlarmSeverity
CiscoInetAddressMask
CiscoNetworkAddress
TimeIntervalSec
Unsigned64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
MacAddress
RowPointer
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue
OIDs

RFC description

Manages external policy objects in Cisco Firepower systems including endpoint registration, provider connections, and FSM state.

Start monitoring Cisco Firepower/UCS management platform with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREPOWER-EXTPOL-MIB