CISCO-FIREPOWER-OS-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FIREPOWER-OS-MIB

Organization: Cisco Systems Inc.

Last Updated: 2022-08-25

Category: Cisco Devices, Hardware and Environment

Description: Provides management objects for monitoring operating system configuration and status on Cisco UCS/Firepower managed compute nodes.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FIREPOWER-OS-MIB?

CISCO-FIREPOWER-OS-MIB is Cisco's vendor MIB modeling operating-system-level management information for Firepower-managed compute nodes running within UCS-based Firepower security appliance chassis. It exposes an "OS agent" data model tracking agent instance identity (distinguished name/relative name), vendor, and type, along with the agent's last and previous administrative command and event, including event timestamps. Its monitoring value is around software/OS agent status: cfprOsAgentLastCmd/cfprOsAgentLastEvt and their timestamp (cfprOsAgentLastEvtTs) let an operator see the most recent management action taken on a Firepower OS instance and when it occurred, while cfprOsAgentPrevCmd/cfprOsAgentPrevEvt preserve the prior state for change auditing, useful for confirming a reboot, reset, or configuration command completed as expected. As part of Cisco's broader UCS/Firepower management information model, it is closely tied to and modeled after Cisco's UCS Manager (UCSM) management object framework rather than a plain IETF standard. It is typically deployed in data-center security environments running Cisco Firepower Threat Defense on UCS-based compute blades/nodes, where operators can download the CISCO-FIREPOWER-OS-MIB file to track OS-level command/event history for each managed node.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREPOWER-OS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Firepower security appliance (UCS-based compute node)

Monitoring Examples

An admin would poll cfprOsAgentTable (indexed by cfprOsAgentInstanceId) and read cfprOsAgentLastCmd together with cfprOsAgentLastEvt and cfprOsAgentLastEvtTs to confirm a recent administrative command issued to a Firepower OS agent actually completed, and when. Comparing cfprOsAgentPrevCmd/cfprOsAgentPrevEvt to the current values reveals whether the agent's state changed since the last poll, useful for detecting an unexpected or unauthorized command execution. cfprOsAgentDn/cfprOsAgentRn identify exactly which managed object in the Firepower/UCS hierarchy the event pertains to, letting an operator pinpoint the affected compute node.

What Can Be Monitored

  • OS agent last command
  • OS agent last event and timestamp
  • OS agent previous command/event
  • managed object identity (DN/RN)
Imported Objects

From CISCO-FIREPOWER-MIB

CfprManagedObjectDn
CfprManagedObjectId
ciscoFirepowerMIBObjectsOBJECT-IDENTITY

From CISCO-FIREPOWER-TC-MIB

CfprConditionRemoteInvRslt
CfprFsmCompletion
CfprFsmFsmStageStatus
CfprHostagAction
CfprHostagAgentType
CfprHostagEvent
CfprOsBootingUpType
CfprOsControllerBootMode
CfprOsControllerFormatDisk
CfprOsControllerFsmCurrentFsm
CfprOsControllerFsmStageName
CfprOsControllerFsmTaskFlags
CfprOsControllerFsmTaskItem
CfprOsDeployState
CfprOsInitState
CfprOsInstallLicenseState
CfprOsOsMode
CfprOsOsType
CfprOsUpgradeReturnCode
CfprOsUpgradeState

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoAlarmSeverity
CiscoInetAddressMask
CiscoNetworkAddress
TimeIntervalSec
Unsigned64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
MacAddress
RowPointer
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue
OIDs

RFC description

MIB representation of Cisco Firepower OS management information model covering operating system deployment, licensing, and upgrades.

Start monitoring Cisco Firepower security appliance (UCS-based compute node) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREPOWER-OS-MIB