CISCO-FIREPOWER-POLICY-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FIREPOWER-POLICY-MIB

Organization: Cisco Systems Inc.

Last Updated: 2022-08-25

Category: Cisco Devices, Hardware and Environment

Description: Provides management objects for policy definition, inheritance, and enforcement across Cisco UCS/Firepower service profiles and pools.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-FIREPOWER-POLICY-MIB?

CISCO-FIREPOWER-POLICY-MIB is part of the Cisco UCS/Firepower model-based MIB family covering policy definition, inheritance, and enforcement across service profiles and resource pools, including synchronization between central and local policy managers in a multi-domain deployment. It exposes objects describing policy synchronization state (comparing data on each side of a central/local sync relationship) and communication policy settings governing how domains talk to each other. This is a configuration/software-status MIB relevant to monitoring whether policy propagation across a Cisco UCS Central-managed domain hierarchy is consistent, catching drift or failed synchronization before it causes inconsistent enforcement. As with sibling Firepower MIBs, it follows the shared Dn/Rn/InstanceId managed-object model of Cisco's UCS Manager information model rather than an external standards dependency. It is deployed in multi-domain Cisco UCS/Firepower environments managed centrally via UCS Central. Engineers can download the CISCO-FIREPOWER-POLICY-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREPOWER-POLICY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco UCS/Firepower domains managed via UCS Central

Monitoring Examples

An admin can poll cfprPolicyCentraleSyncTable/cfprPolicyCentraleSyncEntry to compare cfprPolicyCentraleSyncLeftData against cfprPolicyCentraleSyncRightData, detecting a mismatch that indicates a central policy has not yet propagated to a local domain; cfprPolicyCommunicationTable reveals the current communication policy state between domains, useful for diagnosing why sync is stalled.

What Can Be Monitored

  • policy synchronization state (left/right data comparison)
  • communication policy status between domains
  • policy inheritance/enforcement drift
Imported Objects

From CISCO-FIREPOWER-MIB

CfprManagedObjectDn
CfprManagedObjectId
ciscoFirepowerMIBObjectsOBJECT-IDENTITY

From CISCO-FIREPOWER-TC-MIB

CfprConditionRemoteInvRslt
CfprFsmCompletion
CfprFsmFlags
CfprFsmFsmStageStatus
CfprPolicyCleanupMode
CfprPolicyControlEpFsmCurrentFsm
CfprPolicyControlEpFsmStageName
CfprPolicyControlEpFsmTaskItem
CfprPolicyControlEpType
CfprPolicyControlSource
CfprPolicyControlledTypeFsmCurrentFsm
CfprPolicyControlledTypeFsmStageName
CfprPolicyControlledTypeFsmTaskItem
CfprPolicyIdResolvePolicyType
CfprPolicyPolicyOperStatus
CfprPolicyPolicyOwner
CfprPolicyPolicyResolveType
CfprPolicyPolicyScopeFsmCurrentFsm
CfprPolicyPolicyScopeFsmStageName
CfprPolicyPolicyScopeFsmTaskItem
CfprPolicyRegistrationStateType
CfprPolicyRepairStateType
CfprPolicyResumeAckState
CfprPolicyState
CfprPolicySuspendState

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoAlarmSeverity
CiscoInetAddressMask
CiscoNetworkAddress
TimeIntervalSec
Unsigned64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
Gauge32
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
MacAddress
RowPointer
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue
OIDs

RFC description

Cisco Firepower security policy management and threat control.

Start monitoring Cisco UCS/Firepower domains managed via UCS Central with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREPOWER-POLICY-MIB