CISCO-FIREWALL-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-FIREWALL-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2005-12-06

Category: Cisco Devices, VPN and Security

Description: Monitors Cisco firewall devices, providing connection statistics and security event information for firewall activity tracking.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-FIREWALL-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-FIREWALL-MIB?

CISCO-FIREWALL-MIB is a Cisco enterprise MIB for monitoring firewall-capable Cisco devices such as PIX, ASA, and IOS Firewall-enabled routers. It centers on an events table capturing security, content-inspection, connection, access, authentication, and generic firewall event types, each carrying a timestamp, index, and description. Rather than physical hardware sensors, it focuses on software-level security and connection status, letting administrators track attack attempts, authentication failures, and connection anomalies in near real time. It follows standard SNMP notification conventions and is commonly paired with other Cisco security MIBs (e.g. syslog or IPSec MIBs) for a fuller picture on the same platform. It is deployed on Cisco perimeter and internal firewalls in enterprise and service-provider networks needing centralized SNMP-based event correlation. Security teams building centralized firewall event correlation frequently search for the cisco-firewall-mib specification when integrating Cisco ASA/PIX alerts into their SNMP monitoring pipeline.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco PIX/ASA firewalls
  • Cisco IOS Firewall-enabled routers

Monitoring Examples

An NMS can poll cfwBasicEventsTable, indexed by cfwBasicEventIndex, to retrieve entries with cfwBasicEventTime, cfwBasicSecurityEventType or cfwBasicConnectionEventType, and cfwBasicEventDescription. A sudden spike in cfwBasicAccessEventType or cfwBasicAuthenticationEventType entries would reveal a brute-force login attempt or access policy violation. cfwBasicEventsTableLastRow lets a poller fetch only new events efficiently since the previous check.

What Can Be Monitored

  • firewall security events
  • connection events
  • access control violations
  • authentication failures
  • content inspection events
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From IF-MIB

InterfaceIndexOrZero

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
RowPointer
TEXTUAL-CONVENTION
OIDs

RFC description

Monitors Cisco Firewalls (PIX and IOS devices) providing status, statistics, and events for firewall system management.

Start monitoring Cisco PIX/ASA firewalls and IOS Firewall-enabled routers (legacy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-FIREWALL-MIB