CISCO-IETF-NAT-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IETF-NAT-MIB

Organization: Cisco Systems, Inc

Last Updated: 2001-03-01

Category: Cisco Devices, VPN and Security

Description: Contains objects for monitoring and managing Network Address Translation (NAT) operations including NAT configuration, address bindings, and runtime statistics.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-IETF-NAT-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-IETF-NAT-MIB?

CISCO-IETF-NAT-MIB is Cisco's implementation of a generic Network Address Translation (NAT) management module, modeled on IETF NAT MIB concepts, for configuring and monitoring NAT operation on Cisco routers and firewalls. It belongs to Cisco's IP services/security MIB family and exposes NAT configuration profiles (service type, protocol idle/negotiation timeouts for ICMP, UDP, and TCP) alongside address-binding and configuration-storage objects. Its monitoring value is chiefly in the NAT software service's operational configuration and binding behavior: administrators track timeout settings and binding lifetimes to understand and troubleshoot how quickly translated sessions age out, which can explain premature session drops or lingering stale translations. It is explicitly modeled after IETF NAT MIB work, adapted to Cisco's configuration model, rather than a strict RFC implementation. It is deployed on Cisco routers and security appliances performing NAT/PAT for enterprise or service-provider edge networks. Engineers can download the CISCO-IETF-NAT-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-IETF-NAT-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco router or security appliance performing NAT/PAT

Monitoring Examples

An administrator would inspect cnatConfTable/cnatConfEntry by cnatConfName to review cnatConfServiceType along with cnatConfTimeoutTcpIdle, cnatConfTimeoutUdpIdle, and cnatConfTimeoutIcmpIdle for a given NAT policy. Comparing cnatConfMaxBindLeaseTime and cnatConfMaxBindIdleTime against observed session-drop complaints can reveal whether translations are timing out too aggressively. Under cnatConfig/cnatBind, checking cnatConfStorageType confirms whether NAT configuration persists across a reload, relevant when unexpected NAT policy resets are reported after a device restart.

What Can Be Monitored

  • NAT configuration profiles
  • protocol-specific idle/negotiation timeouts (TCP/UDP/ICMP)
  • maximum binding lease and idle time
  • NAT binding table
  • configuration storage type
Imported Objects

From CISCO-SMI

ciscoExperimentOBJECT-IDENTITY

From IF-MIB

InterfaceIndex

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32
mib-2

From SNMPv2-TC

RowStatus
StorageType
TEXTUAL-CONVENTION

How to Use in IPNetwork Monitor

Example using cnatAddrBindInTranslate OID:

Select a Cisco router or security appliance performing NAT/PAT as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cnatAddrBindInTranslate into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. The number of inbound packets that were translated as per this BIND entry. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Generic NAT configuration, bindings, and statistics management for Cisco devices.

Start monitoring Cisco router or security appliance performing NAT/PAT with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-IETF-NAT-MIB