CISCO-UNIFIED-FIREWALL-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIB

Organization: Cisco Systems

Last Updated: 2021-03-18

Category: Cisco Devices, VPN and Security

Description: Manages Cisco unified firewall providing session statistics, connection counts, and policy enforcement metrics.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-UNIFIED-FIREWALL-MIB?

CISCO-UNIFIED-FIREWALL-MIB models status and performance statistics common to Cisco's stateful firewall implementations (such as those on ASA and IOS Zone-Based/Context-Based firewalls), covering stateful packet filtering and related connection-management features. It exposes global connection counters covering attempts, successful setups, aborted/declined setups (due to policy or resource limits), half-open and fully active connections, expirations, and connection-setup rate over rolling intervals. This makes it a strong performance/fault monitoring MIB for firewall software health: rising cufwConnGlobalNumHalfOpen or cufwConnGlobalNumEmbryonic counts can indicate a SYN-flood style attack, while cufwConnGlobalNumPolicyDeclined and cufwConnGlobalNumResDeclined reveal connections being rejected by policy or due to resource exhaustion, and setup-rate objects show real-time connection load trends. It is a self-contained Cisco enterprise MIB, explicitly scoped to exclude firewall configuration (only status/statistics), so it complements rather than depends on separate configuration-oriented MIBs. It is deployed on Cisco firewall/security appliances and IOS devices running firewall features, monitored by security operations teams for both capacity planning and attack detection. Engineers can download the CISCO-UNIFIED-FIREWALL-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-UNIFIED-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco ASA firewalls
  • Cisco IOS devices with zone-based/context-based firewall features

Monitoring Examples

A security operator would poll cufwConnGlobalNumActive alongside cufwConnGlobalNumHalfOpen and cufwConnGlobalNumEmbryonic to gauge current connection load and detect a potential SYN-flood if half-open/embryonic counts spike disproportionately to active connections. cufwConnGlobalNumSetupsAborted and cufwConnGlobalNumPolicyDeclined would be checked to distinguish legitimate policy blocking from resource exhaustion (cufwConnGlobalNumResDeclined). cufwConnGlobalConnSetupRate1 and cufwConnGlobalConnSetupRate5 (1- and 5-minute setup rates) give a rolling view of connection churn useful for correlating a traffic spike with a firewall performance event, and ciscoUnifiedFirewallMIBNotifs would fire traps for related fault conditions.

What Can Be Monitored

  • total connection attempts and successful setups
  • aborted/policy-declined/resource-declined connections
  • half-open and embryonic connection counts
  • active and expired connection counts
  • 1-minute and 5-minute connection setup rates
Imported Objects

From BRIDGE-MIB

dot1dTpFdbPort
dot1dTpFdbStatus

From CISCO-FIREWALL-MIB

Hardware
HardwareStatus

From CISCO-FIREWALL-TC

CFWApplicationProtocol
CFWNetworkProtocol
CFWPolicy
CFWPolicyTarget
CFWPolicyTargetType
CFWUrlServerStatus
CFWUrlfVendorId

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From IF-MIB

InterfaceIndex

From INET-ADDRESS-MIB

InetAddress
InetAddressType
InetPortNumber

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE

From SNMPv2-TC

DateAndTime
DisplayString
TEXTUAL-CONVENTION
TimeStamp
TruthValue
OIDs

RFC description

Cisco firewall statistics and status monitoring MIB covering policies, protocols, and performance metrics.

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-UNIFIED-FIREWALL-MIB