CISCO-UNIFIED-FIREWALL-MIB :: ciscoUFwL2StaticMacAddressMoved

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBciscoUFwL2StaticMacAddressMoved

ciscoUFwL2StaticMacAddressMoved

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::ciscoUFwL2StaticMacAddressMoved

OID (numeric): 1.3.6.1.4.1.9.9.491.0.2

Node type: NOTIFICATION-TYPE

Description: This notification is generated when the firewall detects the move of a static MAC address to a new port.

Such a change could occur either as a result of physical move of the device with the MAC Address to the new port, due to management action of relocating the MAC address at the new location or due to MAC address spoofing.

The varbinds identify the new location (port) of the MAC Address and its status at the new location.

This notification is issued if and only if the object 'cufwCntlL2StaticMacAddressMoved' has been set to 'true'.

Examples

Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):

snmptrap -v2c -c public <manager> '' CISCO-UNIFIED-FIREWALL-MIB::ciscoUFwL2StaticMacAddressMoved
snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.9.9.491.0.2

Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):

snmptrapd -f -Lo -c /dev/null authCommunity log public

Example snmptrapd log entry:

zoo11-linux.zoo [UDP: [192.168.30.111]:62344->[192.168.30.10]:162]:
  DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (230766472) 26 days, 17:01:04.72
  SNMPv2-MIB::snmpTrapOID.0 = OID: CISCO-UNIFIED-FIREWALL-MIB::ciscoUFwL2StaticMacAddressMoved

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::ciscoUFwL2StaticMacAddressMoved OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.0ciscoUnifiedFirewallMIBNotifsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.0.2ciscoUFwL2StaticMacAddressMovedCISCO-UNIFIED-FIREWALL-MIB