CISCO-UNIFIED-FIREWALL-MIB :: cufwAaicFwdbeforeDropCount

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwAaicFwdbeforeDropCount

cufwAaicFwdbeforeDropCount

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicFwdbeforeDropCount

OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.3.1.11

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: Valid for NGIPS interfaces only. This is the number of to-be-dropped packets forwarded to Snort. When the Lina process decides to drop the frame for some reason such as (Invalid TCP header length, Invalid UDP length or Invalid IP length), the frames are also sent to Snort for visibility.

What is cufwAaicFwdbeforeDropCount?

This Counter64, in Packet, applies only to NGIPS interfaces and counts to-be-dropped packets that were still forwarded to Snort for visibility, such as packets with an invalid TCP, UDP, or IP header length that Lina had already decided to drop. An admin uses this to understand how many packets Snort gets to see purely for logging and analysis purposes even though the firewall has already decided to discard them. A high count here would tell an admin that malformed packets, while dropped, are still being surfaced to Snort's visibility rather than silently disappearing.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.3.1.11
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicFwdbeforeDropCount

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.3.1.11.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicFwdbeforeDropCount.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicFwdbeforeDropCount OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5cuFwAaicGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.3cufwAaicEngineStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.3.1cufwAaicLinaSnortStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.3.1.11cufwAaicFwdbeforeDropCountCISCO-UNIFIED-FIREWALL-MIB