All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAaicGlobalNumBadPortRange
cufwAaicGlobalNumBadPortRange
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadPortRange
OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.1.3
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: Number of application protocol units that attempted to advertise illegal port ranges for secondary connections. An example of such an occurrence would be a passive FTP connection, where the server advertises a disallowed port range for data connection.
For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of application traffic payloads.
This value is accumulated from the last reboot of the firewall.
What is cufwAaicGlobalNumBadPortRange?
This Counter64, in Protocol Data Units, counts application PDUs that attempted to advertise illegal port ranges for secondary connections, such as a passive FTP server advertising a disallowed data-connection port range, and requires deep packet inspection to be implemented. An admin uses this to catch applications trying to open secondary connections outside the ports policy permits, a classic evasion pattern for protocols like FTP that negotiate ports dynamically. A rising count here tied to FTP traffic would suggest an FTP server or client is misbehaving or attempting to bypass port restrictions.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.1.3 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadPortRange
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.1.3.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadPortRange.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadPortRange OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5 | cuFwAaicGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.1 | cufwAaicGlobals | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.1.3 | cufwAaicGlobalNumBadPortRange | CISCO-UNIFIED-FIREWALL-MIB |