All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAaicGlobalNumBadProtocolOps
cufwAaicGlobalNumBadProtocolOps
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadProtocolOps
OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.1.1
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: 'Protocol Operation' is the application protocol specific operation that the PDU is intended to perform. An example of 'protocol operation' is the HELO command of SMTP protocol.
This MIB object records the number of application protocol data units that contained a protocol operation which was disallowed by the local security policy.
For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of application traffic payloads.
This value is accumulated from the last reboot of the firewall.
What is cufwAaicGlobalNumBadProtocolOps?
This Counter64, in Protocol Data Units, counts application-layer PDUs whose protocol operation, such as the HELO command in SMTP, was disallowed by the firewall's local security policy, and requires the firewall to be doing deep packet inspection of application traffic to be meaningful. An admin uses it to detect clients or servers attempting application-protocol commands that policy has decided to forbid. A rising count on this counter after enabling a new application inspection policy would confirm that policy is actively catching disallowed protocol operations.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.1.1 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadProtocolOps
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.1.1.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadProtocolOps.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicGlobalNumBadProtocolOps OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5 | cuFwAaicGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.1 | cufwAaicGlobals | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.1.1 | cufwAaicGlobalNumBadProtocolOps | CISCO-UNIFIED-FIREWALL-MIB |