All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAaicHttpNumBadPDUSize
cufwAaicHttpNumBadPDUSize
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadPDUSize
OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.2.1.2
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of PDUs corresponding to HTTP protocol that had either an invalid header size or an invalid payload size, as determined by the local security policy.
For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads.
This value is accumulated from the last reboot of the firewall.
What is cufwAaicHttpNumBadPDUSize?
This Counter64, in HTTP Protocol Data Units, counts HTTP PDUs with an invalid header or payload size per local security policy, requiring HTTP-layer deep packet inspection, accumulated since the last reboot. An admin uses it to detect malformed or oversized HTTP traffic that policy rejects at the protocol level. A sustained increase in this counter tied to a specific web application could indicate that application is sending malformed HTTP requests that need investigation.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.2 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadPDUSize
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.2.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadPDUSize.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadPDUSize OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5 | cuFwAaicGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2 | cufwAaicProtocolStats | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2.1 | cufwAaicHttpProtocolStats | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2.1.2 | cufwAaicHttpNumBadPDUSize | CISCO-UNIFIED-FIREWALL-MIB |