CISCO-UNIFIED-FIREWALL-MIB :: cufwAaicHttpNumBadProtocolOps

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwAaicHttpNumBadProtocolOps

cufwAaicHttpNumBadProtocolOps

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadProtocolOps

OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.2.1.1

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of PDUs corresponding to HTTP protocol which were detected to be containing HTTP protocol methods which are disallowed by the local security policy.

For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads.

This value is accumulated from the last reboot of the firewall.

What is cufwAaicHttpNumBadProtocolOps?

This Counter64, in HTTP Protocol Data Units, counts PDUs detected containing HTTP methods disallowed by local security policy, and requires the firewall to be performing deep packet inspection of HTTP traffic, accumulating since the last reboot. An admin uses it to catch clients using HTTP verbs the policy has decided to block, such as unusual or risky methods. A spike in this counter would prompt an admin to check whether a client is issuing disallowed HTTP methods, whether by misconfiguration or by design.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.1
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadProtocolOps

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.1.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadProtocolOps.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumBadProtocolOps OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5cuFwAaicGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2cufwAaicProtocolStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2.1cufwAaicHttpProtocolStatsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.5.2.1.1cufwAaicHttpNumBadProtocolOpsCISCO-UNIFIED-FIREWALL-MIB