All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAaicHttpNumDoubleEncodedPkts
cufwAaicHttpNumDoubleEncodedPkts
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumDoubleEncodedPkts
OID (numeric): 1.3.6.1.4.1.9.9.491.1.5.2.1.7
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of PDUs corresponding to HTTP protocol which were detected to be containing double encoding. Double encoding is a mechanism to obfuscate content in which a encoded data is re-encoded so as to evade deep packet inspections.
For this MIB to be implemented, the managed firewall must be implementing deep packet inspection of HTTP traffic payloads.
This value is accumulated from the last reboot of the firewall.
What is cufwAaicHttpNumDoubleEncodedPkts?
This Counter64, in HTTP Protocol Data Units, counts HTTP PDUs detected using double encoding, a technique where already-encoded data is re-encoded to evade deep packet inspection, requiring HTTP-layer deep packet inspection, accumulated since the last reboot. An admin uses this counter specifically to spot obfuscation attempts aimed at slipping malicious content past the inspection engine. A jump in this counter would be a strong signal to an admin that someone is actively trying to evade the firewall's HTTP inspection rather than simply generating normal traffic.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.7 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumDoubleEncodedPkts
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.5.2.1.7.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumDoubleEncodedPkts.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAaicHttpNumDoubleEncodedPkts OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5 | cuFwAaicGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2 | cufwAaicProtocolStats | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2.1 | cufwAaicHttpProtocolStats | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.5.2.1.7 | cufwAaicHttpNumDoubleEncodedPkts | CISCO-UNIFIED-FIREWALL-MIB |