All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwCntlL2StaticMacAddressMoved
cufwCntlL2StaticMacAddressMoved
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwCntlL2StaticMacAddressMoved
OID (numeric): 1.3.6.1.4.1.9.9.491.1.7.2
Node type: OBJECT-TYPE
Type: TruthValue
Access: read-write
Description: This object defines the administrative state of sending the SNMP notification to signal the move of a statically configured MAC address to a new port.
Such a change could occur either as a result of physical move of the device with the MAC Address to the new port or due to MAC address spoofing.
What is cufwCntlL2StaticMacAddressMoved?
This read-write TruthValue controls the administrative state of whether the firewall sends an SNMP notification when a statically configured MAC address moves to a new port, which could happen either from a legitimate physical relocation of the device or from MAC address spoofing. An admin enables this to get alerted to potential spoofing attempts or unauthorized device moves on a transparent firewall's L2 segment. Turning this on for a segment with critical statically-pinned devices would let an admin catch a spoofing attempt targeting one of those devices as soon as it occurs.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.7.2 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwCntlL2StaticMacAddressMoved
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.7.2.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwCntlL2StaticMacAddressMoved.1
Set instance 1 (SNMPv2c):
snmpset -v2c -c private <target> 1.3.6.1.4.1.9.9.491.1.7.2.1 s <value>
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwCntlL2StaticMacAddressMoved OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.7 | cuFwNotifCntlGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.7.2 | cufwCntlL2StaticMacAddressMoved | CISCO-UNIFIED-FIREWALL-MIB |