CISCO-UNIFIED-FIREWALL-MIB :: cufwL2GlobalNumSpoofedArpResps

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwL2GlobalNumSpoofedArpResps

cufwL2GlobalNumSpoofedArpResps

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwL2GlobalNumSpoofedArpResps

OID (numeric): 1.3.6.1.4.1.9.9.491.1.6.1.11

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of spoofed ARP responses received by the firewall. Such an event would occur when the firewall encounters an ARP response mapping an IP address to a different MAC Address from the one present in the local ARP cache.

This counter is accumulated since the last reboot of the firewall.

What is cufwL2GlobalNumSpoofedArpResps?

This Counter64, in ARP Responses, counts spoofed ARP responses received by the firewall, meaning an ARP response mapped an IP address to a different MAC address than the one already in the firewall's local ARP cache, accumulated since the last reboot. An admin uses this as a direct security signal for ARP spoofing or man-in-the-middle attempts on the local segment. A sudden burst of spoofed responses tied to a specific IP address would point an admin toward investigating a possible ARP poisoning attack targeting that host.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.6.1.11
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwL2GlobalNumSpoofedArpResps

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.6.1.11.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwL2GlobalNumSpoofedArpResps.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwL2GlobalNumSpoofedArpResps OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.6cuFwL2FwGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.6.1cufwL2FwGlobalsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.6.1.11cufwL2GlobalNumSpoofedArpRespsCISCO-UNIFIED-FIREWALL-MIB