All MIBs › CORERO-CMS-MIB
Organization: Corero Network Security
Last Updated: 2017-06-16
Category: Alarm and Event Management, VPN and Security, Vendor: Corero
Description: Manages Corero CMS DDoS mitigation platform configuration and attack detection statistics.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CORERO-CMS-MIB?
CORERO-CMS-MIB is a Corero Network Security (enterprise OID 41036) proprietary MIB for the Corero Management Server, reporting DDoS/traffic-anomaly detection rates. Its objects cover excessive-rate indicators (packets from bad clients, proxy-setup rate, new IP addresses, address-table usage, TCP/non-TCP setup rate, failed-proxy rate), block-rate counters broken down by category (all rules, system issue, network/application access-restriction, rate-limit, protocol-validation, integrity-analysis), setup-rate counters (TCP, non-TCP, UDP, ICMP, other-IP), and in-use flow counts (total, TCP, UDP). As a performance/security MIB it lets an administrator watch DDoS-mitigation block rates and active-flow volume on a Corero Network Security appliance. It is deployed on Corero Network Security DDoS-mitigation appliances. Engineers can download the CORERO-CMS-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CORERO-CMS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Corero Network Security DDoS-mitigation appliances
Monitoring Examples
An administrator checks allRulesBlockRate and excessiveTcpSetupRate to watch DDoS-mitigation activity on a Corero Network Security appliance.
What Can Be Monitored
- DDoS-mitigation block rates and active-flow volume
Imported Objects
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| NOTIFICATION-GROUP | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Counter32 | |
| Counter64 | |
| Gauge32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| TimeTicks | |
| Unsigned32 | |
| enterprises |
From SNMPv2-TC
| DisplayString | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TestAndIncr | |
| TimeStamp | |
| TruthValue |
How to Use in IPNetwork Monitor
Example using externalPortReceivedPackets OID:
OIDs
RFC description
Corero Management Server MIB for DDoS mitigation defense status and interface statistics.
Start monitoring Corero Network Security DDoS-mitigation appliance (Management Server) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.