FOUNDRY-SN-IP-ACL-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsFOUNDRY-SN-IP-ACL-MIB

Organization: Brocade Communications Systems, Inc.

Last Updated: 2014--0-1-

Category: Domain: Security, Vendor: Foundry/Brocade

Description: Brocade Foundry IP ACL MIB providing configuration and monitoring of IP access control lists for traffic filtering on FastIron switches and routers.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is FOUNDRY-SN-IP-ACL-MIB?

FOUNDRY-SN-IP-ACL-MIB is a Brocade (Foundry Networks) vendor-specific MIB for configuring and monitoring IP access control lists (ACLs) used to filter traffic on FastIron switches and routers. It exposes ACL definition tables (indexed by ACL number/name), global accounting-enable flags, per-interface IPv4/IPv6 ACL accounting clear controls, and policy-based-routing ACL accounting filters with counter types. Its monitoring value lies in security/configuration status and traffic-filtering accounting: snAgAclGblAcctEnable and the accounting clear objects control whether ACL hit-counting is active, while brcdPbrAclAccntFilterAclName and brcdPbrAclAccntCounterType let an operator track how many packets matched a specific policy-routing ACL rule, revealing whether filtering policy is behaving as intended. It is a self-contained Brocade enterprise MIB with no evident dependency on external standard MIBs beyond typical SNMP table conventions. It is deployed on Brocade/Foundry FastIron switches and routers for network security policy enforcement and traffic filtering audits. Network engineers evaluating or troubleshooting this functionality can download the FOUNDRY-SN-IP-ACL-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in FOUNDRY-SN-IP-ACL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Brocade (Foundry) FastIron switches and routers

Monitoring Examples

Polling snAgAclTable/snAgAclEntry by snAgAclIndex and snAgAclNumber lets an operator enumerate configured ACLs on a FastIron device and confirm which policy is bound to which interface via snAgAclGblRebindAclNumber/snAgAclGblRebindAclName. Checking brcdPbrAclAccntFilterAclName together with brcdPbrAclAccntCounterType reveals hit-count statistics for a specific policy-based-routing ACL rule, showing how much traffic that filter is matching. If snAgAclGblIfIPv4AcctClear or snAgAclGblIfIPv6AcctClear counters reset unexpectedly or accounting values stay at zero when traffic is known to be flowing, it would suggest the ACL accounting feature is misconfigured or disabled (snAgAclGblAcctEnable).

What Can Be Monitored

  • configured ACL definitions and bindings
  • ACL accounting enable/clear state
  • per-rule matched-packet counters (policy-based routing ACLs)
  • ACL rebind configuration
Imported Objects

From FOUNDRY-SN-IP-MIB

RtrStatus

From FOUNDRY-SN-ROOT-MIB

routerOBJECT-IDENTITY

From FOUNDRY-SN-SWITCH-GROUP-MIB

FdryVlanIdOrNoneTC
PortQosTC

From IF-MIB

InterfaceIndex
InterfaceIndexOrZero
ifIndexOBJECT-TYPE

From SNMPv2-SMI

Counter64
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
MacAddress
RowStatus
TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using snAgAclFlowCounter OID:

Select a Brocade/Foundry FastIron switch/router (IP ACL config/accounting) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type snAgAclFlowCounter into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. It reports the approximate count of flows matching individual ACL entry. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Manages IP Access Control Lists (ACLs) for packet filtering and security policies on Foundry/Brocade network devices.

Start monitoring Brocade/Foundry FastIron switch/router (IP ACL config/accounting) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download FOUNDRY-SN-IP-ACL-MIB