HP-ICF-DHCP-SNOOP-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsHP-ICF-DHCP-SNOOP-MIB

Organization: HP Networking

Last Updated: 2016-06-01

Category: Protocol: DHCP, Vendor: HP/HPE

Description: HP ICF SNMP MIB for DHCP snooping configuration and statistics, validating DHCP traffic on HP ProCurve switch ports.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is HP-ICF-DHCP-SNOOP-MIB?

HP-ICF-DHCP-SNOOP-MIB is an HP-proprietary (ICF, Industry-Consistent Framework) SNMP module for managing DHCP Snooping, a security feature on HP ProCurve switches that validates DHCP traffic on untrusted ports to prevent rogue DHCP servers and IP spoofing. It exposes configuration objects covering whether errant DHCP replies are dropped/logged, database validation settings including an SFTP server used to save the snooping binding database, and objects describing the source IP type/address of detected errant DHCP traffic. As a monitoring MIB it is squarely about a security/software feature's operational status: hpicfDhcpSnoopErrantSrcIP and hpicfDhcpSnoopErrantSrcIPType let an operator identify the source of a rogue or spoofed DHCP reply caught on the network, while hpicfDhcpSnoopErrantReplyEnable shows whether that detection/blocking behavior is active. It is a vendor-specific extension with no direct dependency on a standard IETF DHCP-snooping MIB (none exists), though it parallels similar vendor features elsewhere. It is deployed on HP ProCurve access-layer switches in enterprise networks where DHCP snooping is enabled on untrusted client-facing ports to guard against DHCP-based attacks, and administrators can download the HP-ICF-DHCP-SNOOP-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in HP-ICF-DHCP-SNOOP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • HP ProCurve switches

Monitoring Examples

An operator would check hpicfDhcpSnoopErrantReplyEnable to confirm errant-reply detection is turned on, then monitor hpicfDhcpSnoopErrantSrcIPType and hpicfDhcpSnoopErrantSrcIP to identify the address of a rogue DHCP server that sent an unauthorized reply on an untrusted port. hpicfDhcpSnoopDatabaseValidateSFTPServer would be checked to ensure the snooping binding database is being backed up to the correct SFTP server, so that bindings survive a switch reboot.

What Can Be Monitored

  • errant DHCP reply detection enable state
  • errant DHCP reply source IP address/type
  • DHCP snooping database SFTP backup server
Imported Objects

From HP-ICF-OID

hpSwitchOBJECT-IDENTITY

From IF-MIB

InterfaceIndex
InterfaceIndexOrZero
ifIndexOBJECT-TYPE

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From Q-BRIDGE-MIB

VlanIndex

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
MacAddress
RowStatus
TruthValue

How to Use in IPNetwork Monitor

Example using hpicfDhcpSnoopCSForwards OID:

Select an HP ProCurve switch (DHCP Snooping) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type hpicfDhcpSnoopCSForwards into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of snooped DHCP packets that were successfully forwarded from untrusted client ports towards trusted DHCP server ports. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

HP proprietary MIB for DHCP Snooping, managing DHCP bindings and client IP tracking.

Start monitoring HP ProCurve switch (DHCP Snooping) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download HP-ICF-DHCP-SNOOP-MIB