HUAWEI-FIREWALL-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsHUAWEI-FIREWALL-MIB

Organization: Huawei Technologies Co.,Ltd.

Last Updated: 2013-07-30

Category: Domain: Security, VPN and Security, Vendor: Huawei

Description: Huawei firewall MIB providing objects to configure security zones, policies, NAT rules, and monitor session tables on Huawei firewall products.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is HUAWEI-FIREWALL-MIB?

HUAWEI-FIREWALL-MIB is a Huawei-specific SNMP MIB (referencing draft-grall-firewall-mib-01) for monitoring firewall state on Huawei datacom devices under the hwDatacomm enterprise branch. It models security zones (hwFwZoneTable, indexed by hwFwZoneIndex, exposing hwFwZoneName, hwFwZonePriority, hwFwZoneIfList, and hwFwZoneIfNum), inter-zone relationships (hwFwInterZoneTable), connection-level statistics (hwFwConnectionStatTable keyed on hwFwConnectionStatService/hwFwConnectionStatType with hwFwConnectionStatCount), and event logging (hwFwBasicEventsTable, hwFwNetEventsTable) alongside notifications under hwFirewallMIBNotifications. This exposes counters that reveal firewall session/connection load and zone configuration state useful for capacity and security-posture monitoring. It depends on the broader Huawei enterprise MIB tree for its OID placement and complements other Huawei device MIBs. It is deployed on Huawei USG/Eudemon-class firewall appliances, and the HUAWEI-FIREWALL-MIB MIB is what network engineers load into their monitoring tools to poll this zone and connection data.

IPNetwork Monitor allows you to monitor SNMP objects defined in HUAWEI-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Huawei USG/Eudemon-series firewalls (hwDatacomm platforms)

Monitoring Examples

An operator polls hwFwConnectionStatTable to track hwFwConnectionStatCount for a given hwFwConnectionStatService/hwFwConnectionStatType pair, and cross-checks hwFwZoneIfNum in hwFwZoneTable; a spike in half-open connection counts alongside an unexpected zone interface count would indicate a connection-exhaustion attack or misconfigured zone.

What Can Be Monitored

  • firewall connection/session statistics
  • security zone table entries and interface counts
  • inter-zone relationship table
  • basic and network firewall event logs
  • protocol aging-time settings
  • firewall notification/trap objects
Imported Objects

From HUAWEI-MIB

hwDatacommOBJECT-IDENTITY

From IF-MIB

InterfaceIndexOrZero

From Q-BRIDGE-MIB

PortList

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using hwFwConnectionStatCount OID:

Select a Huawei USG/Eudemon-series firewall appliance as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type hwFwConnectionStatCount into the Find box to locate it in the OID tree, then select it and click OK. This is an integer that contains the value of the resource statistic. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Firewall security events, attack detection, and blacklist management for Huawei devices.

Start monitoring Huawei USG/Eudemon-series firewall appliance with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download HUAWEI-FIREWALL-MIB