MCAFEE-MWG-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsMCAFEE-MWG-MIB

Organization: McAfee Inc.

Last Updated: 2014-11-10

Category: Domain: Security, Vendor: McAfee

Description: McAfee Web Gateway (MWG) SNMP MIB defining management objects for monitoring proxy traffic, policy, and security events.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is MCAFEE-MWG-MIB?

This is a McAfee (Skyhigh) private MIB for the McAfee Web Gateway (MWG), a secure web proxy appliance that inspects and filters HTTP/HTTPS traffic for malware, policy violations, and data loss. It exposes management objects covering proxy traffic statistics, policy enforcement counters, and security event notifications generated by the gateway's scanning engine. Its monitoring value centers on software/service status of the gateway itself: traffic throughput and connection counts reveal load and potential bottlenecks, while security event counters (malware blocks, policy violations) indicate active threat activity requiring review. It is a self-contained appliance MIB, generally used alongside standard host-resource MIBs (for CPU/memory/disk on the underlying appliance) since MCAFEE-MWG-MIB itself focuses on proxy-application-layer metrics. It is deployed at enterprise network edges or in cloud secure web gateway deployments, where security teams rely on MCAFEE-MWG-MIB SNMP monitoring for real-time visibility into web traffic filtering and threat detection.

IPNetwork Monitor allows you to monitor SNMP objects defined in MCAFEE-MWG-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • McAfee Web Gateway appliance

Monitoring Examples

A security operations team would poll traffic and policy-violation counters to spot a spike in blocked malware downloads, potentially indicating a compromised endpoint repeatedly attempting outbound callbacks. Proxy connection/session counters would be watched for unusual load that could indicate a misconfigured client or a denial-of-service condition against the gateway. Security event trap objects would typically feed a SIEM to correlate web-layer threats with other security telemetry.

What Can Be Monitored

  • proxy traffic volume/connections
  • policy violation counts
  • malware/security event counts
  • gateway scanning engine activity
Imported Objects

From MCAFEE-SMI

mcafeeGATEWAYOBJECT-IDENTITY

From RFC-1215

TRAP-TYPE

From RFC1155-SMI

enterprises

From RFC1213-MIB

DisplayString
PhysAddress

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32
mib-2

How to Use in IPNetwork Monitor

Example using stMalwareDetected OID:

Select a McAfee Web Gateway appliance as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type stMalwareDetected into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of infections detected by the McAfee Gateway Antimalware Engine. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Monitors McAfee Web Gateway performance including HTTP/HTTPS/FTP statistics and threat protection metrics.

Start monitoring McAfee Web Gateway appliances with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download MCAFEE-MWG-MIB