NETSCREEN-TRAP-MIB

MIB Reference — IPNetwork Monitor

All MIBsNETSCREEN-TRAP-MIB

Organization: Juniper Networks, Inc.

Last Updated: 2009-07-17

Category: Network Management

Description:

Defines SNMP trap types and notification objects for system events and alerts on Juniper NetScreen firewalls.

Imported Objects

From NETSCREEN-SMI

netscreenTrapOBJECT-IDENTITY
netscreenTrapInfoOBJECT-IDENTITY

From SNMPv2-SMI

MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE

From SNMPv2-TC

DisplayString

What Is NETSCREEN-TRAP-MIB?

NETSCREEN-TRAP-MIB defines SNMP trap notifications for Juniper NetScreen firewall/security appliances (the NetScreen ScreenOS product line acquired by Juniper). It belongs to the network security/firewall technology area. Its data is entirely fault/event-oriented — it enumerates a large set of trap types (dozens of numeric codes covering system, security, VPN, and hardware events) along with descriptive text for each, rather than polled counters or tables. It is explicitly a faults/traps-focused module, used to alert operators in real time to security events, VPN state changes, hardware failures, or system-level issues on the firewall, rather than to poll ongoing hardware/software health metrics directly. Because it is trap-oriented, the NETSCREEN-TRAP-MIB MIB is consulted mainly as a lookup reference for decoding the numeric trap codes a NetScreen firewall emits rather than as a source of pollable counters. It depends on the base NetScreen/Juniper enterprise MIB tree for identifying the device generating each trap. It is deployed wherever Juniper/NetScreen ScreenOS firewalls send SNMP traps to a network or security monitoring system for real-time alerting.

IPNetwork Monitor allows you to monitor SNMP objects defined in NETSCREEN-TRAP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • firewall trap type
  • firewall trap description/event text

Supported Devices

  • Juniper NetScreen ScreenOS firewall/security appliance (SNMP trap notifications)

Monitoring Examples

A SIEM or NMS would subscribe to traps carrying netscreenTrapType and netscreenTrapDesc to identify which of the many defined event codes fired — for instance distinguishing a VPN tunnel-down event from a hardware fault code — and use netscreenTrapDesc's human-readable text to populate an alert without a separate lookup table. Because the module is trap-oriented rather than table/counter-oriented, monitoring here means capturing and classifying incoming traps rather than periodically polling gauge values.

OIDs
OID symbolicOID numericTypeAccessDescription
NTF netscreenTrapHw1.3.6.1.4.1.3224.0.100This trap indicates that some kind of hardware problem has occured.
NTF netscreenTrapFw1.3.6.1.4.1.3224.0.200This trap indicates that some kind of firewall functions has been triggered.
NTF netscreenTrapSw1.3.6.1.4.1.3224.0.300This trap indicates that some kind of software problem has occured.
NTF netscreenTrapTrf1.3.6.1.4.1.3224.0.400This trap indicates that some kind of traffic conditions has been triggered.
NTF netscreenTrapVpn1.3.6.1.4.1.3224.0.500This trap indicates that VPN tunnel status has occured.
NTF netscreenTrapNsrp1.3.6.1.4.1.3224.0.600This trap indicates that NSRP status has occured.
NTF netscreenTrapGPRO1.3.6.1.4.1.3224.0.700This trap indicates that some kind of Global PRO problems has occurred.
NTF netscreenTrapDrp1.3.6.1.4.1.3224.0.800This trap indicates that Drp status has occured.
NTF netscreenTrapIFFailover1.3.6.1.4.1.3224.0.900This trap indicates that interface fail over status has occured.
NTF netscreenTrapIDPAttack1.3.6.1.4.1.3224.0.1000This trap indicates that IDP attack status has occured.
netscreenTrapMibModule1.3.6.1.4.1.3224.2.0Added new traps introduced in 6.3, which includes 3, 35, 39, 52, 53, 54, 66, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 94, 105, 110, 111, 112, 113, 114, 200, 201, 202, 203, 204, 226, 227, 228, 229, 230, 231, 426, 427, 442, 443, 554, 600, 601, 602, 701, 702, 703, 704, 804, 805, 806, 850
INT netscreenTrapType1.3.6.1.4.1.3224.2.1INTEGERaccessible-for-notifyThe integer value of the raised alarm type. Note that the type should be interpreted within a specific trap
STR netscreenTrapDesc1.3.6.1.4.1.3224.2.3DisplayStringaccessible-for-notifyThe textual description of the alarm

RFC description

Defines SNMP trap notifications for Juniper NetScreen ScreenOS firewalls.

Start monitoring Juniper NetScreen ScreenOS firewall/security appliance (SNMP trap notifications) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download NETSCREEN-TRAP-MIB