SONICWALL-FIREWALL-TRAP-MIB

MIB Reference — IPNetwork Monitor

All MIBsSONICWALL-FIREWALL-TRAP-MIB

Organization: DELL SonicWALL

Last Updated: 2015-01-08

Category: Dell SonicWall Network Security

Description:

Defines Dell SonicWall firewall event traps for security incidents, policy violations, and operational alerts.

Imported Objects

From SNMPv2-SMI

IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32
snmpModules

From SNMPv2-TC

DisplayString
TEXTUAL-CONVENTION

From SONICWALL-SMI

sonicwallFwOBJECT-IDENTITY

What Is SONICWALL-FIREWALL-TRAP-MIB?

SONICWALL-FIREWALL-TRAP-MIB is a vendor-specific MIB from Dell SonicWALL (formerly SonicWALL) that defines SNMP trap/notification objects sent by SonicWALL firewall appliances for security incidents, policy violations, and other operational alerts. It exposes trap-payload objects describing the event, including trap type and description, source/destination IP and MAC addresses, source/destination ports, IP protocol type, and free-text messages/service-area names associated with the triggering event. In monitoring terms this MIB is entirely about real-time security/fault event notification rather than polled counters, letting a security operations team receive and parse firewall-generated traps to identify what kind of security event occurred, such as an intrusion attempt or policy block, and the exact flow involved. It has no apparent dependency on other standard MIBs beyond the base SNMP notification framework, functioning as a self-contained trap-definition module. It is deployed wherever Dell/SonicWALL firewalls are configured to forward security and operational alerts to a central SNMP trap receiver or SIEM. Network engineers evaluating or troubleshooting this functionality can download the SONICWALL-FIREWALL-TRAP-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in SONICWALL-FIREWALL-TRAP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • firewall security event/trap type
  • event description
  • source/destination IP and MAC addresses
  • source/destination ports
  • affected security service/rule area

Supported Devices

  • Dell SonicWALL firewall appliance

Monitoring Examples

A security team's trap receiver would parse an incoming SonicWALL trap's swTrapInfoTrapType and swTrapInfoTrapDescription to classify the event, then inspect swTrapInfoSrcIpAddress/swTrapInfoDstIpAddress and swTrapInfoSrcPort/swTrapInfoDstPort to identify the exact flow that triggered it. The swTrapInfoTable holds these fields as trap varbinds accompanying each sonicwallFwTrapInfo notification, and swTrapInfoSaName can identify the security service/rule area involved. A burst of traps sharing the same swTrapInfoSrcIpAddress and an intrusion or policy-violation trap type would point to a single source actively probing or attacking the network. This MIB is used purely for security-event notification, not routine performance polling.

OIDs
OID symbolicOID numericTypeAccessDescription
sonicwallFwTrapModule1.3.6.1.4.1.8741.1.1The MIB Module for SonicWALL Firewall Trap.
sonicwallFwTrapInfo1.3.6.1.4.1.8741.1.1.1
swTrapInfoTable1.3.6.1.4.1.8741.1.1.1.1
FWT swTrapInfoTrapType1.3.6.1.4.1.8741.1.1.1.1.1FwTrapTypeaccessible-for-notifytrap type .
STR swTrapInfoTrapDescription1.3.6.1.4.1.8741.1.1.1.1.2DisplayStringaccessible-for-notifyThe description of the trap.
IP swTrapInfoSrcIpAddress1.3.6.1.4.1.8741.1.1.1.1.3IpAddressaccessible-for-notifyThe source ip address.
IP swTrapInfoDstIpAddress1.3.6.1.4.1.8741.1.1.1.1.4IpAddressaccessible-for-notifyThe destination ip address.
INT swTrapInfoSrcPort1.3.6.1.4.1.8741.1.1.1.1.5INTEGERaccessible-for-notifyThe destination port.
INT swTrapInfoDstPort1.3.6.1.4.1.8741.1.1.1.1.6INTEGERaccessible-for-notifyThe destination port.
MAC swTrapInfoSrcMacAddress1.3.6.1.4.1.8741.1.1.1.1.7MacAddressaccessible-for-notifyThe source MAC address.
MAC swTrapInfoDstMacAddress1.3.6.1.4.1.8741.1.1.1.1.8MacAddressaccessible-for-notifyThe destination MAC address.
INT swTrapInfoIpType1.3.6.1.4.1.8741.1.1.1.1.9INTEGERaccessible-for-notifyThe ip type.
STR swTrapInfoPrivMsg1.3.6.1.4.1.8741.1.1.1.1.10DisplayStringaccessible-for-notifyThe additional message.
IP swTrapInfoIpAddress1.3.6.1.4.1.8741.1.1.1.1.11IpAddressaccessible-for-notifyThe ip address.
STR swTrapInfoSaName1.3.6.1.4.1.8741.1.1.1.1.12DisplayStringaccessible-for-notifyName of the SA.
STR swTrapInfoFwSrlNumber1.3.6.1.4.1.8741.1.1.1.1.13DisplayStringaccessible-for-notifySerial number of the firewall this trap is coming from.
INT swTrapInfoSaStatus1.3.6.1.4.1.8741.1.1.1.1.14INTEGERaccessible-for-notifyThe status of the IPSec Tunnel.
IP swTrapInfoSrcAddrBegin1.3.6.1.4.1.8741.1.1.1.1.15IpAddressaccessible-for-notifyFirst address of the local network behind the firewall ( LAN side).
IP swTrapInfoSrcAddrEnd1.3.6.1.4.1.8741.1.1.1.1.16IpAddressaccessible-for-notifyLast address of the local network. ( LAN side).
IP swTrapInfoDstAddrBegin1.3.6.1.4.1.8741.1.1.1.1.17IpAddressaccessible-for-notifyFirst address of the remote network .
IP swTrapInfoDstAddrEnd1.3.6.1.4.1.8741.1.1.1.1.18IpAddressaccessible-for-notifyLast address of the remote network.
IP swTrapInfoGateway1.3.6.1.4.1.8741.1.1.1.1.19IpAddressaccessible-for-notifyAddress of the tunnel end point.
INT swTrapInfoIsDHCPCentral1.3.6.1.4.1.8741.1.1.1.1.20INTEGERaccessible-for-notifyIf the Tunnel is a DHCP Central
STR swTrapInfoSrcResolvedHostName1.3.6.1.4.1.8741.1.1.1.1.21DisplayStringaccessible-for-notifySource IP address' resolved host name.
STR swTrapInfoDstResolvedHostName1.3.6.1.4.1.8741.1.1.1.1.22DisplayStringaccessible-for-notifyDestination IP address' resolved host name.
U32 swTrapInfoSrcInterface1.3.6.1.4.1.8741.1.1.1.1.23Unsigned32accessible-for-notifySource interface
U32 swTrapInfoDstInterface1.3.6.1.4.1.8741.1.1.1.1.24Unsigned32accessible-for-notifyDestination interface
STR swTrapInfoClientUserName1.3.6.1.4.1.8741.1.1.1.1.25DisplayStringaccessible-for-notifyClient User Name associated with the trap
sonicwallFwTrapRoot1.3.6.1.4.1.8741.1.1.2
NTF swFwTrapAttack1.3.6.1.4.1.8741.1.1.2.0.1This trap indicates that the firewall have detected a attack. The bound objects provide more detailed information about this problem.
NTF swFwTrapSysError1.3.6.1.4.1.8741.1.1.2.0.2This trap indicates that there is a system problem with the SonicWALL appliance. The bound objects provide more detailed information about this problem.
NTF swFwTrapBlkWebSite1.3.6.1.4.1.8741.1.1.2.0.3This trap indicates that there is a web site was blocked by the firewall. The bound objects provide more detailed information about this problem.
NTF swFwTrapIpsecTunnel1.3.6.1.4.1.8741.1.1.2.0.4This trap indicates that there has bee a change in the IPSec tunnel status along with the parameters required to indentify the tunnel .
NTF swFwTrapWlanIDS1.3.6.1.4.1.8741.1.1.2.0.5This trap indicates that there is a wireless intrusion detected by the firewall. The bound objects provide more detailed information about this problem.
NTF swFwTrapSysEnv1.3.6.1.4.1.8741.1.1.2.0.6This trap indicates that there is a system environment problem detected by the firewall. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhNone1.3.6.1.4.1.8741.1.1.2.0.100This trap may be disabled at this time.
NTF swFwTrapEnhUnused1.3.6.1.4.1.8741.1.1.2.0.101This trap may be disabled at this time.
NTF swFwTrapEnhLegacySystemMaintenance1.3.6.1.4.1.8741.1.1.2.0.102This is a legacy trap for system maintenance.
NTF swFwTrapEnhLegacySystemErrors1.3.6.1.4.1.8741.1.1.2.0.103Please see description for swFwTrapSysError trap.
NTF swFwTrapEnhLegacyBlockedWebSites1.3.6.1.4.1.8741.1.1.2.0.104Please see description for swFwTrapBlkWebSite trap.
NTF swFwTrapEnhLegacyBlockedJavaEtc1.3.6.1.4.1.8741.1.1.2.0.105This is a legacy trap for blocked java and other blocked application activities.
NTF swFwTrapEnhLegacyUserActivity1.3.6.1.4.1.8741.1.1.2.0.106This is a legacy trap for user activities.
NTF swFwTrapEnhLegacyDeniedLanIp1.3.6.1.4.1.8741.1.1.2.0.107This is a legacy trap for denied LAN IP activities.
NTF swFwTrapEnhLegacyAttacks1.3.6.1.4.1.8741.1.1.2.0.108Please see description for swFwTrapAttack trap.
NTF swFwTrapEnhLegacyDroppedTcp1.3.6.1.4.1.8741.1.1.2.0.109This is a legacy trap for dropped TCP event.
NTF swFwTrapEnhLegacyDroppedUdp1.3.6.1.4.1.8741.1.1.2.0.110This is a legacy trap for dropped UDP event.
NTF swFwTrapEnhLegacyDroppedIcmp1.3.6.1.4.1.8741.1.1.2.0.111This is a legacy trap for dropped ICMP event.
NTF swFwTrapEnhLegacyNetworkDebug1.3.6.1.4.1.8741.1.1.2.0.112This is a legacy trap for network debug event.
NTF swFwTrapEnhLegacySystemEnvironment1.3.6.1.4.1.8741.1.1.2.0.113Please see description for swFwTrapSysEnv trap.
NTF swFwTrapEnhLegacyVpnTunnelStatus1.3.6.1.4.1.8741.1.1.2.0.114This is a legacy trap for VPN tunnel status.
NTF swFwTrapEnhLegacy80211bManagement1.3.6.1.4.1.8741.1.1.2.0.115This is a legacy trap for 802.11 management event.
NTF swFwTrapEnhAuthAccess1.3.6.1.4.1.8741.1.1.2.0.116This trap indicates an activity from log administrator, user and guest account. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhBootp1.3.6.1.4.1.8741.1.1.2.0.117This trap indicates an event happening from BOOTP. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhCrypt1.3.6.1.4.1.8741.1.1.2.0.118This trap indicates an event from crypto algorithm and hardware testing. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhDhcpc1.3.6.1.4.1.8741.1.1.2.0.119This trap indicates an event from DHCP Client protocol activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhDhcpr1.3.6.1.4.1.8741.1.1.2.0.120This trap indicates an event from DHCP central and gateway protocol activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhFwEvent1.3.6.1.4.1.8741.1.1.2.0.121This trap indicates an event from internal firewall activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhFwHardware1.3.6.1.4.1.8741.1.1.2.0.122This trap indicates an event from firewall hardware error. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhFwLogging1.3.6.1.4.1.8741.1.1.2.0.123This trap indicates a general firewall event or error. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhFwRule1.3.6.1.4.1.8741.1.1.2.0.124This trap indicates an event from a firewall rule modification. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhGms1.3.6.1.4.1.8741.1.1.2.0.125This trap indicates a GMS status event. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhHa1.3.6.1.4.1.8741.1.1.2.0.126This trap indicates an event from a high availability activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhIntrusionDetection1.3.6.1.4.1.8741.1.1.2.0.127This trap indicates an event from an intrusion prevention activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhL2tpClient1.3.6.1.4.1.8741.1.1.2.0.128This trap indicates an event from an L2TP client activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhL2tpServer1.3.6.1.4.1.8741.1.1.2.0.129This trap indicates an event from an L2TP server activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhNetwork1.3.6.1.4.1.8741.1.1.2.0.130This trap indicates an event from ARP, fragmentation or MTU activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhNetworkAccess1.3.6.1.4.1.8741.1.1.2.0.131This trap indicates an event from network and firewall protocol access activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhNetworkTraffic1.3.6.1.4.1.8741.1.1.2.0.132This trap indicates a network traffic reporting event. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhPppDialUp1.3.6.1.4.1.8741.1.1.2.0.133This trap indicates an event from a PPP dial-up activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhPppoe1.3.6.1.4.1.8741.1.1.2.0.134This trap indicates an event from a PPPoE activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhPptp1.3.6.1.4.1.8741.1.1.2.0.135This trap indicates an event from a PPTP activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhRadius1.3.6.1.4.1.8741.1.1.2.0.136This trap indicates an event from a RADIUS or LDAP server activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhRip1.3.6.1.4.1.8741.1.1.2.0.137This trap indicates an event from a RIP activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhSecurityServices1.3.6.1.4.1.8741.1.1.2.0.138This trap indicates an event from a security services activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVoip1.3.6.1.4.1.8741.1.1.2.0.139This trap indicates an event from a VoIP H.323/RAS, H.323/H.225, and H.323/H.245 activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVpn1.3.6.1.4.1.8741.1.1.2.0.140This trap indicates an event from a VPN activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVpnClient1.3.6.1.4.1.8741.1.1.2.0.141This trap indicates an event from a VPN client activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVpnIke1.3.6.1.4.1.8741.1.1.2.0.142This trap indicates an event from a VPN IKE activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVpnIpsec1.3.6.1.4.1.8741.1.1.2.0.143This trap indicates an event from a VPN IPSec ctivity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhVpnPki1.3.6.1.4.1.8741.1.1.2.0.144This trap indicates an event from a VPN PKI activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhWanFailover1.3.6.1.4.1.8741.1.1.2.0.145This trap indicates an event from a WAN failover activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhWireless1.3.6.1.4.1.8741.1.1.2.0.146This trap indicates an event from a wireless activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhSonicPoint1.3.6.1.4.1.8741.1.1.2.0.147This trap indicates an event from a SonicPoint activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhMcast1.3.6.1.4.1.8741.1.1.2.0.148This trap indicates an event from an IGMP activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhWlanIds1.3.6.1.4.1.8741.1.1.2.0.149This trap indicates an event from a WLAN IDS activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhLegacyModemDebug1.3.6.1.4.1.8741.1.1.2.0.150This is a legacy trap for modem debug.
NTF swFwTrapEnhModemDebug1.3.6.1.4.1.8741.1.1.2.0.151This trap indicates an event from modem debug. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhPpp1.3.6.1.4.1.8741.1.1.2.0.152This trap indicates an event from a generic PPP activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhMsAd1.3.6.1.4.1.8741.1.1.2.0.153This trap indicates an event from an MsAD activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhDdns1.3.6.1.4.1.8741.1.1.2.0.154This trap indicates an event from Dynamic DNS. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhRbl1.3.6.1.4.1.8741.1.1.2.0.155This trap indicates an event from a real-time black list activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhARS1.3.6.1.4.1.8741.1.1.2.0.156This trap may be disabled at this time.
NTF swFwTrapEnhIpcomp1.3.6.1.4.1.8741.1.1.2.0.157This trap indicates an event from an IP compression activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhCia1.3.6.1.4.1.8741.1.1.2.0.158This trap indicates an event from a CIA activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhRFManagement1.3.6.1.4.1.8741.1.1.2.0.159This trap indicates an event from an RF management activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhDynAddrObjs1.3.6.1.4.1.8741.1.1.2.0.160This trap indicates an event from a dynamic address object activity. The bound objects provide more detailed information about this problem.
NTF swFwTrapEnhApplicationFirewall1.3.6.1.4.1.8741.1.1.2.0.161This trap indicates an application firewall event.
NTF swFwTrapEnhSslvpn1.3.6.1.4.1.8741.1.1.2.0.162This trap indicates an SSL-VPN event.
NTF swFwTrapEnhSonicPointN1.3.6.1.4.1.8741.1.1.2.0.163This trap indicates a SonicPoint-N event.
NTF swFwTrapEnhAntispam1.3.6.1.4.1.8741.1.1.2.0.164This trap indicates an Anti-Spam event.
NTF swFwTrapEnhNetworkMonitor1.3.6.1.4.1.8741.1.1.2.0.165This trap indicates a Network Monitor event.
NTF swFwTrapEnhDhcpServer1.3.6.1.4.1.8741.1.1.2.0.166This trap indicates a DHCP Server event.
NTF swFwTrapEnhFtp1.3.6.1.4.1.8741.1.1.2.0.167This trap indicates a FTP event.
NTF swFwTrapEnhDPISSL1.3.6.1.4.1.8741.1.1.2.0.168This trap indicates a DPI SSL event.
NTF swFwTrapEnhApplicationControl1.3.6.1.4.1.8741.1.1.2.0.169This trap indicates an Application Control event.
NTF swFwTrapEnhWanAcceleration1.3.6.1.4.1.8741.1.1.2.0.170This trap indicates a WAN Acceleration event.
snmpTraps1.3.6.1.6.3.1.1.5
NTF coldStart1.3.6.1.6.3.1.1.5.1This trap signifies that the SonicWALL appliance is re-initializing itself such that the agent's configuration or the appliance itself implementation may be altered.
NTF warmStart1.3.6.1.6.3.1.1.5.2This trap signifies that the SonicWALL appliance is re-initializing itself such that neither the agent configuration nor the appliance implementation is altered.
NTF authenticationFailure1.3.6.1.6.3.1.1.5.5This trap signifies that the SonicWALL appliance is the addressee of a protocol message that is not properly authenticated.

RFC description

SonicWall firewall SNMP MIB defining trap notifications for various firewall security events. Includes trap types for antivirus alerts, content filtering, IPSEC events, TCP scan detection, and security subscription status notifications.

Start monitoring Dell SonicWALL firewall appliance (security/operational event trap notifications) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download SONICWALL-FIREWALL-TRAP-MIB