All MIBs › SONICWALL-FIREWALL-TRAP-MIB
Organization: DELL SonicWALL
Last Updated: 2015-01-08
Category: Dell SonicWall Network Security
Description:
Defines Dell SonicWall firewall event traps for security incidents, policy violations, and operational alerts.
Imported Objects
From SNMPv2-SMI
| IpAddress | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| Unsigned32 | |
| snmpModules |
From SNMPv2-TC
| DisplayString | |
| TEXTUAL-CONVENTION |
From SONICWALL-SMI
| sonicwallFw | OBJECT-IDENTITY |
What Is SONICWALL-FIREWALL-TRAP-MIB?
SONICWALL-FIREWALL-TRAP-MIB is a vendor-specific MIB from Dell SonicWALL (formerly SonicWALL) that defines SNMP trap/notification objects sent by SonicWALL firewall appliances for security incidents, policy violations, and other operational alerts. It exposes trap-payload objects describing the event, including trap type and description, source/destination IP and MAC addresses, source/destination ports, IP protocol type, and free-text messages/service-area names associated with the triggering event. In monitoring terms this MIB is entirely about real-time security/fault event notification rather than polled counters, letting a security operations team receive and parse firewall-generated traps to identify what kind of security event occurred, such as an intrusion attempt or policy block, and the exact flow involved. It has no apparent dependency on other standard MIBs beyond the base SNMP notification framework, functioning as a self-contained trap-definition module. It is deployed wherever Dell/SonicWALL firewalls are configured to forward security and operational alerts to a central SNMP trap receiver or SIEM. Network engineers evaluating or troubleshooting this functionality can download the SONICWALL-FIREWALL-TRAP-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in SONICWALL-FIREWALL-TRAP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
What Can Be Monitored
- firewall security event/trap type
- event description
- source/destination IP and MAC addresses
- source/destination ports
- affected security service/rule area
Supported Devices
- Dell SonicWALL firewall appliance
Monitoring Examples
A security team's trap receiver would parse an incoming SonicWALL trap's swTrapInfoTrapType and swTrapInfoTrapDescription to classify the event, then inspect swTrapInfoSrcIpAddress/swTrapInfoDstIpAddress and swTrapInfoSrcPort/swTrapInfoDstPort to identify the exact flow that triggered it. The swTrapInfoTable holds these fields as trap varbinds accompanying each sonicwallFwTrapInfo notification, and swTrapInfoSaName can identify the security service/rule area involved. A burst of traps sharing the same swTrapInfoSrcIpAddress and an intrusion or policy-violation trap type would point to a single source actively probing or attacking the network. This MIB is used purely for security-event notification, not routine performance polling.
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| sonicwallFwTrapModule | 1.3.6.1.4.1.8741.1.1 | The MIB Module for SonicWALL Firewall Trap. | ||
| sonicwallFwTrapInfo | 1.3.6.1.4.1.8741.1.1.1 | |||
| swTrapInfoTable | 1.3.6.1.4.1.8741.1.1.1.1 | |||
| FWT swTrapInfoTrapType | 1.3.6.1.4.1.8741.1.1.1.1.1 | FwTrapType | accessible-for-notify | trap type . |
| STR swTrapInfoTrapDescription | 1.3.6.1.4.1.8741.1.1.1.1.2 | DisplayString | accessible-for-notify | The description of the trap. |
| IP swTrapInfoSrcIpAddress | 1.3.6.1.4.1.8741.1.1.1.1.3 | IpAddress | accessible-for-notify | The source ip address. |
| IP swTrapInfoDstIpAddress | 1.3.6.1.4.1.8741.1.1.1.1.4 | IpAddress | accessible-for-notify | The destination ip address. |
| INT swTrapInfoSrcPort | 1.3.6.1.4.1.8741.1.1.1.1.5 | INTEGER | accessible-for-notify | The destination port. |
| INT swTrapInfoDstPort | 1.3.6.1.4.1.8741.1.1.1.1.6 | INTEGER | accessible-for-notify | The destination port. |
| MAC swTrapInfoSrcMacAddress | 1.3.6.1.4.1.8741.1.1.1.1.7 | MacAddress | accessible-for-notify | The source MAC address. |
| MAC swTrapInfoDstMacAddress | 1.3.6.1.4.1.8741.1.1.1.1.8 | MacAddress | accessible-for-notify | The destination MAC address. |
| INT swTrapInfoIpType | 1.3.6.1.4.1.8741.1.1.1.1.9 | INTEGER | accessible-for-notify | The ip type. |
| STR swTrapInfoPrivMsg | 1.3.6.1.4.1.8741.1.1.1.1.10 | DisplayString | accessible-for-notify | The additional message. |
| IP swTrapInfoIpAddress | 1.3.6.1.4.1.8741.1.1.1.1.11 | IpAddress | accessible-for-notify | The ip address. |
| STR swTrapInfoSaName | 1.3.6.1.4.1.8741.1.1.1.1.12 | DisplayString | accessible-for-notify | Name of the SA. |
| STR swTrapInfoFwSrlNumber | 1.3.6.1.4.1.8741.1.1.1.1.13 | DisplayString | accessible-for-notify | Serial number of the firewall this trap is coming from. |
| INT swTrapInfoSaStatus | 1.3.6.1.4.1.8741.1.1.1.1.14 | INTEGER | accessible-for-notify | The status of the IPSec Tunnel. |
| IP swTrapInfoSrcAddrBegin | 1.3.6.1.4.1.8741.1.1.1.1.15 | IpAddress | accessible-for-notify | First address of the local network behind the firewall ( LAN side). |
| IP swTrapInfoSrcAddrEnd | 1.3.6.1.4.1.8741.1.1.1.1.16 | IpAddress | accessible-for-notify | Last address of the local network. ( LAN side). |
| IP swTrapInfoDstAddrBegin | 1.3.6.1.4.1.8741.1.1.1.1.17 | IpAddress | accessible-for-notify | First address of the remote network . |
| IP swTrapInfoDstAddrEnd | 1.3.6.1.4.1.8741.1.1.1.1.18 | IpAddress | accessible-for-notify | Last address of the remote network. |
| IP swTrapInfoGateway | 1.3.6.1.4.1.8741.1.1.1.1.19 | IpAddress | accessible-for-notify | Address of the tunnel end point. |
| INT swTrapInfoIsDHCPCentral | 1.3.6.1.4.1.8741.1.1.1.1.20 | INTEGER | accessible-for-notify | If the Tunnel is a DHCP Central |
| STR swTrapInfoSrcResolvedHostName | 1.3.6.1.4.1.8741.1.1.1.1.21 | DisplayString | accessible-for-notify | Source IP address' resolved host name. |
| STR swTrapInfoDstResolvedHostName | 1.3.6.1.4.1.8741.1.1.1.1.22 | DisplayString | accessible-for-notify | Destination IP address' resolved host name. |
| U32 swTrapInfoSrcInterface | 1.3.6.1.4.1.8741.1.1.1.1.23 | Unsigned32 | accessible-for-notify | Source interface |
| U32 swTrapInfoDstInterface | 1.3.6.1.4.1.8741.1.1.1.1.24 | Unsigned32 | accessible-for-notify | Destination interface |
| STR swTrapInfoClientUserName | 1.3.6.1.4.1.8741.1.1.1.1.25 | DisplayString | accessible-for-notify | Client User Name associated with the trap |
| sonicwallFwTrapRoot | 1.3.6.1.4.1.8741.1.1.2 | |||
| NTF swFwTrapAttack | 1.3.6.1.4.1.8741.1.1.2.0.1 | This trap indicates that the firewall have detected a attack. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapSysError | 1.3.6.1.4.1.8741.1.1.2.0.2 | This trap indicates that there is a system problem with the SonicWALL appliance. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapBlkWebSite | 1.3.6.1.4.1.8741.1.1.2.0.3 | This trap indicates that there is a web site was blocked by the firewall. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapIpsecTunnel | 1.3.6.1.4.1.8741.1.1.2.0.4 | This trap indicates that there has bee a change in the IPSec tunnel status along with the parameters required to indentify the tunnel . | ||
| NTF swFwTrapWlanIDS | 1.3.6.1.4.1.8741.1.1.2.0.5 | This trap indicates that there is a wireless intrusion detected by the firewall. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapSysEnv | 1.3.6.1.4.1.8741.1.1.2.0.6 | This trap indicates that there is a system environment problem detected by the firewall. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhNone | 1.3.6.1.4.1.8741.1.1.2.0.100 | This trap may be disabled at this time. | ||
| NTF swFwTrapEnhUnused | 1.3.6.1.4.1.8741.1.1.2.0.101 | This trap may be disabled at this time. | ||
| NTF swFwTrapEnhLegacySystemMaintenance | 1.3.6.1.4.1.8741.1.1.2.0.102 | This is a legacy trap for system maintenance. | ||
| NTF swFwTrapEnhLegacySystemErrors | 1.3.6.1.4.1.8741.1.1.2.0.103 | Please see description for swFwTrapSysError trap. | ||
| NTF swFwTrapEnhLegacyBlockedWebSites | 1.3.6.1.4.1.8741.1.1.2.0.104 | Please see description for swFwTrapBlkWebSite trap. | ||
| NTF swFwTrapEnhLegacyBlockedJavaEtc | 1.3.6.1.4.1.8741.1.1.2.0.105 | This is a legacy trap for blocked java and other blocked application activities. | ||
| NTF swFwTrapEnhLegacyUserActivity | 1.3.6.1.4.1.8741.1.1.2.0.106 | This is a legacy trap for user activities. | ||
| NTF swFwTrapEnhLegacyDeniedLanIp | 1.3.6.1.4.1.8741.1.1.2.0.107 | This is a legacy trap for denied LAN IP activities. | ||
| NTF swFwTrapEnhLegacyAttacks | 1.3.6.1.4.1.8741.1.1.2.0.108 | Please see description for swFwTrapAttack trap. | ||
| NTF swFwTrapEnhLegacyDroppedTcp | 1.3.6.1.4.1.8741.1.1.2.0.109 | This is a legacy trap for dropped TCP event. | ||
| NTF swFwTrapEnhLegacyDroppedUdp | 1.3.6.1.4.1.8741.1.1.2.0.110 | This is a legacy trap for dropped UDP event. | ||
| NTF swFwTrapEnhLegacyDroppedIcmp | 1.3.6.1.4.1.8741.1.1.2.0.111 | This is a legacy trap for dropped ICMP event. | ||
| NTF swFwTrapEnhLegacyNetworkDebug | 1.3.6.1.4.1.8741.1.1.2.0.112 | This is a legacy trap for network debug event. | ||
| NTF swFwTrapEnhLegacySystemEnvironment | 1.3.6.1.4.1.8741.1.1.2.0.113 | Please see description for swFwTrapSysEnv trap. | ||
| NTF swFwTrapEnhLegacyVpnTunnelStatus | 1.3.6.1.4.1.8741.1.1.2.0.114 | This is a legacy trap for VPN tunnel status. | ||
| NTF swFwTrapEnhLegacy80211bManagement | 1.3.6.1.4.1.8741.1.1.2.0.115 | This is a legacy trap for 802.11 management event. | ||
| NTF swFwTrapEnhAuthAccess | 1.3.6.1.4.1.8741.1.1.2.0.116 | This trap indicates an activity from log administrator, user and guest account. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhBootp | 1.3.6.1.4.1.8741.1.1.2.0.117 | This trap indicates an event happening from BOOTP. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhCrypt | 1.3.6.1.4.1.8741.1.1.2.0.118 | This trap indicates an event from crypto algorithm and hardware testing. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhDhcpc | 1.3.6.1.4.1.8741.1.1.2.0.119 | This trap indicates an event from DHCP Client protocol activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhDhcpr | 1.3.6.1.4.1.8741.1.1.2.0.120 | This trap indicates an event from DHCP central and gateway protocol activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhFwEvent | 1.3.6.1.4.1.8741.1.1.2.0.121 | This trap indicates an event from internal firewall activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhFwHardware | 1.3.6.1.4.1.8741.1.1.2.0.122 | This trap indicates an event from firewall hardware error. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhFwLogging | 1.3.6.1.4.1.8741.1.1.2.0.123 | This trap indicates a general firewall event or error. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhFwRule | 1.3.6.1.4.1.8741.1.1.2.0.124 | This trap indicates an event from a firewall rule modification. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhGms | 1.3.6.1.4.1.8741.1.1.2.0.125 | This trap indicates a GMS status event. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhHa | 1.3.6.1.4.1.8741.1.1.2.0.126 | This trap indicates an event from a high availability activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhIntrusionDetection | 1.3.6.1.4.1.8741.1.1.2.0.127 | This trap indicates an event from an intrusion prevention activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhL2tpClient | 1.3.6.1.4.1.8741.1.1.2.0.128 | This trap indicates an event from an L2TP client activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhL2tpServer | 1.3.6.1.4.1.8741.1.1.2.0.129 | This trap indicates an event from an L2TP server activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhNetwork | 1.3.6.1.4.1.8741.1.1.2.0.130 | This trap indicates an event from ARP, fragmentation or MTU activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhNetworkAccess | 1.3.6.1.4.1.8741.1.1.2.0.131 | This trap indicates an event from network and firewall protocol access activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhNetworkTraffic | 1.3.6.1.4.1.8741.1.1.2.0.132 | This trap indicates a network traffic reporting event. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhPppDialUp | 1.3.6.1.4.1.8741.1.1.2.0.133 | This trap indicates an event from a PPP dial-up activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhPppoe | 1.3.6.1.4.1.8741.1.1.2.0.134 | This trap indicates an event from a PPPoE activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhPptp | 1.3.6.1.4.1.8741.1.1.2.0.135 | This trap indicates an event from a PPTP activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhRadius | 1.3.6.1.4.1.8741.1.1.2.0.136 | This trap indicates an event from a RADIUS or LDAP server activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhRip | 1.3.6.1.4.1.8741.1.1.2.0.137 | This trap indicates an event from a RIP activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhSecurityServices | 1.3.6.1.4.1.8741.1.1.2.0.138 | This trap indicates an event from a security services activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVoip | 1.3.6.1.4.1.8741.1.1.2.0.139 | This trap indicates an event from a VoIP H.323/RAS, H.323/H.225, and H.323/H.245 activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVpn | 1.3.6.1.4.1.8741.1.1.2.0.140 | This trap indicates an event from a VPN activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVpnClient | 1.3.6.1.4.1.8741.1.1.2.0.141 | This trap indicates an event from a VPN client activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVpnIke | 1.3.6.1.4.1.8741.1.1.2.0.142 | This trap indicates an event from a VPN IKE activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVpnIpsec | 1.3.6.1.4.1.8741.1.1.2.0.143 | This trap indicates an event from a VPN IPSec ctivity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhVpnPki | 1.3.6.1.4.1.8741.1.1.2.0.144 | This trap indicates an event from a VPN PKI activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhWanFailover | 1.3.6.1.4.1.8741.1.1.2.0.145 | This trap indicates an event from a WAN failover activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhWireless | 1.3.6.1.4.1.8741.1.1.2.0.146 | This trap indicates an event from a wireless activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhSonicPoint | 1.3.6.1.4.1.8741.1.1.2.0.147 | This trap indicates an event from a SonicPoint activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhMcast | 1.3.6.1.4.1.8741.1.1.2.0.148 | This trap indicates an event from an IGMP activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhWlanIds | 1.3.6.1.4.1.8741.1.1.2.0.149 | This trap indicates an event from a WLAN IDS activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhLegacyModemDebug | 1.3.6.1.4.1.8741.1.1.2.0.150 | This is a legacy trap for modem debug. | ||
| NTF swFwTrapEnhModemDebug | 1.3.6.1.4.1.8741.1.1.2.0.151 | This trap indicates an event from modem debug. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhPpp | 1.3.6.1.4.1.8741.1.1.2.0.152 | This trap indicates an event from a generic PPP activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhMsAd | 1.3.6.1.4.1.8741.1.1.2.0.153 | This trap indicates an event from an MsAD activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhDdns | 1.3.6.1.4.1.8741.1.1.2.0.154 | This trap indicates an event from Dynamic DNS. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhRbl | 1.3.6.1.4.1.8741.1.1.2.0.155 | This trap indicates an event from a real-time black list activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhARS | 1.3.6.1.4.1.8741.1.1.2.0.156 | This trap may be disabled at this time. | ||
| NTF swFwTrapEnhIpcomp | 1.3.6.1.4.1.8741.1.1.2.0.157 | This trap indicates an event from an IP compression activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhCia | 1.3.6.1.4.1.8741.1.1.2.0.158 | This trap indicates an event from a CIA activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhRFManagement | 1.3.6.1.4.1.8741.1.1.2.0.159 | This trap indicates an event from an RF management activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhDynAddrObjs | 1.3.6.1.4.1.8741.1.1.2.0.160 | This trap indicates an event from a dynamic address object activity. The bound objects provide more detailed information about this problem. | ||
| NTF swFwTrapEnhApplicationFirewall | 1.3.6.1.4.1.8741.1.1.2.0.161 | This trap indicates an application firewall event. | ||
| NTF swFwTrapEnhSslvpn | 1.3.6.1.4.1.8741.1.1.2.0.162 | This trap indicates an SSL-VPN event. | ||
| NTF swFwTrapEnhSonicPointN | 1.3.6.1.4.1.8741.1.1.2.0.163 | This trap indicates a SonicPoint-N event. | ||
| NTF swFwTrapEnhAntispam | 1.3.6.1.4.1.8741.1.1.2.0.164 | This trap indicates an Anti-Spam event. | ||
| NTF swFwTrapEnhNetworkMonitor | 1.3.6.1.4.1.8741.1.1.2.0.165 | This trap indicates a Network Monitor event. | ||
| NTF swFwTrapEnhDhcpServer | 1.3.6.1.4.1.8741.1.1.2.0.166 | This trap indicates a DHCP Server event. | ||
| NTF swFwTrapEnhFtp | 1.3.6.1.4.1.8741.1.1.2.0.167 | This trap indicates a FTP event. | ||
| NTF swFwTrapEnhDPISSL | 1.3.6.1.4.1.8741.1.1.2.0.168 | This trap indicates a DPI SSL event. | ||
| NTF swFwTrapEnhApplicationControl | 1.3.6.1.4.1.8741.1.1.2.0.169 | This trap indicates an Application Control event. | ||
| NTF swFwTrapEnhWanAcceleration | 1.3.6.1.4.1.8741.1.1.2.0.170 | This trap indicates a WAN Acceleration event. | ||
| snmpTraps | 1.3.6.1.6.3.1.1.5 | |||
| NTF coldStart | 1.3.6.1.6.3.1.1.5.1 | This trap signifies that the SonicWALL appliance is re-initializing itself such that the agent's configuration or the appliance itself implementation may be altered. | ||
| NTF warmStart | 1.3.6.1.6.3.1.1.5.2 | This trap signifies that the SonicWALL appliance is re-initializing itself such that neither the agent configuration nor the appliance implementation is altered. | ||
| NTF authenticationFailure | 1.3.6.1.6.3.1.1.5.5 | This trap signifies that the SonicWALL appliance is the addressee of a protocol message that is not properly authenticated. |
RFC description
SonicWall firewall SNMP MIB defining trap notifications for various firewall security events. Includes trap types for antivirus alerts, content filtering, IPSEC events, TCP scan detection, and security subscription status notifications.
Start monitoring Dell SonicWALL firewall appliance (security/operational event trap notifications) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.