STONESOFT-FIREWALL-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsSTONESOFT-FIREWALL-MIB

Organization: Forcepoint LLC

Last Updated: 2016-08-17

Category: Firewall / Security Appliance, Security / Access Control

Description: Manages Forcepoint Stonesoft next-generation firewall policy enforcement, connection state, and traffic statistics.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is STONESOFT-FIREWALL-MIB?

STONESOFT-FIREWALL-MIB is a proprietary Forcepoint (formerly McAfee/Stonesoft) MIB for the vendor's next-generation firewall (NGFW), covering security policy enforcement, connection state, and traffic statistics. It exposes software identity data (version, active policy name and timestamp), connection performance counters (accepted/dropped/logged/accounted/rejected packets, current connection count), and per-interface traffic statistics, plus fault-oriented notifications. Its monitoring emphasis spans both software status - confirming the correct firmware and policy revision is active - and ongoing security/performance health via connection and drop/reject counters that reveal blocked attacks or misapplied rules. It complements standard IF-MIB interface indexing for its per-interface stats and uses SNMPv2 notification conventions for its firewallEvents/firewallEventsV2 traps. Typical deployment is Forcepoint Stonesoft NGFW appliances at the network perimeter. Engineers can download the STONESOFT-FIREWALL-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in STONESOFT-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Forcepoint Stonesoft next-generation firewall (NGFW)

Monitoring Examples

Polling fwConnNumber alongside fwAccepted, fwDropped, and fwRejected gives a real-time view of connection volume and how much traffic the firewall is blocking, while fwSoftwareVersion and fwPolicyTime confirm which firmware and policy revision is currently active after a policy push. fwIfStatsTable/Entry (indexed by fwIfStatsIndex) exposes per-interface traffic counters, letting an admin spot an interface where dropped/rejected counts spike unexpectedly, which could indicate a misapplied rule or an attack in progress; firewallEvents/firewallEventsV2 traps notify on significant security events.

What Can Be Monitored

  • software version
  • active security policy and policy timestamp
  • current connection count
  • accepted/dropped/rejected/logged packet counts
  • per-interface traffic statistics
Imported Objects

From HCNUM-TC

CounterBasedGauge64

From INET-ADDRESS-MIB

InetAddressIPv4
InetAddressIPv6

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
TEXTUAL-CONVENTION
TimeStamp

From STONESOFT-SMI-MIB

stonesoftFirewallOBJECT-IDENTITY
stonesoftModulesOBJECT-IDENTITY

How to Use in IPNetwork Monitor

Example using fwAccepted OID:

Select a Forcepoint Stonesoft next-generation firewall (policy/connection statistics) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type fwAccepted into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of accepted packets. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Stonesoft/Forcepoint enterprise MIB for NGFW (Next-Generation Firewall) engines that manages firewall-specific objects including security policies, software versions, and firewall events. Provides SNMP monitoring and configuration capabilities for firewall/VPN, IPS, and Layer 2 Firewall roles.

Start monitoring Forcepoint Stonesoft next-generation firewall (policy/connection statistics) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download STONESOFT-FIREWALL-MIB