TPT-NGFW-SYSTEM-INFO-MIB

MIB Reference — IPNetwork Monitor

All MIBsTPT-NGFW-SYSTEM-INFO-MIB

Organization: Trend Micro, Inc.

Last Updated: 2016-05-25

Category: Firewall and Intrusion Prevention

Description:

Provides Trend Micro TippingPoint NGFW system information including version, model, and uptime.

Imported Objects

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
TimeTicks

From SNMPv2-TC

DateAndTime
TEXTUAL-CONVENTION
TruthValue

From TPT-NGFW-REG-MIB

tpt-ngfw-compls
tpt-ngfw-eventsV2
tpt-ngfw-groups
tpt-ngfw-objs
tptNgfwNotifySeverityOBJECT-TYPE

What Is TPT-NGFW-SYSTEM-INFO-MIB?

TPT-NGFW-SYSTEM-INFO-MIB is a Trend Micro TippingPoint proprietary MIB module supporting the Next-Generation Firewall (NGFW) product line, a security-focused enterprise networking technology area. It exposes system identity and version data, covering hardware serials and revisions, software/firmware build details, failsafe versions, and boot/runtime timing information. It is explicitly useful for monitoring hardware and software status of the appliance, reporting device uptime and boot time as well as tracking the exact software version, build type/revision, and Digital Vaccine (threat signature) version installed, which is critical for verifying patch and security-content currency. As a vendor-specific module it does not depend on other standard MIBs but is typically deployed alongside broader system and interface MIBs on the same device, and administrators mapping polled values back to the TPT-NGFW-SYSTEM-INFO-MIB OID tree can quickly identify which numeric identifier corresponds to each system attribute. It is typically deployed in enterprise or data center perimeter security environments where administrators track firmware compliance and appliance health across a fleet of NGFW appliances.

IPNetwork Monitor allows you to monitor SNMP objects defined in TPT-NGFW-SYSTEM-INFO-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • system uptime
  • boot time
  • software version
  • hardware serial number
  • hardware revision
  • Digital Vaccine version

Supported Devices

  • Trend Micro TippingPoint NGFW product line, entire range (S/T-series and VTPS virtual models)

Monitoring Examples

An administrator would poll tptNgfwSystemUpTime and tptNgfwSystemBootTime to detect unexpected reboots, and tptNgfwSystemSoftwareVersion together with tptNgfwSystemDigitalVaccineVersion to confirm all NGFW units are running current firmware and threat signatures. tptNgfwSystemSerial and tptNgfwSystemHardwareSerial let an inventory system correlate SNMP data with asset records. A sudden change in tptNgfwSystemBuildRevision without a corresponding maintenance record could indicate an unauthorized firmware change.

OIDs
OID symbolicOID numericTypeAccessDescription
tptNgfwSystemInfoGroup1.3.6.1.4.1.10734.3.9.1.1.1System group for Next-generation Firewall products consisting of hardware and software version information.
tptNgfwSystemNotificationGroup1.3.6.1.4.1.10734.3.9.1.1.9A group of notifications related to NGFW system status.
tptNgfwSystemInfoCompl1.3.6.1.4.1.10734.3.9.1.2.1Compliance for TippingPoint Next-generation Firewall products.
tptNgfwSystemInfo1.3.6.1.4.1.10734.3.9.2.1Hardware and system software version and runtime information for TippingPoint Next-Generation Firewall products. Copyright (C) 2016 Trend Micro Incorporated. All Rights Reserved. Trend Micro makes no warranty of any kind with regard to this material, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose. Trend Micro shall not be liable for errors contained herein or for incidental or consequential damages in connection with the furnishing, performance, or use of this material. This document contains proprietary information, which is protected by copyright. No part of this document may be photocopied, reproduced, or translated into another language without the prior written consent of Trend Micro. The information is provided 'as is' without warranty of any kind and is subject to change without notice. The only warranties for Trend Micro products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Trend Micro shall not be liable for technical or editorial errors or omissions contained herein. TippingPoint(R), the TippingPoint logo, and Digital Vaccine(R) are registered trademarks of Trend Micro. All other company and product names may be trademarks of their respective holders. All rights reserved. This document contains confidential information, trade secrets or both, which are the property of Trend Micro. No part of this documentation may be reproduced in any form or by any means or used to make any derivative work (such as translation, transformation, or adaptation) without written permission from Trend Micro or one of its subsidiaries. All other company and product names may be trademarks of their respective holders.
STR tptNgfwSystemSerial1.3.6.1.4.1.10734.3.9.2.1.1SnmpAdminStringread-onlyThe installed software serial number.
STR tptNgfwSystemSoftwareVersion1.3.6.1.4.1.10734.3.9.2.1.2SnmpAdminStringread-onlyThe installed software version.
DAT tptNgfwSystemBuildDate1.3.6.1.4.1.10734.3.9.2.1.3DateAndTimeread-onlyThe software build date & time.
BUI tptNgfwSystemBuildType1.3.6.1.4.1.10734.3.9.2.1.4BuildTyperead-onlyThe software build type (production, or development). If a development build, the revision object is populated with the source code revision otherwise it's not provided.
STR tptNgfwSystemBuildRevision1.3.6.1.4.1.10734.3.9.2.1.5SnmpAdminStringread-onlyThe software build revision. This object reports the source code revision of the development build that's installed and running. This object is empty if a production build is installed.
STR tptNgfwSystemDigitalVaccineVersion1.3.6.1.4.1.10734.3.9.2.1.6SnmpAdminStringread-onlyThe installed Digital Vaccine version.
STR tptNgfwSystemModel1.3.6.1.4.1.10734.3.9.2.1.7SnmpAdminStringread-onlyThe model number.
STR tptNgfwSystemHardwareSerial1.3.6.1.4.1.10734.3.9.2.1.8SnmpAdminStringread-onlyThe hardware serial number.
STR tptNgfwSystemHardwareRevision1.3.6.1.4.1.10734.3.9.2.1.9SnmpAdminStringread-onlyThe hardware revision.
STR tptNgfwSystemFailsafeVersion1.3.6.1.4.1.10734.3.9.2.1.10SnmpAdminStringread-onlyThe fail-safe boot image version.
DAT tptNgfwSystemBootTime1.3.6.1.4.1.10734.3.9.2.1.11DateAndTimeread-onlyThe local date and time when the device was powered on.
TIK tptNgfwSystemUpTime1.3.6.1.4.1.10734.3.9.2.1.12TimeTicksread-onlyThe time (in 100th/second) since the system was powered on.
T/F tptNgfwSystemSmsManaged1.3.6.1.4.1.10734.3.9.2.1.13TruthValueread-onlyIndicates if this device is under SMS management control. This object is set to true when the device is under SMS control, false otherwise.
IPt tptNgfwSystemSmsIpAddressType1.3.6.1.4.1.10734.3.9.2.1.14InetAddressTyperead-onlyThe SMS IP address type.
IP tptNgfwSystemSmsIpAddress1.3.6.1.4.1.10734.3.9.2.1.15InetAddressread-onlyThe SMS IP address that is managing this device. Only set if SMS is managing the device.
FIP tptNgfwSystemFipsAdminState1.3.6.1.4.1.10734.3.9.2.1.16FipsStateread-onlyThe administrative state of FIPS (140-2) encryption (disabled, crypto, or full)
FIP tptNgfwSystemFipsOperState1.3.6.1.4.1.10734.3.9.2.1.17FipsStateread-onlyThe operational state of FIPS (140-2) encryption (disabled, crypto, or full.)
T/F tptNgfwSystemMasterKeySet1.3.6.1.4.1.10734.3.9.2.1.18TruthValueread-onlyIndicates if a master key (or password) has been set for the device. The value is true when a master key is set (configured), false otherwise.
NTF tptNgfwSystemReadyNotify1.3.6.1.4.1.10734.3.9.3.0.11A notification that the system has achieved the system ready state.
NTF tptNgfwSystemShutdownNotify1.3.6.1.4.1.10734.3.9.3.0.12A notification that the system is performing a controlled shutdown or reboot.
NTF tptNgfwSystemSmsNotAuthNotify1.3.6.1.4.1.10734.3.9.3.0.13A notification that a management station was denied control of the system because it did not have an authorized IP address. Notification includes the IP address of the management station that attempted control.

FAQ

What is TPT-NGFW-SYSTEM-INFO-MIB used for when monitoring TippingPoint NGFW appliances?
It exposes system identity and version data for Trend Micro TippingPoint Next-Generation Firewall appliances -- hardware serials and revisions, software/firmware build details, failsafe versions, and boot/runtime timing -- so administrators can verify device uptime, boot time, and exactly which firmware and Digital Vaccine (threat signature) version is running.

How would a security team use this MIB to confirm threat-signature currency across a fleet of firewalls?
By polling the Digital Vaccine version object alongside the software version/build/revision fields, a fleet-wide dashboard can flag any TippingPoint appliance running an outdated signature set or firmware build, which is critical for verifying patch and security-content compliance across perimeter security devices.

RFC description

Threat Prevention Toolkit Next-Generation Firewall vendor-private MIB for monitoring system information, status, and health metrics.

Start monitoring Trend Micro TippingPoint NGFW product line, entire range (S/T-series and VTPS virtual models) (hardware/firmware version and uptime status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download TPT-NGFW-SYSTEM-INFO-MIB