UDP-MIB

MIB Reference — IPNetwork Monitor

All MIBsUDP-MIB

Organization: IETF IPv6 Working Group http://www.ietf.org/html.charters/ipv6-charter.html

Last Updated: 2005-05-20

Category: IP and Core Protocols

Description:

Defines managed objects for managing UDP implementations, including transmitted and received datagram counters and listener information.

Imported Objects

From INET-ADDRESS-MIB

InetAddress
InetAddressType
InetPortNumber

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32
mib-2

What Is UDP-MIB?

UDP-MIB is a vendor-neutral IETF standards-track MIB (RFC 4113) defining managed objects for monitoring UDP protocol implementations on any networked device or host. It exposes datagram traffic counters (received, sent, high-capacity 64-bit variants) and error counters for datagrams received on ports with no listener, plus a listener endpoint table identifying local and remote address/port bindings. It is used for monitoring software/protocol status: administrators track udpNoPorts and udpInErrors to detect misdirected traffic or application misconfiguration, and the udpEndpointTable to confirm which UDP services are actively bound and listening on a device; consulting the UDP-MIB OID list shows the module is compact, covering only datagram counters, error counts, and the listener endpoint table without vendor extensions. As a core IETF standard it is typically deployed alongside the companion TCP-MIB and IP-MIB for a complete transport-layer picture of a host's networking stack. It is deployed universally on any SNMP-manageable host, server, or network device running a UDP/IP stack.

IPNetwork Monitor allows you to monitor SNMP objects defined in UDP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • UDP datagrams received/sent
  • high-capacity 64-bit datagram counters
  • datagrams received with no listening port (errors)
  • active UDP listener endpoints (local/remote address and port)

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer; applies to any host, server, or network device running a UDP/IP stack

Monitoring Examples

An administrator would poll udpInDatagrams/udpOutDatagrams (or their udpHCInDatagrams/udpHCOutDatagrams high-capacity counterparts) to baseline UDP traffic volume, and watch udpNoPorts for a rising count indicating packets arriving for services that are not listening, e.g. a crashed or misconfigured daemon. Checking udpEndpointTable/udpEndpointEntry for udpEndpointLocalAddress and udpEndpointLocalPort confirms whether an expected UDP service is actually bound and listening on the device.

OIDs
OID symbolicOID numericTypeAccessDescription
udp1.3.6.1.2.1.7
C32 udpInDatagrams1.3.6.1.2.1.7.1Counter32read-onlyThe total number of UDP datagrams delivered to UDP users. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
C32 udpNoPorts1.3.6.1.2.1.7.2Counter32read-onlyThe total number of received UDP datagrams for which there was no application at the destination port. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
C32 udpInErrors1.3.6.1.2.1.7.3Counter32read-onlyThe number of received UDP datagrams that could not be delivered for reasons other than the lack of an application at the destination port. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
C32 udpOutDatagrams1.3.6.1.2.1.7.4Counter32read-onlyThe total number of UDP datagrams sent from this entity. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
udpTable1.3.6.1.2.1.7.5not-accessibleA table containing IPv4-specific UDP listener information. It contains information about all local IPv4 UDP end-points on which an application is currently accepting datagrams. This table has been deprecated in favor of the version neutral udpEndpointTable.
udpEntry1.3.6.1.2.1.7.5.1not-accessibleInformation about a particular current UDP listener.
IP udpLocalAddress1.3.6.1.2.1.7.5.1.1IpAddressread-onlyThe local IP address for this UDP listener. In the case of a UDP listener that is willing to accept datagrams for any IP interface associated with the node, the value 0.0.0.0 is used.
I32 udpLocalPort1.3.6.1.2.1.7.5.1.2Integer32read-onlyThe local port number for this UDP listener.
udpEndpointTable1.3.6.1.2.1.7.7not-accessibleA table containing information about this entity's UDP endpoints on which a local application is currently accepting or sending datagrams. The address type in this table represents the address type used for the communication, irrespective of the higher-layer abstraction. For example, an application using IPv6 'sockets' to communicate via IPv4 between ::ffff:10.0.0.1 and ::ffff:10.0.0.2 would use InetAddressType ipv4(1). Unlike the udpTable in RFC 2013, this table also allows the representation of an application that completely specifies both local and remote addresses and ports. A listening application is represented in three possible ways: 1) An application that is willing to accept both IPv4 and IPv6 datagrams is represented by a udpEndpointLocalAddressType of unknown(0) and a udpEndpointLocalAddress of ''h (a zero-length octet-string). 2) An application that is willing to accept only IPv4 or only IPv6 datagrams is represented by a udpEndpointLocalAddressType of the appropriate address type and a udpEndpointLocalAddress of '0.0.0.0' or '::' respectively. 3) An application that is listening for datagrams only for a specific IP address but from any remote system is represented by a udpEndpointLocalAddressType of the appropriate address type, with udpEndpointLocalAddress specifying the local address. In all cases where the remote is a wildcard, the udpEndpointRemoteAddressType is unknown(0), the udpEndpointRemoteAddress is ''h (a zero-length octet-string), and the udpEndpointRemotePort is 0. If the operating system is demultiplexing UDP packets by remote address and port, or if the application has 'connected' the socket specifying a default remote address and port, the udpEndpointRemote* values should be used to reflect this.
udpEndpointEntry1.3.6.1.2.1.7.7.1not-accessibleInformation about a particular current UDP endpoint. Implementers need to be aware that if the total number of elements (octets or sub-identifiers) in udpEndpointLocalAddress and udpEndpointRemoteAddress exceeds 111, then OIDs of column instances in this table will have more than 128 sub-identifiers and cannot be accessed using SNMPv1, SNMPv2c, or SNMPv3.
IPt udpEndpointLocalAddressType1.3.6.1.2.1.7.7.1.1InetAddressTypenot-accessibleThe address type of udpEndpointLocalAddress. Only IPv4, IPv4z, IPv6, and IPv6z addresses are expected, or unknown(0) if datagrams for all local IP addresses are accepted.
IP udpEndpointLocalAddress1.3.6.1.2.1.7.7.1.2InetAddressnot-accessibleThe local IP address for this UDP endpoint. The value of this object can be represented in three possible ways, depending on the characteristics of the listening application: 1. For an application that is willing to accept both IPv4 and IPv6 datagrams, the value of this object must be ''h (a zero-length octet-string), with the value of the corresponding instance of the udpEndpointLocalAddressType object being unknown(0). 2. For an application that is willing to accept only IPv4 or only IPv6 datagrams, the value of this object must be '0.0.0.0' or '::', respectively, while the corresponding instance of the udpEndpointLocalAddressType object represents the appropriate address type. 3. For an application that is listening for data destined only to a specific IP address, the value of this object is the specific IP address for which this node is receiving packets, with the corresponding instance of the udpEndpointLocalAddressType object representing the appropriate address type. As this object is used in the index for the udpEndpointTable, implementors of this table should be careful not to create entries that would result in OIDs with more than 128 subidentifiers; else the information cannot be accessed using SNMPv1, SNMPv2c, or SNMPv3.
INE udpEndpointLocalPort1.3.6.1.2.1.7.7.1.3InetPortNumbernot-accessibleThe local port number for this UDP endpoint.
IPt udpEndpointRemoteAddressType1.3.6.1.2.1.7.7.1.4InetAddressTypenot-accessibleThe address type of udpEndpointRemoteAddress. Only IPv4, IPv4z, IPv6, and IPv6z addresses are expected, or unknown(0) if datagrams for all remote IP addresses are accepted. Also, note that some combinations of udpEndpointLocalAdressType and udpEndpointRemoteAddressType are not supported. In particular, if the value of this object is not unknown(0), it is expected to always refer to the same IP version as udpEndpointLocalAddressType.
IP udpEndpointRemoteAddress1.3.6.1.2.1.7.7.1.5InetAddressnot-accessibleThe remote IP address for this UDP endpoint. If datagrams from any remote system are to be accepted, this value is ''h (a zero-length octet-string). Otherwise, it has the type described by udpEndpointRemoteAddressType and is the address of the remote system from which datagrams are to be accepted (or to which all datagrams will be sent). As this object is used in the index for the udpEndpointTable, implementors of this table should be careful not to create entries that would result in OIDs with more than 128 subidentifiers; else the information cannot be accessed using SNMPv1, SNMPv2c, or SNMPv3.
INE udpEndpointRemotePort1.3.6.1.2.1.7.7.1.6InetPortNumbernot-accessibleThe remote port number for this UDP endpoint. If datagrams from any remote system are to be accepted, this value is zero.
U32 udpEndpointInstance1.3.6.1.2.1.7.7.1.7Unsigned32not-accessibleThe instance of this tuple. This object is used to distinguish among multiple processes 'connected' to the same UDP endpoint. For example, on a system implementing the BSD sockets interface, this would be used to support the SO_REUSEADDR and SO_REUSEPORT socket options.
U32 udpEndpointProcess1.3.6.1.2.1.7.7.1.8Unsigned32read-onlyThe system's process ID for the process associated with this endpoint, or zero if there is no such process. This value is expected to be the same as HOST-RESOURCES-MIB::hrSWRunIndex or SYSAPPL-MIB:: sysApplElmtRunIndex for some row in the appropriate tables.
C64 udpHCInDatagrams1.3.6.1.2.1.7.8Counter64read-onlyThe total number of UDP datagrams delivered to UDP users, for devices that can receive more than 1 million UDP datagrams per second. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
C64 udpHCOutDatagrams1.3.6.1.2.1.7.9Counter64read-onlyThe total number of UDP datagrams sent from this entity, for devices that can transmit more than 1 million UDP datagrams per second. Discontinuities in the value of this counter can occur at re-initialization of the management system, and at other times as indicated by discontinuities in the value of sysUpTime.
udpMIB1.3.6.1.2.1.50The MIB module for managing UDP implementations. Copyright (C) The Internet Society (2005). This version of this MIB module is part of RFC 4113; see the RFC itself for full legal notices.
udpMIBConformance1.3.6.1.2.1.50.2
udpMIBCompliances1.3.6.1.2.1.50.2.1
udpMIBCompliance1.3.6.1.2.1.50.2.1.1The compliance statement for IPv4-only systems that implement UDP. For IP version independence, this compliance statement is deprecated in favor of udpMIBCompliance2. However, agents are still encouraged to implement these objects in order to interoperate with the deployed base of managers.
udpMIBCompliance21.3.6.1.2.1.50.2.1.2The compliance statement for systems that implement UDP. There are a number of INDEX objects that cannot be represented in the form of OBJECT clauses in SMIv2, but for which we have the following compliance requirements, expressed in OBJECT clause form in this description clause: -- OBJECT udpEndpointLocalAddressType -- SYNTAX InetAddressType { unknown(0), ipv4(1), -- ipv6(2), ipv4z(3), -- ipv6z(4) } -- DESCRIPTION -- Support for dns(5) is not required. -- OBJECT udpEndpointLocalAddress -- SYNTAX InetAddress (SIZE(0|4|8|16|20)) -- DESCRIPTION -- Support is only required for zero-length -- octet-strings, and for scoped and unscoped -- IPv4 and IPv6 addresses. -- OBJECT udpEndpointRemoteAddressType -- SYNTAX InetAddressType { unknown(0), ipv4(1), -- ipv6(2), ipv4z(3), -- ipv6z(4) } -- DESCRIPTION -- Support for dns(5) is not required. -- OBJECT udpEndpointRemoteAddress -- SYNTAX InetAddress (SIZE(0|4|8|16|20)) -- DESCRIPTION -- Support is only required for zero-length -- octet-strings, and for scoped and unscoped -- IPv4 and IPv6 addresses.
udpMIBGroups1.3.6.1.2.1.50.2.2
udpGroup1.3.6.1.2.1.50.2.2.1The deprecated group of objects providing for management of UDP over IPv4.
udpBaseGroup1.3.6.1.2.1.50.2.2.2The group of objects providing for counters of UDP statistics.
udpHCGroup1.3.6.1.2.1.50.2.2.3The group of objects providing for counters of high speed UDP implementations.
udpEndpointGroup1.3.6.1.2.1.50.2.2.4The group of objects providing for the IP version independent management of UDP 'endpoints'.

FAQ

How would an admin use UDP-MIB to catch a misconfigured application on a server?
By tracking udpNoPorts and udpInErrors, they can detect datagrams arriving on ports with no listener, which often signals misdirected traffic or an application that isn't bound where expected; cross-checking the udpEndpointTable confirms which UDP services are actually listening.

What traffic counters does UDP-MIB expose for a host's UDP stack?
It provides datagram received/sent counters, including high-capacity 64-bit variants for high-volume hosts, alongside the no-listener error counter and the endpoint table of local/remote address-port bindings, typically polled alongside TCP-MIB and IP-MIB for a complete transport-layer view.

RFC description

SNMP MIB for monitoring UDP (User Datagram Protocol) statistics including datagram counts, port information, and endpoint data as defined in RFC 3493.

Start monitoring vendor-neutral, standards-based MIB, any host/server/network device running a UDP/IP stack (datagram counter/listener-endpoint status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download UDP-MIB