All MIBs › XG-FIREWALL-MIB
Organization: Sophos PLC
Last Updated: 2017-03-20
Category: Network Security and Firewalls, Sophos Security
Description: Monitors Sophos XG Firewall policy enforcement, threat detection events, and network security statistics.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is XG-FIREWALL-MIB?
The XG-FIREWALL-MIB is a vendor-specific MIB for the Sophos XG Firewall unified threat management appliance, exposing device identity, security subsystem versions, and system resource statistics. It covers categories such as appliance identity (model, key), subsystem software versions (web-category, antivirus, anti-spam, IDP engines), and system resource stats (CPU, disk, memory) plus overall system status. Its monitoring emphasis is squarely on hardware/software health: CPU and memory usage track processing and memory load, disk capacity and usage track storage health, sysStatus and sysInstall track overall device and installation state, and version objects confirm security engines are current. There is no apparent dependency on other standard MIBs; it is a self-contained Sophos enterprise MIB. It is deployed on Sophos XG Firewall appliances (physical or virtual) at network perimeters, monitored by NMS/SIEM tooling for both security and operational health. Network engineers evaluating or troubleshooting this functionality can download the XG-FIREWALL-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in XG-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Sophos XG Firewall appliance
Monitoring Examples
An admin would poll cpuPercentUsage and diskPercentUsage/memoryCapacity to watch for resource exhaustion on the firewall appliance, and check sysStatus to confirm the system is reporting healthy operation. avVersion, asVersion, and idpVersion let an operator confirm the antivirus, anti-spam, and intrusion-detection signature engines are on current versions, flagging an appliance that has fallen behind on security updates.
What Can Be Monitored
- CPU utilization
- memory capacity/usage
- disk capacity/usage
- system status
- AV/IDP/anti-spam/web-category engine versions
- firmware/software version
Imported Objects
From SNMPv2-SMI
| Counter32 | |
| Counter64 | |
| Gauge32 | |
| Integer32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-IDENTITY | |
| OBJECT-TYPE | |
| enterprises | |
| snmpModules |
From SNMPv2-TC
| DateAndTime | |
| DisplayString | |
| TEXTUAL-CONVENTION | |
| TruthValue |
How to Use in IPNetwork Monitor
Example using httpHits OID:
OIDs
RFC description
SNMP configuration and monitoring for Sophos XG firewall appliance parameters and service status.
Start monitoring Sophos XG Firewall appliance (CPU/memory/disk/security-engine-version status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.