XG-FIREWALL-MIB

MIB Reference — IPNetwork Monitor

All MIBsXG-FIREWALL-MIB

Organization: Sophos PLC

Last Updated: 2017-03-20

Category: Network Security and Firewalls, Sophos Security

Description:

Monitors Sophos XG Firewall policy enforcement, threat detection events, and network security statistics.

Imported Objects

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-IDENTITY
OBJECT-TYPE
enterprises
snmpModules

From SNMPv2-TC

DateAndTime
DisplayString
TEXTUAL-CONVENTION
TruthValue

What Is XG-FIREWALL-MIB?

The XG-FIREWALL-MIB is a vendor-specific MIB for the Sophos XG Firewall unified threat management appliance, exposing device identity, security subsystem versions, and system resource statistics. It covers categories such as appliance identity (model, key), subsystem software versions (web-category, antivirus, anti-spam, IDP engines), and system resource stats (CPU, disk, memory) plus overall system status. Its monitoring emphasis is squarely on hardware/software health: CPU and memory usage track processing and memory load, disk capacity and usage track storage health, sysStatus and sysInstall track overall device and installation state, and version objects confirm security engines are current. There is no apparent dependency on other standard MIBs; it is a self-contained Sophos enterprise MIB. It is deployed on Sophos XG Firewall appliances (physical or virtual) at network perimeters, monitored by NMS/SIEM tooling for both security and operational health. Network engineers evaluating or troubleshooting this functionality can download the XG-FIREWALL-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in XG-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • CPU utilization
  • memory capacity/usage
  • disk capacity/usage
  • system status
  • AV/IDP/anti-spam/web-category engine versions
  • firmware/software version

Supported Devices

  • Sophos XG Firewall appliance

Monitoring Examples

An admin would poll cpuPercentUsage and diskPercentUsage/memoryCapacity to watch for resource exhaustion on the firewall appliance, and check sysStatus to confirm the system is reporting healthy operation. avVersion, asVersion, and idpVersion let an operator confirm the antivirus, anti-spam, and intrusion-detection signature engines are on current versions, flagging an appliance that has fallen behind on security updates.

OIDs
OID symbolicOID numericTypeAccessDescription
sophos1.3.6.1.4.1.21067This MIB module defines MIB objects which provide mechanisms to remotely configure the parameters used by XG-Firewall Agent for the generation of SNMP messages.
xG_Firewall1.3.6.1.4.1.21067.2
sfosSystem1.3.6.1.4.1.21067.2.1
sysInstall1.3.6.1.4.1.21067.2.1.1
STR applianceKey1.3.6.1.4.1.21067.2.1.1.1DisplayStringread-only
STR applianceModel1.3.6.1.4.1.21067.2.1.1.2DisplayStringread-only
STR xG_FirewallVersion1.3.6.1.4.1.21067.2.1.1.3DisplayStringread-only
STR webcatVersion1.3.6.1.4.1.21067.2.1.1.4DisplayStringread-only
STR avVersion1.3.6.1.4.1.21067.2.1.1.5DisplayStringread-only
STR asVersion1.3.6.1.4.1.21067.2.1.1.6DisplayStringread-only
STR idpVersion1.3.6.1.4.1.21067.2.1.1.7DisplayStringread-only
sysStatus1.3.6.1.4.1.21067.2.1.2
DAT systemDate1.3.6.1.4.1.21067.2.1.2.1DateAndTimeread-only
cpuStatus1.3.6.1.4.1.21067.2.1.2.2
I32 cpuPercentUsage1.3.6.1.4.1.21067.2.1.2.2.1Integer32read-only% cpu usage
diskStatus1.3.6.1.4.1.21067.2.1.2.3
G32 diskCapacity1.3.6.1.4.1.21067.2.1.2.3.1Gauge32read-onlyDisk capacity in MB
G32 diskPercentUsage1.3.6.1.4.1.21067.2.1.2.3.2Gauge32read-only% Disk usage
memoryStatus1.3.6.1.4.1.21067.2.1.2.4
G32 memoryCapacity1.3.6.1.4.1.21067.2.1.2.4.1Gauge32read-onlyMemory capacity in MB
G32 memoryPercentUsage1.3.6.1.4.1.21067.2.1.2.4.2Gauge32read-only% usage of main memory
G32 swapCapacity1.3.6.1.4.1.21067.2.1.2.4.3Gauge32read-onlySwap Capacity in MB
G32 swapPercentUsage1.3.6.1.4.1.21067.2.1.2.4.4Gauge32read-only% usage of swap
HAM haMode1.3.6.1.4.1.21067.2.1.2.5HaModeTyperead-only
G32 liveUsers1.3.6.1.4.1.21067.2.1.2.6Gauge32read-only
C64 httpHits1.3.6.1.4.1.21067.2.1.2.7Counter64read-only
C64 ftpHits1.3.6.1.4.1.21067.2.1.2.8Counter64read-only
mailHits1.3.6.1.4.1.21067.2.1.2.9
C64 pop3Hits1.3.6.1.4.1.21067.2.1.2.9.1Counter64read-only
C64 imapHits1.3.6.1.4.1.21067.2.1.2.9.2Counter64read-only
C64 smtpHits1.3.6.1.4.1.21067.2.1.2.9.3Counter64read-only
serviceStats1.3.6.1.4.1.21067.2.1.2.10
SER pop3Service1.3.6.1.4.1.21067.2.1.2.10.1ServiceStatsTyperead-only
SER imap4Service1.3.6.1.4.1.21067.2.1.2.10.2ServiceStatsTyperead-only
SER smtpService1.3.6.1.4.1.21067.2.1.2.10.3ServiceStatsTyperead-only
SER ftpService1.3.6.1.4.1.21067.2.1.2.10.4ServiceStatsTyperead-only
SER httpService1.3.6.1.4.1.21067.2.1.2.10.5ServiceStatsTyperead-only
SER avService1.3.6.1.4.1.21067.2.1.2.10.6ServiceStatsTyperead-only
SER asService1.3.6.1.4.1.21067.2.1.2.10.7ServiceStatsTyperead-only
SER dnsService1.3.6.1.4.1.21067.2.1.2.10.8ServiceStatsTyperead-only
SER haService1.3.6.1.4.1.21067.2.1.2.10.9ServiceStatsTyperead-only
SER idpService1.3.6.1.4.1.21067.2.1.2.10.10ServiceStatsTyperead-only
SER apacheService1.3.6.1.4.1.21067.2.1.2.10.11ServiceStatsTyperead-only
SER ntpService1.3.6.1.4.1.21067.2.1.2.10.12ServiceStatsTyperead-only
SER tomcatService1.3.6.1.4.1.21067.2.1.2.10.13ServiceStatsTyperead-only
SER sslvpnService1.3.6.1.4.1.21067.2.1.2.10.14ServiceStatsTyperead-only
SER dataBaseService1.3.6.1.4.1.21067.2.1.2.10.15ServiceStatsTyperead-only
SER networkService1.3.6.1.4.1.21067.2.1.2.10.16ServiceStatsTyperead-only
SER garnerService1.3.6.1.4.1.21067.2.1.2.10.17ServiceStatsTyperead-only
SER droutingService1.3.6.1.4.1.21067.2.1.2.10.18ServiceStatsTyperead-only
SER sshdService1.3.6.1.4.1.21067.2.1.2.10.19ServiceStatsTyperead-only
SER dgdService1.3.6.1.4.1.21067.2.1.2.10.20ServiceStatsTyperead-only
sysLicense1.3.6.1.4.1.21067.2.1.3
liAppliance1.3.6.1.4.1.21067.2.1.3.1
REG appRegStatus1.3.6.1.4.1.21067.2.1.3.1.1RegistrationStatusTyperead-only
DAT appExpiryDate1.3.6.1.4.1.21067.2.1.3.1.2DateAndTimeread-only
liSupport1.3.6.1.4.1.21067.2.1.3.2
SUP supportSubStatus1.3.6.1.4.1.21067.2.1.3.2.1SupportStatusTyperead-only
DAT supportExpiryDate1.3.6.1.4.1.21067.2.1.3.2.2DateAndTimeread-only
liAntivirus1.3.6.1.4.1.21067.2.1.3.3
SUB avSubStatus1.3.6.1.4.1.21067.2.1.3.3.1SubscriptionStatusTyperead-only
DAT avExpiryDate1.3.6.1.4.1.21067.2.1.3.3.2DateAndTimeread-only
liAntispam1.3.6.1.4.1.21067.2.1.3.4
SUB asSubStatus1.3.6.1.4.1.21067.2.1.3.4.1SubscriptionStatusTyperead-only
DAT asExpiryDate1.3.6.1.4.1.21067.2.1.3.4.2DateAndTimeread-only
liIdp1.3.6.1.4.1.21067.2.1.3.5
SUB idpSubStatus1.3.6.1.4.1.21067.2.1.3.5.1SubscriptionStatusTyperead-only
DAT idpExpiryDate1.3.6.1.4.1.21067.2.1.3.5.2DateAndTimeread-only
liWebcat1.3.6.1.4.1.21067.2.1.3.6
SUB webcatSubStatus1.3.6.1.4.1.21067.2.1.3.6.1SubscriptionStatusTyperead-only
DAT webcatExpiryDate1.3.6.1.4.1.21067.2.1.3.6.2DateAndTimeread-only
sysAlerts1.3.6.1.4.1.21067.2.1.4
NTF highCpuUsage1.3.6.1.4.1.21067.2.1.4.1
highDiskUsage1.3.6.1.4.1.21067.2.1.4.2
NTF highConfDiskUsage1.3.6.1.4.1.21067.2.1.4.2.1
NTF highSigDiskUsage1.3.6.1.4.1.21067.2.1.4.2.2
NTF highReportDiskUsage1.3.6.1.4.1.21067.2.1.4.2.3
highMemUsage1.3.6.1.4.1.21067.2.1.4.3
NTF highPhyMemUsage1.3.6.1.4.1.21067.2.1.4.3.1
NTF highSwapMemUsage1.3.6.1.4.1.21067.2.1.4.3.2
avAlerts1.3.6.1.4.1.21067.2.1.4.4
NTF httpVirus1.3.6.1.4.1.21067.2.1.4.4.1
NTF smtpVirus1.3.6.1.4.1.21067.2.1.4.4.2
NTF pop3Virus1.3.6.1.4.1.21067.2.1.4.4.3
NTF imap4Virus1.3.6.1.4.1.21067.2.1.4.4.4
NTF ftpVirus1.3.6.1.4.1.21067.2.1.4.4.5
dgdAlerts1.3.6.1.4.1.21067.2.1.4.5
NTF gwLiveDead1.3.6.1.4.1.21067.2.1.4.5.1
idpAlerts1.3.6.1.4.1.21067.2.1.4.6
NTF idpAlert1.3.6.1.4.1.21067.2.1.4.6.1
dosAlerts1.3.6.1.4.1.21067.2.1.4.7
NTF synFlood1.3.6.1.4.1.21067.2.1.4.7.1
NTF tcpFlood1.3.6.1.4.1.21067.2.1.4.7.2
NTF udpFlood1.3.6.1.4.1.21067.2.1.4.7.3
NTF icmpFlood1.3.6.1.4.1.21067.2.1.4.7.4
cscAlerts1.3.6.1.4.1.21067.2.1.4.8
NTF opcodeFail1.3.6.1.4.1.21067.2.1.4.8.1
NTF serviceFail1.3.6.1.4.1.21067.2.1.4.8.2

RFC description

SNMP configuration and monitoring for Sophos XG firewall appliance parameters and service status.

Start monitoring Sophos XG Firewall appliance (CPU/memory/disk/security-engine-version status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download XG-FIREWALL-MIB