XG-FIREWALL-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsXG-FIREWALL-MIB

Organization: Sophos PLC

Last Updated: 2017-03-20

Category: Network Security and Firewalls, Sophos Security

Description: Monitors Sophos XG Firewall policy enforcement, threat detection events, and network security statistics.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is XG-FIREWALL-MIB?

The XG-FIREWALL-MIB is a vendor-specific MIB for the Sophos XG Firewall unified threat management appliance, exposing device identity, security subsystem versions, and system resource statistics. It covers categories such as appliance identity (model, key), subsystem software versions (web-category, antivirus, anti-spam, IDP engines), and system resource stats (CPU, disk, memory) plus overall system status. Its monitoring emphasis is squarely on hardware/software health: CPU and memory usage track processing and memory load, disk capacity and usage track storage health, sysStatus and sysInstall track overall device and installation state, and version objects confirm security engines are current. There is no apparent dependency on other standard MIBs; it is a self-contained Sophos enterprise MIB. It is deployed on Sophos XG Firewall appliances (physical or virtual) at network perimeters, monitored by NMS/SIEM tooling for both security and operational health. Network engineers evaluating or troubleshooting this functionality can download the XG-FIREWALL-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in XG-FIREWALL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Sophos XG Firewall appliance

Monitoring Examples

An admin would poll cpuPercentUsage and diskPercentUsage/memoryCapacity to watch for resource exhaustion on the firewall appliance, and check sysStatus to confirm the system is reporting healthy operation. avVersion, asVersion, and idpVersion let an operator confirm the antivirus, anti-spam, and intrusion-detection signature engines are on current versions, flagging an appliance that has fallen behind on security updates.

What Can Be Monitored

  • CPU utilization
  • memory capacity/usage
  • disk capacity/usage
  • system status
  • AV/IDP/anti-spam/web-category engine versions
  • firmware/software version
Imported Objects

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-IDENTITY
OBJECT-TYPE
enterprises
snmpModules

From SNMPv2-TC

DateAndTime
DisplayString
TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using httpHits OID:

Select a Sophos XG Firewall appliance (CPU/memory/disk/security-engine-version status) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type httpHits into the Find box to locate it in the OID tree, then select it and click OK. The total number of HTTP hits processed by the firewall. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

SNMP configuration and monitoring for Sophos XG firewall appliance parameters and service status.

Start monitoring Sophos XG Firewall appliance (CPU/memory/disk/security-engine-version status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download XG-FIREWALL-MIB