Cisco 7604 Configuration Manual page 589

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 25
Monitoring the Firewall Services Module
Table 25-3
SNMP MIB and Trap Support (continued)
MIB and Trap
CISCO-IP-PROTOCOL-FILTER-MIB
(Continued)
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Description
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.13.3.97.97.97.1 =
Gauge32: 0 <- 0 means any port.
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.16.3.97.97.97.1 =
INTEGER: 2 <- 2 means log for ACL is disabled.
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.17.3.97.97.97.1 =
INTEGER: 1 <- 1 means ACL log enabled.
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.22.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.23.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.24.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.25.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.26.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.3.1.27.3.97.97.97.1 = ""
SNMPv2-SMI::enterprises.9.9.278.1.1.4.1.2.3.97.97.97.1 = INTEGER:
0
SNMPv2-SMI::enterprises.9.9.278.1.1.4.1.3.3.97.97.97.1 = Gauge32:
0
SNMPv2-SMI::enterprises.9.9.278.1.2.1.1.1.3.97.97.97.1 =
Counter64: 0
<<<< 0 is current ACL hit counter for ACL 'aaa'
where "3.97.97.97" denotes the access-list name in ASCII characters. The
access-list name "aaa" translates to 97.97.97, where "97" is the ASCII
equivalent of the character "a." The "3" denotes the number of characters in
the ASCII list name.
The following example shows an unexpanded access-list with a network
object-group, which can be retrieved through SNMP operations. The hit
counter for individual access-lists is aggregated and displayed in the SNMP
OID "cipppfIpFilterHits."
!
interface Vlan50
nameif inside
security-level 100
ip address 50.0.0.2 255.0.0.0
!
interface Vlan60
nameif outside
security-level 0
ip address 60.0.0.2 255.0.0.0
!
object-group network src-network
network-object 50.1.1.1 255.255.255.255
network-object 50.1.1.2 255.255.255.255
network-object 50.1.1.3 255.255.255.255
object-group network dest-network
network-object 60.1.1.1 255.255.255.255
network-object 60.1.1.2 255.255.255.255
network-object 60.1.1.3 255.255.255.255
access-list aaa extended permit tcp object-group src-network
object-group dest-network
!
snmp-server host outside 60.0.0.1 community public version 2c
udp-port 161
!
hostname(config)# show access-list
Configuring SNMP
25-23

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents