Home/Catalog/NETSCREEN-POLICY-MIB

NETSCREEN-POLICY-MIB

AI MIB Summary

The NETSCREEN-POLICY-MIB enables monitoring of firewall policy statistics and session states on Juniper NetScreen security appliances via SNMP. It provides access to specific counters and gauges tracking policy hits, drops, and active session counts for security policy enforcement analysis.

This module defines NetScreen private MIBs for Policy Monitoring
Main OID:
netscreenPolicyMibModule.1.3.6.1.4.1.3224.10.0
41
Objects
Active
Status
3
Dependencies

Imported Objects

Objects

41 total
Object Name
netscreenPolicyMibModuleThis module defines NetScreen private MIBs for Policy Monitoring
MODULE-IDENTITY
.1.3.6.1.4.1.3224.10.0
nsPlyTableA firewall provides a network boundary with a single point of entry and exit-a choke point.You can screen and direct all that traffic through the implementation of a set of access policies. Access policies allow you to permit, deny, encrypt, authenticate, prioritize, schedule, and monitor the traffic attemption to cross your firewall. This table collects all the policy configuration information existing in NetScreen Device.
SEQUENCE OF NsPlyEntry
.1.3.6.1.4.1.3224.10.1
nsPlyEntryEach entry in the nsPlyTable holds a set of configuration parameters associatied with an instance of policy.
NsPlyEntry
.1.3.6.1.4.1.3224.10.1.1
nsPlyIdEach policy is identified by a unique policy ID.ro
Integer32
.1.3.6.1.4.1.3224.10.1.1.1
nsPlyVsysVitural system's name this polic entry belongs to.ro
Integer32
.1.3.6.1.4.1.3224.10.1.1.2
nsPlySrcZoneTraffic through a firewall means that traffic flows from one security zone to another. This object describes the source zone name traffic flow passes.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.3
nsPlyDstZoneTraffic through a firewall means that traffic flows from one security zone to another. This object describes the destination zone name traffic flow passes.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.4
nsPlySrcAddrAddresses are objects that identify network devices such as hosts and networks by their location in relation to the firwall on which security zone.To create an access policy for specific addresses, you must first create entries for the relevant hosts and networks in the address book.Source IP address indicates the address in source zone, 0.0.0.0 means any address.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.5
nsPlyDstAddrAddresses are objects that identify network devices such as hosts and networks by their location in relation to the firwall-on which security zone.To create an access policy for specific addresses, you must first create entries for the relevant hosts and networks in the address book.Source IP address indicates the address in destination zone, 0.0.0.0 means any address.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.6
nsPlyServiceSevices are objects that identify application protocols using layer 4 information such as standard and accepted TCP and UDP port numbers for application services like Telnet, FTP, SMTP and HTTP. This object indicates all the traffic service type this policy allows. 'Any' means all this policy allows all service go through. 'Other' could be a configured service or not in the list. See nsPlyServiceName for service name.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.7
nsPlyActionActions objects that describe what the firewall does to the traffic it receives. Permit allows the packet to pass the firewall. Deny blocks the packet from traversing the firewall. Tunnel encapsulates outgoing IP packets and decapsulates incoming IP packets.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.8
nsPlyNatYou can apply NAT at the interface level or at the policy level. With policy-based NAT, you can translate the source address on either incoming or outging network and VPN traffic. This object indicates if this is a policy-based NAT.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.9
nsPlyFixPortWhen in policy-based NAT, the new secure address can come from either a Dynamic IP or from a Mapped IP. This object indicates if poliy-based NAT uses fix port when working on NAT mode.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.10
nsPlyDipIdThis object indicates the Dynamic ID chosen for NAT policy.ro
Integer32
.1.3.6.1.4.1.3224.10.1.1.11
nsPlyVpnTunnelVPN tunnel this access policy applies to.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.12
nsPlyL2tpTunnelL2TP tunnel this access policy applies to.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.13
nsPlyAuthThis object indicates the selecting this option requires the user at the source address to authenticate his/her identiry by supplying a user name and password before traffic is allowed to graverw the firewall or enter the VPN tunnel.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.14
nsPlyLogEnableWhen you enable logging in an access policy, the NetScreen device logs all connections to which that paticular access policy applies.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.15
nsPlyCountEnableWhen you enable counting in an access plicy, the NetScreen device counts the total number of bytes of traffic to which this access policy applies and records the informaiton in historical graphs.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.16
nsPlyAlarmBPSUser can set a threshold that triggers an alarm when the traffic permitted by the access policy exceeds a specified number of bytes per second.ro
Integer32
.1.3.6.1.4.1.3224.10.1.1.17
nsPlyAlarmBPMUser can set a threshold that triggers an alarm when the traffic permitted by the access policy exceeds a specified number of bytes per Minute.ro
Integer32
.1.3.6.1.4.1.3224.10.1.1.18
nsPlyScheduleBy associating a schedule to an access policy, you can determine when the access policy is in effect.ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.19
nsPlyTrafficShapeEnableUser can set parameters for the control and shaping of traffic for each access policy.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.20
nsPlyTrafficPriorityTraffic priority for this policy.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.21
nsPlyDSEnableDifferentiated Services is a system for tagging traffic at a position within a hierarchy of priority.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.22
nsPlyActiveStatusShow the status of one policy entry.ro
Enumeration
.1.3.6.1.4.1.3224.10.1.1.23
nsPlyNamepolicy name (optional)ro
DisplayString
.1.3.6.1.4.1.3224.10.1.1.24
nsPlyServiceNameSevices name that identify application protocols using layer 4 information such as standard and accepted TCP and UDP port numbers for application services like Telnet, FTP, SMTP and HTTP. This object indicates all the traffic service type this policy allows. 'Any' means all this policy allows all service go through.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.3224.10.1.1.25
nsPlyMonTabletraffic information for the policy-based traffic.
SEQUENCE OF NsPlyMonEntry
.1.3.6.1.4.1.3224.10.2
nsPlyMonEntryAn entry holds a set of traffic counters of a specific policy.
NsPlyMonEntry
.1.3.6.1.4.1.3224.10.2.1
nsPlyMonIdPolicy Id, also used as index in this tablero
Integer32
.1.3.6.1.4.1.3224.10.2.1.1
nsPlyMonVsysvsys this policy belongs toro
Integer32
.1.3.6.1.4.1.3224.10.2.1.2
nsPlyMonPackPerSecPackets go through this policy per secondro
Integer32
.1.3.6.1.4.1.3224.10.2.1.3
nsPlyMonPackPerMinPackets go through this policy per minutero
Integer32
.1.3.6.1.4.1.3224.10.2.1.4
nsPlyMonTotalPackettotal packets go through this policyro
Counter32
.1.3.6.1.4.1.3224.10.2.1.5
nsPlyMonBytePerSecBytes go through this policy per secondro
Integer32
.1.3.6.1.4.1.3224.10.2.1.6
nsPlyMonBytePerMinBytes go through this policy per minutero
Integer32
.1.3.6.1.4.1.3224.10.2.1.7
nsPlyMonTotalByteTotal bytes go through this policyro
Counter32
.1.3.6.1.4.1.3224.10.2.1.8
nsPlyMonSessionPerSecSessions go through this policy per secondro
Integer32
.1.3.6.1.4.1.3224.10.2.1.9
nsPlyMonSessionPerMinSessions go through this policy per minutero
Integer32
.1.3.6.1.4.1.3224.10.2.1.10
nsPlyMonTotalSessionTotal Sessions go through this policyro
Counter32
.1.3.6.1.4.1.3224.10.2.1.11
NETSCREEN-POLICY-MIB - SNMP MIB Reference | MIBs Explorer