CHECKPOINT-MIB-2 :: icmpInTimeExcds

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCHECKPOINT-MIB-2icmpInTimeExcds

icmpInTimeExcds

Module: CHECKPOINT-MIB-2

OID (symbolic): CHECKPOINT-MIB-2::icmpInTimeExcds

OID (numeric): 1.3.6.1.2.1.5.4

Node type: OBJECT-TYPE

Type: Counter

Access: read-only

Description: The number of ICMP Time Exceeded messages received.

What is icmpInTimeExcds?

Counts ICMP Time Exceeded messages received by the device, typically generated by a router along a path when a packet's TTL hit zero. A rise here specifically on a firewall usually comes from traceroute-style diagnostic traffic or, less innocently, TTL-based network reconnaissance probing the path, either way evidence someone is mapping the hop count to or from this gateway. Example: a burst of icmpInTimeExcds right before a fwRejected spike from the same external range suggests the source was traceroute-mapping the path before launching whatever probe got rejected.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.2.1.5.4
snmpwalk -v2c -c public <target> CHECKPOINT-MIB-2::icmpInTimeExcds

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.2.1.5.4.1
snmpget -v2c -c public <target> CHECKPOINT-MIB-2::icmpInTimeExcds.1

Start monitoring Check Point security gateway/firewall appliances with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CHECKPOINT-MIB-2::icmpInTimeExcds OID value, configure state conditions and alerts, and monitor any Check Point security gateway/firewall appliances from a single console.

OID Breakdown

Upper-level ancestors (6 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.2mgmtAXON-MIB
1.3.6.1.2.1mib_2AXON-MIB
Numeric OIDNameModule
1.3.6.1.2.1.5icmpCHECKPOINT-MIB-2
1.3.6.1.2.1.5.4icmpInTimeExcdsCHECKPOINT-MIB-2