CISCO-IKE-FLOW-MIB :: cifIkeGlobalInP2ExchgInvalids

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeGlobalInP2ExchgInvalids

cifIkeGlobalInP2ExchgInvalids

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgInvalids

OID (numeric): 1.3.6.1.4.1.9.9.429.1.1.1.1.2

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The total number of Phase-2 exchanges which were received and found to be invalid by all currently and previously active Phase-1 Tunnels.

What is cifIkeGlobalInP2ExchgInvalids?

This counts received Phase-2 exchanges that this device determined were invalid, out of the total tracked by cifIkeGlobalInP2Exchgs, representing malformed or policy-mismatched negotiation attempts rather than successful SA establishments. A rising ratio of invalid to total Phase-2 exchanges points at a specific peer or set of peers sending negotiation proposals this device's IPsec policy can't accept, such as a transform set or proposal mismatch, rather than a general connectivity problem. This is the counter to check first when a specific site-to-site VPN tunnel keeps failing to establish its IPsec SAs even though the underlying Phase-1 (ISAKMP) tunnel itself is up and healthy.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.2
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgInvalids

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.2.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgInvalids.1

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgInvalids OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1cifIkeCurrentActivityCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1cifIkeGlobalStatsTableCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1cifIkeGlobalStatsEntryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1.2cifIkeGlobalInP2ExchgInvalidsCISCO-IKE-FLOW-MIB