All MIBs › CISCO-IKE-FLOW-MIB › cifIkeGlobalInP2ExchgRejects
cifIkeGlobalInP2ExchgRejects
Module: CISCO-IKE-FLOW-MIB
OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects
OID (numeric): 1.3.6.1.4.1.9.9.429.1.1.1.1.3
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The total number of Phase-2 exchanges which were received and rejected by all currently and previously active Phase-1 Tunnels.
What is cifIkeGlobalInP2ExchgRejects?
This counts received Phase-2 exchanges that this device explicitly rejected, a distinct outcome from cifIkeGlobalInP2ExchgInvalids, representing negotiations that were well-formed but denied for policy reasons, such as the offered security parameters not matching any configured transform set. A climbing rejects count alongside a low invalids count suggests peers are sending syntactically correct proposals that simply don't match this device's configured IPsec policy, pointing an engineer toward comparing transform sets and proxy IDs between the two ends rather than suspecting packet corruption. This distinction between invalid and rejected matters for correctly diagnosing whether a failing VPN tunnel has a formatting problem or a policy mismatch.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.3 snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.3.1 snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects.1
Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.429 | ciscoIkeFlowMIB | CISCO-IKE-FLOW-MIB |
| 1.3.6.1.4.1.9.9.429.1 | ciscoIkeFlowMIBObjects | CISCO-IKE-FLOW-MIB |
| 1.3.6.1.4.1.9.9.429.1.1 | cifIkeCurrentActivity | CISCO-IKE-FLOW-MIB |
| 1.3.6.1.4.1.9.9.429.1.1.1 | cifIkeGlobalStatsTable | CISCO-IKE-FLOW-MIB |
| 1.3.6.1.4.1.9.9.429.1.1.1.1 | cifIkeGlobalStatsEntry | CISCO-IKE-FLOW-MIB |
| 1.3.6.1.4.1.9.9.429.1.1.1.1.3 | cifIkeGlobalInP2ExchgRejects | CISCO-IKE-FLOW-MIB |