CISCO-IKE-FLOW-MIB :: cifIkeGlobalInP2ExchgRejects

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeGlobalInP2ExchgRejects

cifIkeGlobalInP2ExchgRejects

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects

OID (numeric): 1.3.6.1.4.1.9.9.429.1.1.1.1.3

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The total number of Phase-2 exchanges which were received and rejected by all currently and previously active Phase-1 Tunnels.

What is cifIkeGlobalInP2ExchgRejects?

This counts received Phase-2 exchanges that this device explicitly rejected, a distinct outcome from cifIkeGlobalInP2ExchgInvalids, representing negotiations that were well-formed but denied for policy reasons, such as the offered security parameters not matching any configured transform set. A climbing rejects count alongside a low invalids count suggests peers are sending syntactically correct proposals that simply don't match this device's configured IPsec policy, pointing an engineer toward comparing transform sets and proxy IDs between the two ends rather than suspecting packet corruption. This distinction between invalid and rejected matters for correctly diagnosing whether a failing VPN tunnel has a formatting problem or a policy mismatch.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.3
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.3.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects.1

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeGlobalInP2ExchgRejects OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1cifIkeCurrentActivityCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1cifIkeGlobalStatsTableCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1cifIkeGlobalStatsEntryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1.3cifIkeGlobalInP2ExchgRejectsCISCO-IKE-FLOW-MIB