CISCO-IKE-FLOW-MIB :: cifIkeGlobalOutP2ExchgRejects

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeGlobalOutP2ExchgRejects

cifIkeGlobalOutP2ExchgRejects

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeGlobalOutP2ExchgRejects

OID (numeric): 1.3.6.1.4.1.9.9.429.1.1.1.1.6

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The total number of Phase-2 exchanges which were sent and rejected by all currently and previously active Phase-1 IKE Tunnels.

What is cifIkeGlobalOutP2ExchgRejects?

This counts Phase-2 exchanges this device sent that were rejected by the receiving peer based on their policy, out of the total in cifIkeGlobalOutP2Exchgs, essentially the outbound mirror of cifIkeGlobalInP2ExchgRejects. A climbing count here means remote peers are turning down this device's own negotiation proposals, which points an engineer toward reviewing this device's own configured transform sets and proxy IDs against what specific peers expect, rather than assuming the problem is entirely on the remote end. This is a particularly useful counter on a hub device serving many spoke sites, since it can reveal that this device's own default IPsec policy doesn't match what one or more particular spokes were configured to expect.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.6
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalOutP2ExchgRejects

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.6.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalOutP2ExchgRejects.1

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeGlobalOutP2ExchgRejects OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1cifIkeCurrentActivityCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1cifIkeGlobalStatsTableCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1cifIkeGlobalStatsEntryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1.6cifIkeGlobalOutP2ExchgRejectsCISCO-IKE-FLOW-MIB