CISCO-IKE-FLOW-MIB :: cifIkeGlobalOutXauthFailures

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeGlobalOutXauthFailures

cifIkeGlobalOutXauthFailures

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeGlobalOutXauthFailures

OID (numeric): 1.3.6.1.4.1.9.9.429.1.1.1.1.9

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of times the extended authentication information supplied by the managed entity to an IKE peer was found to be invalid by the remote peer.

What is cifIkeGlobalOutXauthFailures?

This counter tracks how many times the Extended Authentication (Xauth) credentials this device presented to a remote IKE peer were rejected as invalid, exactly as its description states. Because it counts only outbound Xauth failures, a climbing value points to a username, password, or secret mismatch configured on this router's side of a client-based VPN rather than a peer-side issue. For example, if a branch office's local Xauth username was changed but the head-end's user database wasn't updated, this counter could jump from 0 to 20 within an hour of repeated failed connection attempts.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.9
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalOutXauthFailures

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.1.1.1.9.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeGlobalOutXauthFailures.1

SNMPv3 example:

snmpget -v3 -l authPriv -u snmpv3-user -a SHA -A "AuthPassword1" -x AES -X "PrivPassword1" <target> cifIkeGlobalOutXauthFailures.1

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeGlobalOutXauthFailures OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1cifIkeCurrentActivityCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1cifIkeGlobalStatsTableCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1cifIkeGlobalStatsEntryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.1.1.1.9cifIkeGlobalOutXauthFailuresCISCO-IKE-FLOW-MIB