CISCO-IKE-FLOW-MIB :: cifIkeNotifCntlOutNewGrpRejected

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeNotifCntlOutNewGrpRejected

cifIkeNotifCntlOutNewGrpRejected

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeNotifCntlOutNewGrpRejected

OID (numeric): 1.3.6.1.4.1.9.9.429.1.3.2

Node type: OBJECT-TYPE

Type: TruthValue

Access: read-write

Description: The generation of the 'ciscoIkeFlowOutNewGrpRejected' notification is enabled if and only if this object has the value 'true'.

What is cifIkeNotifCntlOutNewGrpRejected?

This is the outbound counterpart switch: setting it to 'true' enables the ciscoIkeFlowOutNewGrpRejected notification, which fires when this device's own New Group Mode request is rejected by a peer, per its description. It lets an admin get proactively notified the instant a locally configured custom DH group is refused by a remote peer, instead of discovering the failure only by noticing a stalled Phase-1 negotiation. This is typically enabled together with the inbound version above so both directions of custom-group rejection generate alerts.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.3.2
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeNotifCntlOutNewGrpRejected

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.3.2.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeNotifCntlOutNewGrpRejected.1

Set instance 1 (SNMPv2c):

snmpset -v2c -c private <target> 1.3.6.1.4.1.9.9.429.1.3.2.1 s <value>

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeNotifCntlOutNewGrpRejected OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.3cifIkeNotifControlCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.3.2cifIkeNotifCntlOutNewGrpRejectedCISCO-IKE-FLOW-MIB