CISCO-IKE-FLOW-MIB :: cifIkeTunHistInP2ExchgRejects

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IKE-FLOW-MIBcifIkeTunHistInP2ExchgRejects

cifIkeTunHistInP2ExchgRejects

Module: CISCO-IKE-FLOW-MIB

OID (symbolic): CISCO-IKE-FLOW-MIB::cifIkeTunHistInP2ExchgRejects

OID (numeric): 1.3.6.1.4.1.9.9.429.1.2.1.1.7

Node type: OBJECT-TYPE

Type: Counter32

Access: read-only

Description: The total number of Phase-2 exchanges received on this tunnel that were validated but were rejected by the local policy.

What is cifIkeTunHistInP2ExchgRejects?

This preserves the count of Phase-2 exchanges on an expired tunnel that were correctly formed but turned down by this device's local policy, per its description - distinguishing policy rejections from the unrecognized-parameter failures tracked separately in HistInP2ExchgInvalids. It helps an admin reviewing a closed tunnel determine whether the peer kept proposing traffic selectors or algorithms the local crypto map simply didn't permit. A high value here alongside a short tunnel lifetime suggests the tunnel never stabilized because of an unresolved policy mismatch.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.2.1.1.7
snmpwalk -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeTunHistInP2ExchgRejects

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.429.1.2.1.1.7.1
snmpget -v2c -c public <target> CISCO-IKE-FLOW-MIB::cifIkeTunHistInP2ExchgRejects.1

Start monitoring Cisco IOS routers and VPN concentrators terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IKE-FLOW-MIB::cifIkeTunHistInP2ExchgRejects OID value, configure state conditions and alerts, and monitor any Cisco IOS routers and VPN concentrators terminating IPsec tunnels from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.429ciscoIkeFlowMIBCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1ciscoIkeFlowMIBObjectsCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.2cifIkeHistoryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.2.1cifIkeTunnelHistTableCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.2.1.1cifIkeTunnelHistEntryCISCO-IKE-FLOW-MIB
1.3.6.1.4.1.9.9.429.1.2.1.1.7cifIkeTunHistInP2ExchgRejectsCISCO-IKE-FLOW-MIB