CISCO-IPSEC-SIGNALING-MIB :: cisgIpsSgGlobalBadTunnelRefs

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IPSEC-SIGNALING-MIBcisgIpsSgGlobalBadTunnelRefs

cisgIpsSgGlobalBadTunnelRefs

Module: CISCO-IPSEC-SIGNALING-MIB

OID (symbolic): CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgGlobalBadTunnelRefs

OID (numeric): 1.3.6.1.4.1.9.9.438.1.1.1.1.22

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The total number of incoming packets that refer to non-existent Phase-1 control tunnels which occurred during processing of all current and previous Phase-1 Control Tunnels.

What is cisgIpsSgGlobalBadTunnelRefs?

This Counter64 totals incoming packets that referenced a non-existent Phase-1 control tunnel, occurring during processing across all current and previous tunnels, per its description - meaning a peer sent a message tagged with a tunnel/SA identifier this device no longer recognizes. It commonly happens when one side has already torn down a tunnel while the other side is still unaware and keeps sending traffic referencing the old tunnel ID. A steady low rate of this counter is often benign residual traffic after normal tunnel teardown, but a sustained high rate on one peer relationship would suggest the two sides have fallen out of sync about tunnel state.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.1.1.1.22
snmpwalk -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgGlobalBadTunnelRefs

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.1.1.1.22.1
snmpget -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgGlobalBadTunnelRefs.1

Start monitoring Cisco VPN gateway equipment with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgGlobalBadTunnelRefs OID value, configure state conditions and alerts, and monitor any Cisco VPN gateway equipment from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.438ciscoIPsecSignalingMIBCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1ciscoIPsecSigMIBObjectsCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.1cisgIpsSgCurrentActivityCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.1.1cisgIpsSgGlobalStatsTableCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.1.1.1cisgIpsSgGlobalStatsEntryCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.1.1.1.22cisgIpsSgGlobalBadTunnelRefsCISCO-IPSEC-SIGNALING-MIB