CISCO-IPSEC-SIGNALING-MIB :: cisgIpsSgNotifCntlCertCrlFail

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-IPSEC-SIGNALING-MIBcisgIpsSgNotifCntlCertCrlFail

cisgIpsSgNotifCntlCertCrlFail

Module: CISCO-IPSEC-SIGNALING-MIB

OID (symbolic): CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail

OID (numeric): 1.3.6.1.4.1.9.9.438.1.5.5

Node type: OBJECT-TYPE

Type: TruthValue

Access: read-write

Description: This object defines the administrative state of sending the Certificate/CRL Failure notification.

If the value of this object is 'true', the issuing of the notification 'ciscoIpsSgCertCrlFailure' is enabled.

What is cisgIpsSgNotifCntlCertCrlFail?

This is a read-write switch that, per its description, enables the ciscoIpsSgCertCrlFailure notification when set to true, firing when a certificate or Certificate Revocation List (CRL) check fails during IPsec/IKE negotiation, again gated by the master cisgIpsSgNotifCntlAllNotifs switch. It matters specifically for deployments using certificate-based authentication, since a CRL fetch failure or certificate validation problem could otherwise silently block new tunnel establishment without any other counter making the root cause obvious. An admin running a PKI-based VPN fleet would enable this so an expired CA certificate or an unreachable CRL distribution point gets flagged the moment it starts blocking negotiations, rather than being discovered only through a flood of generic authentication failures.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.5.5
snmpwalk -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.5.5.1
snmpget -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail.1

Set instance 1 (SNMPv2c):

snmpset -v2c -c private <target> 1.3.6.1.4.1.9.9.438.1.5.5.1 s <value>

Start monitoring Cisco VPN gateway equipment with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail OID value, configure state conditions and alerts, and monitor any Cisco VPN gateway equipment from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.438ciscoIPsecSignalingMIBCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1ciscoIPsecSigMIBObjectsCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.5cisgIpsSgNotificationCntlCISCO-IPSEC-SIGNALING-MIB
1.3.6.1.4.1.9.9.438.1.5.5cisgIpsSgNotifCntlCertCrlFailCISCO-IPSEC-SIGNALING-MIB