All MIBs › CISCO-IPSEC-SIGNALING-MIB › cisgIpsSgNotifCntlCertCrlFail
cisgIpsSgNotifCntlCertCrlFail
Module: CISCO-IPSEC-SIGNALING-MIB
OID (symbolic): CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail
OID (numeric): 1.3.6.1.4.1.9.9.438.1.5.5
Node type: OBJECT-TYPE
Type: TruthValue
Access: read-write
Description: This object defines the administrative state of sending the Certificate/CRL Failure notification.
If the value of this object is 'true', the issuing of the notification 'ciscoIpsSgCertCrlFailure' is enabled.
What is cisgIpsSgNotifCntlCertCrlFail?
This is a read-write switch that, per its description, enables the ciscoIpsSgCertCrlFailure notification when set to true, firing when a certificate or Certificate Revocation List (CRL) check fails during IPsec/IKE negotiation, again gated by the master cisgIpsSgNotifCntlAllNotifs switch. It matters specifically for deployments using certificate-based authentication, since a CRL fetch failure or certificate validation problem could otherwise silently block new tunnel establishment without any other counter making the root cause obvious. An admin running a PKI-based VPN fleet would enable this so an expired CA certificate or an unreachable CRL distribution point gets flagged the moment it starts blocking negotiations, rather than being discovered only through a flood of generic authentication failures.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.5.5 snmpwalk -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.438.1.5.5.1 snmpget -v2c -c public <target> CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail.1
Set instance 1 (SNMPv2c):
snmpset -v2c -c private <target> 1.3.6.1.4.1.9.9.438.1.5.5.1 s <value>
Start monitoring Cisco VPN gateway equipment with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-IPSEC-SIGNALING-MIB::cisgIpsSgNotifCntlCertCrlFail OID value, configure state conditions and alerts, and monitor any Cisco VPN gateway equipment from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.438 | ciscoIPsecSignalingMIB | CISCO-IPSEC-SIGNALING-MIB |
| 1.3.6.1.4.1.9.9.438.1 | ciscoIPsecSigMIBObjects | CISCO-IPSEC-SIGNALING-MIB |
| 1.3.6.1.4.1.9.9.438.1.5 | cisgIpsSgNotificationCntl | CISCO-IPSEC-SIGNALING-MIB |
| 1.3.6.1.4.1.9.9.438.1.5.5 | cisgIpsSgNotifCntlCertCrlFail | CISCO-IPSEC-SIGNALING-MIB |