CISCO-REMOTE-ACCESS-MONITOR-MIB :: crasNumDeclinedSessions

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-REMOTE-ACCESS-MONITOR-MIBcrasNumDeclinedSessions

crasNumDeclinedSessions

Module: CISCO-REMOTE-ACCESS-MONITOR-MIB

OID (symbolic): CISCO-REMOTE-ACCESS-MONITOR-MIB::crasNumDeclinedSessions

OID (numeric): 1.3.6.1.4.1.9.9.392.1.4.1.2

Node type: OBJECT-TYPE

Type: Unsigned32

Access: read-only

Description: The number of session setup attempts, counted since the last time the notification 'ciscoRasTooManyFailedAuths' was issued, which were declined due to authentication or authorization failure.

What is crasNumDeclinedSessions?

This object counts session setup attempts that were declined specifically due to authentication or authorization failure, with the counter resetting each time the device fires the ciscoRasTooManyFailedAuths notification. Because the counting window resets on that trap, an admin reading a low value here does not necessarily mean things are fine - it may mean the threshold trap just fired and reset the tally, so this should be read alongside the trap history. A sudden run of, say, 50 declined logins in minutes pointing at one username strongly suggests a credential-stuffing or brute-force attempt against that account.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.392.1.4.1.2
snmpwalk -v2c -c public <target> CISCO-REMOTE-ACCESS-MONITOR-MIB::crasNumDeclinedSessions

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.392.1.4.1.2.1
snmpget -v2c -c public <target> CISCO-REMOTE-ACCESS-MONITOR-MIB::crasNumDeclinedSessions.1

SNMPv3 example:

snmpget -v3 -l authPriv -u snmpv3-user -a SHA -A "AuthPassword1" -x AES -X "PrivPassword1" <target> crasNumDeclinedSessions.1

Start monitoring Cisco VPN concentrator/remote-access router with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-REMOTE-ACCESS-MONITOR-MIB::crasNumDeclinedSessions OID value, configure state conditions and alerts, and monitor any Cisco VPN concentrator/remote-access router from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.392ciscoRemoteAccessMonitorMIBCISCO-REMOTE-ACCESS-MONITOR-MIB
1.3.6.1.4.1.9.9.392.1ciscoRasMonitorMIBObjectsCISCO-REMOTE-ACCESS-MONITOR-MIB
1.3.6.1.4.1.9.9.392.1.4crasFailuresCISCO-REMOTE-ACCESS-MONITOR-MIB
1.3.6.1.4.1.9.9.392.1.4.1crasFailuresGlobalsCISCO-REMOTE-ACCESS-MONITOR-MIB
1.3.6.1.4.1.9.9.392.1.4.1.2crasNumDeclinedSessionsCISCO-REMOTE-ACCESS-MONITOR-MIB