All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAppConnNumPolicyDeclined
cufwAppConnNumPolicyDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumPolicyDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.2.1.4
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwAppConnProtocol'.
This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.
What is cufwAppConnNumPolicyDeclined?
This Counter64, measured in Connections, tallies connection attempts for the protocol identified by cufwAppConnProtocol that the firewall turned away because they violated the configured security policy. An admin watching this counter can spot a spike to know the firewall is actively enforcing policy against a particular protocol, which is useful when troubleshooting why certain application traffic keeps failing to connect. For example, if this counter climbs sharply for an FTP-tagged row right after a new access rule is pushed, it confirms the rule is blocking FTP connection attempts as intended.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.2.1.4 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumPolicyDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.2.1.4.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumPolicyDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumPolicyDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4 | cuFwConnectionSummaryTables | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2 | cufwAppConnSummaryTable | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2.1 | cufwAppConnSummaryEntry | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2.1.4 | cufwAppConnNumPolicyDeclined | CISCO-UNIFIED-FIREWALL-MIB |