All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwAppConnNumResDeclined
cufwAppConnNumResDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumResDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.2.1.5
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwAppConnProtocol'.
This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.
What is cufwAppConnNumResDeclined?
This Counter64 counts connection attempts for the protocol in cufwAppConnProtocol that were rejected not because of policy but because the firewall ran out of resources to handle them. A rising value tells an admin the firewall is resource-starved for that protocol's connection handling, a sign it may be time to check memory, session table limits, or CPU load rather than security rules. For instance, a surge in this counter during a traffic spike for a VoIP-related protocol row would point to the firewall hitting a resource ceiling rather than a policy block.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.2.1.5 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumResDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.2.1.5.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumResDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwAppConnNumResDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4 | cuFwConnectionSummaryTables | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2 | cufwAppConnSummaryTable | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2.1 | cufwAppConnSummaryEntry | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.2.1.5 | cufwAppConnNumResDeclined | CISCO-UNIFIED-FIREWALL-MIB |