CISCO-UNIFIED-FIREWALL-MIB :: cufwConnGlobalNumAttempted

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwConnGlobalNumAttempted

cufwConnGlobalNumAttempted

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumAttempted

OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.1.1

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: Connection Statistics Aggregation

Connection 1  +-----------+ 
------------->|           |-------> Global Connection Summary
Connection 2  |           |
------------->|           |
Connection 3  |           |
------------->|   First   |------------> ConnSummary 
  |   Level   |            (i.e, L-3/4 Protocol
Connection 4  |Aggregation|             Connection Summary)
------------->|           |
.    |           |
.    |           |---------------> PolicyConnSummary 
Connection N  |           |       (i.e, L-3/4 Policy Target based
------------->|           |        Protocol Connection Summary)
  +-----------+


  +-----------+ 
L-3/4 Protocol   |           |
Connection Summary |           |
------------------>|           |---------> AppConnSummary 
  |           |         (i.e, L-7 Protocol 
  |  Second   |          Connection Summary)
  |---Level---|
L-3/4 Policy Target |Aggregation|
based Protocol    |           |
Connection Summary  |           |
------------------>|           |---------------> PolicyAppConnSummary
  |           |       (i.e, L-7 Policy Target based
  |           |        Protocol Connection Summary)
  +-----------+


Specifically, the object 
'cufwConnGlobalNumAttempted' models
the number of connections which are attempted to
be set up through the firewall.

This value is accumulated from the last reboot of
the firewall.

What is cufwConnGlobalNumAttempted?

This is a 64-bit counter of the total number of connection setup attempts the firewall has seen across all protocols since it last rebooted. An admin watches this global total as the top-level indicator of overall traffic volume hitting the firewall, useful as a baseline before drilling into the per-protocol cufwConnNumAttempted breakdown. For example, a sudden jump in this counter's rate compared to normal daily patterns could be the first sign of a connection flood or scan hitting the device.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.1
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumAttempted

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.1.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumAttempted.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumAttempted OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1cuFwConnectionGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.1cuFwConnectionGlobalsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.1.1cufwConnGlobalNumAttemptedCISCO-UNIFIED-FIREWALL-MIB