All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwConnGlobalNumPolicyDeclined
cufwConnGlobalNumPolicyDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumPolicyDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.1.3
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connections which were attempted to be setup but which were declined due to reasons of security policy.
This includes the connections that failed authentication.
This value is accumulated from the last reboot of the firewall.
What is cufwConnGlobalNumPolicyDeclined?
This is a 64-bit counter, accumulated since the last reboot, of connections that were attempted but declined specifically because of security policy, including connections that failed authentication. An admin monitoring this counter can distinguish deliberate policy enforcement, such as an access rule or failed login, from other kinds of connection failures like resource exhaustion. For example, a spike in this counter coinciding with a new user rollout could indicate a misconfigured authentication policy is blocking legitimate connections rather than attackers.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.3 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumPolicyDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.3.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumPolicyDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumPolicyDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.1 | cuFwConnectionGlobals | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.1.3 | cufwConnGlobalNumPolicyDeclined | CISCO-UNIFIED-FIREWALL-MIB |