CISCO-UNIFIED-FIREWALL-MIB :: cufwConnGlobalNumResDeclined

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwConnGlobalNumResDeclined

cufwConnGlobalNumResDeclined

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumResDeclined

OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.1.4

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of connections which were attempted to be setup but which were declined due to non-availability of required resources.

This value is accumulated from the last reboot of the firewall.

What is cufwConnGlobalNumResDeclined?

This is a 64-bit counter, accumulated since the last reboot, of connections that were attempted but declined because the firewall did not have the resources available to set them up. An admin checks this counter to tell whether connection failures are caused by capacity limits (like exhausted connection-table memory) rather than security policy. For example, a firewall under a connection flood might show this counter climbing rapidly while cufwConnGlobalNumPolicyDeclined stays flat, pointing the admin toward a resource-sizing or DoS-mitigation problem instead of an ACL issue.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.4
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumResDeclined

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.1.4.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumResDeclined.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwConnGlobalNumResDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1cuFwConnectionGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.1cuFwConnectionGlobalsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.1.4cufwConnGlobalNumResDeclinedCISCO-UNIFIED-FIREWALL-MIB