CISCO-UNIFIED-FIREWALL-MIB :: cufwConnNumPolicyDeclined

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwConnNumPolicyDeclined

cufwConnNumPolicyDeclined

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwConnNumPolicyDeclined

OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.1.1.4

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwConnProtocol'.

This value is accumulated from the last reboot of the firewall.

What is cufwConnNumPolicyDeclined?

This is a 64-bit counter, accumulated since the last reboot, of connection attempts for the specific protocol denoted by cufwConnProtocol that were declined due to security policy. An admin uses this per-protocol figure to identify exactly which protocol's traffic is being blocked by policy, rather than only knowing that policy declines are happening somewhere on the firewall. For example, if this counter is high only for the row corresponding to a particular protocol, the admin would go check the access rules governing that specific protocol.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.1.1.4
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnNumPolicyDeclined

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.1.1.4.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwConnNumPolicyDeclined.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwConnNumPolicyDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1cuFwConnectionGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4cuFwConnectionSummaryTablesCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.1cufwConnSummaryTableCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.1.1cufwConnSummaryEntryCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.1.1.4cufwConnNumPolicyDeclinedCISCO-UNIFIED-FIREWALL-MIB