All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwPolAppConnNumPolicyDeclined
cufwPolAppConnNumPolicyDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumPolicyDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.4.1.7
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'.
This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.
What is cufwPolAppConnNumPolicyDeclined?
This Counter64 counts, for the protocol/policy/target combination in cufwPolAppConnProtocol, cufwPolAppConnPolicy, and cufwPolAppConnPolicyTarget, connections declined specifically for violating security policy, with accumulation subject to cufwConnReptAppStats control. This lets an admin confirm at the application-policy level that a specific rule applied to a specific target is actively rejecting traffic. A jump in this counter right after tightening an application inspection policy for a target would confirm the new restriction is being enforced.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.4.1.7 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumPolicyDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.4.1.7.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumPolicyDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumPolicyDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4 | cuFwConnectionSummaryTables | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4 | cufwPolicyAppConnSummaryTable | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4.1 | cufwPolicyAppConnSummaryEntry | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4.1.7 | cufwPolAppConnNumPolicyDeclined | CISCO-UNIFIED-FIREWALL-MIB |