All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwPolAppConnNumResDeclined
cufwPolAppConnNumResDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumResDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.4.1.8
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwPolAppConnProtocol', in the policy 'cufwPolAppConnPolicy' applied to the entity identified by 'cufwPolAppConnPolicyTarget'.
This value is accumulated from the last reboot of the firewall subject to the control exercised by cufwConnReptAppStats.
What is cufwPolAppConnNumResDeclined?
This Counter64 counts, for the same protocol/policy/target scope (cufwPolAppConnProtocol, cufwPolAppConnPolicy, cufwPolAppConnPolicyTarget), connections declined due to resource unavailability, again subject to cufwConnReptAppStats control over accumulation. It helps an admin tell resource exhaustion apart from deliberate policy blocking at the application-inspection level for one specific target. A steady rise here for a policy applied to a busy application target would suggest the firewall's application-inspection resources for that pairing are being outstripped by demand.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.4.1.8 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumResDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.4.1.8.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumResDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwPolAppConnNumResDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4 | cuFwConnectionSummaryTables | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4 | cufwPolicyAppConnSummaryTable | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4.1 | cufwPolicyAppConnSummaryEntry | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.4.1.8 | cufwPolAppConnNumResDeclined | CISCO-UNIFIED-FIREWALL-MIB |