CISCO-UNIFIED-FIREWALL-MIB :: cufwPolConnNumHalfOpen

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwPolConnNumHalfOpen

cufwPolConnNumHalfOpen

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumHalfOpen

OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.3.1.9

Node type: OBJECT-TYPE

Type: Gauge32

Access: read-only

Description: The number of connections that are currently in the process of being established, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

What is cufwPolConnNumHalfOpen?

This Gauge32 reports how many connections are currently mid-establishment for the protocol/policy/target combination identified by cufwPolConnProtocol, cufwPolConnPolicy, and cufwPolConnPolicyTarget. It gives an admin a live view of in-progress connection setup specifically under one policy applied to one target, useful for isolating congestion to a particular rule rather than the firewall as a whole. A persistently elevated value for a policy governing a particular server target could indicate that target is slow to complete handshakes under that policy's current constraints.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.9
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumHalfOpen

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.9.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumHalfOpen.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumHalfOpen OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1cuFwConnectionGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4cuFwConnectionSummaryTablesCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3cufwPolicyConnSummaryTableCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3.1cufwPolicyConnSummaryEntryCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3.1.9cufwPolConnNumHalfOpenCISCO-UNIFIED-FIREWALL-MIB