All MIBs › CISCO-UNIFIED-FIREWALL-MIB › cufwPolConnNumPolicyDeclined
cufwPolConnNumPolicyDeclined
Module: CISCO-UNIFIED-FIREWALL-MIB
OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumPolicyDeclined
OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.3.1.7
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: The number of connection attempts that were declined due to security policy, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.
What is cufwPolConnNumPolicyDeclined?
This Counter64 counts, for the protocol/policy/target combination in cufwPolConnProtocol, cufwPolConnPolicy, and cufwPolConnPolicyTarget, the connection attempts declined specifically because of security policy. An admin can use this to verify that a given policy applied to a given target is actually enforcing the rule it was configured for. If this counter starts increasing for a policy applied to a partner-facing target right after a rule change, it confirms the new rule is now actively blocking connections there.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.7 snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumPolicyDeclined
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.7.1 snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumPolicyDeclined.1
Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumPolicyDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.9 | ciscoMgmt | CISCO-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.9.491 | ciscoUnifiedFirewallMIB | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1 | ciscoUnifiedFirewallMIBObjects | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1 | cuFwConnectionGrp | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4 | cuFwConnectionSummaryTables | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.3 | cufwPolicyConnSummaryTable | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.3.1 | cufwPolicyConnSummaryEntry | CISCO-UNIFIED-FIREWALL-MIB |
| 1.3.6.1.4.1.9.9.491.1.1.4.3.1.7 | cufwPolConnNumPolicyDeclined | CISCO-UNIFIED-FIREWALL-MIB |