CISCO-UNIFIED-FIREWALL-MIB :: cufwPolConnNumResDeclined

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-UNIFIED-FIREWALL-MIBcufwPolConnNumResDeclined

cufwPolConnNumResDeclined

Module: CISCO-UNIFIED-FIREWALL-MIB

OID (symbolic): CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumResDeclined

OID (numeric): 1.3.6.1.4.1.9.9.491.1.1.4.3.1.8

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: The number of connection attempts that were declined due to resource unavailability, corresponding to the protocol denoted by 'cufwPolConnProtocol', in the policy 'cufwPolConnPolicy' applied to the entity identified by 'cufwPolConnPolicyTarget'.

What is cufwPolConnNumResDeclined?

This Counter64 counts, for the same protocol/policy/target scope (cufwPolConnProtocol, cufwPolConnPolicy, cufwPolConnPolicyTarget), connection attempts declined due to resource unavailability rather than policy. This distinguishes capacity problems from deliberate blocking for a specific policy-target pairing, which matters when deciding whether to adjust a rule or add capacity. A rising count here for a policy applied to a heavily-used target would point an admin toward resource exhaustion under that policy rather than a security decision.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.8
snmpwalk -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumResDeclined

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.9.9.491.1.1.4.3.1.8.1
snmpget -v2c -c public <target> CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumResDeclined.1

Start monitoring Cisco ASA firewalls / IOS zone-based firewall devices with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCO-UNIFIED-FIREWALL-MIB::cufwPolConnNumResDeclined OID value, configure state conditions and alerts, and monitor any Cisco ASA firewalls / IOS zone-based firewall devices from a single console.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.9ciscoCAT2600-MIB
1.3.6.1.4.1.9.9ciscoMgmtCISCO-SMI
Numeric OIDNameModule
1.3.6.1.4.1.9.9.491ciscoUnifiedFirewallMIBCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1ciscoUnifiedFirewallMIBObjectsCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1cuFwConnectionGrpCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4cuFwConnectionSummaryTablesCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3cufwPolicyConnSummaryTableCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3.1cufwPolicyConnSummaryEntryCISCO-UNIFIED-FIREWALL-MIB
1.3.6.1.4.1.9.9.491.1.1.4.3.1.8cufwPolConnNumResDeclinedCISCO-UNIFIED-FIREWALL-MIB