<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Packet Dropped problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671197#M1010233</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show ver:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh ver"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.1(1) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Thu 19-Jan-06 15:02 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa711-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HMLXFW up 5 days 4 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   ASA5510, 256 MB RAM, CPU Pentium 4 Celeron 1600 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 64MB&lt;/P&gt;&lt;P&gt;BIOS Flash AT49LW080: @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt; 0: Ext: Ethernet0/0         : address is 0015.c695.d70c, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet0/1         : address is 0015.c695.d70d, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: Ethernet0/2         : address is 0015.c695.d70e, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: Not licensed        : irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0015.c695.d710, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : 4         &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 10        &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Disabled&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 0         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 250       &lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has a Base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: JMX1014K0GK&lt;/P&gt;&lt;P&gt;Running Activation Key: xxx &lt;/P&gt;&lt;P&gt;Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Configuration last modified by Admin at 14:55:46.659 EDT Fri Mar 16 2007&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Mar 2007 07:55:01 GMT</pubDate>
    <dc:creator>michael.orshansky</dc:creator>
    <dc:date>2007-03-18T07:55:01Z</dc:date>
    <item>
      <title>ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671193#M1010229</link>
      <description>&lt;P&gt;Hi, my customer is complaining that every once in a while his browsing gets real slow and he needed a reboot of his ASA to resolve the issue. I cannot find anything wrong with the ASA apart from packet drops indicated here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/0 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 100 Mbps&lt;/P&gt;&lt;P&gt;        Full-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;/P&gt;&lt;P&gt;        MAC address 0015.c695.d70c, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 59.x.x.6, subnet mask 255.255.255.252&lt;/P&gt;&lt;P&gt;        87915 packets input, 58923662 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 0 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 L2 decode drops&lt;/P&gt;&lt;P&gt;        87045 packets output, 44806355 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions&lt;/P&gt;&lt;P&gt;        0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (0/25) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/223) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "outside":&lt;/P&gt;&lt;P&gt;        87915 packets input, 57214791 bytes&lt;/P&gt;&lt;P&gt;        87045 packets output, 43065295 bytes&lt;/P&gt;&lt;P&gt;        4853 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This drop is constant and I cannot find the reason why. I suspect this could be the key to my problem. The setup is LAN-ASA-Carrier CAT3750-Internet We did see previously errors on the carrier switch. Every once in a while the link would become extremely slow and the LED on the 3750 would blink amber, removing and replacing the CAT5 between the ASA and the 3750 would solve the problem until next time. Any ideas? Thanks, Michael.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671193#M1010229</guid>
      <dc:creator>michael.orshansky</dc:creator>
      <dc:date>2019-03-11T09:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671194#M1010230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try the command: "show asp drop"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will tell you why the ASA is dropping packets. One thing to check is MSS Exceeded. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 15:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671194#M1010230</guid>
      <dc:creator>kenfulmer</dc:creator>
      <dc:date>2007-03-16T15:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671195#M1010231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;send me &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)sh asp drop&lt;/P&gt;&lt;P&gt;2)sh run pol&lt;/P&gt;&lt;P&gt;3)sh run | inc url&lt;/P&gt;&lt;P&gt;4)sh ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As if now the above output should be enough to at least start with...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 17:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671195#M1010231</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-16T17:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671196#M1010232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show asp drop:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show asp drop"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;/P&gt;&lt;P&gt;  Invalid tcp length                                        314&lt;/P&gt;&lt;P&gt;  Invalid udp length                                        364&lt;/P&gt;&lt;P&gt;  No valid adjacency                                        498&lt;/P&gt;&lt;P&gt;  No route to host                                          301&lt;/P&gt;&lt;P&gt;  Reverse-path verify failed                              35871&lt;/P&gt;&lt;P&gt;  Flow is denied by access rule                        23629600&lt;/P&gt;&lt;P&gt;  First TCP packet not SYN                               990684&lt;/P&gt;&lt;P&gt;  Bad TCP flags                                          116790&lt;/P&gt;&lt;P&gt;  Bad option length in TCP                                  526&lt;/P&gt;&lt;P&gt;  TCP MSS was too large                                   39790&lt;/P&gt;&lt;P&gt;  TCP Window scale on non-SYN                               602&lt;/P&gt;&lt;P&gt;  Bad TCP SACK ALLOW option                                7642&lt;/P&gt;&lt;P&gt;  TCP Dual open denied                                      217&lt;/P&gt;&lt;P&gt;  TCP data send after FIN                                    16&lt;/P&gt;&lt;P&gt;  TCP failed 3 way handshake                              69239&lt;/P&gt;&lt;P&gt;  TCP RST/FIN out of order                               443766&lt;/P&gt;&lt;P&gt;  TCP SEQ in SYN/SYNACK invalid                             494&lt;/P&gt;&lt;P&gt;  TCP ACK in SYNACK invalid                                   3&lt;/P&gt;&lt;P&gt;  TCP SYNACK on established conn                            482&lt;/P&gt;&lt;P&gt;  TCP packet SEQ past window                             112317&lt;/P&gt;&lt;P&gt;  TCP invalid ACK                                        944724&lt;/P&gt;&lt;P&gt;  TCP packet out of order                                     7&lt;/P&gt;&lt;P&gt;  TCP packet buffer full                                1069976&lt;/P&gt;&lt;P&gt;  TCP RST/SYN in window                                  197135&lt;/P&gt;&lt;P&gt;  TCP DUP and has been ACKed                            4398494&lt;/P&gt;&lt;P&gt;  TCP packet failed PAWS test                            106837&lt;/P&gt;&lt;P&gt;  Early security checks failed                                9&lt;/P&gt;&lt;P&gt;  Slowpath security checks failed                        289357&lt;/P&gt;&lt;P&gt;  ICMP Error Inspect no existing conn                        30&lt;/P&gt;&lt;P&gt;  ICMP Error Inspect different embedded conn             157639&lt;/P&gt;&lt;P&gt;  DNS Inspect invalid packet                                208&lt;/P&gt;&lt;P&gt;  DNS Inspect invalid domain label                       251064&lt;/P&gt;&lt;P&gt;  DNS Inspect packet too long                            123545&lt;/P&gt;&lt;P&gt;  DNS Inspect id not matched                              71052&lt;/P&gt;&lt;P&gt;  Interface is down                                           4&lt;/P&gt;&lt;P&gt;  Invalid ASDP packet received from SSM card               1702&lt;/P&gt;&lt;P&gt;  Service module is down                                    113&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;  NAT failed                                              67792&lt;/P&gt;&lt;P&gt;  NAT reverse path failed                                     6&lt;/P&gt;&lt;P&gt;  Inspection failure                                     330070&lt;/P&gt;&lt;P&gt;  Service module failed                                       6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run pol:&lt;/P&gt;&lt;P&gt;Result of the command: "show run pol"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect pptp &lt;/P&gt;&lt;P&gt;  inspect http &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt; class csc_inside&lt;/P&gt;&lt;P&gt;  csc fail-open&lt;/P&gt;&lt;P&gt; class csc_DMZ&lt;/P&gt;&lt;P&gt;  csc fail-open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show run | i url:&lt;/P&gt;&lt;P&gt;None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 07:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671196#M1010232</guid>
      <dc:creator>michael.orshansky</dc:creator>
      <dc:date>2007-03-18T07:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671197#M1010233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show ver:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh ver"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.1(1) &lt;/P&gt;&lt;P&gt;Device Manager Version 5.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Thu 19-Jan-06 15:02 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa711-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HMLXFW up 5 days 4 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   ASA5510, 256 MB RAM, CPU Pentium 4 Celeron 1600 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 64MB&lt;/P&gt;&lt;P&gt;BIOS Flash AT49LW080: @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt; 0: Ext: Ethernet0/0         : address is 0015.c695.d70c, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet0/1         : address is 0015.c695.d70d, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: Ethernet0/2         : address is 0015.c695.d70e, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: Not licensed        : irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0015.c695.d710, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : 4         &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 10        &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Disabled&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 0         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 250       &lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has a Base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: JMX1014K0GK&lt;/P&gt;&lt;P&gt;Running Activation Key: xxx &lt;/P&gt;&lt;P&gt;Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Configuration last modified by Admin at 14:55:46.659 EDT Fri Mar 16 2007&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 07:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671197#M1010233</guid>
      <dc:creator>michael.orshansky</dc:creator>
      <dc:date>2007-03-18T07:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Packet Dropped problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671198#M1010234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everyone, I eralised what it is, its just shows how many packets are dropped due to access-lists and other security policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 08:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-dropped-problem/m-p/671198#M1010234</guid>
      <dc:creator>michael.orshansky</dc:creator>
      <dc:date>2007-03-18T08:06:36Z</dc:date>
    </item>
  </channel>
</rss>

