<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA packet drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733319#M1020753</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I have an ASA 5520 running version 8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed in a sho int, that packets are being dropped on an interfaces and there are overruns.&lt;/P&gt;&lt;P&gt;I have checked the sho int again after a period of time and the overruns are not increasig but the packet drops are.&lt;/P&gt;&lt;P&gt;There are no CRC's or collisons errors.( I have included the sho int below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is are the packet drops due to denied packets or something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/2 "X", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;/P&gt;&lt;P&gt;        Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;/P&gt;&lt;P&gt;        Description: LOCAL LAN&lt;/P&gt;&lt;P&gt;        MAC address 0018.73d7.0f06, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address x.x.x.x subnet mask x.x.x.x&lt;/P&gt;&lt;P&gt;        425900047 packets input, 175660341830 bytes, 16 no buffer&lt;/P&gt;&lt;P&gt;        Received 113 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 715396 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 L2 decode drops&lt;/P&gt;&lt;P&gt;        331813766 packets output, 122952124630 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 input reset drops, 0 output reset drops&lt;/P&gt;&lt;P&gt;        input queue (curr/max packets): hardware (1/33) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max packets): hardware (0/75) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Longford-LAN":&lt;/P&gt;&lt;P&gt;        425891541 packets input, 167577995460 bytes&lt;/P&gt;&lt;P&gt;        331813766 packets output, 116281711092 bytes&lt;/P&gt;&lt;P&gt;        308924 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 606 pkts/sec,  43234 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 526 pkts/sec,  128487 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 0 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 609 pkts/sec,  51994 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 521 pkts/sec,  111727 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 0 pkts/sec&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:02:13 GMT</pubDate>
    <dc:creator>johnroche_2</dc:creator>
    <dc:date>2019-03-11T11:02:13Z</dc:date>
    <item>
      <title>ASA packet drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733319#M1020753</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I have an ASA 5520 running version 8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed in a sho int, that packets are being dropped on an interfaces and there are overruns.&lt;/P&gt;&lt;P&gt;I have checked the sho int again after a period of time and the overruns are not increasig but the packet drops are.&lt;/P&gt;&lt;P&gt;There are no CRC's or collisons errors.( I have included the sho int below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is are the packet drops due to denied packets or something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/2 "X", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;/P&gt;&lt;P&gt;        Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;/P&gt;&lt;P&gt;        Description: LOCAL LAN&lt;/P&gt;&lt;P&gt;        MAC address 0018.73d7.0f06, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address x.x.x.x subnet mask x.x.x.x&lt;/P&gt;&lt;P&gt;        425900047 packets input, 175660341830 bytes, 16 no buffer&lt;/P&gt;&lt;P&gt;        Received 113 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 715396 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 L2 decode drops&lt;/P&gt;&lt;P&gt;        331813766 packets output, 122952124630 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 input reset drops, 0 output reset drops&lt;/P&gt;&lt;P&gt;        input queue (curr/max packets): hardware (1/33) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max packets): hardware (0/75) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Longford-LAN":&lt;/P&gt;&lt;P&gt;        425891541 packets input, 167577995460 bytes&lt;/P&gt;&lt;P&gt;        331813766 packets output, 116281711092 bytes&lt;/P&gt;&lt;P&gt;        308924 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 606 pkts/sec,  43234 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 526 pkts/sec,  128487 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 0 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 609 pkts/sec,  51994 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 521 pkts/sec,  111727 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 0 pkts/sec&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733319#M1020753</guid>
      <dc:creator>johnroche_2</dc:creator>
      <dc:date>2019-03-11T11:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA packet drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733320#M1020754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See if the "show asp drop" command gives you any useful output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s2_72.html#wp1174636" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s2_72.html#wp1174636&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 11:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733320#M1020754</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-08-24T11:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA packet drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733321#M1020755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;/P&gt;&lt;P&gt;  Invalid IP header                                           1&lt;/P&gt;&lt;P&gt;  No valid adjacency                                        231&lt;/P&gt;&lt;P&gt;  No route to host                                           34&lt;/P&gt;&lt;P&gt;  Flow is denied by configured rule                       76107&lt;/P&gt;&lt;P&gt;  First TCP packet not SYN                                62169&lt;/P&gt;&lt;P&gt;  Bad option length in TCP                                  137&lt;/P&gt;&lt;P&gt;  TCP data exceeded MSS                                     132&lt;/P&gt;&lt;P&gt;  TCP failed 3 way handshake                              53062&lt;/P&gt;&lt;P&gt;  TCP RST/FIN out of order                                    3&lt;/P&gt;&lt;P&gt;  TCP packet SEQ past window                              13128&lt;/P&gt;&lt;P&gt;  TCP RST/SYN in window                                      11&lt;/P&gt;&lt;P&gt;  TCP DUP and has been ACKed                             246414&lt;/P&gt;&lt;P&gt;  IPSEC Spoof detected                                        2&lt;/P&gt;&lt;P&gt;  IPSEC tunnel is down                                   580274&lt;/P&gt;&lt;P&gt;  ICMP Inspect seq num not matched                           65&lt;/P&gt;&lt;P&gt;  DNS Inspect id not matched                                  6&lt;/P&gt;&lt;P&gt;  FP L2 rule drop                                        400047&lt;/P&gt;&lt;P&gt;  Interface is down                                         891&lt;/P&gt;&lt;P&gt;  Dropped pending packets in a closed socket               9227&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;  NAT failed                                              35014&lt;/P&gt;&lt;P&gt;  NAT reverse path failed                                     6&lt;/P&gt;&lt;P&gt;  Need to start IKE negotiation                            1340&lt;/P&gt;&lt;P&gt;  Inspection failure                                         62&lt;/P&gt;&lt;P&gt;  SSL received close alert                                    8&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 12:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733321#M1020755</guid>
      <dc:creator>johnroche_2</dc:creator>
      <dc:date>2007-08-24T12:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA packet drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733322#M1020756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noticed there was a lot of packets dropped for IPSEC tunnel down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSEC tunnel is down 580274&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the Syslog and the firewall was set to 86400 secs but the responder was setting 3600 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the SA on the far side and havent seen any drops "yet" for IPSEC tunnel down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2007 14:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-drops/m-p/733322#M1020756</guid>
      <dc:creator>johnroche_2</dc:creator>
      <dc:date>2007-08-24T14:00:56Z</dc:date>
    </item>
  </channel>
</rss>

