<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM drop packets after change from single to multi context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660887#M1037323</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'show interface' commands in a context shows packets dropped by policy (access list, implied drops, broadcast packet drops) - not packets dropped because of interface errors.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to see the interface errors, you have to change to the system context using a 'ch  con system' and do a 'show interface' there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it helped solve some or all of your issue/question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Dec 2006 02:59:33 GMT</pubDate>
    <dc:creator>jgervia_2</dc:creator>
    <dc:date>2006-12-07T02:59:33Z</dc:date>
    <item>
      <title>FWSM drop packets after change from single to multi context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660886#M1037321</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few days ago I changed the mode of our FWSM 3.1 from single mode to multicontext. I created one context, made it admin, and configured it with the same config as the FWSM had as a single mode. Everything seems to work fine, packets are forwarded as before through the interfaces&lt;/P&gt;&lt;P&gt;The problem is that after the mode change the context in use is reporting a large amount of dropped packets on all interfaces.&lt;/P&gt;&lt;P&gt;Example:  Traffic Statistics for "INTERNET":&lt;/P&gt;&lt;P&gt;       364 packets input, 51877 bytes&lt;/P&gt;&lt;P&gt;       279 packets output, 327922 bytes&lt;/P&gt;&lt;P&gt;       150 packets dropped&lt;/P&gt;&lt;P&gt;Nothing out of the ordinary is shown in any logs and all pings to and from the different interfaces are 100%.&lt;/P&gt;&lt;P&gt;Is this part of the multicontext/classifier process or is this a sign of an error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Fredrik Hofgren&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660886#M1037321</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2019-03-11T09:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM drop packets after change from single to multi context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660887#M1037323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'show interface' commands in a context shows packets dropped by policy (access list, implied drops, broadcast packet drops) - not packets dropped because of interface errors.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to see the interface errors, you have to change to the system context using a 'ch  con system' and do a 'show interface' there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it helped solve some or all of your issue/question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2006 02:59:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660887#M1037323</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-12-07T02:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM drop packets after change from single to multi context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660888#M1037325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats interesting. Because my connected vlans and the traffic on them has not changed. We use Solarwinds Orio to monitor our Cisco equipment. If it's true what you say, then the OID that Solarwinds access on the single context FWSM to retrieve dropped packets due to interface errors has changed meaning and in a multicontext FWSM show the number of packets dropped by policy. This render the indicator useless in my perspective, especially since I can't find a way to change the OID in Solarwinds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2006 20:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-drop-packets-after-change-from-single-to-multi-context/m-p/660888#M1037325</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2006-12-07T20:25:04Z</dc:date>
    </item>
  </channel>
</rss>

