<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting packet drop in ASP-drop in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699330#M1094028</link>
    <description>&lt;P&gt;Using the website ip address.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 15:38:44 GMT</pubDate>
    <dc:creator>Chandresh</dc:creator>
    <dc:date>2022-10-06T15:38:44Z</dc:date>
    <item>
      <title>Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699180#M1094010</link>
      <description>&lt;P&gt;I am seeing asp packet drop on FTD in my captured logs for one of the website which user is trying to access on https. It is a intermittent issue where couple of time website is not opening or opening slow.&lt;/P&gt;&lt;P&gt;1: 23:07:25.774770 802.1Q vlan#2926 P0 14X.XX.XX.XX:443 &amp;gt; 10X.XX.XX.XX:59411: . ack 2225558804 win 24567 Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x000055656c83116f flow (NA)/NA&lt;/P&gt;&lt;P&gt;Note: On firewall rule is allowed and packet tracer also hitting the correct rule.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 11:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699180#M1094010</guid>
      <dc:creator>Chandresh</dc:creator>
      <dc:date>2022-10-06T11:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699205#M1094011</link>
      <description>&lt;P&gt;can you share the packet tracer&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 12:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699205#M1094011</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-10-06T12:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699220#M1094013</link>
      <description>&lt;P&gt;Are you using the website IP address or the FQDN on the access list?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 12:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699220#M1094013</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-06T12:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699330#M1094028</link>
      <description>&lt;P&gt;Using the website ip address.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 15:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699330#M1094028</guid>
      <dc:creator>Chandresh</dc:creator>
      <dc:date>2022-10-06T15:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699332#M1094030</link>
      <description>&lt;P&gt;Like i said earlier there is no issue in the packet tracer output.As it is everytime showing showing allowed and taking the expected rule.&lt;/P&gt;&lt;P&gt;The problem here is the intermittent issue and very difficult to catch exactly.Out of 10 times i would say 7 or 8times we are able to access the website ip address without any issue but couple of times it is getting loaded slowly or failed to load.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 15:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4699332#M1094030</guid>
      <dc:creator>Chandresh</dc:creator>
      <dc:date>2022-10-06T15:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Getting packet drop in ASP-drop</title>
      <link>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4700386#M1094075</link>
      <description>&lt;P&gt;Not sure what would cause this issue in this case. Another thought I have could be related to the rules if they are using the app IDs instead of the service ports?! sometimes when using the app IDs the firewall needs to see more traffic before it can understand what app ID is inside the payload, that could potentially cause some temp drops.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 09:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-packet-drop-in-asp-drop/m-p/4700386#M1094075</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-10-09T09:42:01Z</dc:date>
    </item>
  </channel>
</rss>

