<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD issue - connection limit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832984#M1100320</link>
    <description>&lt;P&gt;I already isolated it..ofcourse! But my question sis that does the connection count of 10Million cause future connections to be dropped? How long does the cumulative connection count kept?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2023 06:15:11 GMT</pubDate>
    <dc:creator>S891</dc:creator>
    <dc:date>2023-05-11T06:15:11Z</dc:date>
    <item>
      <title>FTD issue - connection limit</title>
      <link>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832771#M1100312</link>
      <description>&lt;P&gt;I experienced a network downtime due to possible issue with Firepower 4115 and the suspect was high number of connections/ scanning. It caused downtime/ slowness for about 10 minutes and then problem went away automatically.&lt;/P&gt;&lt;P&gt;These are some of the messages in the log aroud the time the issue happened.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%FTD-3-209006: Fragment queue threshold exceeded, dropped UDP fragment&lt;/P&gt;&lt;P&gt;%FTD-4-209005: Discard IP fragment set with more than 24 elements:&lt;/P&gt;&lt;P&gt;%FTD-4-733101: Host 10.60.0.88 is attacking. Current burst rate is 11212 per second, max configured rate is 10; Current average rate is 8489 per second, max configured rate is 5; Cumulative total count is 10244532%&lt;/P&gt;&lt;P&gt;There are fewer logs on the FTD during the time we experienced issue.&lt;/P&gt;&lt;P&gt;It seems like the FTD was under attack as you can see the cumulaive count crossed 10 Million mark.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the cumulative count the actual threshold of 10 Million?&lt;/P&gt;&lt;P&gt;Any idea what could have happened and how to avoid in future?&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 16:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832771#M1100312</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2023-05-10T16:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD issue - connection limit</title>
      <link>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832981#M1100319</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;...&lt;SPAN&gt;%FTD-4-733101: &lt;FONT color="#FF6600"&gt;&lt;EM&gt;Host &lt;STRONG&gt;10.60.0.88&lt;/STRONG&gt; &lt;U&gt;is attacking.&amp;nbsp;&lt;/U&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The particular host address seems local , you could query it's owner and or isolate it on the network ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 06:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832981#M1100319</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-05-11T06:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD issue - connection limit</title>
      <link>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832984#M1100320</link>
      <description>&lt;P&gt;I already isolated it..ofcourse! But my question sis that does the connection count of 10Million cause future connections to be dropped? How long does the cumulative connection count kept?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 06:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-issue-connection-limit/m-p/4832984#M1100320</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2023-05-11T06:15:11Z</dc:date>
    </item>
  </channel>
</rss>

