<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312415#M1121948</link>
    <description>&lt;P&gt;Show run nat &amp;lt;&amp;lt;- in both fw check hit count is same&lt;/P&gt;
&lt;P&gt;Show xlate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if NAT is sync from active to standby' if not sync and traffic hit FW the traffic will drop&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jul 2025 14:36:39 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-07-22T14:36:39Z</dc:date>
    <item>
      <title>FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped conn</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311976#M1121926</link>
      <description>&lt;P&gt;Good afternoon&lt;/P&gt;&lt;P&gt;We downgraded our FTD's from 7.6.0 to 7.4.2.2 - due to instability, bugs and snort 3 issues. We factory reset the FTD's and rebuild it successfully. Configuration is the same as before. FMC is stable.&lt;/P&gt;&lt;P&gt;FTD1 - we receive the following warning : ASP drop - missing existing xlate for PAT pool mapped connection intermittently.&lt;BR /&gt;FTD2 - no problem at all and is in healthy state.&lt;/P&gt;&lt;P&gt;Configurations on the failover are the same and the same before the rebuild. No changes&lt;BR /&gt;&lt;BR /&gt;Has anyone else run into this scenario where you would receive the ASP drop warning intermittently.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 17:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311976#M1121926</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-21T17:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311979#M1121927</link>
      <description>&lt;P&gt;hello.&amp;nbsp;&lt;SPAN&gt;That "ASP drop - missing xlate" warning usually means NAT state mismatches after major changes like ur downgrade. Since only FTD1 shows this despite identical configs, i would try some steps:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. first force a full HA resync with the : &lt;STRONG&gt;#conf high-availability failover reset&lt;/STRONG&gt; and after that check Nat tables..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Re=apply Nat rules manually in case Snort 3 leftovers linger: the command is : &lt;STRONG&gt;conf policy-engine and policy-apply&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3. also u have some known 7.4.2.2 Pat bugs like the well known CSCwd12345, which may need workarounds (let me know if u want the commands for that G..)&lt;/P&gt;&lt;P&gt;And if DROPS continue: Go ahead and capture traffic drops, and compare Nat stats..&lt;/P&gt;&lt;P&gt;also check these links G:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2023/pdf/BRKSEC-2102.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2023/pdf/BRKSEC-2102.pdf&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://rayka-co.com/lesson/cisco-ftd-nat-configuration/" target="_blank"&gt;https://rayka-co.com/lesson/cisco-ftd-nat-configuration/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://networkinterview.com/cisco-ftd-packet-flow-troubleshooting/" target="_blank"&gt;https://networkinterview.com/cisco-ftd-packet-flow-troubleshooting/&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EnesSimnica_0-1753120424723.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248751i7D90062284BC7878/image-size/medium?v=v2&amp;amp;px=400" role="button" title="EnesSimnica_0-1753120424723.png" alt="EnesSimnica_0-1753120424723.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Enes&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 17:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311979#M1121927</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-07-21T17:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311981#M1121928</link>
      <description>&lt;P&gt;also check these:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/show_asp_drop_command_usage/show-asp-drop-command-usage.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/show_asp_drop_command_usage/show-asp-drop-command-usage.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/216745-troubleshoot-firepower-threat-defense-f.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/216745-troubleshoot-firepower-threat-defense-f.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;pat config:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html#toc-hId--1367832884" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html#toc-hId--1367832884&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 17:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311981#M1121928</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-07-21T17:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311984#M1121930</link>
      <description>&lt;P&gt;Are you use FW HA?&lt;/P&gt;
&lt;P&gt;Is HA healthy?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311984#M1121930</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-21T18:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311987#M1121931</link>
      <description>&lt;P&gt;Yes FW is HA and HA is healthy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311987#M1121931</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-21T18:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311989#M1121932</link>
      <description>Yes FW's are HA and yes HA is healthy&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311989#M1121932</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-21T18:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311991#M1121933</link>
      <description>&lt;P&gt;ASP Drop warning message is intermittent - throughout the day - sometimes I will have no warnings for a couple of hours and then it pops back up&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311991#M1121933</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-21T18:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311995#M1121934</link>
      <description>&lt;PRE style="margin-top: 10px; margin-bottom: 10px; padding: 0px 0px 5px; font-variant-numeric: inherit; font-variant-east-asian: inherit; font-variant-alternates: inherit; font-variant-position: inherit; font-variant-emoji: inherit; font-stretch: inherit; font-size: 14px; line-height: inherit; font-family: courier; font-optical-sizing: inherit; font-size-adjust: inherit; font-kerning: inherit; font-feature-settings: inherit; font-variation-settings: inherit; vertical-align: baseline; text-wrap-mode: wrap; max-width: 97%; color: #58585b; background-color: #ffffff; border: 0px initial initial;"&gt;&amp;gt; &lt;SPAN&gt;show failover history&lt;BR /&gt;&lt;BR /&gt;Check history' do you see any issue??&lt;BR /&gt;MHM&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311995#M1121934</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-21T18:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311996#M1121935</link>
      <description>&lt;P&gt;I did check that and everything is normal&amp;nbsp; - no errors&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311996#M1121935</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-21T18:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311999#M1121936</link>
      <description>&lt;P&gt;Any change of FW role from active to standby?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5311999#M1121936</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-21T18:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312398#M1121947</link>
      <description>&lt;P&gt;No same behavior - whatever one is active has the intermittent warning - standby is in good stand&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 13:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312398#M1121947</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-22T13:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312415#M1121948</link>
      <description>&lt;P&gt;Show run nat &amp;lt;&amp;lt;- in both fw check hit count is same&lt;/P&gt;
&lt;P&gt;Show xlate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if NAT is sync from active to standby' if not sync and traffic hit FW the traffic will drop&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312415#M1121948</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-22T14:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312903#M1121960</link>
      <description>&lt;P&gt;active&lt;BR /&gt;&amp;nbsp;show xlate count&lt;BR /&gt;25950 in use, 26317 most used&lt;BR /&gt;&amp;gt; show conn count&lt;BR /&gt;26429 in use, 26940 most used&lt;BR /&gt;&lt;SPAN&gt;Inspect Snort:&lt;/SPAN&gt;preserve-connection: 25807 enabled, 0 in effect, 36570 most enabled, 0 most in effect&lt;BR /&gt;&lt;BR /&gt;standby&lt;BR /&gt;&amp;gt; show xlate count&lt;BR /&gt;25780 in use, 27607 most used&lt;BR /&gt;&amp;gt; show conn count&lt;BR /&gt;26150 in use, 42707 most used&lt;BR /&gt;Inspect Snort&lt;BR /&gt;&amp;nbsp;preserve-connection: 25629 enabled, 0 in effect, 27505 most enabled, 0 most in effect&lt;BR /&gt;&lt;BR /&gt;show failover&amp;nbsp;&lt;BR /&gt;active : show failover--&amp;gt;&amp;nbsp; interface is up, xmit&amp;nbsp; 155001 / rcv 0 / err 989&lt;BR /&gt;TCP conn rcv err 988 / UPD conn rcv err 1&lt;BR /&gt;standby : show failover __&amp;gt; interface is up, xmit 74636 / rcv 10 / err 0&lt;BR /&gt;TCP conn, UDP conn, ARP table all receiving values&lt;BR /&gt;No rcv erro (0)&lt;BR /&gt;&lt;BR /&gt;Standby replication is clean&lt;BR /&gt;Active is still showing 989 replication errors for stateful objects (most likely connection table) after I did a "clear failover statistics"&lt;BR /&gt;The errors are in connection replication, does not appear to be NAT. NAT is in sync&lt;BR /&gt;&lt;BR /&gt;Checked for failover link health&lt;BR /&gt;Active - see 525 packets dropped&amp;nbsp; --- this is not normal for a stateful failover link and lines up with the 989 replication errors I saw&lt;BR /&gt;Standby - see 0 packets dropped&lt;BR /&gt;when I did a "show asp drop frame" is saw the following :&lt;BR /&gt;dropped by standby-unit (fo-standby) 2717293. The packets hit the standby but were dropped because its not active or it didnt have valid state info. This lines up wit the replication errors and failover link drops I saw.&lt;BR /&gt;&lt;BR /&gt;thank you for pointing me in the right direction&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312903#M1121960</guid>
      <dc:creator>BACANEL</dc:creator>
      <dc:date>2025-07-23T14:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Vers 7.4.2.2 ASP Drop Missing existing xlate pat pool mapped c</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312920#M1121961</link>
      <description>&lt;P&gt;As I suspect&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show failover state &amp;lt;&amp;lt;- check if there is error&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Capture traffic in failover link' see if hello is send/receive in same period&lt;/P&gt;
&lt;P&gt;Check failover interface is there is any collision or drop&lt;/P&gt;
&lt;P&gt;The conn is not little close between two FW and there is error&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So something wrong with HA.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vers-7-4-2-2-asp-drop-missing-existing-xlate-pat-pool-mapped/m-p/5312920#M1121961</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-23T14:19:05Z</dc:date>
    </item>
  </channel>
</rss>

