<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If this is related to the bug in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861063#M154798</link>
    <description>&lt;P&gt;If this is related to the bug then an upgrade is the only solution.&lt;/P&gt;
&lt;P&gt;drop explanation from Cisco doc &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html&lt;/A&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Name: tcp-fo-drop
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435594"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;TCP replicated flow pak drop:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435595"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    This counter is incremented and the packet is dropped when appliance receives a TCP 
packet with control flag like SYN, FIN or RST on an established connection just after the 
appliance has taken over as active unit.
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435596"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435597"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Recommendations:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435598"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    None
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435599"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435600"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Syslogs:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435601"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    None&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2016 17:28:10 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2016-04-21T17:28:10Z</dc:date>
    <item>
      <title>Packets drops due to tcp-fo-drop</title>
      <link>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861061#M154796</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have problems with cisco ASA using 8.3(1) Software Version, the symptoms indicates to this bug&amp;nbsp;CSCsg09419 but with different version of OS. below is output from show asp drop command :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;7: 10:44:13.240176 x.x.x.x.4427 &amp;gt; 1x.x.x.x.449: S 3127442769:3127442769(0) win 65535 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt; Drop-reason: (tcp-fo-drop) TCP replicated flow pak drop&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 53: 10:44:40.383921 x.x.x.x.4517 &amp;gt; x.x.x.x.449: S 4030465714:4030465714(0) win 65535 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt; &lt;BR /&gt;&amp;nbsp; 71: 10:44:46.315901 x.x.x.x.4517 &amp;gt; x.x.x.x.449: S 4030465714:4030465714(0) win 65535 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt; &lt;BR /&gt;&amp;nbsp;194: 10:45:37.507938 x.x.x.x.22570 &amp;gt; x.x.x.x.449: S 4274859623:4274859623(0) win 64240 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any suggestion about this problems?&lt;/P&gt;
&lt;P&gt;i need help soon as possible...thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Fahmi&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861061#M154796</guid>
      <dc:creator>nur fahmi hamdika</dc:creator>
      <dc:date>2019-03-12T07:37:40Z</dc:date>
    </item>
    <item>
      <title>8.3(1) is getting pretty old.</title>
      <link>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861062#M154797</link>
      <description>&lt;P&gt;8.3(1) is getting pretty old. &amp;nbsp;Are you able to upgrade?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 09:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861062#M154797</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-04-21T09:19:05Z</dc:date>
    </item>
    <item>
      <title>If this is related to the bug</title>
      <link>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861063#M154798</link>
      <description>&lt;P&gt;If this is related to the bug then an upgrade is the only solution.&lt;/P&gt;
&lt;P&gt;drop explanation from Cisco doc &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html&lt;/A&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Name: tcp-fo-drop
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435594"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;TCP replicated flow pak drop:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435595"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    This counter is incremented and the packet is dropped when appliance receives a TCP 
packet with control flag like SYN, FIN or RST on an established connection just after the 
appliance has taken over as active unit.
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435596"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435597"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Recommendations:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435598"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    None
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435599"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435600"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;Syslogs:
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A name="wp1435601"&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE class="prettyprint"&gt;    None&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 17:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861063#M154798</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-04-21T17:28:10Z</dc:date>
    </item>
    <item>
      <title>Hi marius,</title>
      <link>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861064#M154799</link>
      <description>&lt;P&gt;Hi marius,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;The issue is resolved by clearing the connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;found that the timeout is 00:00:00 which is unreasonable value so we changed it to the recommended (1:00:00)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;also we've plan to upgrade the software...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;rgds&lt;/P&gt;
&lt;P&gt;NFH&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 05:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packets-drops-due-to-tcp-fo-drop/m-p/2861064#M154799</guid>
      <dc:creator>nur fahmi hamdika</dc:creator>
      <dc:date>2016-05-04T05:26:58Z</dc:date>
    </item>
  </channel>
</rss>

