<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA - High bps In on outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-high-bps-in-on-outside-interface/m-p/2769478#M166741</link>
    <description>&lt;P&gt;A couple of days ago the receiving interface utilization on our ASA's outside interface spiked to over 100 times what's normal. Below are some show commands I ran. I'm not great with firewalls, so any help at all is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show traffic&lt;BR /&gt;inside:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; received (in 157419.900 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 392718 packets &amp;nbsp;79601094 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;14 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; transmitted (in 157419.900 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 218752 packets &amp;nbsp;21963534 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;3 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 2 pkts/sec, &amp;nbsp;240 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;103 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 5 pkts/sec, &amp;nbsp;1137 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 3 pkts/sec, &amp;nbsp;332 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 1 pkts/sec&lt;/P&gt;&lt;P&gt;outside:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; received (in 157419.930 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 204561925 packets &amp;nbsp; &amp;nbsp; &amp;nbsp; 9440820414 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1026 pkts/sec &amp;nbsp; 59017 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; transmitted (in 157419.930 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 278947 packets &amp;nbsp;94372148 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;26 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 732 pkts/sec, &amp;nbsp;33832 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;234 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 319 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 937 pkts/sec, &amp;nbsp;43566 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 4 pkts/sec, &amp;nbsp;1320 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 474 pkts/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show resource usage&lt;BR /&gt;Resource &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Current &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Peak &amp;nbsp; &amp;nbsp; &amp;nbsp;Limit &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Denied Context&lt;BR /&gt;SSH &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Syslogs [rate] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3081 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Conns &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;39 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 67 &amp;nbsp; &amp;nbsp; &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Xlates &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Hosts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show inter out det&lt;BR /&gt;Interface Vlan2 "outside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address c471.fe4a.2062, MTU 1500&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address 74.213.161.150, subnet mask 255.255.255.240&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "outside":&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 203719444 packets input, 9401777193 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 275162 packets output, 93454007 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 119693306 packets dropped&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 716 pkts/sec, &amp;nbsp;33133 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;271 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 302 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 803 pkts/sec, &amp;nbsp;37282 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 3 pkts/sec, &amp;nbsp;1046 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 340 pkts/sec&lt;BR /&gt;&amp;nbsp; Control Point Interface States:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface number is 16&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface config status is active&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface state is active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; Punt rate limit exceeded (punt-rate-limit) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 119827225&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule (acl-drop) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14638&lt;BR /&gt;&amp;nbsp; Invalid SPI (np-sp-invalid-spi) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;180&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 114&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order (tcp-rstfin-ooo) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8&lt;BR /&gt;&amp;nbsp; TCP RST/SYN in window (tcp-rst-syn-in-win) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3&lt;BR /&gt;&amp;nbsp; IPSEC tunnel is down (ipsec-tun-down) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;109&lt;BR /&gt;&amp;nbsp; Slowpath security checks failed (sp-security-failed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 64076&lt;BR /&gt;&amp;nbsp; Interface is down (interface-down) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; Non-IP packet received in routed mode (non-ip-pkt-in-routed-mode) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;BR /&gt;&amp;nbsp; Dropped pending packets in a closed socket (np-socket-closed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 13&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; Need to start IKE negotiation (need-ike) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;56&lt;BR /&gt;&amp;nbsp; Inspection failure (inspect-fail) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3072&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:46:11 GMT</pubDate>
    <dc:creator>esa_fresa</dc:creator>
    <dc:date>2019-03-12T06:46:11Z</dc:date>
    <item>
      <title>ASA - High bps In on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-high-bps-in-on-outside-interface/m-p/2769478#M166741</link>
      <description>&lt;P&gt;A couple of days ago the receiving interface utilization on our ASA's outside interface spiked to over 100 times what's normal. Below are some show commands I ran. I'm not great with firewalls, so any help at all is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show traffic&lt;BR /&gt;inside:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; received (in 157419.900 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 392718 packets &amp;nbsp;79601094 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;14 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; transmitted (in 157419.900 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 218752 packets &amp;nbsp;21963534 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;3 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 2 pkts/sec, &amp;nbsp;240 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;103 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 5 pkts/sec, &amp;nbsp;1137 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 3 pkts/sec, &amp;nbsp;332 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 1 pkts/sec&lt;/P&gt;&lt;P&gt;outside:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; received (in 157419.930 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 204561925 packets &amp;nbsp; &amp;nbsp; &amp;nbsp; 9440820414 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1026 pkts/sec &amp;nbsp; 59017 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; transmitted (in 157419.930 secs):&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 278947 packets &amp;nbsp;94372148 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 pkts/sec &amp;nbsp; &amp;nbsp; &amp;nbsp;26 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 732 pkts/sec, &amp;nbsp;33832 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;234 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 319 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 937 pkts/sec, &amp;nbsp;43566 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 4 pkts/sec, &amp;nbsp;1320 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 474 pkts/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show resource usage&lt;BR /&gt;Resource &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Current &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Peak &amp;nbsp; &amp;nbsp; &amp;nbsp;Limit &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Denied Context&lt;BR /&gt;SSH &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Syslogs [rate] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3081 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Conns &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;39 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 67 &amp;nbsp; &amp;nbsp; &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Xlates &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;BR /&gt;Hosts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 System&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show inter out det&lt;BR /&gt;Interface Vlan2 "outside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address c471.fe4a.2062, MTU 1500&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address 74.213.161.150, subnet mask 255.255.255.240&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "outside":&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 203719444 packets input, 9401777193 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 275162 packets output, 93454007 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 119693306 packets dropped&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute input rate 716 pkts/sec, &amp;nbsp;33133 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute output rate 1 pkts/sec, &amp;nbsp;271 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 minute drop rate, 302 pkts/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute input rate 803 pkts/sec, &amp;nbsp;37282 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute output rate 3 pkts/sec, &amp;nbsp;1046 bytes/sec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 minute drop rate, 340 pkts/sec&lt;BR /&gt;&amp;nbsp; Control Point Interface States:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface number is 16&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface config status is active&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface state is active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# show asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; Punt rate limit exceeded (punt-rate-limit) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 119827225&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule (acl-drop) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14638&lt;BR /&gt;&amp;nbsp; Invalid SPI (np-sp-invalid-spi) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;180&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 114&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order (tcp-rstfin-ooo) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8&lt;BR /&gt;&amp;nbsp; TCP RST/SYN in window (tcp-rst-syn-in-win) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3&lt;BR /&gt;&amp;nbsp; IPSEC tunnel is down (ipsec-tun-down) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;109&lt;BR /&gt;&amp;nbsp; Slowpath security checks failed (sp-security-failed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 64076&lt;BR /&gt;&amp;nbsp; Interface is down (interface-down) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; Non-IP packet received in routed mode (non-ip-pkt-in-routed-mode) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;BR /&gt;&amp;nbsp; Dropped pending packets in a closed socket (np-socket-closed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 13&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; Need to start IKE negotiation (need-ike) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;56&lt;BR /&gt;&amp;nbsp; Inspection failure (inspect-fail) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3072&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-high-bps-in-on-outside-interface/m-p/2769478#M166741</guid>
      <dc:creator>esa_fresa</dc:creator>
      <dc:date>2019-03-12T06:46:11Z</dc:date>
    </item>
    <item>
      <title>Hello, You can use enable</title>
      <link>https://community.cisco.com/t5/network-security/asa-high-bps-in-on-outside-interface/m-p/2769479#M166742</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use enable threat detection from ASDM and enable top 10 source/destinations, this will provide you IP addresses that are sending most of the traffic through the ASA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/asdm64/configuration_guide/asdm_64_config/protect_threat.html#wp1104293&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it will be good to see the stats for outside physical interface, if it's an ASA5505 you can do "show interface fa&amp;nbsp;0/0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe check any new traffic that could be passing through the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Harvey&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2015 23:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-high-bps-in-on-outside-interface/m-p/2769479#M166742</guid>
      <dc:creator>Harvey</dc:creator>
      <dc:date>2015-10-24T23:36:35Z</dc:date>
    </item>
  </channel>
</rss>

