<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You aren't running out of NIC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810304#M173897</link>
    <description>&lt;P&gt;You aren't running out of NIC buffers (like the problem I had).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see your voice vlan has dropped quite a few packets (&lt;SPAN&gt;27944 packets dropped).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm not convinced you have an actual problem. &amp;nbsp;Is there any problem observable by the users?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you watch the log in ASDM does it mention anything about dropping packets?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Dec 2015 03:21:03 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2015-12-21T03:21:03Z</dc:date>
    <item>
      <title>Cisco ASA Inside Interface Packet Loss</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810300#M173893</link>
      <description>&lt;P&gt;Hey everyone. I have an ASA firewall connected at a site and I'm noticing a lot of packet loss on the inside interface. The duplex and speed are set to auto, so they've negotiated to 100/Full. But even with that I still see heavy packet loss. I'm not too sure what to look at that would cause such a high loss. Any thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810300#M173893</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2019-03-12T07:03:23Z</dc:date>
    </item>
    <item>
      <title>I have had an issue like this</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810301#M173894</link>
      <description>&lt;P&gt;I have had an issue like this happen before where the interface buffers simply ran out - packets came in faster than the ASA could process and forward them.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I ended up using a Gigabit connection so that I could enable Gigabit pause frames (needs the device that the ASA plugs into to also support pause frames).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible that the some of the traffic on other interfaces is greater than 100Mb/s? &amp;nbsp;Perhaps more load is being generated than a single 100Mb/s link can handle.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does the 100Mb/s interface perhaps have lots of VLANs on it? &amp;nbsp;If so, could you use an additional interface and move some of the VLANs off to it? &amp;nbsp;Extra interfaces means extra interface buffers.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 09:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810301#M173894</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-20T09:13:36Z</dc:date>
    </item>
    <item>
      <title>Can you paste the "show</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810302#M173895</link>
      <description>&lt;P&gt;Can you paste the "show interface" output? &amp;nbsp;Exactly which type of packet loss is happening? &amp;nbsp;Is it intermittent or happening all the time?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 09:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810302#M173895</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-20T09:14:41Z</dc:date>
    </item>
    <item>
      <title>Below is a copy of my show</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810303#M173896</link>
      <description>&lt;P&gt;Below is a copy of my show interface on my ASA. To add some detail:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;The ASA is GB but it is going to a 10/100 fast ethernet port on the switch.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;The inside interface does have multiple VLANs on it currently. Only 3 are in use at the moment, the inside, partner1, and guest-wifi. The inside and guest-wifi are the more heavily used interfaces if anything. The others haven't been put in to production just yet.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Could I possibly need to go GB to GB from ASA to switch?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;show int&lt;BR /&gt;Interface GigabitEthernet0/0 "outside", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Full-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; Description: Internet-Fiber&lt;BR /&gt; MAC address 84b8.F01E.4fc2, MTU 1500&lt;BR /&gt; IP address COMPANY--ASA, subnet mask 255.255.255.248&lt;BR /&gt; 3926664 packets input, 2535791275 bytes, 0 no buffer&lt;BR /&gt; Received 2363 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 3846526 packets output, 2158300376 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (481/451)&lt;BR /&gt; output queue (blocks free curr/low): hardware (451/420)&lt;BR /&gt; Traffic Statistics for "outside":&lt;BR /&gt; 3937625 packets input, 2465246863 bytes&lt;BR /&gt; 3846526 packets output, 2088302023 bytes&lt;BR /&gt; 1236 packets dropped&lt;BR /&gt; 1 minute input rate 34 pkts/sec, 20527 bytes/sec&lt;BR /&gt; 1 minute output rate 35 pkts/sec, 18336 bytes/sec&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt; &lt;BR /&gt; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt; 5 minute input rate 32 pkts/sec, 19047 bytes/sec&lt;BR /&gt; 5 minute output rate 32 pkts/sec, 17178 bytes/sec&lt;BR /&gt; 5 minute drop rate, 0 pkts/sec&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;Interface GigabitEthernet0/5 "", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 3830871 packets input, 2052901389 bytes, 0 no buffer&lt;BR /&gt; Received 53903 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 3687298 packets output, 2301695984 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 3 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt; &lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (508/456)&lt;BR /&gt; output queue (blocks free curr/low): hardware (493/438)&lt;BR /&gt;Interface GigabitEthernet0/5.10 "voice", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 10&lt;BR /&gt; Description: **-Voice-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt; IP address COMPANY--Voice-Gateway, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "voice":&lt;BR /&gt; 2717070 packets input, 1511158732 bytes&lt;BR /&gt; 2509155 packets output, 1484089001 bytes&lt;BR /&gt; 204284 packets dropped&lt;BR /&gt;Interface GigabitEthernet0/5.20 "inside", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 20&lt;BR /&gt; Description: **COMPANY-End-User-Data-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt; IP address 10.100.20.1, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "inside":&lt;BR /&gt; 1102620 packets input, 454243555 bytes&lt;BR /&gt; 1164140 packets output, 719318151 bytes&lt;BR /&gt; 27944 packets dropped&lt;BR /&gt;Interface GigabitEthernet0/5.30 "PARTNER1", is up, line protocol is up&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt; &lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 30&lt;BR /&gt; Description: **PARTNER1-Data-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt; IP address 10.100.30.1, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "PARTNER1":&lt;BR /&gt; 4608 packets input, 949674 bytes&lt;BR /&gt; 1 packets output, 28 bytes&lt;BR /&gt; 4608 packets dropped&lt;BR /&gt;Interface GigabitEthernet0/5.40 "PARTNER2", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 40&lt;BR /&gt; Description: **PARTNER2-Data-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt; IP address 10.100.40.1, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "PARTNER2":&lt;BR /&gt; 0 packets input, 0 bytes&lt;BR /&gt; 1 packets output, 28 bytes&lt;BR /&gt; 0 packets dropped&lt;BR /&gt;Interface GigabitEthernet0/5.50 "general", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 50&lt;BR /&gt; Description: **General-Data-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt; &lt;BR /&gt; IP address 10.100.50.1, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "general":&lt;BR /&gt; 0 packets input, 0 bytes&lt;BR /&gt; 1 packets output, 28 bytes&lt;BR /&gt; 0 packets dropped&lt;BR /&gt;Interface GigabitEthernet0/5.60 "guest-wifi", is up, line protocol is up&lt;BR /&gt; Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier 60&lt;BR /&gt; Description: **Guest-Wireless-Data-VLAN**&lt;BR /&gt; MAC address 84b8.F01E.4fc1, MTU 1500&lt;BR /&gt; IP address 10.100.60.1, subnet mask 255.255.255.0&lt;BR /&gt; Traffic Statistics for "guest-wifi":&lt;BR /&gt; 6563 packets input, 675344 bytes&lt;BR /&gt; 14023 packets output, 15925180 bytes&lt;BR /&gt; 60 packets dropped&lt;BR /&gt;Interface Management0/0 "management", is down, line protocol is down&lt;BR /&gt; Hardware is en_vtun rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Auto-Duplex, Auto-Speed&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; MAC address 84b8.F01E.4fbe, MTU 1500&lt;BR /&gt; IP address 192.168.1.1, subnet mask 255.255.255.0&lt;BR /&gt; 29742 packets input, 1249164 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt; &lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 1 packets output, 42 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt; output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt; Traffic Statistics for "management":&lt;BR /&gt; 0 packets input, 0 bytes&lt;BR /&gt; 1 packets output, 28 bytes&lt;BR /&gt; 0 packets dropped&lt;BR /&gt; 1 minute input rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt; 1 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt; 5 minute input rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt; 5 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt; 5 minute drop rate, 0 pkts/sec&lt;BR /&gt; Management-only interface. Blocked 0 through-the-device packets&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 16:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810303#M173896</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2015-12-20T16:52:13Z</dc:date>
    </item>
    <item>
      <title>You aren't running out of NIC</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810304#M173897</link>
      <description>&lt;P&gt;You aren't running out of NIC buffers (like the problem I had).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see your voice vlan has dropped quite a few packets (&lt;SPAN&gt;27944 packets dropped).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm not convinced you have an actual problem. &amp;nbsp;Is there any problem observable by the users?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you watch the log in ASDM does it mention anything about dropping packets?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 03:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810304#M173897</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-21T03:21:03Z</dc:date>
    </item>
    <item>
      <title>Well this particular site</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810305#M173898</link>
      <description>&lt;P&gt;Well this particular site happens to be having internet speed issues, so this was something I was looking at as a possible cause. My network monitoring is not alerting high packet loss though so this may be normal.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I do however have another ASA that is alerting high packet loss and shows a similar result in the output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 14:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810305#M173898</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2015-12-21T14:11:55Z</dc:date>
    </item>
    <item>
      <title>Try using the "show asp drop"</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810306#M173899</link>
      <description>&lt;P&gt;Try using the "show asp drop" command to get more detailed reasons as to why the interface is showing so many drops. &amp;nbsp;It should give a big hint.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 18:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810306#M173899</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-21T18:54:31Z</dc:date>
    </item>
    <item>
      <title>Here's the results.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810307#M173900</link>
      <description>&lt;P&gt;Here's the results.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Frame drop:&lt;BR /&gt; IPSEC tunnel is down (ipsec-tun-down) 74&lt;BR /&gt; SVC Module does not have a session (mp-svc-no-session) 3&lt;BR /&gt; Invalid encapsulation (invalid-encap) 377&lt;BR /&gt; No valid adjacency (no-adjacency) 18&lt;BR /&gt; No route to host (no-route) 613&lt;BR /&gt; Flow is denied by configured rule (acl-drop) 256104&lt;BR /&gt; First TCP packet not SYN (tcp-not-syn) 4152&lt;BR /&gt; Bad TCP flags (bad-tcp-flags) 31&lt;BR /&gt; TCP failed 3 way handshake (tcp-3whs-failed) 164&lt;BR /&gt; TCP RST/FIN out of order (tcp-rstfin-ooo) 3127&lt;BR /&gt; TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 15&lt;BR /&gt; TCP SYNACK on established conn (tcp-synack-ooo) 7&lt;BR /&gt; TCP packet SEQ past window (tcp-seq-past-win) 58&lt;BR /&gt; TCP RST/SYN in window (tcp-rst-syn-in-win) 20&lt;BR /&gt; Early security checks failed (security-failed) 1&lt;BR /&gt; Slowpath security checks failed (sp-security-failed) 84119&lt;BR /&gt; IP option drop (invalid-ip-option) 1&lt;BR /&gt; ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched) 1&lt;BR /&gt; ICMP Error Inspect no existing conn (inspect-icmp-error-no-existing-conn) 1&lt;BR /&gt; DNS Inspect invalid packet (inspect-dns-invalid-pak) 5&lt;BR /&gt; DNS Inspect id not matched (inspect-dns-id-not-matched) 55&lt;BR /&gt; FP L2 rule drop (l2_acl) 345&lt;BR /&gt; Interface is down (interface-down) 54830&lt;BR /&gt; Dropped pending packets in a closed socket (np-socket-closed) 97&lt;BR /&gt; IKE new SA limit exceeded (ike-sa-rate-limit) 206052&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;/P&gt;
&lt;P&gt;Flow drop:&lt;BR /&gt; Need to start IKE negotiation (need-ike) 427792&lt;BR /&gt; Inspection failure (inspect-fail) 394&lt;BR /&gt; SSL handshake failed (ssl-handshake-failed) 30&lt;BR /&gt; DTLS hello processed and closed (dtls-hello-close) 3&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 21:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810307#M173900</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2015-12-21T21:14:38Z</dc:date>
    </item>
    <item>
      <title>I don't think you have any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810308#M173901</link>
      <description>&lt;P&gt;I don't think you have any problems.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A huge number of the drops are because of "deny" rules:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Flow is denied by configured rule (acl-drop) 256104&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 21:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810308#M173901</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-21T21:19:49Z</dc:date>
    </item>
    <item>
      <title>What's your taking on this</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810309#M173902</link>
      <description>&lt;P&gt;What's your taking on this one? This one is the ASA alerting of dropped packets on the inside interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Frame drop:&lt;BR /&gt; IPSEC tunnel is down (ipsec-tun-down) 198&lt;BR /&gt; VPN reclassify failed (vpn-reclassify-failed) 14&lt;BR /&gt; Invalid IP header (invalid-ip-header) 10&lt;BR /&gt; Invalid IP length (invalid-ip-length) 2&lt;BR /&gt; Invalid UDP Length (invalid-udp-length) 3&lt;BR /&gt; No valid adjacency (no-adjacency) 236&lt;BR /&gt; No route to host (no-route) 206&lt;BR /&gt; Reverse-path verify failed (rpf-violated) 427&lt;BR /&gt; Flow is denied by configured rule (acl-drop) 756704&lt;BR /&gt; Invalid SPI (np-sp-invalid-spi) 14&lt;BR /&gt; First TCP packet not SYN (tcp-not-syn) 16301&lt;BR /&gt; Bad TCP flags (bad-tcp-flags) 13&lt;BR /&gt; TCP data send after FIN (tcp-data-past-fin) 34&lt;BR /&gt; TCP failed 3 way handshake (tcp-3whs-failed) 910&lt;BR /&gt; TCP RST/FIN out of order (tcp-rstfin-ooo) 55107&lt;BR /&gt; TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 25&lt;BR /&gt; TCP SYNACK on established conn (tcp-synack-ooo) 86&lt;BR /&gt; TCP packet SEQ past window (tcp-seq-past-win) 107&lt;BR /&gt; TCP RST/SYN in window (tcp-rst-syn-in-win) 288&lt;BR /&gt; Slowpath security checks failed (sp-security-failed) 468064&lt;BR /&gt; ICMP Inspect bad icmp code (inspect-icmp-bad-code) 1&lt;BR /&gt; ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched) 66&lt;BR /&gt; DNS Inspect id not matched (inspect-dns-id-not-matched) 76&lt;BR /&gt; FP L2 rule drop (l2_acl) 9953949&lt;BR /&gt; Interface is down (interface-down) 24&lt;BR /&gt; IKE new SA limit exceeded (ike-sa-rate-limit) 4505&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;/P&gt;
&lt;P&gt;Flow drop:&lt;BR /&gt; Tunnel has been torn down (tunnel-torn-down) 28&lt;BR /&gt; Need to start IKE negotiation (need-ike) 32098&lt;BR /&gt; VPN handle not found (vpn-handle-not-found) 2&lt;BR /&gt; Expired VPN context (vpn-context-expired) 4&lt;BR /&gt; Inspection failure (inspect-fail) 76988&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 21:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810309#M173902</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2015-12-21T21:35:40Z</dc:date>
    </item>
    <item>
      <title>You are getting a lot of:</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810310#M173903</link>
      <description>&lt;P&gt;You are getting a lot of:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Slowpath security checks failed (sp-security-failed) 468064&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check out this article describing causes:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/discussion/11168351/sp-security-failed"&gt;https://supportforums.cisco.com/discussion/11168351/sp-security-failed&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you are getting lots and lots of these:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;FP L2 rule drop (l2_acl) 9953949&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It tends to suggest that a lot of packets are being dropped by a configured rule.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 21:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810310#M173903</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2015-12-21T21:44:23Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810311#M173904</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You mentioned that the packets are getting dropped on ASA interface. could you tell what kind of traffic? is it for a specific IP or random packet drop?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the traffic drop is for VPN traffic or traffic to internet? Are you seeing drop for TCP or UDP?&lt;/P&gt;
&lt;P&gt;If it is a specific traffic getting dropped by the ASA then you check the packet tracer for the source and destination IP address.&lt;/P&gt;
&lt;P&gt;When you take the "show asp drop" please take it multiple times to check the increment in the value of the counters.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 01:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-interface-packet-loss/m-p/2810311#M173904</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-22T01:28:50Z</dc:date>
    </item>
  </channel>
</rss>

