<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High latency and packet drops observed between the physical interfaces of ASA 5510 Ver 8.4(6)5 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698856#M190715</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I am observing&amp;nbsp;packet drops between the interfaces of ASA firewall. In other terms, I have PC-A on Vlan-48&amp;nbsp;associated with the physical interface Ethernet 0/0.48 and PC-B on Vlan 52 associated with the physical interface Ethernet 0/1.52. When I try to ping between the PC's, I get latencies upto 50ms with packet drops. But when I ping a different Vlan configured under the same physical interface, the response is fine without drops. Below are the interface stats of both the interfaces. Can anyone show some light on the actual problem that's causing this? Would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/0 "", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Available but not configured via nameif&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address 44d3.ca0f.0e9c, MTU not set&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address unassigned&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 978429 packets input, 484401147 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Received 79970 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause input, 0 resume input&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 52740 L2 decode drops&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1160863 packets output, 777595252 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause output, 0 resume output&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 late collisions, 0 deferred&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; output queue (blocks free curr/low): hardware (255/65)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/1 "inside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address 44d3.ca0f.0e9d, MTU 1500&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address unassigned&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1456106 packets input, 506247554 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Received 84411 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause input, 0 resume input&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 87040 L2 decode drops&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1416324 packets output, 1322034376 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause output, 0 resume output&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 late collisions, 0 deferred&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; output queue (blocks free curr/low): hardware (255/0)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "inside":&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11594 packets input, 731663 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3 packets output, 84 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11594 packets dropped&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cyril&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:05:38 GMT</pubDate>
    <dc:creator>canand001</dc:creator>
    <dc:date>2019-03-12T06:05:38Z</dc:date>
    <item>
      <title>High latency and packet drops observed between the physical interfaces of ASA 5510 Ver 8.4(6)5</title>
      <link>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698856#M190715</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I am observing&amp;nbsp;packet drops between the interfaces of ASA firewall. In other terms, I have PC-A on Vlan-48&amp;nbsp;associated with the physical interface Ethernet 0/0.48 and PC-B on Vlan 52 associated with the physical interface Ethernet 0/1.52. When I try to ping between the PC's, I get latencies upto 50ms with packet drops. But when I ping a different Vlan configured under the same physical interface, the response is fine without drops. Below are the interface stats of both the interfaces. Can anyone show some light on the actual problem that's causing this? Would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/0 "", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Available but not configured via nameif&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address 44d3.ca0f.0e9c, MTU not set&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address unassigned&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 978429 packets input, 484401147 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Received 79970 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause input, 0 resume input&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 52740 L2 decode drops&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1160863 packets output, 777595252 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause output, 0 resume output&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 late collisions, 0 deferred&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; output queue (blocks free curr/low): hardware (255/65)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/1 "inside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC address 44d3.ca0f.0e9d, MTU 1500&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP address unassigned&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1456106 packets input, 506247554 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Received 84411 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause input, 0 resume input&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 87040 L2 decode drops&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1416324 packets output, 1322034376 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 pause output, 0 resume output&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 late collisions, 0 deferred&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; output queue (blocks free curr/low): hardware (255/0)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "inside":&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11594 packets input, 731663 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3 packets output, 84 bytes&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11594 packets dropped&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cyril&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698856#M190715</guid>
      <dc:creator>canand001</dc:creator>
      <dc:date>2019-03-12T06:05:38Z</dc:date>
    </item>
    <item>
      <title>Hi,Okay , so you checked the</title>
      <link>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698857#M190722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Okay , so you checked the latency test on one end of the Sub Interfaces. Can you also check on the other end and see if that also works fine ?&lt;/P&gt;&lt;P&gt;After that , i would recommend taking the captures on the ASA device on the Ingress and Egress and see how much time difference is there when the packet enters and leaves the ASA device.&lt;/P&gt;&lt;P&gt;Packet Captures:-&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/6971/packet-capture-asapix-fwsm&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 16:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698857#M190722</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-11T16:43:12Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,Sorry for the delay</title>
      <link>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698858#M190727</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;Sorry for the delay in revert. Yes, I did check the other end as well. They also seem to be fine without any issues.&lt;/P&gt;&lt;P&gt;As suggested, I had taken captures between the Src &amp;amp; Dstn in the Ingress and the egress interfaces of the firewall respectively. Yet..I don't observe much of a difference/delay in the query and reply timings.But I still can find&amp;nbsp;drops to the destination hosts while performing a continuous ping. Logs attached for your kind reference.&lt;/P&gt;&lt;P&gt;I am afraid this could be due to the high CPU utilization (90% Avg.). I doubt this could possibly be a bug as I don't find the reason behind the high utilization. Traffic status,connection counts and service policy for TCP inspection everything has been thoroughly checked....yet couldn't find the cause for this...&lt;/P&gt;&lt;P&gt;Any help on this will always be welcomed....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cyril&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2015 18:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-latency-and-packet-drops-observed-between-the-physical/m-p/2698858#M190727</guid>
      <dc:creator>canand001</dc:creator>
      <dc:date>2015-06-14T18:26:48Z</dc:date>
    </item>
  </channel>
</rss>

