<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,I think you should still in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735905#M192273</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you should still the drop logs on the router.&lt;/P&gt;&lt;P&gt;What is you try to configure a "parameter map" specifically for logging the drops and then reference it in the class-default ?&lt;/P&gt;&lt;P&gt;Also , re-apply the policy-map configuration with "drop log" and see if that resolves this issue.&lt;/P&gt;&lt;P&gt;Have you enabled the Console debugging and verified if you see the drops ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Sun, 30 Aug 2015 14:10:55 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-08-30T14:10:55Z</dc:date>
    <item>
      <title>IOS ZBPFW</title>
      <link>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735904#M192272</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; line-height: normal;"&gt;When configuring an ASR1001 with ZBPFW, and when using a class class-default / drop log, for an OUTSIDE_TO_SELF zone (basically the outside interface ip address), I do not see the drop action log for any dropped packets, but the drop counter is actualy incrementing. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Helvetica"&gt;&lt;SPAN style="font-size: 12px; line-height: normal;"&gt;I know the counter is incrementing because i can firstly see the counters increase, but also because i am specifically sending a load of small packets to the outside interface to see what happens under a DOS type attack.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; line-height: normal;" /&gt;&lt;BR style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; line-height: normal;"&gt;Is this the expected result or should i actually capture the dropped traffic specifically by creating a dedicated drop class rather than rely on the class-default ?&lt;/SPAN&gt;&lt;BR style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; line-height: normal;" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Thanks for your help and comments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Chris.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735904#M192272</guid>
      <dc:creator>Chris Lester</dc:creator>
      <dc:date>2019-03-12T06:31:04Z</dc:date>
    </item>
    <item>
      <title>Hi,I think you should still</title>
      <link>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735905#M192273</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you should still the drop logs on the router.&lt;/P&gt;&lt;P&gt;What is you try to configure a "parameter map" specifically for logging the drops and then reference it in the class-default ?&lt;/P&gt;&lt;P&gt;Also , re-apply the policy-map configuration with "drop log" and see if that resolves this issue.&lt;/P&gt;&lt;P&gt;Have you enabled the Console debugging and verified if you see the drops ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 14:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735905#M192273</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-08-30T14:10:55Z</dc:date>
    </item>
    <item>
      <title>I've got same problem on 15.5</title>
      <link>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735906#M192274</link>
      <description>&lt;P&gt;I've got same problem on 15.5 ASR&amp;nbsp;1001-x.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does anybody know a solution? This looks a bug to me so far.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Apr 2016 01:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-zbpfw/m-p/2735906#M192274</guid>
      <dc:creator>Sergej Tiurin</dc:creator>
      <dc:date>2016-04-10T01:01:31Z</dc:date>
    </item>
  </channel>
</rss>

