<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sh asp drop output. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391687#M271633</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for this command I will try it out now.&amp;nbsp; This should have no effects on my traffic or slow it down correct?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Jan 2014 18:57:39 GMT</pubDate>
    <dc:creator>bryanrobh</dc:creator>
    <dc:date>2014-01-13T18:57:39Z</dc:date>
    <item>
      <title>Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391682#M271628</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I am new to the world of ASA's and I am trying to figure out when I do a sh asp drop I get this output &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; Invalid UDP Length (invalid-udp-length)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule (acl-drop)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40954&lt;BR /&gt;&amp;nbsp; Flow denied due to resource limitation (unable-to-create-flow)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&lt;BR /&gt;&amp;nbsp; Invalid SPI (np-sp-invalid-spi)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;&amp;nbsp; TCP failed 3 way handshake (tcp-3whs-failed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 360&lt;BR /&gt;&amp;nbsp; IPSEC tunnel is down (ipsec-tun-down)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;&amp;nbsp; Slowpath security checks failed (sp-security-failed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 33585&lt;BR /&gt;&amp;nbsp; Interface is down (interface-down)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; Non-IP packet received in routed mode (non-ip-pkt-in-routed-mode)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; Need to start IKE negotiation (need-ike)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 680&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to figure out what frames were dropped due to ACL's the biggest number up there?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391682#M271628</guid>
      <dc:creator>bryanrobh</dc:creator>
      <dc:date>2019-03-12T03:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391683#M271629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that there is a default deny ip any any at the bootom of each ACL so it's expected to see a LOT of ACL drops &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; even more if the ASA sits on the edge of the network so no need to worry about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said if you want to see that you could enable logging on the FW and then look for the Message ID &lt;/P&gt;&lt;P&gt;106023.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to add the keyword log to the implicit deny at the end of each ACL as it does not log anything by default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.co" rel="nofollow"&gt;http://laguiadelnetworking.co&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391683#M271629</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-13T18:33:58Z</dc:date>
    </item>
    <item>
      <title>Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391684#M271630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't give you an 100% answer but to my understanding in the following conditions atleast the counter above increases&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Traffic dropped by &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; check when not using ACLs on the interface (traffic from lower to higher denied)&lt;/LI&gt;&lt;LI&gt;Traffic is dropped by interface&lt;STRONG&gt; "access-list"&lt;/STRONG&gt; attached with &lt;STRONG&gt;"access-group"&lt;/STRONG&gt; command&lt;/LI&gt;&lt;LI&gt;Traffic is dropped by having the interfaces &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; equal and have not used&lt;STRONG&gt; "same-security-traffic &lt;ADDITIONAL parameters=""&gt;"&lt;/ADDITIONAL&gt;&lt;/STRONG&gt; to enable it. (Even if ACLs are configured you will need this&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said I can't say this for 100% certainty but the above situation sure do end with a ACL drop when you are testing with &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt;. Unless I have remembered something wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd assume that most of these ACL drop result in traffic hitting your ASAs external interface connected to Internet. There is usually constant scanning traffic day by day that increases the counter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391684#M271630</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-01-13T18:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391685#M271631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I added the log keyword on to the ACL line that I want to verify the traffic is passing from.&amp;nbsp; I am just trying to make sure traffic from a specific IP is getting through. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391685#M271631</guid>
      <dc:creator>bryanrobh</dc:creator>
      <dc:date>2014-01-13T18:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391686#M271632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bryan,&lt;/P&gt;&lt;P&gt;You could do &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show logging | include x.x.x.x (IP address of the Host)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or even better and more Advanced &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap asp type asp-drop all circular-buffer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to connect via the host that you want to test if it's allowed through the firewall&lt;/P&gt;&lt;P&gt;and then&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show cap asp | include x.x.x.x (IP of the host)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see any output there then those packets shown in the capture are being dropped by the ASA.&lt;/P&gt;&lt;P&gt;If u do not see any FW is letting that traffic to go through&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391686#M271632</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-13T18:51:21Z</dc:date>
    </item>
    <item>
      <title>Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391687#M271633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for this command I will try it out now.&amp;nbsp; This should have no effects on my traffic or slow it down correct?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391687#M271633</guid>
      <dc:creator>bryanrobh</dc:creator>
      <dc:date>2014-01-13T18:57:39Z</dc:date>
    </item>
    <item>
      <title>Sh asp drop output.</title>
      <link>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391688#M271634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It wil capture a bunch of traffic but no, I have not see it cause any issues in my entire TAC experience so no worries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the test do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no cap asp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's all and by the way Bryan &lt;STRONG&gt;Remember to rate all of the helpful posts &lt;/STRONG&gt;such as the ones I provided in this posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 19:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-asp-drop-output/m-p/2391688#M271634</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-13T19:00:29Z</dc:date>
    </item>
  </channel>
</rss>

