<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High Discard rate on a FW interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205935#M348074</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Thanks.&amp;nbsp; The threshold I was speaking of would be on the monitoring system (when to alert on)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jun 2013 17:44:27 GMT</pubDate>
    <dc:creator>e.craig</dc:creator>
    <dc:date>2013-06-13T17:44:27Z</dc:date>
    <item>
      <title>High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205933#M348072</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am getting alert on high discard rates on FW interfaces via a monitoring tool.&amp;nbsp; Just want to validate if the packets dropped by ACL's are also contributing to the high discard rate counter?&amp;nbsp; If this is the case what would be an acceptable threshold to set High Discard rate on FW interfaces to insure I do not miss an actual issue regarding high discard rate. "Interface::I-Interface_Performance_CiscoRouter_Ethernet-IF-XXX-XXXX-SEC/4::HighDiscardRate"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205933#M348072</guid>
      <dc:creator>e.craig</dc:creator>
      <dc:date>2019-03-12T01:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205934#M348073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet-drop being seeing on the ASA interfaces are related to the security checks being done by the firewall (involves Inspections, ACLs, RPF checks, etc) so there is no treshold, it will all depends on how much traffic u are receiving on your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205934#M348073</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-13T17:31:16Z</dc:date>
    </item>
    <item>
      <title>High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205935#M348074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Thanks.&amp;nbsp; The threshold I was speaking of would be on the monitoring system (when to alert on)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205935#M348074</guid>
      <dc:creator>e.craig</dc:creator>
      <dc:date>2013-06-13T17:44:27Z</dc:date>
    </item>
    <item>
      <title>High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205936#M348075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, that would depend again of the enviroment you have there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an example I would not focus much on ACL drops logs ( as they are already being denied, altough it will let you know what traffic is trying to reach ur network) but the treshold would be way higher based on the fact that is common to drop a lot of traffic via an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I do not have a specific treshold that I could provide as it will depend on the enviroment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205936#M348075</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-13T17:49:32Z</dc:date>
    </item>
    <item>
      <title>High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205937#M348076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you for your feedback, much appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205937#M348076</guid>
      <dc:creator>e.craig</dc:creator>
      <dc:date>2013-06-13T17:51:30Z</dc:date>
    </item>
    <item>
      <title>High Discard rate on a FW interface</title>
      <link>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205938#M348077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do u have any other question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise u can mark the question as answered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 17:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-discard-rate-on-a-fw-interface/m-p/2205938#M348077</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-13T17:56:52Z</dc:date>
    </item>
  </channel>
</rss>

