<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA  dropping packets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093722#M395120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did sh access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It shows me&amp;nbsp; quite a few hit counts.&lt;/P&gt;&lt;P&gt;Should i look for hit count with exact number&amp;nbsp; like&amp;nbsp; 8295 &lt;/P&gt;&lt;P&gt;or does i have to find all hit counts and see that sum matches with current&amp;nbsp; ASP&amp;nbsp; drop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Nov 2012 15:58:50 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2012-11-27T15:58:50Z</dc:date>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093720#M395118</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see this in ASA&amp;nbsp; logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-4-733100: [ Scanning] drop rate-1 exceeded. Current burst rate is 0 per second, max configured rate is 10; Current average rate is 22 per second, max configured rate is 5; Cumulative total count is 13472&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after this i did sh asp drop and then clear asp drops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sh asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule (acl-drop)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8295&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 165&lt;BR /&gt;&amp;nbsp; TCP failed 3 way handshake (tcp-3whs-failed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order (tcp-rstfin-ooo)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 140&lt;BR /&gt;&amp;nbsp; TCP packet SEQ past window (tcp-seq-past-win)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 101&lt;BR /&gt;&amp;nbsp; TCP Out-of-Order packet buffer full (tcp-buffer-full)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&lt;BR /&gt;&amp;nbsp; TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&lt;BR /&gt;&amp;nbsp; TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77&lt;BR /&gt;&amp;nbsp; TCP packet failed PAWS test (tcp-paws-fail)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&lt;/P&gt;&lt;P&gt;Last clearing: 20:46:35 UTC Nov 26 2012 by cc4708n&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; Flow is denied by access rule (acl-drop)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 168&lt;BR /&gt;&amp;nbsp; NAT reverse path failed (nat-rpf-failed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 44&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it shows frames drop due to ACL .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any may i can see which ACL&amp;nbsp; is this and whether it is inbound or outbound?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093720#M395118</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T00:28:14Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093721#M395119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;sh access-list should give you the hit counts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 08:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093721#M395119</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2012-11-27T08:44:35Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093722#M395120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did sh access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It shows me&amp;nbsp; quite a few hit counts.&lt;/P&gt;&lt;P&gt;Should i look for hit count with exact number&amp;nbsp; like&amp;nbsp; 8295 &lt;/P&gt;&lt;P&gt;or does i have to find all hit counts and see that sum matches with current&amp;nbsp; ASP&amp;nbsp; drop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 15:58:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093722#M395120</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-11-27T15:58:50Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093723#M395121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I took a closer lokk at the doc concerning asp drop and it can be lots of stuff so I don't think that the show access-list will be enough to troubleshoot the issue, I'll leave firewall experts help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 18:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093723#M395121</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2012-11-27T18:07:09Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093724#M395122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well the log you are seeing is related to threat detection feature with scanning enable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat&amp;nbsp; detection basically collects information such as access list, ports,&amp;nbsp; protocol, etc and creates a “database”. The log just indicates the burst&amp;nbsp; threshold rate or average threshold rate has exceeded. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now, the show asp drop command shows the packets or connections&amp;nbsp; dropped by the ASA and the “flow is denied by configured rule&amp;nbsp; (acl-drop)” counter is incremented when a drop rule is hit by the packet&amp;nbsp; and gets dropped (99% by implicit deny on the outside interface), when&amp;nbsp; an acl is applied to interface or any other feature etc. Apart from&amp;nbsp; default rule drops, a packet could be dropped because of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL configured on an interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ACL configured for AAA and AAA denied the user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thru-box traffic arriving at management-only ifc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unencrypted traffic arriving on a ipsec-enabled interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to look at which ACL is dropping packets&amp;nbsp; there is no detailed information on the asp drop output, most likely&amp;nbsp; it’s going to generate 106023, 106100, 106004 if one of ACLs listed&amp;nbsp; below are fired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt;"&gt;Juan Lombana &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 19:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093724#M395122</guid>
      <dc:creator>julomban</dc:creator>
      <dc:date>2012-11-27T19:02:35Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093725#M395123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Juan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; for reply.&lt;/P&gt;&lt;P&gt;So these are just&amp;nbsp; informational messages?&lt;/P&gt;&lt;P&gt;They have no impact on the performance of ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there way&amp;nbsp; i can get rid of these logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 19:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093725#M395123</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-11-28T19:46:07Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093726#M395124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct, they do not impact on the ASA performance. You can stop the log from been generated, so you won’t see it on the syslog server or ASDM. You can run the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no logging message 733100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the beginning of the syslog you can see the ID:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-4-733100: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps&lt;/P&gt;&lt;P&gt;Juan Lombana&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 20:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093726#M395124</guid>
      <dc:creator>julomban</dc:creator>
      <dc:date>2012-11-28T20:29:58Z</dc:date>
    </item>
    <item>
      <title>ASA  dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093727#M395125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Many thanks Alain &amp;amp; Juan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 22:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-packets/m-p/2093727#M395125</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-11-28T22:00:30Z</dc:date>
    </item>
  </channel>
</rss>

