<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA sh asp drop and syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993515#M435347</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for hint. I know this explanation - but it dind't help, so I've put question here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is it written, that those messages are printed only in transparent mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4771509"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4771509&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have fw in routed mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I give you example of capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 11:48:13.171301 5c26.0a4c.ed53 0100.5e0c.0045 0x0800 492: 10.18.0.69.61818 &amp;gt; 227.12.0.69.11000:&amp;nbsp; [udp sum ok] udp 450 [ttl 1] (id 22159) Drop-reason: (punt-rate-limit) Punt rate limit exceeded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 11:48:13.171377 5c26.0a4c.ed53 0100.5e0c.0045 0x0800 492: 10.18.0.69.61818 &amp;gt; 227.12.0.69.11000:&amp;nbsp; [udp sum ok] udp 450 [ttl 1] (id 22160) Drop-reason: (punt-rate-limit) Punt rate limit exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I involve ARP inspection on ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 03 Jun 2012 19:15:09 GMT</pubDate>
    <dc:creator>Pavel Pokorny</dc:creator>
    <dc:date>2012-06-03T19:15:09Z</dc:date>
    <item>
      <title>ASA sh asp drop and syslog</title>
      <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993513#M435345</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a little confusion about logging.&lt;/P&gt;&lt;P&gt;My setup (8.2.4):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run logg&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging emblem&lt;/P&gt;&lt;P&gt;logging list all level debugging&lt;/P&gt;&lt;P&gt;logging buffer-size 100000&lt;/P&gt;&lt;P&gt;logging asdm-buffer-size 512&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;logging asdm errors&lt;/P&gt;&lt;P&gt;logging queue 8192&lt;/P&gt;&lt;P&gt;logging host inside monitor&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;no logging message 313005&lt;/P&gt;&lt;P&gt;no logging message 713042&lt;/P&gt;&lt;P&gt;logging message 111001 level errors&lt;/P&gt;&lt;P&gt;logging rate-limit 1000 10 level 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to see in syslog (ie):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;#sh asp drop&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Frame drop:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; Punt rate limit exceeded (punt-rate-limit)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;NUMBER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding to doc, when something happens, what increases this counter, then syslog message should follow (322002, 322003).&lt;/P&gt;&lt;P&gt;But I can't see anything in syslog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it bug or feature?&lt;/P&gt;&lt;P&gt;This same happens with other accidents regarding to asp drop.&lt;/P&gt;&lt;P&gt;Is there any other chance (even temporarily) to start producing syslog messages for particular Frame drop, or Flow drop?&lt;/P&gt;&lt;P&gt;Or do I have to use packet capture only (which increases load of ASA, and in this case is not flexible as syslog)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993513#M435345</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2019-03-11T23:13:47Z</dc:date>
    </item>
    <item>
      <title>ASA sh asp drop and syslog</title>
      <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993514#M435346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/s2.html#wp1555034"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/s2.html#wp1555034&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;Name: punt-rate-limit
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508956"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;Punt rate limit exceeded:
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508957"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; This counter will increment when the appliance attempts to forward a layer-2 packet to 
a rate-limited control point service routine and the rate limit (per/second) is now being 
exceeded. Currently, the only layer-2 packets destined for a control point service routine 
which are rate limited are ARP packets. The ARP packet rate limit is 500 ARPs per second 
per interface.
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508958"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508959"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;Recommendation:
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508960"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Analyze your network traffic to determine the reason behind the high rate of ARP 
packets.
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508961"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508962"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt; Syslogs:
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1508963"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 322002, 322003 
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are arp inspection syslogs which get printed only in transparent mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the times, the reason for theat asp drop message is a loop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 15:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993514#M435346</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2012-06-03T15:36:19Z</dc:date>
    </item>
    <item>
      <title>ASA sh asp drop and syslog</title>
      <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993515#M435347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for hint. I know this explanation - but it dind't help, so I've put question here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is it written, that those messages are printed only in transparent mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4771509"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4771509&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have fw in routed mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I give you example of capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 11:48:13.171301 5c26.0a4c.ed53 0100.5e0c.0045 0x0800 492: 10.18.0.69.61818 &amp;gt; 227.12.0.69.11000:&amp;nbsp; [udp sum ok] udp 450 [ttl 1] (id 22159) Drop-reason: (punt-rate-limit) Punt rate limit exceeded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 11:48:13.171377 5c26.0a4c.ed53 0100.5e0c.0045 0x0800 492: 10.18.0.69.61818 &amp;gt; 227.12.0.69.11000:&amp;nbsp; [udp sum ok] udp 450 [ttl 1] (id 22160) Drop-reason: (punt-rate-limit) Punt rate limit exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I involve ARP inspection on ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 19:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993515#M435347</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2012-06-03T19:15:09Z</dc:date>
    </item>
    <item>
      <title>ASA sh asp drop and syslog</title>
      <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993516#M435348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arp inspection can only be enabled on TFW.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/a2.html#wp1716385"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/a2.html#wp1716385&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the table - command modes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 22:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993516#M435348</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2012-06-03T22:49:45Z</dc:date>
    </item>
    <item>
      <title>ASA sh asp drop and syslog</title>
      <link>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993517#M435349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aaah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Blind, sorry.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Al right, but tell me please, right explanation of messages I gave you.&lt;/P&gt;&lt;P&gt;Because, I have 8.2.4 in Routed mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 05:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-sh-asp-drop-and-syslog/m-p/1993517#M435349</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2012-06-04T05:53:39Z</dc:date>
    </item>
  </channel>
</rss>

