<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic %FW-4-TCP_OoO_SEG: Dropping TCP Segment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fw-4-tcp-ooo-seg-dropping-tcp-segment/m-p/1946659#M458541</link>
    <description>&lt;P&gt;Any idea what this means? Why are these packets being dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 13:46:11.315: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:1826858942 1492 bytes is out-of-order; expected seq:1826829902. Reason: TCP reassembly queue overflow - session 10.2.31.31:50052 to 31.13.69.42:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 13:52:13.439: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:1264022358 1492 bytes is out-of-order; expected seq:1263984606. Reason: TCP reassembly queue overflow - session 10.2.31.31:50228 to 184.84.239.17:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 14:08:46.261: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:3591782745 1492 bytes is out-of-order; expected seq:3591717405. Reason: TCP reassembly queue overflow - session 10.2.31.13:58412 to 207.46.206.46:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 14:08:47.825: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:3591726117 1492 bytes is out-of-order; expected seq:3591720309. Reason: TCP reassembly queue overflow - session 10.2.31.13:58412 to 207.46.206.46:80&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:37:56 GMT</pubDate>
    <dc:creator>network770</dc:creator>
    <dc:date>2019-03-11T22:37:56Z</dc:date>
    <item>
      <title>%FW-4-TCP_OoO_SEG: Dropping TCP Segment</title>
      <link>https://community.cisco.com/t5/network-security/fw-4-tcp-ooo-seg-dropping-tcp-segment/m-p/1946659#M458541</link>
      <description>&lt;P&gt;Any idea what this means? Why are these packets being dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 13:46:11.315: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:1826858942 1492 bytes is out-of-order; expected seq:1826829902. Reason: TCP reassembly queue overflow - session 10.2.31.31:50052 to 31.13.69.42:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 13:52:13.439: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:1264022358 1492 bytes is out-of-order; expected seq:1263984606. Reason: TCP reassembly queue overflow - session 10.2.31.31:50228 to 184.84.239.17:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 14:08:46.261: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:3591782745 1492 bytes is out-of-order; expected seq:3591717405. Reason: TCP reassembly queue overflow - session 10.2.31.13:58412 to 207.46.206.46:80&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 14:08:47.825: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:3591726117 1492 bytes is out-of-order; expected seq:3591720309. Reason: TCP reassembly queue overflow - session 10.2.31.13:58412 to 207.46.206.46:80&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fw-4-tcp-ooo-seg-dropping-tcp-segment/m-p/1946659#M458541</guid>
      <dc:creator>network770</dc:creator>
      <dc:date>2019-03-11T22:37:56Z</dc:date>
    </item>
    <item>
      <title>%FW-4-TCP_OoO_SEG: Dropping TCP Segment</title>
      <link>https://community.cisco.com/t5/network-security/fw-4-tcp-ooo-seg-dropping-tcp-segment/m-p/1946660#M458542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ronni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like you are running some firewall inspection features on your router. What's happening is your out-of-order queue is getting full and dropping packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing you can try is increasing the queue size:&lt;/P&gt;&lt;PRE style="color: #000000; font-size: 12px; text-align: -webkit-auto; background-color: #ffffff;"&gt;&lt;STRONG&gt;ip inspect tcp reassembly queue length &lt;SIZE&gt;&lt;/SIZE&gt;&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest starting with a size of about 80 to see if it has any effect on the logs. If you are still seeing an issue, could you provide a &lt;STRONG&gt;'show ip inspect statistics'&lt;/STRONG&gt; and any relevant configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Joey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 19:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fw-4-tcp-ooo-seg-dropping-tcp-segment/m-p/1946660#M458542</guid>
      <dc:creator>johuggin</dc:creator>
      <dc:date>2012-03-02T19:40:56Z</dc:date>
    </item>
  </channel>
</rss>

