<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connection limits questions. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875926#M460104</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're welcome. Thanks for the rating. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah I was thinking something like a DDos attack when I alluded to "one-time event". I hesitate to raise that spectre directly though so as not to "cry wolf" and unduly alarms folks without any corroborating data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 05 Feb 2012 18:27:12 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2012-02-05T18:27:12Z</dc:date>
    <item>
      <title>Connection limits questions.</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875923#M460101</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i got a crahed 5520 this week and was showing &lt;/P&gt;&lt;P&gt;&amp;lt;163&amp;gt;Nov 28 2011 11:34:45: %ASA-3-201013: Per-client connection limit exceeded -125/100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What the negative number tells ?&amp;nbsp; i usually see same numbers like 100/100 with means the connection limited has reached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also the box was showing &lt;/P&gt;&lt;P&gt;&amp;lt;163&amp;gt;Nov 28 2011 19:51:17: %ASA-3-210007: LU allocate xlate failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;161&amp;gt;Nov 28 2011 17:50:44: %ASA-1-105005: (Primary) Lost Failover communications with mate on interface OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the last 2 log messages its showing that the box was out of resources correct ?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875923#M460101</guid>
      <dc:creator>laerciotobias</dc:creator>
      <dc:date>2019-03-11T22:23:58Z</dc:date>
    </item>
    <item>
      <title>Connection limits questions.</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875924#M460102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The negative numbers reading is caused by a bug. Please see "CSCtl23397 - ASA may log negative values for Per-client conn limit exceeded messg".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 210007 message is indicating stateful failover is out of resources. See &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4770249"&gt;this explanation&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Overall it appears your boxes may be pushing the limit of their capabilities connection-wise. Some further investigation would be required to determine whether that was a one-time event or indicative of a need to upgrade (memory or device).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Feb 2012 18:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875924#M460102</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-02-05T18:06:14Z</dc:date>
    </item>
    <item>
      <title>Connection limits questions.</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875925#M460103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Marvin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually was a DDos attack.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Feb 2012 18:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875925#M460103</guid>
      <dc:creator>laerciotobias</dc:creator>
      <dc:date>2012-02-05T18:20:31Z</dc:date>
    </item>
    <item>
      <title>Connection limits questions.</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875926#M460104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're welcome. Thanks for the rating. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah I was thinking something like a DDos attack when I alluded to "one-time event". I hesitate to raise that spectre directly though so as not to "cry wolf" and unduly alarms folks without any corroborating data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Feb 2012 18:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-questions/m-p/1875926#M460104</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-02-05T18:27:12Z</dc:date>
    </item>
  </channel>
</rss>

