<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Major ASA 5510 Issue / Input errors / Overruns in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748585#M532508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attached is the output.&amp;nbsp; I could not paste it into a message for some reason?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Aug 2011 13:55:00 GMT</pubDate>
    <dc:creator>RICK MANCINELLI</dc:creator>
    <dc:date>2011-08-25T13:55:00Z</dc:date>
    <item>
      <title>Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748582#M532505</link>
      <description>&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an ASA 5510 that has been in production for some time now and all has been well.&amp;nbsp; Traffic on it has been increasing over time, but nothing outrageous.&amp;nbsp; Two days ago we began taking MAJOR input errors (every single one is an overrun) on our inside interface.&amp;nbsp;&amp;nbsp; The errors come in LARGE lumps - 100k, 200k, 300k at a time.&amp;nbsp; I have attached a summary of timestamps and input error counts to demonstrate what I am talking about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh blocks" looks very good:&lt;/P&gt;&lt;P&gt;&amp;nbsp; SIZE&amp;nbsp;&amp;nbsp;&amp;nbsp; MAX&amp;nbsp;&amp;nbsp;&amp;nbsp; LOW&amp;nbsp;&amp;nbsp;&amp;nbsp; CNT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; 400&amp;nbsp;&amp;nbsp;&amp;nbsp; 399&amp;nbsp;&amp;nbsp;&amp;nbsp; 400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp; 200&amp;nbsp;&amp;nbsp;&amp;nbsp; 199&amp;nbsp;&amp;nbsp;&amp;nbsp; 199&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&amp;nbsp;&amp;nbsp;&amp;nbsp; 725&amp;nbsp;&amp;nbsp;&amp;nbsp; 702&amp;nbsp;&amp;nbsp;&amp;nbsp; 725&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 256&amp;nbsp;&amp;nbsp; 2412&amp;nbsp;&amp;nbsp; 2374&amp;nbsp;&amp;nbsp; 2411&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1550&amp;nbsp;&amp;nbsp; 2932&amp;nbsp;&amp;nbsp; 2635&amp;nbsp;&amp;nbsp; 2673&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2048&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp; 567&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2560&amp;nbsp;&amp;nbsp;&amp;nbsp; 900&amp;nbsp;&amp;nbsp;&amp;nbsp; 899&amp;nbsp;&amp;nbsp;&amp;nbsp; 900&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4096&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8192&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&amp;nbsp;&amp;nbsp;&amp;nbsp; 100&lt;/P&gt;&lt;P&gt;16384&amp;nbsp;&amp;nbsp;&amp;nbsp; 102&amp;nbsp;&amp;nbsp;&amp;nbsp; 102&amp;nbsp;&amp;nbsp;&amp;nbsp; 102&lt;/P&gt;&lt;P&gt;65536&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh traffic" looks fine as well:&lt;/P&gt;&lt;P&gt;inside:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; received (in 683.730 secs):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 87210 packets&amp;nbsp;&amp;nbsp; 33517539 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 127 pkts/sec&amp;nbsp;&amp;nbsp;&amp;nbsp; 49021 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; transmitted (in 683.730 secs):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1979502 packets 243386175 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2895 pkts/sec&amp;nbsp;&amp;nbsp; 355968 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 138 pkts/sec,&amp;nbsp; 101261 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 2449 pkts/sec,&amp;nbsp; 556063 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 127 pkts/sec,&amp;nbsp; 64917 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 1874 pkts/sec,&amp;nbsp; 335035 bytes/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh cpu" eliminates CPU hog as a potential issue:&lt;/P&gt;&lt;P&gt;CPU utilization for 5 seconds = 4%; 1 minute: 6%; 5 minutes: 6%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot figure out how an interface that is moving only about 3000pkts/s can suddenly take 100,000+ input errors in a 1 second period?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far we have:&lt;/P&gt;&lt;P&gt;- replaced the cable (three times)&lt;/P&gt;&lt;P&gt;- moved switch ports&lt;/P&gt;&lt;P&gt;- moved connection to another physical switch &lt;/P&gt;&lt;P&gt;- upgraded to ASA 8.2.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748582#M532505</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2019-03-11T21:17:05Z</dc:date>
    </item>
    <item>
      <title>Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748583#M532506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide the output of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear interface&lt;/P&gt;&lt;P&gt;and 3 outputs of show interface &lt;INTERFACE having="" overruns=""&gt; taken at an interval of one minute&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear asp drop&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;then show asp drop (3 outputs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What effects did you notice due to these error on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 13:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748583#M532506</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-25T13:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748584#M532507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so I ran the clear int and then did show int three times at one minute intervals.&amp;nbsp; I followed that with a clear asp drop followed by show asp drop at three minute intervals.&amp;nbsp; I finished with two more show int.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The impact this issue is having on our network is horrible.&amp;nbsp; Internet connectivity is horrific, and remote desktop usage is all but impossible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am noticing the 20k pps output rate from time to time.&amp;nbsp; This is somewhat concerning because we do not have anything that should be generating that level of traffic.&amp;nbsp; (Still, the ASA is supposedly rated for 190k pps, so this shouldn't be an issue).&amp;nbsp; Further, the outside interface does not report anything near that level of traffic, which is even more puzzling.&amp;nbsp; That interface (inside) does have several sub-interfaces each on their own VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(will post output in next message, getting error about "message cannot be displayed due to its content")&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 13:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748584#M532507</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2011-08-25T13:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748585#M532508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attached is the output.&amp;nbsp; I could not paste it into a message for some reason?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 13:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748585#M532508</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2011-08-25T13:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748586#M532509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These stats are very huge, I would recommend you to check the amount of connections being built on the firewall, the overruns would only occur if the traffic hitting the firewall is far greter than the speed with which the ASA can process those packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the show conn and show conn count tell, are these numbers also very high???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we need to identify is what traffic is this which is getting dropped by the firewall. There is also one new feature which was introduced in version 8.2.5, whihc is flow control, by default is disabled, it was introduced to better the performance handling in case of high traffic. Flow control is the process of managing the pacing of data transmission between two nodes to prevent a fast sender from outrunning a slow receiver, on the ASA we can try enabling the same feature. To enable this feature on ASA, here is the link to it: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrf" target="_blank" title="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrf"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrf&lt;/A&gt;&lt;SPAN style="text-decoration: underline;"&gt;ace.html &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; "&gt;I am not sure whether this would alleviate the issue completely but overruns only encountered if the ASA is overwhelmed by the incoming traffic, so it fails to process those packets and report overruns on the interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; "&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; "&gt;Varun&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 15:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748586#M532509</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-25T15:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748587#M532510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will take a look at the link.&amp;nbsp;&amp;nbsp; Also, check out the attached image!&amp;nbsp;&amp;nbsp; It seems that things chug along nicely and then, suddenly, there is a HUGE traffic spike on the "inside" interface.&amp;nbsp;&amp;nbsp; When I say huge, I mean we go from an average of less than 250pps to over 11k pps and then immediately back down to normal.&amp;nbsp;&amp;nbsp; At the same time, this is when the input/overrun errors are logged.&amp;nbsp;&amp;nbsp; I have the graphs side by side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now the question becomes... what can possibly be generating this traffic.&amp;nbsp; It is "outbound" from the inside interface.&amp;nbsp; There is NO corresponding traffic on the outside interface in either direction.&amp;nbsp; If the traffic didn't come in to the outside interface and it didn't come in to the inside interface, then how the heck is it being sent OUT of the inside interface.&amp;nbsp; IE where is it coming from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps I need to setup some packet caps and see if I can figure it out.&amp;nbsp;&amp;nbsp; Any other ideas?&amp;nbsp;&amp;nbsp; Is it possible that this is a failing NIC on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 15:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748587#M532510</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2011-08-25T15:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748588#M532511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Just a quick follow up.&amp;nbsp; As we continue to watch, we have seen two spikes above 25k pps, and one as high as 60k pps.&amp;nbsp; Again, no corresponding traffic on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is all OUTBOUND from the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is almost as if the traffic is originating from the ASA itself!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 15:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748588#M532511</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2011-08-25T15:42:16Z</dc:date>
    </item>
    <item>
      <title>Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748589#M532512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Definitely we need to verify what traffic is this, whether it is normal network traffic or some malicious broadcast packet from any rogue machine. Captures would be the right option, along with the logs on the ASA, I guess we should follow that. Check whether it is any broadcast packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 15:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748589#M532512</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-25T15:47:56Z</dc:date>
    </item>
    <item>
      <title>Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748590#M532513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;As Varun said you will need to see what is generating that amount of traffic in the inside of your network using logs and captures , also you can enable " ip verify reverse-path" on the asa so that it drops traffic that is being generated from inside network with bogus Source IP's. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you should verify the speed/duplex setting on the interface on the asa and device connecting to it on the inside interface. I can see in your output , that you have speed/duplex hard coded on the asa. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 16:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748590#M532513</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-08-25T16:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748591#M532514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;May I suggest that you setup a sniffer and mirror the port to the asa and if you have the hardware also any port in the network. wireshark is a free, well working standard sniffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just concerned that it might be that you get a network loop from time to time somewhere and that that is causing the traffic to spike like that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 17:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748591#M532514</guid>
      <dc:creator>hobbe</dc:creator>
      <dc:date>2011-08-25T17:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748592#M532515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun, others-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First I wanted to extend my sincere gratitude for your help in getting to the bottom of this issue.&amp;nbsp; Capturing the packet data, I was able to identify THREE servers which were inexplicably sending out occasional, but very large, broadcast storms.&amp;nbsp; The broadcasts were all Windows Browser Host Announcements.&amp;nbsp; They were sent at 4 min, 8 min, and 12 min after bootup of the device and then again at 12 minute intervals.&amp;nbsp; This is by design.&amp;nbsp; However, instead of sending a single Host Announcement as they are supposed to, they were each sending some random number of packets in excess of 12,000.&amp;nbsp; At times they would send as many as 60,000 packets!&amp;nbsp; I suppose they REALLY wanted to make their presence known.&amp;nbsp; LOL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing in common with the three servers is that they are all Windows 2003 based.&amp;nbsp; All have been up and in production for many years.&amp;nbsp; Two were physical, one was virtual (a P2V).&amp;nbsp; They all seemed to get sick at precisely the same time, which to me anyway, would indicate some sort of bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ultimate fix was to simply disable NetBIOS on those boxes.&amp;nbsp;&amp;nbsp; Since then, no more traffic spikes, no errors on the ASA either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the part that really confused me, and perhaps someone can shed some light on this, is that the ASA only showed outbound traffic on the inside interface.&amp;nbsp; Why not inbound traffic, since the packets were broadcasts originating from somewhere else and destined for the inside network's broadcast address?&amp;nbsp; Had the ASA shown these as "inbound" packets, I would have never suspected the ASA in the first place.&amp;nbsp; I am clearly misunderstanding something...so always willing to learn something new if someone cares to explain it to me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again and kudos to all for the help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 22:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748592#M532515</guid>
      <dc:creator>RICK MANCINELLI</dc:creator>
      <dc:date>2011-08-25T22:45:09Z</dc:date>
    </item>
    <item>
      <title>Major ASA 5510 Issue / Input errors / Overruns</title>
      <link>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748593#M532516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats really awesome you were able to nail down the issue. Those graphs with an exact periodic spike looked suspicious to me, so yes, capturing the traffic was some good job done by you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coming back to your confusion, if those servers are located on the internal lan, then this traffic would definitely be outbound for the interface (leaving the inside interface), so you might be seeing it as outbound traffic. Or may be I could be wrong, because I am not really sure to which data are you pointing to? So can you shed some more light on it, with the help of the data?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2011 07:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/major-asa-5510-issue-input-errors-overruns/m-p/1748593#M532516</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-26T07:24:31Z</dc:date>
    </item>
  </channel>
</rss>

