<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet drop in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665095#M561278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello, Varun! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cleaned the xlate, even restarted the ASA asking for downtime to my boss, i have checked al the translations to that server but they do not have configured the connection limits, like you can see above, the one that is in bold is the problematic one. I will wait tomorrow to see if the problem presents again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz4,inside) tcp 10.1.115.31 smtp SVDGTEC51 smtp netmask 255.255.255.255&amp;nbsp; dns &lt;/P&gt;&lt;P&gt;static (dmz4,dmz6-tmp) tcp 10.1.115.31 smtp SVDGTEC51 smtp netmask 255.255.255.255&amp;nbsp; dns &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (dmz4,dmz5) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;static (dmz4,outside) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (outside,dmz4) SVDGTEC51 10.1.115.31 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (dmz4,outside-s) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (dmz4,siscae) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Edmundo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jun 2011 20:26:18 GMT</pubDate>
    <dc:creator>cisco_sigfa</dc:creator>
    <dc:date>2011-06-08T20:26:18Z</dc:date>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665091#M561269</link>
      <description>&lt;P&gt;Hello, Everyone!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a problem with the an ASA Version 8.2, when i try these port it sends me the following result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PERIMETRAL#packet-tracer input dmz5 tcp 10.16.120.66 1026 10.1.115.31 5001 detailed&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (dmz4,dmz5) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;BR /&gt;nat-control&lt;BR /&gt;&amp;nbsp; match ip dmz4 host SVDGTEC51 dmz5 any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.1.115.31&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 417, untranslate_hits = 6028&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface dmz4&lt;BR /&gt;Untranslate 10.1.115.31/0 to SVDGTEC51/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 10.16.120.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.128 dmz5&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz5&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: dmz5&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (conn-limit) Connection limit reached&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have search on the statics but i have no limit on it, someone has an idea of what can be the cause of the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Edmundo Vado&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665091#M561269</guid>
      <dc:creator>cisco_sigfa</dc:creator>
      <dc:date>2019-03-11T20:42:20Z</dc:date>
    </item>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665092#M561272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Connection limit can also be configured under "policy-map"/"class-map" configuration. You might want to check if it has been configured under MPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command is under "set connection" command line.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 03:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665092#M561272</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-06T03:43:17Z</dc:date>
    </item>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665093#M561275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i have checked and i do not have configured any policy map with connectios limits, what else should i check?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Edmundo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 22:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665093#M561275</guid>
      <dc:creator>cisco_sigfa</dc:creator>
      <dc:date>2011-06-06T22:36:28Z</dc:date>
    </item>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665094#M561277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Edmundo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To begin troubleshooting this i would suggest you to check the syslogs at the time of the issue as well, when you try to access the server does it not connect, I would suggest you to collect the logs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the connection limit is not set on ASA, and it should be 65535 only, then my suggestion to you would be to clear the connection and xlates and check it again, it should not be an issue after that, but please if it is a live production firewall then you would need to plan it out, since it would need some downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 06:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665094#M561277</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-06-07T06:45:08Z</dc:date>
    </item>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665095#M561278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello, Varun! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cleaned the xlate, even restarted the ASA asking for downtime to my boss, i have checked al the translations to that server but they do not have configured the connection limits, like you can see above, the one that is in bold is the problematic one. I will wait tomorrow to see if the problem presents again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz4,inside) tcp 10.1.115.31 smtp SVDGTEC51 smtp netmask 255.255.255.255&amp;nbsp; dns &lt;/P&gt;&lt;P&gt;static (dmz4,dmz6-tmp) tcp 10.1.115.31 smtp SVDGTEC51 smtp netmask 255.255.255.255&amp;nbsp; dns &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (dmz4,dmz5) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;static (dmz4,outside) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (outside,dmz4) SVDGTEC51 10.1.115.31 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (dmz4,outside-s) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;static (dmz4,siscae) 10.1.115.31 SVDGTEC51 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Edmundo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 20:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665095#M561278</guid>
      <dc:creator>cisco_sigfa</dc:creator>
      <dc:date>2011-06-08T20:26:18Z</dc:date>
    </item>
    <item>
      <title>Packet drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665096#M561280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;input-interface: dmz5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;output-interface: dmz5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the route look like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run route | i&amp;nbsp; dmz5|dmz4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 03:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drop/m-p/1665096#M561280</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-06-09T03:09:43Z</dc:date>
    </item>
  </channel>
</rss>

