<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA error message/Is my network under attack? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575258#M578785</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great reply.&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 04 Dec 2010 16:49:22 GMT</pubDate>
    <dc:creator>Russell Pearson</dc:creator>
    <dc:date>2010-12-04T16:49:22Z</dc:date>
    <item>
      <title>ASA error message/Is my network under attack?</title>
      <link>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575256#M578783</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;&lt;P&gt;My network has been slow and I'm looking in the asa logs.&lt;BR /&gt;I see the following message...&lt;BR /&gt;Dec 03 2010 14:32:34: %ASA-4-733100: [ Scanning] drop rate-1 exceeded. Current burst rate is 11 per second, max configured rate is 10; Current average rate is 2 per second, max configured rate is 5; Cumulative total count is 1302&lt;/P&gt;&lt;P&gt;What exactly does this mean?&lt;BR /&gt;Is it a vulnerable network/device attack, or intended as a DOS attack?&lt;BR /&gt;If so, what can I do to stop it?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575256#M578783</guid>
      <dc:creator>Russell Pearson</dc:creator>
      <dc:date>2019-03-11T19:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA error message/Is my network under attack?</title>
      <link>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575257#M578784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're seeing those messages because the threat-detection feature on the ASA is enabled and it is letting you know that the ASA was dropping packets at a burst rate of 11 per second. This message is intended as an alert that the ASA is dropping a significant amount of packets that is beyond the configured threshold (10).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see what packets are being dropped, you can do a 'show asp drop'. This will give you the number of packets that have been dropped by the ASA and the reasons they were dropped. The best way to troubleshoot this is to do 'clear asp drop' to reset the counters and then configure an ASP drop capture with the 'capture drop type asp-drop all' command. Once this is setup, you can use 'show asp drop' and 'show capture drop' to understand what specific packets are being dropped and why. This will give you an indication if the messages are referring to a network attack, a configuration problem, or if this is just a normal rate of dropped packets for your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a list of the various drop reasons and their explanations:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s2.html#wp1435096"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s2.html#wp1435096&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is an explanation of the syslog message you're seeing, which includes some recommended actions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4963969"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4963969&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Dec 2010 14:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575257#M578784</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-12-04T14:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA error message/Is my network under attack?</title>
      <link>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575258#M578785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great reply.&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Dec 2010 16:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-error-message-is-my-network-under-attack/m-p/1575258#M578785</guid>
      <dc:creator>Russell Pearson</dc:creator>
      <dc:date>2010-12-04T16:49:22Z</dc:date>
    </item>
  </channel>
</rss>

