<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone based firewall dropping tcp sessions. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513195#M588091</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is probably due to the fact that we see&amp;nbsp; lot of out of order packets coming to the router/firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have seen this error before when there r lot of out of order packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what code of ios r u running on router... out of order support for ZBF is avalable only from 15.0 code...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think this is the cause, if you r ok with upgrade you can try to upgrade to 15.0 or higher code, again i am guessing this based on my experience&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Dec 2010 15:19:28 GMT</pubDate>
    <dc:creator>Jitendriya Athavale</dc:creator>
    <dc:date>2010-12-07T15:19:28Z</dc:date>
    <item>
      <title>Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513191#M588087</link>
      <description>&lt;P&gt;We are currently running 2811 routers for our remote locations.&amp;nbsp; We have implemented a DMVPN network and we are using a ZBF to allow split tunneling for internet connections.&amp;nbsp; We have been seeing log messages indicating that packets and sessions are being dropped. &lt;/P&gt;&lt;P&gt;Is there any support documentation for troubleshooting and/or a message hierachy?&amp;nbsp; Specifically if a log message indicates the session has been dropped due to a stray segment if there are other packets on the wire how will they be handled by the router and how will that action be logged?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513191#M588087</guid>
      <dc:creator>les_davis</dc:creator>
      <dc:date>2019-03-11T19:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513192#M588088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Les,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following table is going to explain you the different messages that you are going to see on your FW log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i2.html#wp1048937"&gt;http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i2.html#wp1048937&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the traffic that is being dropped from the inside to the DMVPN zone? What traffic is the one that is being dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 04:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513192#M588088</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-12-07T04:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513193#M588089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The &lt;SPAN style="background-color: #f8fafd;"&gt;session drops are both ways.&amp;nbsp; We are trying to figure out how to use the logs to determine if there are any "main" event that causes the other issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Sample router log &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dec&amp;nbsp; 7 06:52:03.918 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:42905 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:52:34.355 CST: %FW-6-DROP_PKT: Dropping tcp session 173.188.247.146:43004 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:53:04.556 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:42999&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:53:34.557 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:42999&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:54:05.690 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43118&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:54:36.071 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43181&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:55:06.244 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.174:34634 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:56:14.230 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43208&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:57:09.591 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.174:34682 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:58:20.938 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.174:34738&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 06:59:37.604 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:43392 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:00:14.321 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.174:34814&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:00:48.398 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.174:34743&amp;nbsp; due to&amp;nbsp; policy match failure with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:01:36.204 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.174:34815&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:05:20.406 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:43506 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:06:44.729 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:43651 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:08:29.400 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:43687 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:09:02.577 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43778&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:13:15.469 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43883&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:14:36.275 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43923&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:15:06.852 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:43963&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:16:11.942 CST: %FW-6-DROP_PKT: Dropping tcp session 10.13.240.199:43977 216.52.207.65:80&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:17:01.764 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:44006&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:18:00.722 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:44016&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:18:49.583 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.199:44092&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;BR /&gt;Dec&amp;nbsp; 7 07:21:21.496 CST: %FW-6-DROP_PKT: Dropping tcp session 216.52.207.65:80 10.13.240.174:35156&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 14:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513193#M588089</guid>
      <dc:creator>les_davis</dc:creator>
      <dc:date>2010-12-07T14:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513194#M588090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see, Are you noticing problems on the final PC's? Normally this could be because a rst packet get into the firewall once the session was closed, hence it the firewall should drop it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 15:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513194#M588090</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-12-07T15:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513195#M588091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is probably due to the fact that we see&amp;nbsp; lot of out of order packets coming to the router/firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have seen this error before when there r lot of out of order packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what code of ios r u running on router... out of order support for ZBF is avalable only from 15.0 code...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think this is the cause, if you r ok with upgrade you can try to upgrade to 15.0 or higher code, again i am guessing this based on my experience&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 15:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513195#M588091</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-12-07T15:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513196#M588092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We keep running into other issues using 15.x IOS and have not been able to move to that IOS version.&amp;nbsp; 15.1 and .2 has a socket error issue keeping one of the mGRE tunnels from functioning.&amp;nbsp; 15.1 has a problem with router crashing with zone base firewall when fragmentation is on the network.&amp;nbsp; We are currently regression testing 15.3T but have yet to deploy to the field.&amp;nbsp; We currently have 1600 loctions converted and don't want to add any other issues without sufficient lab testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently running with c2800nm-advsecurityk9-mz.124-24.T1.bin.&amp;nbsp; The tcp reassembly support is resident with this IOS.&amp;nbsp; We are currently working to increase the queue depth to 64 packets from the default of 16.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are several configruation options with the queue depth and I currently have a case requesting more details on that configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main question is what are the best practices for determining the tcp reassembly queue depth?&amp;nbsp; I don't think that just raising the value until we stop getting the queue overflow alarms is a good practice.&amp;nbsp; Besides we can't do that with 1600 remote locations with another 6000 planned.&lt;/P&gt;&lt;P&gt;There must be some formula/process to determine a good starting point based on circuit type and max latency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other questions concern the trade-offs between increasing the queue depth and memory usage.&amp;nbsp; Is there a break even point with the queue and memory usage that you can affect the router performance?&amp;nbsp; And if you increase the depth to 1024 does that start affecting latency?&amp;nbsp; How does the queue depth and the max memory used configuration items play together?&lt;/P&gt;&lt;P&gt;Once again what are the best practices and where can I find a configuraiton guide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 20:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513196#M588092</guid>
      <dc:creator>les_davis</dc:creator>
      <dc:date>2010-12-09T20:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513197#M588093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been unlucky wih tcp reassembly as far this issue is concerned, but I will certainly want you to try it once.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case my overall take is we should always go forward unless we have no option, we u are being affected with bugs in 15.x code u can wait till it is fixed and go to 15.x code&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But again I would recommend you open a tac case and have this investigated thoroughly  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jitendriya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 08:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513197#M588093</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-12-10T08:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513198#M588094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;the minimum required version 15 512BM RAM &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN&gt;Greetings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 14:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513198#M588094</guid>
      <dc:creator>iec1128759</dc:creator>
      <dc:date>2010-12-10T14:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513199#M588095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do have a case open.&amp;nbsp; I wasn't getting very good information from tac so I started this thread.&amp;nbsp; We are seeing success with changing the tcp reassembly.&amp;nbsp; We have increased the queue to 64 and performance/user experience has improved.&amp;nbsp; We are also working to "certify" 15.1-3T for our production needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everybody for your input.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 14:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513199#M588095</guid>
      <dc:creator>les_davis</dc:creator>
      <dc:date>2010-12-10T14:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513200#M588096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome thts great news you might want to mention the command you put and the code for the benefit of other users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jitendriya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 15:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513200#M588096</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-12-10T15:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall dropping tcp sessions.</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513201#M588097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are currently using 2811 routers running the c2800nm-advsecurityk9-mz.124-24.T1.bin code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We applied 2 commands.&amp;nbsp; 1 to log if we were exceeding the tcp reassembly queue buffer and another to increase the queue depth.&lt;/P&gt;&lt;P&gt;Both commands are global commands.&lt;/P&gt;&lt;P&gt;Enabling logging is a must in this type of situation.&amp;nbsp; The only way to actively find the problem and track if you need to adjust the buffer more is by turning on the logging.&lt;/P&gt;&lt;P&gt;Logging command&lt;/P&gt;&lt;P&gt;ip inspect tcp reassembly alarm on&lt;/P&gt;&lt;P&gt;Sample log output&lt;/P&gt;&lt;P&gt;%FW-4-TCP_OoO_SEG: Dropping TCP Segment: seq:4261387804 1400 bytes is out-of-order; expected seq:4261363324. Reason: TCP reassembly queue overflow - session LOCAL IP :49959 to Remote IP:80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Queue depth increase command.&lt;/P&gt;&lt;P&gt;ip inspect tcp reassembly queue length 64&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To verify if you are having this problem there are a couple of commands to use to verify if you are receiving out of order packets and how many you may be dropping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sho ip inspect statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interfaces configured for inspection 4294967290&lt;BR /&gt;Session creations since subsystem startup or last reset 0&lt;BR /&gt;Current session counts (estab/half-open/terminating) [0:0:0]&lt;BR /&gt;Maxever session counts (estab/half-open/terminating) [45:23:10]&lt;BR /&gt;Last session created 00:00:10&lt;BR /&gt;Last statistic reset never&lt;BR /&gt;Last session creation rate 15&lt;BR /&gt;Maxever session creation rate 241&lt;BR /&gt;Last half-open session total 0&lt;BR /&gt;TCP reassembly statistics&lt;BR /&gt;&amp;nbsp; received 2846 packets out-of-order; dropped 815&lt;BR /&gt;&amp;nbsp; peak memory usage 94 KB; current usage: 0 KB&lt;BR /&gt;&amp;nbsp; peak queue length 16&lt;/P&gt;&lt;P&gt;sho ip inspect tech-support will also give you the same information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 18:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-dropping-tcp-sessions/m-p/1513201#M588097</guid>
      <dc:creator>les_davis</dc:creator>
      <dc:date>2010-12-10T18:01:41Z</dc:date>
    </item>
  </channel>
</rss>

