<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error #733100 - drop rate-1 exceeded in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261043#M857712</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've got the same message on my ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it an attack or a general message?&lt;/P&gt;&lt;P&gt;What can i do to solve the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the relevant syslog message from Kiwi Syslog Server.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Elias&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Jan 2011 14:44:10 GMT</pubDate>
    <dc:creator>Elias Michalitsis</dc:creator>
    <dc:date>2011-01-18T14:44:10Z</dc:date>
    <item>
      <title>Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261041#M857710</link>
      <description>&lt;P&gt;Ok, I've read all the man pages and other discussions on this, so please don't just quote those back to me.&lt;SPAN style="background-color: #f8fafd;"&gt;&amp;nbsp; I know this is an aggregation of the various drop types and that there is no "set" value that you should set your thresholds at.&amp;nbsp; What I want to know is whether there is a way to tell what is triggering this message, ie: exactly what broke the threshold, something like source-IP or what ACL line is causing it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;If not, if this is simply a message that is going to be generated but you can't pull some specific information as to what generated the message, and thus tell whether its something you should take action on or ignore, is there a way to disable it all-together?&amp;nbsp; I already have the "Enable scanning threat detection" box un-checked, so that's not it!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hey Cisco, if you're going to generate these messages, I'm sure there are &amp;gt;tons&amp;lt; of us who would like to know exactly what they mean, how to interpret them and what to do about them in more detail.&amp;nbsp; Your documentation is severely lacking!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261041#M857710</guid>
      <dc:creator>Craig Norborg</dc:creator>
      <dc:date>2019-03-11T16:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261042#M857711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies if you've already seen it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basic threat-detection is enabled by default and is disabled with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no threat-detection basic-threat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For an idea of what's causing the log messages:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; show threat-detection rate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt;also by default, statistics for access lists are enabled. If it's ACLs which are triggering the messages, i suppose the message IDs 106023 is the best place to look.&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/protect.html#wpmkr1076627"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/protect.html#wpmkr1076627&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 16:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261042#M857711</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2009-11-24T16:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261043#M857712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've got the same message on my ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it an attack or a general message?&lt;/P&gt;&lt;P&gt;What can i do to solve the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the relevant syslog message from Kiwi Syslog Server.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Elias&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 14:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261043#M857712</guid>
      <dc:creator>Elias Michalitsis</dc:creator>
      <dc:date>2011-01-18T14:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261044#M857713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I filed a documentation only defect a while ago:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtj02347"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtj02347&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: monospace; font-size: 12px; white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;BR /&gt;This is a documentation only defect.&amp;nbsp; syslog message 733100 needs to include&lt;BR /&gt;"host drop" reason.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4963969"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4963969&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;ASA-4-733100&amp;gt; [10.60.88.2] drop rate-2 exceeded. Current burst rate is 0 per &lt;BR /&gt;second, max configured rate is 8; Current average rate is 5 per second, &lt;BR /&gt;max configured rate is 4; Cumulative total count is 38086&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;BR /&gt;None&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;Issue "show run all threat-detection".&lt;BR /&gt;The number of triggers of different thresholds can be checked in "show&lt;BR /&gt;threat-detection rate".&lt;BR /&gt;&lt;BR /&gt;Syslog 733100 is related to scanning-rate, adjusting this parameter should be&lt;BR /&gt;able to resolve too many messages showing up in the syslogs.&lt;BR /&gt;&lt;BR /&gt;In this case, tuning the command "threat-detection rate scanning-rate 3600&lt;BR /&gt;average-rate 15" stopped too many of these messages being logged. In other&lt;BR /&gt;cases one may have to increase the scanning-rate and average-rate to a higher&lt;BR /&gt;value.&lt;BR /&gt;&lt;BR /&gt;The resolved syslog link: &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4963969"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4963969&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-KS&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 15:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261044#M857713</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-18T15:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261045#M857714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Sankar.&lt;/P&gt;&lt;P&gt;I can understood that this message is not a serious attack but it has to do with the current situation of the firewall. I mean, that my firewall is doing so many scannings and it raises a message about this.&lt;/P&gt;&lt;P&gt;I have increase the average rate and the burst rate and i will see tomorrow what is happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am i right or not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 20:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261045#M857714</guid>
      <dc:creator>Elias Michalitsis</dc:creator>
      <dc:date>2011-01-18T20:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Error #733100 - drop rate-1 exceeded</title>
      <link>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261046#M857715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct. Depending on your network and traffic that the firewall sees you may see these syslogs very often&amp;nbsp; and you may have to tune the settings so, you don't see too many of these too often.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 21:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-733100-drop-rate-1-exceeded/m-p/1261046#M857715</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-18T21:55:20Z</dc:date>
    </item>
  </channel>
</rss>

