<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Viewing ZBPF drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053152#M895944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the end of your policy add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt; drop log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Sep 2008 11:19:37 GMT</pubDate>
    <dc:creator>Gerald Vogt</dc:creator>
    <dc:date>2008-09-25T11:19:37Z</dc:date>
    <item>
      <title>Viewing ZBPF drops</title>
      <link>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053151#M895942</link>
      <description>&lt;P&gt;"show policy-map type inspect zone-pair sessions"  ..does a great job of showing me currently active sessions in the inspection rules.  What if I want to see what traffic is currently being dropped by the class default drop?  How could I view what traffic is being prevented by the ZBPF?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Class-map: class-default (match-any)&lt;/P&gt;&lt;P&gt;      Match: any&lt;/P&gt;&lt;P&gt;      Drop (default action)&lt;/P&gt;&lt;P&gt;        22386 packets, 1473397 bytes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053151#M895942</guid>
      <dc:creator>mmedwid</dc:creator>
      <dc:date>2019-03-11T13:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing ZBPF drops</title>
      <link>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053152#M895944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the end of your policy add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt; drop log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2008 11:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053152#M895944</guid>
      <dc:creator>Gerald Vogt</dc:creator>
      <dc:date>2008-09-25T11:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing ZBPF drops</title>
      <link>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053153#M895946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another handy tool to use when troubleshooting ZBFW is the 'ip inspect log drop' command. When this is enabled, a syslog message will be generated for packets that are dropped due to a firewall rule. The syslogs are usually pretty good about specifying a reason why the traffic was dropped as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2008 15:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/viewing-zbpf-drops/m-p/1053153#M895946</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-09-25T15:32:02Z</dc:date>
    </item>
  </channel>
</rss>

