<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Drops after Implemention of FWSM ..? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101675#M896303</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M getting below respose intermittently,Please let me know what could be issue...Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time=1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Sep 2008 08:51:33 GMT</pubDate>
    <dc:creator>manik.palekar</dc:creator>
    <dc:date>2008-09-18T08:51:33Z</dc:date>
    <item>
      <title>Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101672#M896300</link>
      <description>&lt;P&gt;Hi guys ,&lt;/P&gt;&lt;P&gt;I am facing some packet drops in LAN after implementation of FWSM context .Please let me know is there any configuration need to be done to avoid this ?&lt;/P&gt;&lt;P&gt;Please suggest ..thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101672#M896300</guid>
      <dc:creator>manik.palekar</dc:creator>
      <dc:date>2019-03-11T13:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101673#M896301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to find out what is being dropped. Is it really the FWSM or somewhere else dropping the packets. If your environment didn't have firewall before, and you are introducing FWSM to it. Some applications might not be firewall-friendly, such as in-house built software. If you want to find out if your FWSM is dropping the packets, do "show asp drop" from the CLI. And use "capture capture_name type asp-drop" to capture any dropped packets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 15:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101673#M896301</guid>
      <dc:creator>felixjai</dc:creator>
      <dc:date>2008-09-17T15:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101674#M896302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx frd...Here is the output&lt;/P&gt;&lt;P&gt;FWSM/Infra# sh capture noc&lt;/P&gt;&lt;P&gt;0 packet seen, 0 captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSMPRI/Infra# sh asp drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;/P&gt;&lt;P&gt;  No route to host                                        85151&lt;/P&gt;&lt;P&gt;  Bad TCP flags                                              22&lt;/P&gt;&lt;P&gt;  TCP failed 3 way handshake                                  7&lt;/P&gt;&lt;P&gt;  TCP RST/FIN out of order                                  258&lt;/P&gt;&lt;P&gt;  TCP packet SEQ past window                               1625&lt;/P&gt;&lt;P&gt;  TCP invalid ACK                                    7866937105&lt;/P&gt;&lt;P&gt;  TCP packet buffer full                                  64556&lt;/P&gt;&lt;P&gt;  TCP DUP and has been ACKed                             548228&lt;/P&gt;&lt;P&gt;  TCP packet failed PAWS test                            414366&lt;/P&gt;&lt;P&gt;  Packet hit an invalid connection                          105&lt;/P&gt;&lt;P&gt;  Invalid connection address in delete indication       2783892&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not observed any drops in capture&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 08:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101674#M896302</guid>
      <dc:creator>manik.palekar</dc:creator>
      <dc:date>2008-09-18T08:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101675#M896303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M getting below respose intermittently,Please let me know what could be issue...Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.10.25: Destination host unreachable.&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time=1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;P&gt;Reply from 172.17.117.24: bytes=32 time&amp;lt;1ms TTL=126&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 08:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101675#M896303</guid>
      <dc:creator>manik.palekar</dc:creator>
      <dc:date>2008-09-18T08:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101676#M896304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it random packets or ALL packets going to a VLAN? The FWSM needs an ACL to pass traffic even on highest security level (100) interfaces. This is different from PIX/ASA. If its random you already got the answer from the orignal responder (show asp drop etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check the syslogs for any deny/discards/drops etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 08:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101676#M896304</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-09-18T08:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101677#M896305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an intial setup ,&amp;amp; I have given full access from outside to inside &amp;amp; vice-versa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 09:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101677#M896305</guid>
      <dc:creator>manik.palekar</dc:creator>
      <dc:date>2008-09-18T09:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops after Implemention of FWSM ..?</title>
      <link>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101678#M896306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend that you start by setting up a SPAN session for both VLANs on either side of the FWSM. Depending on what version of FWSM code you are running (and this would be helpful to know as well), captures taken directly on the firewall can be unreliable. The SPAN captures will give you a fairly good indication of what is going on and how the FWSM is affecting the traffic flow, or at least where to start your troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 13:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-drops-after-implemention-of-fwsm/m-p/1101678#M896306</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-09-18T13:13:18Z</dc:date>
    </item>
  </channel>
</rss>

