<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5550 - Interface Problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957699#M940957</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 firewalls ASA5550 in failover mode, in the data sheet says that maximum throughput is 1.2G, but when the outside firewall traffic comes up to 750Mb, i start to have a lot of problems, like packet drops. When the traffic arrives at 800Mb the firewall stop to process the outside failover packets, and drop all packets in the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the show interface command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps&lt;/P&gt;&lt;P&gt;        Full-Duplex(Full-duplex), 1000 Mbps(1000 Mbps)&lt;/P&gt;&lt;P&gt;        MAC address 001a.e2ea.e674, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address xxx.xxx.xxx.xxx, subnet mask xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;        47486821698 packets input, 3893958800868 bytes, 19892367 no buffer&lt;/P&gt;&lt;P&gt;        Received 16876 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 62954747 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 L2 decode drops&lt;/P&gt;&lt;P&gt;        81891090643 packets output, 108809258427982 bytes, 3695 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions&lt;/P&gt;&lt;P&gt;        0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (0/0) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (1/511) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "outside":&lt;/P&gt;&lt;P&gt;        47485878509 packets input, 2841926097278 bytes&lt;/P&gt;&lt;P&gt;        81891094335 packets output, 107330895810065 bytes&lt;/P&gt;&lt;P&gt;        89951783 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 17131 pkts/sec,  1077743 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 29928 pkts/sec,  38704909 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 36 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 17847 pkts/sec,  1059781 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 31439 pkts/sec,  41073382 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 36 pkts/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The overrun and no buffer are to high. It's possible that the ASA5550 has the maximum real throughput less than 800Mb?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:17:49 GMT</pubDate>
    <dc:creator>alexbonatti</dc:creator>
    <dc:date>2019-03-11T12:17:49Z</dc:date>
    <item>
      <title>ASA 5550 - Interface Problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957699#M940957</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 firewalls ASA5550 in failover mode, in the data sheet says that maximum throughput is 1.2G, but when the outside firewall traffic comes up to 750Mb, i start to have a lot of problems, like packet drops. When the traffic arrives at 800Mb the firewall stop to process the outside failover packets, and drop all packets in the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the show interface command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps&lt;/P&gt;&lt;P&gt;        Full-Duplex(Full-duplex), 1000 Mbps(1000 Mbps)&lt;/P&gt;&lt;P&gt;        MAC address 001a.e2ea.e674, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address xxx.xxx.xxx.xxx, subnet mask xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;        47486821698 packets input, 3893958800868 bytes, 19892367 no buffer&lt;/P&gt;&lt;P&gt;        Received 16876 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 62954747 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 L2 decode drops&lt;/P&gt;&lt;P&gt;        81891090643 packets output, 108809258427982 bytes, 3695 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions&lt;/P&gt;&lt;P&gt;        0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (0/0) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (1/511) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "outside":&lt;/P&gt;&lt;P&gt;        47485878509 packets input, 2841926097278 bytes&lt;/P&gt;&lt;P&gt;        81891094335 packets output, 107330895810065 bytes&lt;/P&gt;&lt;P&gt;        89951783 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 17131 pkts/sec,  1077743 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 29928 pkts/sec,  38704909 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 36 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 17847 pkts/sec,  1059781 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 31439 pkts/sec,  41073382 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 36 pkts/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The overrun and no buffer are to high. It's possible that the ASA5550 has the maximum real throughput less than 800Mb?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957699#M940957</guid>
      <dc:creator>alexbonatti</dc:creator>
      <dc:date>2019-03-11T12:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5550 - Interface Problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957700#M940958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Usually the overrun packets means that the interface is handling more traffic than what it can so it is getting overwhelmed with traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 22:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957700#M940958</guid>
      <dc:creator>allanc_16</dc:creator>
      <dc:date>2008-03-14T22:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5550 - Interface Problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957701#M940959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Overruns just means that the interface is receiving more traffic than the one it can handle so you should take a look to the device connected to that interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand, did you clear the counters before getting those outputs? Otherwise, those counters are since the firewall is up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to the mentioned above, drops is not synonym of issues. Drops can also be caused due to policies you have in the configuration such as ACLs, inspections, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Mar 2008 02:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5550-interface-problems/m-p/957701#M940959</guid>
      <dc:creator>jojuarez</dc:creator>
      <dc:date>2008-03-16T02:33:28Z</dc:date>
    </item>
  </channel>
</rss>

