<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet dropped in ASA interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405492#M953231</link>
    <description>So far I have only one suggestion: on the switch port used for trunking towards ASA, make sure you allow to the ASA ONLY the VLANs used by the firewall. This should reduce the noise. &lt;BR /&gt;&lt;BR /&gt;Still there's Gi1/0 on your scenario that seems to use an access ports, right?&lt;BR /&gt;Can you share switch port config used to connect Gi1/0? Also can you share swich port statistics used by Gi1/0?</description>
    <pubDate>Tue, 26 Jun 2018 09:08:50 GMT</pubDate>
    <dc:creator>Florin Barhala</dc:creator>
    <dc:date>2018-06-26T09:08:50Z</dc:date>
    <item>
      <title>Packet dropped in ASA interfaces</title>
      <link>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405409#M953230</link>
      <description>&lt;P&gt;We have ASA 5545-X firewall pair&amp;nbsp;in LAN network, and found lots of packet dropped in each interface ( the following counters are reset every morning for investigation), as below:&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/0 "users", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;(Full-duplex), 1000 Mbps(1000 Mbps)&lt;BR /&gt;&amp;nbsp;Input flow control is unsupported, output flow control is off&lt;/P&gt;
&lt;P&gt;628415157 packets input, 718417012211 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp;Received 73 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp;.....................&lt;BR /&gt;&amp;nbsp;327194378 packets output, 280633649724 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp;.....................&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "users":&lt;BR /&gt;&amp;nbsp;628415153 packets input, 706634816920 bytes&lt;BR /&gt;&amp;nbsp;327194378 packets output, 274259325238 bytes&lt;BR /&gt;&amp;nbsp;300365 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 7182 pkts/sec,&amp;nbsp; 983642 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 21990 pkts/sec,&amp;nbsp; 28999034 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 14 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 3620 pkts/sec,&amp;nbsp; 731810 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 6948 pkts/sec,&amp;nbsp; 7747108 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 15 pkts/sec&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/1 "vlan1", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;(Full-duplex), 1000 Mbps(1000 Mbps)&lt;BR /&gt;&amp;nbsp;Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp;...................&lt;BR /&gt;&amp;nbsp;3709153427 packets input, 4231993670446 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp;Received 2946230 broadcasts, 0 runts, 0 giants&lt;BR /&gt;.............................&lt;BR /&gt;&amp;nbsp;3743225801 packets output, 4211235321046 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp;............................&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "vlan1":&lt;BR /&gt;&amp;nbsp;118274767 packets input, 153379837882 bytes&lt;BR /&gt;&amp;nbsp;32079207 packets output, 5847325514 bytes&lt;BR /&gt;&amp;nbsp;33386 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 1922 pkts/sec,&amp;nbsp; 2475670 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 921 pkts/sec,&amp;nbsp; 92641 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 1 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 895 pkts/sec,&amp;nbsp; 1004171 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 520 pkts/sec,&amp;nbsp; 101586 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 1 pkts/sec&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/1.169 "vlan169", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;VLAN identifier 169&lt;BR /&gt;&amp;nbsp;Traffic Statistics for "vlan169":&lt;BR /&gt;&amp;nbsp;1396663 packets input, 232877131 bytes&lt;BR /&gt;&amp;nbsp;1347307 packets output, 1377419222 bytes&lt;BR /&gt;&amp;nbsp;132616 packets dropped&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/1.261 "vlan261", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;VLAN identifier 261&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Traffic Statistics for "vlan261":&lt;BR /&gt;&amp;nbsp;3578891 packets input, 1241639927 bytes&lt;BR /&gt;&amp;nbsp;4083447 packets output, 1785864313 bytes&lt;BR /&gt;&amp;nbsp;127308 packets dropped&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/2 "", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;(Full-duplex), 1000 Mbps(1000 Mbps)&lt;BR /&gt;&amp;nbsp;Input flow control is unsupported, output flow control is off&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;66111356 packets input, 4808097485 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp;Received 671084 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp;...................&lt;BR /&gt;&amp;nbsp;324571395 packets output, 462270967911 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp;...............&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet1/2.15 "vlan15", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82576F rev01, BW 1000 Mbps, DLY 1000 usec&lt;BR /&gt;&amp;nbsp;VLAN identifier 15&lt;BR /&gt;&amp;nbsp;.......................&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "vlan15":&lt;BR /&gt;&amp;nbsp;69304291 packets input, 5616912963 bytes&lt;BR /&gt;&amp;nbsp;327177069 packets output, 456823365866 bytes&lt;BR /&gt;&amp;nbsp;495391 packets dropped&lt;/P&gt;
&lt;P&gt;.................................................................................................................................&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestion/advice for improvement of the interfaces traffic :&lt;/P&gt;
&lt;P&gt;1. Turn on flowcontrol in each interface ?&lt;/P&gt;
&lt;P&gt;2. Split&amp;nbsp;(VLANS) into more physical interfaces, in order to share LAN traffic&lt;/P&gt;
&lt;P&gt;3. enlarge the interface input buffer/output buffer ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405409#M953230</guid>
      <dc:creator>bensonlei</dc:creator>
      <dc:date>2020-02-21T15:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Packet dropped in ASA interfaces</title>
      <link>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405492#M953231</link>
      <description>So far I have only one suggestion: on the switch port used for trunking towards ASA, make sure you allow to the ASA ONLY the VLANs used by the firewall. This should reduce the noise. &lt;BR /&gt;&lt;BR /&gt;Still there's Gi1/0 on your scenario that seems to use an access ports, right?&lt;BR /&gt;Can you share switch port config used to connect Gi1/0? Also can you share swich port statistics used by Gi1/0?</description>
      <pubDate>Tue, 26 Jun 2018 09:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405492#M953231</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-06-26T09:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Packet dropped in ASA interfaces</title>
      <link>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405738#M953232</link>
      <description>&lt;P&gt;Thx for the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A Juniper switch connects to the ASA:&lt;/P&gt;
&lt;P&gt;1. ASA G1/0 is access port.&lt;/P&gt;
&lt;P&gt;2. ASA G1/1 is trunk port in Juniper switch, some VLANs are configured in ASA G1/1, like above:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; G1/1.160, G1/1.261, more than 10 vlans in Gi1/1 interface.&lt;/P&gt;
&lt;P&gt;3. ASA G1/2 is also trunk port in Juniper switch, but there are two vlans in Gi1/2 interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 15:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-dropped-in-asa-interfaces/m-p/3405738#M953232</guid>
      <dc:creator>bensonlei</dc:creator>
      <dc:date>2018-06-26T15:38:38Z</dc:date>
    </item>
  </channel>
</rss>

