<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Dropped Packets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784552#M981307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tcp-map mss-map&lt;/P&gt;&lt;P&gt;  exceed-mss allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may be what you're looking for...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml" target="_blank"&gt;http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2007 14:40:32 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-05-09T14:40:32Z</dc:date>
    <item>
      <title>ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784547#M981302</link>
      <description>&lt;P&gt;How do you troubleshoot drop packets on the asa. What could be the cause?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show interface inside&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0.100 "inside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;        VLAN identifier 100&lt;/P&gt;&lt;P&gt;        MAC address 0018.73d6.eb96, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 192.x.x.219, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "inside":&lt;/P&gt;&lt;P&gt;        130368043 packets input, 31024111730 bytes&lt;/P&gt;&lt;P&gt;        149620357 packets output, 118858910520 bytes&lt;/P&gt;&lt;P&gt;        14532019 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784547#M981302</guid>
      <dc:creator>p-allen</dc:creator>
      <dc:date>2019-03-11T10:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784548#M981303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;#show asp drop&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 12:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784548#M981303</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-09T12:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784549#M981304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. What does this tell me might be the issue?&lt;/P&gt;&lt;P&gt;show asp drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;/P&gt;&lt;P&gt;  Punt rate limit exceeded                                33396&lt;/P&gt;&lt;P&gt;  Invalid encapsulation                                     122&lt;/P&gt;&lt;P&gt;  Invalid TCP Length                                          1&lt;/P&gt;&lt;P&gt;  Invalid UDP Length                                         18&lt;/P&gt;&lt;P&gt;  No valid adjacency                                      33397&lt;/P&gt;&lt;P&gt;  No route to host                                           28&lt;/P&gt;&lt;P&gt;  Flow is denied by configured rule                     2043650&lt;/P&gt;&lt;P&gt;  Flow denied due to resource limitation                   1878&lt;/P&gt;&lt;P&gt;  Invalid SPI                                                65&lt;/P&gt;&lt;P&gt;  NAT-T keepalive message                                   214&lt;/P&gt;&lt;P&gt;  First TCP packet not SYN                               318758&lt;/P&gt;&lt;P&gt;  Bad TCP flags                                               2&lt;/P&gt;&lt;P&gt;  TCP data exceeded MSS                                     818&lt;/P&gt;&lt;P&gt;  TCP failed 3 way handshake                              15408&lt;/P&gt;&lt;P&gt;  TCP RST/FIN out of order                                89306&lt;/P&gt;&lt;P&gt;  TCP SEQ in SYN/SYNACK invalid                               5&lt;/P&gt;&lt;P&gt;  TCP SYNACK on established conn                            136&lt;/P&gt;&lt;P&gt;  TCP packet SEQ past window                               7620&lt;/P&gt;&lt;P&gt;  TCP invalid ACK                                      11271152&lt;/P&gt;&lt;P&gt;  TCP replicated flow pak drop                              546&lt;/P&gt;&lt;P&gt;  TCP Out-of-0rder packet buffer full                     93419&lt;/P&gt;&lt;P&gt;  TCP Out-of-Order packet buffer timeout                  25409&lt;/P&gt;&lt;P&gt;  TCP RST/SYN in window                                    1516&lt;/P&gt;&lt;P&gt;  TCP DUP and has been ACKed                            1572503&lt;/P&gt;&lt;P&gt;  TCP packet failed PAWS test                            380711&lt;/P&gt;&lt;P&gt;  IPSEC tunnel is down                                      207&lt;/P&gt;&lt;P&gt;  Slowpath security checks failed                       1675491&lt;/P&gt;&lt;P&gt;  Dropped by standby unit                                     2&lt;/P&gt;&lt;P&gt;  Expired flow                                            54224&lt;/P&gt;&lt;P&gt;  ICMP Error Inspect different embedded conn               7801&lt;/P&gt;&lt;P&gt;  DNS Inspect id not matched                                 15&lt;/P&gt;&lt;P&gt;  IPS Module requested drop                                   1&lt;/P&gt;&lt;P&gt;  FP L2 rule drop                                        465522&lt;/P&gt;&lt;P&gt;  Interface is down                                         582&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;  Flow is denied by access rule                             192&lt;/P&gt;&lt;P&gt;  Flow terminated by IPS                                      2&lt;/P&gt;&lt;P&gt;  NAT failed                                              32356&lt;/P&gt;&lt;P&gt;  NAT reverse path failed                                  5176&lt;/P&gt;&lt;P&gt;  Need to start IKE negotiation                           15932&lt;/P&gt;&lt;P&gt;  Inspection failure                                        536&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 12:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784549#M981304</guid>
      <dc:creator>p-allen</dc:creator>
      <dc:date>2007-05-09T12:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784550#M981305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Table 25-1 in link below, it explains all values and provides recommendations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/s2_711.html#wp1116367" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/s2_711.html#wp1116367&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate these if they help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 14:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784550#M981305</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-09T14:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784551#M981306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I am thinking this is what we need to do but I am still unsure of the syntax to add this to the asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp-mss-exceeded &lt;/P&gt;&lt;P&gt; TCP data exceeded MSS &lt;/P&gt;&lt;P&gt; This counter is incremented and the packet is dropped when the security appliance receives a TCP packet with a data length greater than the MSS advertised by the peer TCP endpoint. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommendation: To allow such TCP packets, use the exceed-mss command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System log messages: 4419001 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 14:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784551#M981306</guid>
      <dc:creator>p-allen</dc:creator>
      <dc:date>2007-05-09T14:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784552#M981307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tcp-map mss-map&lt;/P&gt;&lt;P&gt;  exceed-mss allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may be what you're looking for...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml" target="_blank"&gt;http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 14:40:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784552#M981307</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-09T14:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784553#M981308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the highest counters seem to be coming from tcp-invalid-ack but there is no fix or recommendtion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp-invalid-ack &lt;/P&gt;&lt;P&gt; TCP invalid ACK &lt;/P&gt;&lt;P&gt; This counter is incremented and the packet is dropped when the security appliance receives a TCP packet with an acknowledgement number greater than the data sent by the peer TCP endpoint. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommendation: None. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System log messages: None. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 14:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784553#M981308</guid>
      <dc:creator>p-allen</dc:creator>
      <dc:date>2007-05-09T14:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784554#M981309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA is doing exactly what it should do with those packets. Packets with invalid ack numbers may come about if a network delivers an old packet or an attacker attempts to hijack a connection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 15:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784554#M981309</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-09T15:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784555#M981310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks. just another question. What would cause an old packet being delivered and how would we track down a hijack attemt if that was the case. I know my boss would want to know that information if available.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 16:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784555#M981310</guid>
      <dc:creator>p-allen</dc:creator>
      <dc:date>2007-05-09T16:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Dropped Packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784556#M981311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After looking at your asp drop output, it looks like your running into bug CSCsc16014&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsc16014" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsc16014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if you are satisfied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2007 01:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropped-packets/m-p/784556#M981311</guid>
      <dc:creator>joshua.walton</dc:creator>
      <dc:date>2007-05-13T01:29:10Z</dc:date>
    </item>
  </channel>
</rss>

