07-24-2024 05:27 AM
Hi,
We have ASA firewall (ASA5508), and observed two issues:
A. getting some packets dropped unter the WAN interface as following:
output queue (blocks free curr/low): hardware (2047/2000)
Traffic Statistics for "outside2":
13231762 packets input, 7067693348 bytes
9232473 packets output, 1867767940 bytes
2505518 packets dropped
B. also getting following error when console:
Devicename# show interface
Command authorization failed
MAC decrypt: MAC length error
MAC decrypt: MAC length error
any suggestions what could be the possible issues here to be assessed and fixed?
Thanks you
07-24-2024 05:41 AM
MacSec config in your network?
MHM
07-24-2024 06:28 AM - edited 07-24-2024 06:40 AM
Based on the information provided, there are a few potential issues to assess and address with your ASA5508 firewall: A. Packet drops on the WAN interface:
Interface congestion: The high number of dropped packets (2,505,518) suggests the WAN interface may be experiencing congestion. This could be due to:
-Insufficient bandwidth on the WAN link-
-High traffic volume exceeding the interface capacity
-Misconfigured QoS settings
-Hardware limitations: The ASA5508 has a maximum throughput of around 1 Gbps. If your traffic is approaching or exceeding this limit, it could lead to packet drops. Input/Output errors: Check for any input or output errors on the interface that might be causing packet drops
To address this Monitor interface utilization and consider upgrading bandwidth if consistently near capacity.
-Review and optimize QoS configurations.
-Check for any physical layer issues on the WAN connection.
-Consider upgrading to a higher capacity firewall model if traffic consistently exceeds device capabilities.
Console errors:
Command authorization failure: This suggests there may be an issue with user privileges or TACACS+/RADIUS configuration
MAC decrypt errors: These could indicate: Encryption key mismatch
To address these issues:-
Verify and correct user authorization settings. Check TACACS+/RADIUS server configuration if used.
troubleshooting
Use th "show asp drop"command to get more detailed information about packet drops
07-24-2024 07:45 AM
the packet drop can be for many reasons.. its a generic counter..
Please use this link to troubleshoot it.. asp drop will give you more insight..
https://networklessons.com/cisco/asa-firewall/cisco-asa-packet-drop-troubleshooting#Interface_drops
for mac length error, are you seeing that each time ? is this the case for SSH also ? where is your authentication server located with regards to ASA ? is it in the same subnet. tryign to determine the physical path and if there are any issues with packets getting modified.
did this problem happen on day1 or started recently ? Is NTP synced up ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide