cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
235
Views
2
Helpful
3
Replies

ASA Firewall ASA5508 - Output Queue Packets Dropped

bravealikhan
Level 1
Level 1

Hi,

We have ASA firewall (ASA5508), and observed two issues:

A. getting some packets dropped unter the WAN interface as following:

      output queue (blocks free curr/low): hardware (2047/2000)
      Traffic Statistics for "outside2":
     13231762 packets input, 7067693348 bytes
     9232473 packets output, 1867767940 bytes
    2505518 packets dropped

B. also getting following error when console:

Devicename# show interface
Command authorization failed

MAC decrypt: MAC length error
MAC decrypt: MAC length error

 

any suggestions what could be the possible issues here to be assessed and fixed?

Thanks you

 

3 Replies 3

MacSec config in your network?

MHM

Based on the information provided, there are a few potential issues to assess and address with your ASA5508 firewall: A. Packet drops on the WAN interface:

Interface congestion: The high number of dropped packets (2,505,518) suggests the WAN interface may be experiencing congestion. This could be due to:

-Insufficient bandwidth on the WAN link-

-High traffic volume exceeding the interface capacity

-Misconfigured QoS settings

-Hardware limitations: The ASA5508 has a maximum throughput of around 1 Gbps. If your traffic is approaching or exceeding this limit, it could lead to packet drops. Input/Output errors: Check for any input or output errors on the interface that might be causing packet drops

 

 

To address this Monitor interface utilization and consider upgrading bandwidth if consistently near capacity.

-Review and optimize QoS configurations.

-Check for any physical layer issues on the WAN connection.

-Consider upgrading to a higher capacity firewall model if traffic consistently exceeds device capabilities.

Console errors:

Command authorization failure: This suggests there may be an issue with user privileges or TACACS+/RADIUS configuration

MAC decrypt errors: These could indicate: Encryption key mismatch

To address these issues:-

Verify and correct user authorization settings. Check TACACS+/RADIUS server configuration if used.

troubleshooting

Use th "show asp drop"command to get more detailed information about packet drops

 

 
 
 
please do not forget to rate.

ccieexpert
Spotlight
Spotlight

the packet drop can be for many reasons.. its a generic counter..

Please use this link to troubleshoot it.. asp drop will give you more insight..

https://networklessons.com/cisco/asa-firewall/cisco-asa-packet-drop-troubleshooting#Interface_drops

for mac length error, are you seeing that each time ? is this the case for SSH also ? where is your authentication server located with regards to ASA ? is it in the same subnet. tryign to determine the physical path and if there are any issues with packets getting modified.

did this problem happen on day1 or started recently ? Is NTP synced up ?

Review Cisco Networking for a $25 gift card