CIsco 891-K9 OoO queue overflow
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2012 07:39 AM - edited 03-11-2019 05:35 PM
Cisco 891-K9 router, very basic config, minimal firewall in place.
I keep getting warnings in the log:
Dropping TCP Segment:xxxx is out-of-order... Reason:TCP reassembly queue overflow....
I have increased the size of the ooo queue etc. as follows (increased incrementally up to this point...):
parameter-map type ooo global
tcp reassembly timeout 10
tcp reassembly queue length 128
tcp reassembly memory limit 6144
but I am still getting the same errors in the log. The frequency of them has decreased, but there are still well over 150/day. Anyone have any ideas on where I should go from here?
Thanks!
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-10-2012 09:36 AM
Hello Joel,
Receiving OOO packets it's an issue out of your box, you should not receive this, you should contact your ISP if they are comming from the outside,
Anyway try the following :
ip inspect tcp reassembly
http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i2.html#wp1063773
Regards
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
