03-29-2018 12:22 PM - edited 02-21-2020 07:34 AM
I have One Firewall cluster (Two Firepower 4120) with port-channel configuration to Cisco Nexus 7K with VPC.
There lots of drops on Firepower Port-channel2.86 interface and no drops on Cisco Nexus 7K VPC interface.
Here is output of Port-channel2.86 interface:
Interface Port-channel2.86 "Zone2", is up, line protocol is up
Hardware is EtherSVI, BW 20000 Mbps, DLY 1000 usec
VLAN identifier 86
MAC address 70db.9818.f47e, MTU 1500
IP address 10.2.17.129, subnet mask 255.255.255.248
Traffic Statistics for "Zone2":
7236805478 packets input, 5650848586624 bytes
4859489033 packets output, 779832135681 bytes
25438209 packets dropped
Control Point Interface States:
Interface number is 6
Interface config status is active
Interface state is active
Control Point Vlan86 States:
Interface vlan config status is active
Interface vlan state is UP
And after 10 second again:
Interface Port-channel2.86 "Zone2", is up, line protocol is up
Hardware is EtherSVI, BW 20000 Mbps, DLY 1000 usec
VLAN identifier 86
MAC address 70db.9818.f47e, MTU 1500
IP address 10.2.17.129, subnet mask 255.255.255.248
Traffic Statistics for "Zone2":
7237310145 packets input, 5651241935177 bytes
4859825036 packets output, 779883200691 bytes
25440285 packets dropped
Control Point Interface States:
Interface number is 6
Interface config status is active
Interface state is active
Control Point Vlan86 States:
Interface vlan config status is active
Interface vlan state is UP
After this 10 second is
packet input changed: + 504667 packets
packets dropped + 2076
Which is 0,41% packet dropped.
Does packet dropped means error or lets say that packet has been deny by access rule?
Thank you
Petr
03-30-2018 12:54 PM
03-31-2018 03:05 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide