08-29-2015 04:09 AM - edited 03-11-2019 11:31 PM
Hi All,
When configuring an ASR1001 with ZBPFW, and when using a class class-default / drop log, for an OUTSIDE_TO_SELF zone (basically the outside interface ip address), I do not see the drop action log for any dropped packets, but the drop counter is actualy incrementing.
I know the counter is incrementing because i can firstly see the counters increase, but also because i am specifically sending a load of small packets to the outside interface to see what happens under a DOS type attack.
Is this the expected result or should i actually capture the dropped traffic specifically by creating a dedicated drop class rather than rely on the class-default ?
Thanks for your help and comments.
Chris.
08-30-2015 07:10 AM
Hi,
I think you should still the drop logs on the router.
What is you try to configure a "parameter map" specifically for logging the drops and then reference it in the class-default ?
Also , re-apply the policy-map configuration with "drop log" and see if that resolves this issue.
Have you enabled the Console debugging and verified if you see the drops ?
Thanks and Regards,
Vibhor Amrodia
04-09-2016 06:01 PM
I've got same problem on 15.5 ASR 1001-x.
Does anybody know a solution? This looks a bug to me so far.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide