cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
464
Views
0
Helpful
2
Replies

IOS ZBPFW

Chris Lester
Level 1
Level 1

Hi All,

When configuring an ASR1001 with ZBPFW, and when using a class class-default / drop log, for an OUTSIDE_TO_SELF zone (basically the outside interface ip address), I do not see the drop action log for any dropped packets, but the drop counter is actualy incrementing.  

 

I know the counter is incrementing because i can firstly see the counters increase, but also because i am specifically sending a load of small packets to the outside interface to see what happens under a DOS type attack.

Is this the expected result or should i actually capture the dropped traffic specifically by creating a dedicated drop class rather than rely on the class-default ?
 

 

Thanks for your help and comments.

Chris.

2 Replies 2

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I think you should still the drop logs on the router.

What is you try to configure a "parameter map" specifically for logging the drops and then reference it in the class-default ?

Also , re-apply the policy-map configuration with "drop log" and see if that resolves this issue.

Have you enabled the Console debugging and verified if you see the drops ?

Thanks and Regards,

Vibhor Amrodia

Sergej Tiurin
Level 1
Level 1

I've got same problem on 15.5 ASR 1001-x.

Does anybody know a solution? This looks a bug to me so far. 

Review Cisco Networking for a $25 gift card