cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
229
Views
0
Helpful
2
Replies

IOS ZBPFW

Chris Lester
Level 1
Level 1

Hi All,

When configuring an ASR1001 with ZBPFW, and when using a class class-default / drop log, for an OUTSIDE_TO_SELF zone (basically the outside interface ip address), I do not see the drop action log for any dropped packets, but the drop counter is actualy incrementing.  

 

I know the counter is incrementing because i can firstly see the counters increase, but also because i am specifically sending a load of small packets to the outside interface to see what happens under a DOS type attack.

Is this the expected result or should i actually capture the dropped traffic specifically by creating a dedicated drop class rather than rely on the class-default ?
 

 

Thanks for your help and comments.

Chris.

2 Replies 2

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I think you should still the drop logs on the router.

What is you try to configure a "parameter map" specifically for logging the drops and then reference it in the class-default ?

Also , re-apply the policy-map configuration with "drop log" and see if that resolves this issue.

Have you enabled the Console debugging and verified if you see the drops ?

Thanks and Regards,

Vibhor Amrodia

Sergej Tiurin
Level 1
Level 1

I've got same problem on 15.5 ASR 1001-x.

Does anybody know a solution? This looks a bug to me so far. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card