cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1274
Views
0
Helpful
0
Replies

TCP Out-of-Order packet buffer on FTD

Arashai
Level 1
Level 1

Hey all!

I ran into an issue where our firewall was dropping a lot of packets both through and to it.  The output of 'show asp drop' showed that the amount of drops for TCP Out-of-Order packet buffer full (tcp-buffer-full) and TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) were an order of magnitude greater than drops for any other cause.  I failed over to the secondary firewall, and the network traffic seemed to stabilize.  After a while, I did 'show asp drop' on the secondary (now active) firewall and didn't notice any packets dropped for those reasons.

 

What might be the reasons why the TCP out-of-order packet buffer would fill up?

Is there a way to increase the size of the packet buffer?

Are there any show commands or monitoring techniques (syslog, trap, snmp polling), that would show the status of the buffer or help to troubleshoot it?

 

FTD v6.6.3 managed by FMC

 

Thanks!

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card