cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
499
Views
0
Helpful
2
Replies

Threat detection rate

h.dam
Level 1
Level 1

Hello,

Recently I got a strange message in the FW ASA log like this:

 

drop rate-1 exceeded. Current burst rate is 2 per second, max configured rate is -4; Current average rate is 9 per second, max configured rate is -4; Cumulative total count is 11051

 

While I configured the following line in this FW as:

 

threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200

 

Values in this line are bigger if compare with the error message. I didn't understand why this error appeared.

 

Anyone has encountered this case?

 

Regards.

2 Replies 2

Florin Barhala
Level 6
Level 6
I never configured threat defense, here s what I found:

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html#anc12

Can you post full syslog message? I would also review config guide for the OS version you have on ASA.

Hello,

 

Sorry for the late answer.

The message disappeared these days for unknown reason.

The ASA version is 9.8(1), it is a 5525-X.

 

Regards.

Review Cisco Networking for a $25 gift card