cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
754
Views
0
Helpful
1
Replies

Traffic Drop to Certain traffic in FTD

Herald Sison
Level 3
Level 3

Hi Experts,

I hope everyone is doing fine and well. I have this problem with my FTD for more than a month already. I will start this out with what happened at first.

I have a ASA5508X hardware running on FTD7.0.6 with FMC 7.3.1.

End of September we installed a new ISP provider (as our 2nd ISP) and added some configurations in the FTD like Interface IP, Static Routing, NAT, ACP, then later on added PBR Flexconfig to have a load balancing traffic sort of. Then everything went well at first but later on we notice that some users will be disconnected from their VMWareHorizon sessions and Tekla Cloud connection and even accessing Cisco sites like cisco community, cisco software and license site and even cisco bug report sites gets timed out.

So we decided to remove the new ISP connection to see if there is some conflict or something wrong with ISP and at that time we are only using 1 ISP provider which is our old ISP since day 1 but the problem persist without any relevant errors (only errors that says about security intelligence "Cisco-DNS-and-URL-Intelligence-Feed - Unable to determine a host for downloading Cisco_DNS_Intelligence_Feed from the manifest file") and i know for a fact that this error just came out just because of the same connection problem with the whole network are experiencing so we decided to reboot the FTD box and after rebooting the problem got fixed and we continue our monitoring.

But after 2 days the problem went back again and whatever we do like removing ACP policy and just remain the default ACP which is the allow ALL rule, removing the PBR Flexconfig, removing the NAT of the newly installed ISP, removing the routing of the newly installed ISP and removing the interface settings of the newly installed ISP but nothing seems to be working so we decided to reboot the FTD box and after rebooting the problem will get fixed again,

Weeks later after experiencing the same problem over and over again we finally decided to isolate the FTD and upgrade version of both the FTD 7.0.5 and FMC 7.3.0 to FTD 7.0.6 and FMC 7.3.0. then continue monitoring the FTD in an isolated network with 1 ISP and 1 LAN directly connected to a Laptop.

Then just this week we decided to reintegrate the FTD to the internal network hoping that the problem is already fixed by the FTD upgrade but we were wrong. The problem still persist but for now we monitored that users who uses TeklaCloud connection gets disconnected and we do not know anymore what is really happening.

So since day 1 i am in contact with TAC but they themselves cant pin point what is happening they just keep looking on the blocking of the URL or the ACP side which we already disabled so there is no way that there is a category or url blocking happening here. Then just this morning i have requeued my SR to another TAC then what he did is to add a Pre Filter policy and just add 1 VLAN of users who are using TeklaCloud and leave the rest as is then observe if there will be a difference in between then he ran some show asp drop and it shows these data below:

4211a04f-fc37-4d26-a9f7-88bba6ac734b.png

thumbnail_image002.png

my Questions:

1) will these data above from ASP Drop will show us that there is really a traffic problem or dropping of packets happening that is related to the problem that we are facing right now?

2) awhile ago i have added some settings in the Platform settings like these below,

changing the Expiry Entry Timer under DNS Settings in Platform Settings from 1 to 5

Capture.JPG

changing the rate limit and burst size in ICMP UnReachable from 1 to 5 and addes some ICMP service below

3f5291f2-ad94-4b6f-8b81-2906fbc86534.jpg

after changing these values and deploying it all Tekla Access went down and even our Amazon access also went down so i reverted it back and clear all what i added then redeloy it fixed the problem. Will these changes really affect the network? I am not really sure why only certain service or website or access are affected and not all like facebook,youtube,teams,outlook. only specific accesses are affected.

3) After i upgraded my FTD to the latest version 7.0.6 with hotfix applied i got an error from FMC which is this bug https://bst.cisco.com/bugsearch/bug/CSCwh25668 titled ASA 55xx devices running 7.0.6 show up as 100% usage on CPU01 [LINA] and that is exactly the error i got from my end so i concluded that i hit a bug in my FTD so i raised a TAC SR on this one and the TAC told me and assured my that this will not affect the FTD performance and will not disrupt any traffic and there will be a fix soon next month as per what they say. so my question is, will this bug really not affecting my FTD's performance?

4) Does anyone had a similar issue with our FTD? what did you guys do? what are the steps and procedure you had to finally hit the root cause of this problem and what was the resolutions?

5) Does pre-filter policy means that it will bypass all the ACP rule created including the default traffic analyzing rule? would that mean all traffic are bypassed? Would that help in troubleshooting this case?

Capture3.JPG

6) Would there be a possibility that this is a hardware problem already or just another firmware bug that has not been addressed by Cisco engineers? Or just another misconfiguration on my part (which is less likely to happen because the whole configuration was running smoothly way back 3 years ago and only this time this problem came out just right after we added the new ISP and even removing the new configurations for the new ISP did not help or solve the problem or even reverting the configuration back to when it was configured before was not helping at all).

 7) my Final question is, what would be the best thing to really pin point the root cause of this issue that has been giving us sleepless nights and headache for more than a month already. What would be our 1st course of action and what is our go to in this case?

I know this is a long and bit dumb question from me but i really need some help from this community so badly and this is considered urgent since the whole network is being compromised and the amount of time we spent in solving this case is wasted to nothing. i hope you experts can guide me on what is the best option for this case. I hope someone can help me on this.

 

Thanks you and more power to us all here!

1 Reply 1

Herald Sison
Level 3
Level 3

UPDATE ON THIS ONE: We have removed all blocking in ACP rules and added pre filter policy any any to see if there is still blocking or something and still there is. This blocked traffic was not shown in FMC and its weird. Is this some kind of a bug for FTD7.0.5 to 7.0.6?

 

show asp drop

Frame drop:
SVC Module does not have a session (mp-svc-no-session) 2
Flow is being freed (flow-being-freed) 9
Invalid TCP Length (invalid-tcp-hdr-length) 1
No route to host (no-route) 359
Flow is denied by configured rule (acl-drop) 2154
First TCP packet not SYN (tcp-not-syn) 805
Bad TCP flags (bad-tcp-flags) 2
TCP failed 3 way handshake (tcp-3whs-failed) 63
TCP RST/FIN out of order (tcp-rstfin-ooo) 1217
TCP packet SEQ past window (tcp-seq-past-win) 12
TCP invalid ACK (tcp-invalid-ack) 1
TCP RST/SYN in window (tcp-rst-syn-in-win) 1
Slowpath security checks failed (sp-security-failed) 2
FP L2 rule drop (l2_acl) 2
Dropped pending packets in a closed socket (np-socket-closed) 18
TCP Proxy retransmited packet drop (tcp-proxy-retransmit-drop) 15
Packet is blocked as requested by snort (snort-block) 4792
Packet is dropped silently as requested by snort (snort-silent-drop) 42

Last clearing: 11:58:30 UTC Nov 2 2023 by enable_15

Flow drop:

 

and these list below goes on. In summary snort is blocking traffic even if there is NO blocked rule set in ACP and already added Pre-Filter policy as "fastpath".

 

 

611: 12:08:25.757605 172.20.5.105.56441 > 184.51.102.242.443: P 3884664373:3884664560(187) ack 1676388085 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

612: 12:08:26.341184 172.20.9.101.64185 > 13.107.136.10.443: P 3069184709:3069185208(499) ack 105633280 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

613: 12:08:26.595412 172.20.5.121.54750 > 13.107.136.10.443: P 2826234418:2826234917(499) ack 953425473 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

614: 12:08:26.720864 172.20.5.105.5173 > 52.97.176.2.443: . ack 0 win 32768 <mss 1380> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

615: 12:08:26.737648 172.20.5.105.5173 > 52.97.176.2.443: P 1484856145:1484856366(221) ack 4262239437 win 32768 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

616: 12:08:26.802875 172.20.9.105.62547 > 34.210.133.91.443: P 525896683:525896900(217) ack 296975548 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

617: 12:08:26.939938 172.20.5.100.52917 > 13.107.138.10.443: P 1858999217:1858999716(499) ack 4266809705 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

618: 12:08:26.981257 52.97.176.2.443 > 172.20.5.105.5173: . 4262239437:4262240817(1380) ack 1484856355 win 64650 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

619: 12:08:26.981364 52.97.176.2.443 > 172.20.5.105.5173: . 4262240817:4262242197(1380) ack 1484856355 win 64650 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

620: 12:08:27.153236 172.20.30.76.54187 > 13.107.136.10.443: P 4209568914:4209569413(499) ack 2502841473 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

621: 12:08:27.154029 172.20.5.105.56442 > 52.97.176.2.443: P 2346894650:2346894871(221) ack 3138546894 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

622: 12:08:27.733284 172.20.9.126.50331 > 13.107.136.10.443: P 730348968:730349467(499) ack 2361574026 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

623: 12:08:27.823733 172.20.250.120.55119 > 54.212.129.36.443: P 2497488950:2497489167(217) ack 2607241510 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

624: 12:08:28.146415 172.20.5.100.52918 > 20.190.148.163.443: P 4003875469:4003875679(210) ack 813672951 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

625: 12:08:28.415780 172.20.5.105.56444 > 52.98.70.130.443: P 282186649:282186840(191) ack 112960999 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

626: 12:08:28.481054 172.20.30.150.50230 > 20.44.10.122.443: P 4266569647:4266569876(229) ack 3068633249 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

627: 12:08:28.706918 172.20.9.104.56111 > 35.155.212.150.443: P 2613311376:2613311593(217) ack 2466589769 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

628: 12:08:28.972316 172.20.5.102.55755 > 52.98.43.178.443: P 4124921110:4124921624(514) ack 2828701407 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

629: 12:08:28.978541 172.20.5.102.55756 > 52.98.43.178.443: P 3920614314:3920614828(514) ack 3593162594 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

630: 12:08:29.023390 172.20.5.105.56445 > 52.98.43.130.443: P 1598968352:1598968541(189) ack 2650001216 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

631: 12:08:29.069469 172.20.5.100.52919 > 13.107.6.158.443: P 3297516553:3297517144(591) ack 799501588 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

632: 12:08:29.172094 172.20.5.108.59280 > 35.163.92.41.443: P 625628719:625628936(217) ack 725493573 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

633: 12:08:29.446876 172.20.5.101.51365 > 116.89.245.146.443: P 4184529823:4184530340(517) ack 3928998689 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

634: 12:08:29.470816 172.20.9.104.56112 > 35.155.212.150.443: P 720525883:720526100(217) ack 2493139985 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

635: 12:08:29.571763 172.20.5.105.56446 > 13.107.6.163.443: P 3483313727:3483313922(195) ack 227698044 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

636: 12:08:29.939145 172.20.5.108.59281 > 35.163.92.41.443: P 1236543614:1236543831(217) ack 1040218676 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

637: 12:08:30.961559 172.20.9.101.64186 > 20.189.173.14.443: P 460058546:460058777(231) ack 1061071162 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

638: 12:08:31.503575 172.20.5.121.54751 > 13.69.239.74.443: P 328719777:328720008(231) ack 2395181166 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

639: 12:08:32.330656 172.20.5.118.59247 > 20.107.224.24.443: P 1433851079:1433851302(223) ack 1746770174 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

640: 12:08:33.220081 172.20.5.102.55757 > 20.198.147.210.443: P 2429319250:2429319767(517) ack 1131663302 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

641: 12:08:33.371333 172.20.30.67.49635 > 20.198.147.210.443: P 884097789:884098306(517) ack 1300901320 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

642: 12:08:34.484105 172.20.1.100.56619 > 52.123.170.27.443: P 1678373956:1678374473(517) ack 89195059 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

643: 12:08:35.372844 172.20.30.150.50233 > 52.123.129.14.443: P 3956863250:3956863843(593) ack 3410539965 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

644: 12:08:36.088771 172.20.30.150.50236 > 52.114.133.157.443: P 1312009390:1312009907(517) ack 1929947545 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

645: 12:08:36.226703 172.20.1.100.56621 > 142.251.220.227.443: P 780633335:780634334(999) ack 2575137138 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

646: 12:08:36.331830 172.20.30.150.50237 > 52.114.133.157.443: P 569883686:569884203(517) ack 1968972042 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

647: 12:08:37.344556 172.20.5.111.62740 > 54.212.129.36.443: P 3426116287:3426116504(217) ack 2661109920 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

648: 12:08:37.648846 172.20.5.136.57186 > 20.190.144.163.443: P 2377328946:2377329156(210) ack 2844905845 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

649: 12:08:38.301833 172.20.5.136.57187 > 40.65.170.106.443: P 2793460494:2793460692(198) ack 1345632796 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

650: 12:08:38.315520 172.20.5.111.62741 > 35.82.89.103.443: P 104791613:104791830(217) ack 3010422721 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

651: 12:08:38.320890 172.20.5.136.57188 > 13.107.6.158.443: P 13472149:13472659(510) ack 731440619 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

652: 12:08:38.323286 172.20.5.136.57189 > 13.107.6.158.443: P 3326316501:3326317019(518) ack 1886663738 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

653: 12:08:38.325437 172.20.5.136.57190 > 13.107.6.158.443: P 3732025772:3732026282(510) ack 1922244777 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

654: 12:08:38.769567 172.20.5.136.57191 > 20.190.144.163.443: P 3585379293:3585379503(210) ack 3735173898 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

655: 12:08:39.258897 172.20.9.100.51865 > 40.79.141.154.443: P 694529013:694529242(229) ack 1400174017 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

656: 12:08:39.655529 172.20.5.123.61810 > 13.107.21.239.443: P 4282926040:4282926557(517) ack 3556114015 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

657: 12:08:39.740028 172.20.5.136.57193 > 20.190.144.163.443: P 3436598710:3436598920(210) ack 3685639014 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

658: 12:08:39.794377 172.20.5.123.61811 > 184.85.110.111.443: P 4134372582:4134372926(344) ack 2797784699 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

659: 12:08:40.456778 172.20.250.113.54621 > 35.163.92.41.443: P 3783902584:3783902801(217) ack 3017367878 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

660: 12:08:40.706964 172.20.5.118.59250 > 54.212.129.36.443: P 4154798639:4154798856(217) ack 3886472970 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

661: 12:08:40.794865 172.20.9.113.62989 > 13.71.55.58.443: P 1599340340:1599340556(216) ack 1713271760 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

662: 12:08:41.372585 172.20.250.113.54622 > 35.163.92.41.443: P 2108906708:2108906925(217) ack 1159840888 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

663: 12:08:41.496632 172.20.5.118.59251 > 54.212.129.36.443: P 3949015375:3949015592(217) ack 1709600033 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

664: 12:08:42.201848 172.20.9.113.62990 > 13.71.55.58.443: P 1877382069:1877382285(216) ack 1681805292 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

665: 12:08:43.505314 172.20.250.118.57914 > 184.85.108.47.443: P 1891254876:1891255541(665) ack 2277189710 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

666: 12:08:43.743796 172.20.5.101.19114 > 3.213.245.79.443: . ack 0 win 32768 <mss 1380> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

667: 12:08:43.764990 172.20.5.101.19114 > 3.213.245.79.443: P 874107711:874108042(331) ack 777897164 win 32768 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

668: 12:08:44.019606 3.213.245.79.443 > 172.20.5.101.19114: . 777897164:777897268(104) ack 874107935 win 27872 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

669: 12:08:44.023894 3.213.245.79.443 > 172.20.5.101.19114: . 777897268:777898544(1276) ack 874107935 win 27872 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

670: 12:08:44.024031 3.213.245.79.443 > 172.20.5.101.19114: . 777898544:777899924(1380) ack 874107935 win 27872 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

671: 12:08:44.024122 3.213.245.79.443 > 172.20.5.101.19114: . 777899924:777901304(1380) ack 874107935 win 27872 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

672: 12:08:44.024214 3.213.245.79.443 > 172.20.5.101.19114: . 777901304:777902684(1380) ack 874107935 win 27872 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

673: 12:08:44.233325 172.20.5.101.51369 > 3.213.245.79.443: P 1497594366:1497594697(331) ack 1364879924 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

674: 12:08:44.922010 172.20.1.33.45710 > 52.21.117.50.443: P 3670049487:3670050116(629) ack 3656889606 win 502 <nop,nop,timestamp 1054725746 524009204> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

675: 12:08:47.858231 172.20.5.101.51370 > 52.123.128.14.443: P 532100446:532100963(517) ack 2421374708 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

676: 12:08:48.048856 172.20.5.105.56453 > 184.85.108.47.443: P 3720313399:3720314072(673) ack 2589857537 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

677: 12:08:48.467291 172.20.30.76.54190 > 52.178.17.233.443: P 473190441:473190672(231) ack 1138572326 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

678: 12:08:48.715935 172.20.5.105.56457 > 184.85.108.47.443: P 2615952472:2615953145(673) ack 2327808280 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

679: 12:08:49.905638 172.20.5.101.51372 > 20.42.73.25.443: P 2157209202:2157209719(517) ack 2479758332 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

680: 12:08:50.160956 172.20.5.101.51373 > 20.42.73.25.443: P 312265781:312266298(517) ack 4207935753 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

681: 12:08:50.577927 172.20.1.100.56624 > 142.251.221.4.443: P 3023112331:3023113382(1051) ack 1308017647 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

682: 12:08:50.708245 172.20.1.100.56625 > 142.251.220.227.443: P 4096099886:4096100885(999) ack 2912501218 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

683: 12:08:51.182256 172.20.9.108.49913 > 184.85.110.57.443: P 1721580244:1721580592(348) ack 3269961279 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

684: 12:08:51.197285 172.20.9.108.49914 > 184.85.110.57.443: P 2982423945:2982424293(348) ack 3535083529 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

685: 12:08:51.279831 172.20.5.101.51374 > 104.22.18.138.443: P 466263454:466263971(517) ack 2134534611 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

686: 12:08:51.480504 172.20.5.101.51375 > 104.22.18.138.443: P 1006462929:1006463446(517) ack 3856442842 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

687: 12:08:51.837725 172.20.9.108.49916 > 184.85.110.57.443: P 1412728400:1412728748(348) ack 2332176017 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

688: 12:08:51.853318 172.20.9.108.49915 > 184.85.110.57.443: P 2125465914:2125466262(348) ack 2277193792 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

689: 12:08:51.972941 172.20.250.117.54323 > 35.82.89.103.443: P 4098171289:4098171506(217) ack 1927978297 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

690: 12:08:52.660869 172.20.5.101.51377 > 104.22.19.138.443: P 3271600004:3271600181(177) ack 4043002953 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

691: 12:08:53.628034 172.20.250.117.54324 > 35.82.89.103.443: P 1312573105:1312573322(217) ack 742443388 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

692: 12:08:54.677043 172.20.5.115.57437 > 40.99.8.210.443: P 1502183136:1502183342(206) ack 4001745951 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

693: 12:08:56.468725 172.20.30.121.63658 > 13.71.55.58.443: P 3426884323:3426884539(216) ack 1889470423 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

694: 12:08:56.515186 198.148.79.58.443 > 172.20.1.33.57988: . 842567967:842569335(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453433605 1633749342> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

695: 12:08:58.768102 172.20.5.121.54754 > 20.189.173.14.443: P 2457575276:2457575505(229) ack 1066824358 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

696: 12:08:59.500950 172.20.1.100.56629 > 20.210.64.12.443: P 1142473371:1142473910(539) ack 4094479587 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

697: 12:08:59.502384 172.20.1.100.56630 > 20.210.64.12.443: P 2827521855:2827522458(603) ack 884522840 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

698: 12:09:01.418099 172.20.9.110.61315 > 52.27.216.242.443: P 1730856419:1730856636(217) ack 167931819 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

699: 12:09:02.185079 172.20.9.110.61316 > 52.27.216.242.443: P 2522369486:2522369703(217) ack 1756024081 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

700: 12:09:02.190267 172.20.5.123.61814 > 184.85.108.47.443: P 1851015060:1851015733(673) ack 1153142219 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

701: 12:09:02.284576 172.20.5.111.62743 > 52.113.194.132.443: P 540844267:540844867(600) ack 1653980061 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

702: 12:09:02.523746 172.20.1.102.62811 > 52.184.212.181.443: P 345122502:345122724(222) ack 635117327 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

703: 12:09:03.430504 198.148.79.58.443 > 172.20.1.33.57988: . 842611743:842613111(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453440495 1633756233> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

704: 12:09:03.588394 172.20.250.119.63980 > 44.232.14.118.443: P 3907738541:3907738761(220) ack 1730480696 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

705: 12:09:03.654415 172.20.5.100.52920 > 204.79.197.239.443: P 563317195:563317712(517) ack 1625812792 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

706: 12:09:05.893157 172.20.9.111.61459 > 54.212.129.36.443: P 1726065828:1726066045(217) ack 1311235041 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

707: 12:09:06.662822 172.20.9.111.61460 > 54.212.129.36.443: P 2947630246:2947630463(217) ack 3901687469 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

708: 12:09:06.716027 172.20.5.108.59286 > 13.69.239.72.443: P 870947769:870948000(231) ack 3801986476 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

709: 12:09:08.122781 172.20.5.101.51381 > 52.206.187.20.443: P 3923977433:3923977750(317) ack 3471159189 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

710: 12:09:08.570756 198.148.79.58.443 > 172.20.1.33.57988: . 842663727:842665095(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453445645 1633761382> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

711: 12:09:09.049252 172.20.9.104.56117 > 20.54.25.4.443: P 2727101554:2727101776(222) ack 3350830336 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

712: 12:09:09.242571 172.20.1.100.56633 > 52.27.216.242.443: P 1453977430:1453977647(217) ack 2985778112 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

713: 12:09:10.105158 172.20.1.100.56634 > 52.27.216.242.443: P 398195908:398196125(217) ack 1025667839 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

714: 12:09:10.489919 172.20.250.112.61918 > 35.82.89.103.443: P 357661832:357662049(217) ack 1315515036 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

715: 12:09:10.537249 172.20.5.121.54755 > 13.107.21.239.443: P 3668588657:3668589174(517) ack 3259465698 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

716: 12:09:10.679850 172.20.30.150.50243 > 20.189.173.8.443: P 871504529:871504758(229) ack 1865666161 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

717: 12:09:11.040998 172.20.250.119.63982 > 35.155.212.150.443: P 2099949817:2099950034(217) ack 2848011663 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

718: 12:09:11.599776 172.20.5.131.63772 > 52.109.124.29.443: P 1142577455:1142577649(194) ack 946294230 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

719: 12:09:12.480367 172.20.5.118.59266 > 18.172.21.98.443: P 4120600510:4120600827(317) ack 860244576 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

720: 12:09:12.675395 172.20.250.112.61919 > 35.82.89.103.443: P 1555892597:1555892814(217) ack 2265884082 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

721: 12:09:12.790806 172.20.5.118.59267 > 204.79.197.203.443: P 2021359346:2021359542(196) ack 2420955046 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

722: 12:09:12.858048 172.20.5.118.59268 > 23.33.92.51.443: P 2770567136:2770567333(197) ack 2922819840 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

723: 12:09:13.697427 172.20.9.101.64192 > 40.126.35.145.443: P 2629069877:2629070087(210) ack 664069558 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

724: 12:09:13.730720 172.20.9.126.50337 > 52.123.128.14.443: P 3730855844:3730856361(517) ack 3895356965 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

725: 12:09:14.111947 172.20.5.118.59269 > 204.79.197.203.443: P 3704819223:3704819740(517) ack 3281262202 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

726: 12:09:14.125008 172.20.30.129.48798 > 142.251.221.2.443: P 4191644789:4191645306(517) ack 44113827 win 343 <nop,nop,timestamp 185101739 568107407> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

727: 12:09:14.127770 172.20.5.131.63773 > 52.98.84.98.443: P 892460888:892461402(514) ack 2643962411 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

728: 12:09:14.307265 172.20.5.118.59272 > 204.79.197.200.443: P 956673000:956673517(517) ack 4146486839 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

729: 12:09:14.308943 172.20.9.101.64193 > 13.107.6.158.443: P 436295193:436295784(591) ack 1108653051 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

730: 12:09:14.320097 172.20.5.118.59273 > 204.79.197.203.443: P 718520579:718521096(517) ack 931411825 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

731: 12:09:14.323454 172.20.5.118.59271 > 20.205.115.81.443: P 3223184485:3223185002(517) ack 1779716384 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

732: 12:09:14.328611 172.20.5.118.59274 > 204.79.197.203.443: P 1844799915:1844800432(517) ack 2164547842 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

733: 12:09:14.345547 172.20.5.118.59270 > 23.33.92.62.443: P 2514790300:2514790817(517) ack 2543374909 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

734: 12:09:14.355129 172.20.5.118.59277 > 108.158.213.34.443: P 4204370561:4204371078(517) ack 2911248730 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

735: 12:09:14.377437 172.20.5.118.59275 > 23.55.47.58.443: P 4030279738:4030280255(517) ack 3080896421 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

736: 12:09:14.377559 172.20.5.118.59276 > 23.55.47.58.443: P 583118:583635(517) ack 1085076203 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

737: 12:09:14.397531 172.20.5.118.59278 > 116.89.245.146.443: P 904235979:904236496(517) ack 2322315470 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

738: 12:09:14.489018 172.20.5.118.59279 > 13.107.6.158.443: P 1641941967:1641942484(517) ack 2202435739 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

739: 12:09:14.492741 172.20.5.118.59280 > 40.126.35.153.443: P 573333430:573333947(517) ack 2331480944 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

740: 12:09:15.248095 172.20.5.118.59281 > 116.89.245.163.443: P 2060258876:2060259393(517) ack 252865561 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

741: 12:09:16.105036 172.20.5.118.59282 > 204.79.197.203.443: P 4081770455:4081770972(517) ack 4028687950 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

742: 12:09:16.307097 172.20.1.32.53074 > 52.21.117.50.443: P 3713869798:3713870427(629) ack 4113967086 win 502 <nop,nop,timestamp 3447465407 524040548> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

743: 12:09:17.197926 172.20.5.134.52643 > 23.32.77.211.443: P 3974855531:3974856048(517) ack 3961864904 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

744: 12:09:17.685755 172.20.5.136.57206 > 52.98.33.130.443: P 3263772500:3263773014(514) ack 2055469834 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

745: 12:09:18.536333 172.20.9.102.63855 > 35.155.212.150.443: P 2055867142:2055867359(217) ack 697383897 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

746: 12:09:18.636990 198.148.79.58.443 > 172.20.1.33.57988: . 842745819:842747187(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453455725 1633771463> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

747: 12:09:18.755896 172.20.5.136.57207 > 13.107.6.171.443: P 1232941400:1232941917(517) ack 2201799272 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

748: 12:09:18.817401 172.20.9.126.50338 > 20.189.173.11.443: P 2924960249:2924960478(229) ack 344837636 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

749: 12:09:18.947918 172.20.5.127.58518 > 20.54.25.4.443: P 2629087243:2629087465(222) ack 98592539 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

750: 12:09:18.950909 172.20.5.127.58519 > 20.54.25.4.443: P 4288171688:4288171910(222) ack 2949961433 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

751: 12:09:19.300887 172.20.9.102.63856 > 35.155.212.150.443: P 1020886765:1020886982(217) ack 2383410266 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

752: 12:09:22.219349 172.20.5.115.57441 > 35.82.89.103.443: P 2734717870:2734718087(217) ack 2762940379 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

753: 12:09:22.788060 172.20.5.131.63780 > 18.138.42.222.443: P 2944660871:2944661191(320) ack 3509496819 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

754: 12:09:22.803989 172.20.250.122.60266 > 52.184.216.174.443: P 1671962970:1671963192(222) ack 3569950966 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

755: 12:09:22.819278 172.20.1.40.57666 > 104.18.28.159.443: P 2460646823:2460647340(517) ack 3662113854 win 32768 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

756: 12:09:24.079051 172.20.1.40.57672 > 104.18.110.87.443: P 4007486100:4007486617(517) ack 2744361337 win 32768 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

757: 12:09:24.153480 172.20.250.118.57917 > 20.44.10.123.443: P 3725095814:3725096028(214) ack 2269191502 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

758: 12:09:24.342999 172.20.5.136.57210 > 52.112.92.67.443: P 3230056116:3230056633(517) ack 1588602120 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

759: 12:09:25.923826 172.20.5.134.52652 > 54.212.129.36.443: P 3310366908:3310367125(217) ack 288698787 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

760: 12:09:26.607222 172.20.5.127.58522 > 20.44.10.123.443: P 1480108343:1480108557(214) ack 2329282760 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

761: 12:09:27.632871 172.20.5.134.52657 > 23.32.77.211.443: P 2390854705:2390855222(517) ack 4207746282 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

762: 12:09:27.859528 172.20.5.134.52658 > 23.32.77.211.443: P 641835206:641835723(517) ack 3368284541 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

763: 12:09:28.057446 172.20.5.120.51245 > 52.27.216.242.443: P 718320489:718320706(217) ack 1535438823 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

764: 12:09:28.234530 172.20.9.105.62616 > 35.82.89.103.443: P 3087990571:3087990788(217) ack 3610821456 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

765: 12:09:28.743690 172.20.9.111.61464 > 51.104.164.114.443: P 3087425635:3087425857(222) ack 3826626830 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

766: 12:09:28.834810 172.20.5.120.51246 > 52.27.216.242.443: P 3090557877:3090558094(217) ack 1731486710 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

767: 12:09:28.920942 172.20.5.113.51672 > 20.54.25.4.443: P 941794917:941795139(222) ack 4227565432 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

768: 12:09:29.347745 172.20.9.110.61319 > 20.54.25.4.443: P 1461155079:1461155301(222) ack 3127995256 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

769: 12:09:32.063183 172.20.5.131.63787 > 52.123.170.25.443: P 3504643771:3504644288(517) ack 4062840299 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

770: 12:09:32.257783 172.20.5.106.62942 > 23.46.196.74.443: P 2389591705:2389592378(673) ack 1760413932 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

771: 12:09:32.578644 172.20.5.115.57442 > 116.89.245.152.443: P 3800932949:3800933576(627) ack 2339318964 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

772: 12:09:33.829028 172.20.5.113.51675 > 34.210.133.91.443: P 2425422866:2425423083(217) ack 3687518803 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

773: 12:09:33.999490 172.20.9.126.50343 > 20.189.173.16.443: P 3604075779:3604076008(229) ack 4100020169 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

774: 12:09:34.879028 198.148.79.58.443 > 172.20.1.33.57988: . 842970171:842971539(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453471935 1633787675> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

775: 12:09:34.933911 172.20.5.113.51676 > 34.210.133.91.443: P 458062803:458063020(217) ack 4034961125 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

776: 12:09:35.869629 172.20.5.127.58524 > 52.27.216.242.443: P 4152031974:4152032191(217) ack 3878515344 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

777: 12:09:36.512684 172.20.1.100.56641 > 216.239.32.116.443: P 247186487:247187480(993) ack 1077519751 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

778: 12:09:36.608839 172.20.1.100.56640 > 74.125.142.94.443: P 90177835:90178892(1057) ack 3034524732 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

779: 12:09:36.629636 172.20.5.127.58525 > 52.27.216.242.443: P 1251847897:1251848114(217) ack 4229869661 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

780: 12:09:36.760596 172.20.5.136.57214 > 13.107.42.16.443: P 3844703344:3844703861(517) ack 572301063 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

781: 12:09:36.886566 172.20.5.136.57215 > 34.160.176.28.443: P 449456090:449456490(400) ack 588185795 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

782: 12:09:37.774282 198.148.79.58.443 > 172.20.1.33.57988: . 843007107:843008475(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453474855 1633790586> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

783: 12:09:38.287857 172.20.5.101.51391 > 132.226.193.252.443: P 3674500152:3674500669(517) ack 1933783353 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

784: 12:09:38.571152 172.20.5.116.52055 > 23.46.196.74.443: P 4046987742:4046988407(665) ack 1996927243 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

785: 12:09:40.470999 172.20.5.134.52671 > 13.107.21.239.443: P 1987710410:1987711002(592) ack 1085618545 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

786: 12:09:40.992593 172.20.5.121.54758 > 18.172.21.81.443: P 2949739837:2949740150(313) ack 784803301 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

787: 12:09:42.549318 172.20.5.131.63794 > 35.155.212.150.443: P 3320962081:3320962298(217) ack 769901411 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

788: 12:09:43.326460 172.20.5.131.63795 > 35.155.212.150.443: P 2522534365:2522534582(217) ack 330624694 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

789: 12:09:44.256090 172.20.1.33.50300 > 208.90.58.6.443: P 1396843818:1396844335(517) ack 3348511228 win 502 <nop,nop,timestamp 986054109 2035678428> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

790: 12:09:44.458823 172.20.5.134.52672 > 116.89.245.163.443: P 2364379777:2364380406(629) ack 2553756997 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

791: 12:09:44.493947 172.20.5.101.51394 > 23.22.147.252.443: P 3219284260:3219284582(322) ack 2970874023 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

792: 12:09:44.829806 172.20.5.121.54759 > 35.163.92.41.443: P 784457242:784457459(217) ack 621739782 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

793: 12:09:44.926130 172.20.1.33.33726 > 52.70.61.174.443: P 1085484048:1085484677(629) ack 820075692 win 502 <nop,nop,timestamp 929872605 451686116> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

794: 12:09:45.089076 172.20.5.134.52674 > 23.32.77.211.443: P 240671366:240671883(517) ack 3940638584 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

795: 12:09:45.598937 172.20.5.121.54760 > 35.163.92.41.443: P 3923899976:3923900193(217) ack 1037722772 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

796: 12:09:45.819705 172.20.5.101.51395 > 54.209.97.164.443: P 1408747588:1408747906(318) ack 3172854021 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

797: 12:09:46.206517 172.20.30.67.49644 > 23.46.196.74.443: P 1616531174:1616531839(665) ack 1055736669 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

798: 12:09:49.776296 172.20.5.136.57223 > 52.108.8.12.443: P 3626651475:3626652074(599) ack 810772250 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

799: 12:09:50.997461 172.20.5.131.63802 > 35.155.212.150.443: P 872720569:872720786(217) ack 2150815111 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

800: 12:09:52.831164 172.20.1.40.57679 > 38.91.40.244.443: P 3397811513:3397812030(517) ack 908223796 win 32768 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

801: 12:09:54.167029 172.20.5.101.51399 > 3.226.53.215.443: P 4098791590:4098791907(317) ack 4066138202 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

802: 12:09:55.066814 172.20.9.108.49926 > 51.104.164.114.443: P 3669996992:3669997214(222) ack 3673127898 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

803: 12:09:55.924497 172.20.5.123.61817 > 204.79.197.239.443: P 2344704619:2344705136(517) ack 12111061 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

804: 12:09:57.499058 172.20.250.119.64043 > 51.11.168.232.443: P 1529264904:1529265120(216) ack 237817496 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

805: 12:09:57.705346 172.20.5.102.55764 > 35.155.212.150.443: P 4119840978:4119841195(217) ack 1705320589 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

806: 12:09:59.212666 172.20.5.136.57227 > 35.163.92.41.443: P 321048838:321049055(217) ack 1146617390 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

807: 12:09:59.859742 172.20.5.134.52690 > 20.190.163.21.443: P 2561499889:2561500099(210) ack 469046272 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

808: 12:09:59.980418 172.20.5.136.57228 > 35.163.92.41.443: P 1122461432:1122461649(217) ack 2168639404 win 512 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

809: 12:10:00.505634 172.20.1.16.64608 > 44.227.188.64.443: P 3353960478:3353960665(187) ack 2741255141 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

810: 12:10:00.551683 172.20.5.134.52697 > 40.65.170.106.443: P 2656421199:2656421429(230) ack 423911865 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

811: 12:10:00.693003 172.20.5.134.52699 > 20.24.125.47.443: P 704472530:704472740(210) ack 1152423775 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

812: 12:10:00.694315 172.20.1.40.57680 > 44.226.202.197.443: P 1605043994:1605044181(187) ack 1338022148 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

813: 12:10:00.802967 198.148.79.58.443 > 172.20.1.33.57988: . 843317667:843319035(1368) ack 3757691581 win 1035 <nop,nop,timestamp 453497895 1633813628> Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

814: 12:10:01.251039 172.20.1.41.53915 > 44.227.188.64.443: P 1877619084:1877619315(231) ack 1426063874 win 258 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

815: 12:10:02.547441 172.20.5.123.61818 > 20.54.24.169.443: P 3668837293:3668837515(222) ack 4095533927 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

816: 12:10:03.155494 172.20.5.134.52700 > 23.46.198.187.443: P 4039400990:4039401334(344) ack 684622442 win 1024 Drop-reason: (snort-block) Packet is blocked as requested by snort, Drop-location: frame 0x000055e9e3316112 flow (NA)/NA

 

Any Idea?

Review Cisco Networking products for a $25 gift card