cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
94
Views
0
Helpful
1
Replies

Router -CISCO1921- Zone Based Firewall (ZBFW) abnormal Logs

kanuri-murthy
Level 1
Level 1

Hi Team,

we observed few abnormal logs on Router and further investigated with logs it looks like a Cisco Bug on Router “CSCsj30582".

PID: CISCO1921/K9 , VID: V04 , SN: FCZ1618C2B6

Ios Running is c1900-universalk9-mz.SPA.151-4.M4.bin. 

Impact : Intranet is working fine but Internet is not working for all users. No Proxy Issues looks like. Need Soultion. 

Logs 

DWDAPTF0R01#sh logging 
Mar 3 16:16:13 KSA: %FW-6-DROP_PKT: Dropping tcp session 10.136.156.226:58150 10.136.198.152:7680 on zone-pair IN-OUT class class-default due to DROP action found in policy-map with ip ident 0
Mar 3 16:16:44 KSA: %FW-6-DROP_PKT: Dropping tcp session 10.136.156.226:55614 13.89.179.11:443 on zone-pair IN-OUT class class-default due to DROP action found in policy-map with ip ident 0
Mar 3 16:22:12 KSA: %FW-6-DROP_PKT: Dropping tcp session 10.136.156.226:55643 10.148.11.70:7680 on zone-pair IN-OUT class class-default due to DROP action found in policy-map with ip ident 0
Mar 3 16:23:46 KSA: %FW-6-DROP_PKT: Dropping tcp session 10.136.198.152:56205 10.136.156.226:7680 on zone-pair OUT-IN class class-default due to DROP action found in policy-map with ip ident 0
Mar 3 16:25:20 KSA: %FW-6-DROP_PKT: Dropping tcp session 10.136.156.236:52168 10.192.130.209:8080 on zone-pair IN-OUT class class-default due to DROP action found in policy-map with ip ident 0


 

 

 

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

The bug that you reference involves ESP traffic. The logs you post show TCP traffic. Is it possible that this is a configuration issue? Are there instances where a host in the network has some resources that sometimes can access and sometimes can not access that resource?

HTH

Rick
Review Cisco Networking for a $25 gift card