%FW-6-DROP_PKT: Dropping Unknown-l4 session X.X.X.X:0 X.X.X.X:0 on zone-pair ZONE-PAIR class class-default due to DROP action found in policy-map with ip ident 0
Good day all,
Just thought I post this discussion to help somebody that may run into this issue in future. This is how I resolved this problem, may or may not apply to all but worth a shot.
I have a Cisco 2951 ISR running Zone Based Firewall. I kept seeing the unknown Layer 4 error even though the ACL was set to allow all IP traffic (permit IP any any) between the zones and policy-maps were inspecting the resulting packets. However even simple TCP packets were marked as unknown and were getting dropped. Spent hours trying to fix it. At the end it turned out to be a bug in the version of IOS I was running (c2951-universalk9-mz.SPA.152-3.T3.bin). Upgraded the IOS to latest one from Cisco (c2951-universalk9-mz.SPA.155-3.M7.bin) and immediately the router started to identify packets correctly and issue was resolved.
Re: %FW-6-DROP_PKT: Dropping Unknown-l4 session X.X.X.X:0 X.X.X.X:0 on zone-pair ZONE-PAIR class class-default due to DROP action found in policy-map with ip ident 0
Thanks for posting about your experience with this issue. I hope it will be helpful to other readers in the forum. It does remind us that sometimes when we are dealing with a problem and the config seems right that we should consider the possibility of bug in the software. +5 for this.
Cisco SD-Access 184.108.40.206 Features OverviewBorder handoff enhancements: 4-byte ASNEmbedded wireless support on Fabric edgeFiaB deployment models:Multiple VN for Guest Access in Cisco SD-AccessCisco SD-Access Group-Based Access Control PolicyCisco SD-Access ...
. My work contains abbundance of networking gear.i have 3945 routers with attatched nme,3850 switches 48 gig port with 4 tengig port,3850 switch with 16 fiber ports, fortigate 600d along with servers with 8tbs of free space.if you have any labs for me id ...
Hello I have a network in prodcution like it mensionned in this picture. The customer wants to renovate the current infrastructure by changing all the hardware. For this reason we had think about deploying DNA Center and make automat...
I want to show how to quickly and reliably troubleshoot a network using notepad++.If you are not using Cisco GENIE and your network is not very big and you have several routers/switches only.For illustration, I created a simple topology.First, the loopbac...
Join us on Tuesday, October 15 at 10:00 am PT to to learn how Equinix and Cisco enable multicloud and Hybrid IT access.
Digital transformation initiatives are driving the adoption of internet, cloud, mobile and IoT technologies. In order t...