08-07-2009 05:24 AM - edited 03-11-2019 09:03 AM
I am seeing a lot of drops on the interface connected to the inside network. The sh int command reveals a lot of "switch ingress policy drops". What causes it and can be it be fixed?
The ASA 5505 is running ver 7.24
rgds,
08-07-2009 11:47 AM
Are user reporting any performance issue?
If not, check the following bug.
CSCsz33819 "switch ingress policy drops" are corrupted every 65535 packets
08-12-2009 04:00 AM
No, users are not reporting any performance issues. I recently upgraded its software to release 8.0(4) release August 10 2008 but that did not seem to resolve the problem.
08-12-2009 06:36 AM
In that case, you can refer to "Table 26-13 show interface for Switch Interfaces Fields" in the link below to see which drop reason could be applied in your case.
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s3.html#wp1427809
08-12-2009 06:52 AM
Thanks much for the quick reply. None of the mentioned applied to my situation. Please see below:
ASA5505
interface Vlan50
nameif inside
security-level 100
ip address 10.64.50.15 255.255.255.0
!
interface Ethernet0/1
description Uplink to gig0/40 on Core
switchport access vlan 50
speed 100
duplex full
Switch
interface Vlan50
ip address 10.64.50.254 255.255.255.0
!
interface GigabitEthernet0/40
description to e1 on IF1
switchport access vlan 50
switchport mode access
load-interval 30
speed 100
duplex full
=========================================
Regards,
08-12-2009 06:59 AM
You'd better to sniffer the packet on switch port via SPAN to see what kind of packets are sending to ASA.
08-13-2009 06:16 AM
I couldn't find anything there either. I checked other forums and find out quite of number folks reporting this issue with the ASA5505 which lead to me believe it is a problem with the hardware software and nothing else. It would be great to know when this is fixed.
08-13-2009 07:31 AM
Not sure if you have verified this -- ethernet keepalive.
1. change keepalive to 20 sec on switch port.
2. on ASA check "show controller ethernet x/y | i Filtered" to see if the ingress filtered number is incrementing in the same speed as keepalive.
Anyway, if it won't impact the traffic, it should be OK. I did not find any new bug regarding to this so far.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: