08-07-2009 05:24 AM - edited 03-11-2019 09:03 AM
I am seeing a lot of drops on the interface connected to the inside network. The sh int command reveals a lot of "switch ingress policy drops". What causes it and can be it be fixed?
The ASA 5505 is running ver 7.24
rgds,
08-07-2009 11:47 AM
Are user reporting any performance issue?
If not, check the following bug.
CSCsz33819 "switch ingress policy drops" are corrupted every 65535 packets
08-12-2009 04:00 AM
No, users are not reporting any performance issues. I recently upgraded its software to release 8.0(4) release August 10 2008 but that did not seem to resolve the problem.
08-12-2009 06:36 AM
In that case, you can refer to "Table 26-13 show interface for Switch Interfaces Fields" in the link below to see which drop reason could be applied in your case.
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s3.html#wp1427809
08-12-2009 06:52 AM
Thanks much for the quick reply. None of the mentioned applied to my situation. Please see below:
ASA5505
interface Vlan50
nameif inside
security-level 100
ip address 10.64.50.15 255.255.255.0
!
interface Ethernet0/1
description Uplink to gig0/40 on Core
switchport access vlan 50
speed 100
duplex full
Switch
interface Vlan50
ip address 10.64.50.254 255.255.255.0
!
interface GigabitEthernet0/40
description to e1 on IF1
switchport access vlan 50
switchport mode access
load-interval 30
speed 100
duplex full
=========================================
Regards,
08-12-2009 06:59 AM
You'd better to sniffer the packet on switch port via SPAN to see what kind of packets are sending to ASA.
08-13-2009 06:16 AM
I couldn't find anything there either. I checked other forums and find out quite of number folks reporting this issue with the ASA5505 which lead to me believe it is a problem with the hardware software and nothing else. It would be great to know when this is fixed.
08-13-2009 07:31 AM
Not sure if you have verified this -- ethernet keepalive.
1. change keepalive to 20 sec on switch port.
2. on ASA check "show controller ethernet x/y | i Filtered" to see if the ingress filtered number is incrementing in the same speed as keepalive.
Anyway, if it won't impact the traffic, it should be OK. I did not find any new bug regarding to this so far.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide