Cisco Support Community
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ZBF log message reading

Hello Everyone!

I have IOS Version 15.2(3)T and configured Zone Based firewall on it.

There is a log message that I would like to make sure that I read correctly:

%FW-6-DROP_PKT: Dropping tcp session XXX.XXX.XXX.XXX:61581 on zone-pair outside-to-inside class FROMINTERNET-IN-cmap due to  Stray Segment with ip ident 0

Logically I read that my internal host (SMTP server with static NAT) - was accessed by some other host from public interbnet XXX.XXX.XXX.XXX and there was some problem with this connection.

But what is confusing is that if the reported zone-pair is outside-to-inside, then why order of IP addresses or hosts in the log message is not the same way i.e. XXX.XXX.XXX.XXX should be the first one and should be the second one, according to the zone outside-to-inside.

Can somebody clarify this to me?



ZBF log message reading

That looks like it is an out of order packet error.  Although the IOS 15.0 and higher supports out of order packets for ZBF, it is not supported for SMTP traffic.

but you could always try enabling it to see if the error disapears.

parameter-map type ooo global

Please remember to rate and select a correct answer


Please remember to rate and select a correct answer
CreatePlease to create content