Drops in packet capture

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Drops in packet capture

L4 Transporter

Hello Team,

 

I have a question regarding drops during the packet capture.

 

What is the packet drop means - Firewall dropping any packet or firewall detect drops packet.?

 

Once i performed the packet capture at the same time i have run the command global counter but i didn't get any drop in counter.

 

So could you please let me know what is the meaning of this.

 

Regards,

Jafar Hussain

 

 

 

 

14 REPLIES 14

Cyber Elite
Cyber Elite

The drop stage captures packets that the firewall discards

This could be through policy action, threat detection, or packet malformation

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

Thank you for your reply.

 

I have configured a VPN tunnel Site A and site B.My client is in site A and the server belongs from Site B.

 

 - In the security policy allowed traffic any with specific IP addresses b/w client and server.

 - Once i copied any big file from Server to client i am getting drops packet in a packet capture.

 - I have checked the files are copied through NBSS and SMB2 protocol.

 - When i checked the drops packet in Wireshark, i can see multiple packets TCP retransmissions from server-side and 2 packets also from server side with error: - Notify Response, Error: STATUS_NOTIFY_CLEANUP.

 - My concern is why the firewall is drop packets.

 

Note: - Files are copied successfully but it takes a too long time.

 

Please suggest.

 

 

 

Global counters should help with this

It sounds like there may be packets sent out of order or out of window that the firewall is discarding

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaperThanks you for your quick response.

 

While packet capture I have run the global counter but I didn't get any drops.

 

What steps i need to do for fix this issue. is this a firewall issue?

@Jafar_Hussainwhich counters did you see?

 

It sounds like a network issue you may be able to workaround by relaxing the firewalls tolerance if you are unable to address the network latency

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

I have seen show counter global filter packet-filter yes delta yes.

but didn't get any drops.

I am not getting this point workaround by relaxing the firewalls tolerance could you please brief.

 

@Jafar_Hussain  there are several settings that can be set to be less strict (timers, out of window/order packets,...) So network problems are allowed to happen rather than prevented. We'll need to find the global counters you do see to properly advise what to try. Please share the global counters seen

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

Below is the result of counter command:-

Jafar_Hussain_0-1590229149894.png

 

I want to know only is there any issue with the firewall setting? because i have allowed all traffic b/w client and server.

or the traffic is going via a tunnel it may be cause this issue?

Please post the global counters without the drop filter

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

 

Oh, i took the capture with drop filter. now it is very tough to access of firewall again.

 

I will share the counter once i will take access again, apart from this. is there any suggestion from your side?

@reaper 

I am facing this issue with LAN also. traffic is flowing trust zone to DMZ zone internally inside the firewall.

When i check this, the same issue is happening meantime I run the counter and found a firewall drop some packets. below is the snapshot.

 

Jafar_Hussain_0-1590830549726.png

please suggest this.

Thanks in advance.

The content engine queue is getting full

This could be due to too many small/large packets or other issues (fragmentation,...), but you used the drop filter again so there's not enough information to make an educated guess

 

Please try

> Debug dataplane pool statistics

 

 

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

Thanks for the reply.

I will try with command.

@reaper 

Below is the output of the command:- show counter global filter packet-filter yes delta yes

 

Jafar_Hussain_0-1590841254906.png

Jafar_Hussain_1-1590841352771.png

 

Debug command output I will share later.

 

 

 

 

 

 

 

 

 

  • 14498 Views
  • 14 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!