Thank you.
Main Topics
Browse All TopicsI'm trying to troubleshoot a weird vpn reliability issue. Along the way I found 'show asp drop frame'.
What is the meaning of "Slowpath security checks failed"?
Also, is there a way to turn on acl-drop logging without adding log rules to each acl drop?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: ccie22921Posted on 2009-08-19 at 15:58:55ID: 25138165
This counter is incremented and the packet is dropped when the security appliance:
"Is in routed mode and receives a through-the-box:
L2 broadcast packet
IPv4 packet with destination IP address equal to 0.0.0.0
IPv4 packet with source IP address equal to 0.0.0.0
Recommendation: Determine if an external user is trying to compromise the protected network. Check for misconfigured clients.
System log messages: 106016
"Is in routed or transparent mode and receives a through-the-box IPv4 packet with:
The first octet of the source IP address is equal to zero
The source IP address is equal to the loopback IP address
Network part of the source IP address is equal to all 0s
The network part of the source IP address is equal to all 1s
The source IP address host part is equal to all 0s or all 1s
Recommendation: Determine if an external user is trying to compromise the protected network. Check for misconfigured clients.
System log messages: 106016
"In routed or transparent mode and receives an IPv4 or IPv6 packet with the same source and destination IP addresses
Recommendation: If this message counter is incrementing rapidly, an attack may be in progress. Use the packet capture feature to capture type asp packets, and check the source MAC address in the packet to see where they are coming from.
System log messages: 106017
On question 2, not aware of any