Cisco ASA dropping packets

Posted on 2009-05-12
Last Modified: 2012-05-06
I have a Cisco ASA which is dropping packets on both the inside & outside interfaces.  Each of the routers which connect to it via VPN are dropping packets on their ATM interface.  Any suggestions or ideas on how to track this fault down?  It only seems to of had the problem since the introduction of VOIP (a Mitel 3300) at the HQ site, but looking at a packet capture there are no VOIP packets arriving at the interface on the ASA.

Any suggestions most welcome.
Question by:Compaq_Engineer
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Expert Comment

ID: 24367093
can you draw a simple diagram description is not to clear?

Author Comment

ID: 24367218
Yes no prob, although I'm lacking a scanner to hand at home.
A simple line diagram though would be:-
HQ LAN -> ASA -> INTERNET -> 877 -> Remote Office LAN
The HQ connection to the internet is by a BT Net 20mb symetric LES circuit.  The remote office a BT Max ADSL line.
The packets on the ASA are being dropped on both the HQ LAN and INTERNET interfaces, at the remote off just on the INTERNET interface (atm0) of the 877.
I'll post a JPEG of the network tomorrow when I'm back in the office.

Expert Comment

ID: 24370379
do you mean all packets mwaning no data is traversing the firewall or do you mean just voice packets?

Accepted Solution

Compaq_Engineer earned 0 total points
ID: 24373730
The VPN works perfectly apart from being very slow (normal ping on the links of approx 60 - 70ms), now the VOIP phone system is installed (which is not traversing the vpn) the ping time is approx 290 - 310ms.  The only thing i have found is packets dropped counters on both the inside & outside interface's of the ASA are dropping packets.

Expert Comment

ID: 24373753
Is the phone system on a network that was prexisting or did you create a new network for the phone system?

Featured Post

Turn your laptop into a mobile console!

The CV211 Laptop USB Console Adapter provides a direct Laptop-to-Computer connection for fast and easy remote desktop access with no software to install.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses
Course of the Month5 days, 18 hours left to enroll

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question