Cisco ASA dropping packets

Posted on 2009-05-12
Last Modified: 2012-05-06
I have a Cisco ASA which is dropping packets on both the inside & outside interfaces.  Each of the routers which connect to it via VPN are dropping packets on their ATM interface.  Any suggestions or ideas on how to track this fault down?  It only seems to of had the problem since the introduction of VOIP (a Mitel 3300) at the HQ site, but looking at a packet capture there are no VOIP packets arriving at the interface on the ASA.

Any suggestions most welcome.
Question by:Compaq_Engineer
  • 3
  • 2

Expert Comment

ID: 24367093
can you draw a simple diagram description is not to clear?

Author Comment

ID: 24367218
Yes no prob, although I'm lacking a scanner to hand at home.
A simple line diagram though would be:-
HQ LAN -> ASA -> INTERNET -> 877 -> Remote Office LAN
The HQ connection to the internet is by a BT Net 20mb symetric LES circuit.  The remote office a BT Max ADSL line.
The packets on the ASA are being dropped on both the HQ LAN and INTERNET interfaces, at the remote off just on the INTERNET interface (atm0) of the 877.
I'll post a JPEG of the network tomorrow when I'm back in the office.

Expert Comment

ID: 24370379
do you mean all packets mwaning no data is traversing the firewall or do you mean just voice packets?

Accepted Solution

Compaq_Engineer earned 0 total points
ID: 24373730
The VPN works perfectly apart from being very slow (normal ping on the links of approx 60 - 70ms), now the VOIP phone system is installed (which is not traversing the vpn) the ping time is approx 290 - 310ms.  The only thing i have found is packets dropped counters on both the inside & outside interface's of the ASA are dropping packets.

Expert Comment

ID: 24373753
Is the phone system on a network that was prexisting or did you create a new network for the phone system?

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5512 LAN Config 16 79
Hit router interface limit 7 42
Cisco 2960 unable to add SFP modules to device 9 68
CISCO ASA 5505 double Wan 8 19
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question