Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
3-6
思科 ASA 系列命令参考,S 命令
第 3 章 show as-path-access-list 至 show auto-update 命令
show asp drop
Syslogs:
None
----------------------------------------------------------------
Name: bad-ipsec-udp
Bad IPsec UDP packet:
This counter will increment when the appliance receives a packet on an IPsec
connection that has negotiated IPsec over UDP, but the packet has an invalid payload
length.
Recommendation:
Analyze your network traffic to determine the source of the NAT-T traffic.
Syslogs:
None
----------------------------------------------------------------
Name: inspect-srtp-encrypt-failed
Inspect SRTP Encryption failed:
This counter will increment when SRTP encryption fails.
Recommendation:
If error persists even after a reboot please call TAC to see why SRTP encryption is
failing in the hardware crypto accelerator.
Syslogs:
337001.
----------------------------------------------------------------
Name: inspect-srtp-decrypt-failed
Inspect SRTP Decryption failed:
This counter will increment when SRTP decryption fails.
Recommendation:
If error persists even after a reboot please call TAC to see why SRTP decryption is
failing in the hardware crypto accelerator.
Syslogs:
337002.
----------------------------------------------------------------
Name: inspect-srtp-validate-authtag-failed
Inspect SRTP Authentication tag validation failed:
This counter will increment when SRTP authentication tag validation fails.
Recommendation:
No action is required. If error persists SRTP packets arriving at the firewall are
being tampered with and the administrator has to identify the cause.
Syslogs:
337003.
----------------------------------------------------------------
Name: inspect-srtp-generate-authtag-failed
Inspect SRTP Authentication tag generation failed:
This counter will increment when SRTP authentication tag generation fails.