Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet

Page of 1214
 
3-36
思科 ASA 系列命令参考,命令
 
 3       show as-path-access-list  show auto-update 命令
  show asp drop
Syslogs:
429001
----------------------------------------------------------------
Name: cxsc-bad-tlv-received
CXSC Module requested drop:
    This counter is incremented and the packet is dropped as requested by CXSC module when 
the packet has bad TLV's.
Recommendations:
    Check syslogs and alerts on CXSC module.
Syslogs:
    None
----------------------------------------------------------------
Name: cxsc-ha-request
CXSC HA replication drop:
    This counter is incremented when the security appliance receives a CXSC HA request 
packet, but could not process it and the packet is dropped.
Recommendation:
    This could happen occasionally when CXSC does not have the latest ASA HA state, like 
right after ASA HA state change.If the counter is constantly increasing however, then it 
can be because CXSC and ASA are out of sync.If that happens, contact Cisco TAC for 
assistance.
Syslogs:
    None.
----------------------------------------------------------------
Name: cxsc-invalid-encap
CXSC invalid header drop:
    This counter is incremented when the security appliance receives a CXSC packet with 
invalid messsage header, and the packet is dropped.
Recommendation:
    This should not happen.Contact Cisco TAC for assistance.
Syslogs:
    None.
----------------------------------------------------------------
Name: cxsc-malformed-packet
CXSC Module requested drop:
    This counter is incremented and the packet is dropped as requested by CXSC module when 
the packet is malformed.
Recommendations:
    Check syslogs and alerts on CXSC module.
Syslogs:
    None
----------------------------------------------------------------
Name: ips-request
IPS Module requested drop:
    This counter is incremented and the packet is dropped as requested by IPS module when 
the packet matches a signature on the IPS engine.