Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet

Page of 1214
 
3-42
思科 ASA 系列命令参考,命令
 
 3       show as-path-access-list  show auto-update 命令
  show asp drop
Recommendation:
    It is common to see this counter increment as part of normal operation.However, if the 
counter is rapidly incrementing and there is a major malfunction of socket-based 
applications, then this may be caused by a software defect.Contact the Cisco TAC to 
investigate the issue further.
Syslogs:
    None.
----------------------------------------------------------------
Name: mp-pf-queue-full
Port Forwarding Queue Is Full:
       This counter is incremented when the Port Forwarding application's internal queue 
is full and it receives another packet  for transmission.
Recommendation:
    This indicates that a software error should be reported to the Cisco TAC.
Syslogs:
    None.
----------------------------------------------------------------
Name: ssm-dpp-invalid
Invalid packet received from SSM card:
    This counter only applies to the ASA 5500 series adaptive security appliance.It is 
incremented when the security appliance receives a packet from the internal data plane 
interface but could not find the proper driver to parse it.
Recommendation:
    The data plane driver is dynamically registered depending on the type of SSM installed 
in the system.So this could happen if data plane packets arrive before the security 
appliance is fully initialized.This counter is usually 0.You should not be concerned if 
there are a few drops.However, if this counter keeps rising when system is up and running, 
it may indicate a problem.Please contact Cisco Technical Assistance Center (TAC) if you 
suspect it affects the normal operation of your the security appliance.
Syslogs:
    None.
----------------------------------------------------------------
Name: ssm-asdp-invalid
Invalid ASDP packet received from SSM card:
    This counter only applies to the ASA 5500 series adaptive security appliance.It is 
incremented when the security appliance receives an ASA SSM Dataplane Protocol (ASDP) 
packet from the internal data plane interface, but the driver encountered a problem when 
parsing the packet.ASDP is a protocol used by the security appliance to communicate with 
certain types of SSMs, like the CSC-SSM.This could happen for various reasons, for example 
ASDP protocol version is not compatible between the security appliance and SSM, in which 
case the card manager process in the control plane issues system messages and CLI warnings 
to inform you of the proper version of images that need to be installed; the ASDP packet 
belongs to a connection that has already been terminated on the security appliance; the 
security appliance has switched to the standby state (if failover is enable) in which case 
it can no longer pass traffic; or any unexpected value when parsing the ASDP header and 
payload.
Recommendation:
    The counter is usually 0 or a very small number.But user should not be concerned if 
the counter slowly increases over the time, especially when there has been a failover, or 
you have manually cleared connections on the security appliance via CLI.If the counter 
increases drastically during normal operation, please contact Cisco Technical Assistance 
Center (TAC).