Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
3-85
思科 ASA 系列命令参考,S 命令
第 3 章 show as-path-access-list 至 show auto-update 命令
show asp drop
Name: route-change
Flow terminated due to route change:
When the system adds a lower cost (better metric) route, incoming packets that match
the new route will cause their existing connection to be torn down after the user
configured timeout (floating-conn) value.Subsequent packets will rebuild the connection
out the interface with the better metric.
Recommendation:
To prevent the addition of lower cost routes from affecting active flows, the
'floating-conn' configuration timeout value can be set to 0:0:0.
Syslogs:
None.
----------------------------------------------------------------
Name: svc-selector-failure
SVC VPN inner policy selector mismatch detected:
This counter is incremented when an SVC packet is received with an inner IP header
that does not match the policy for the tunnel.
Recommendation:
None. This packet will be discarded automatically.
Syslogs:
None.
----------------------------------------------------------------
Name: dtls-hello-close
DTLS hello processed and closed:
This counter is incremented when the UDP connection is dropped after the DTLS client
hello message processing is finished.This does not indicate an error.
Recommendation:
None.
Syslogs:
None.
----------------------------------------------------------------
Name: svc-conn-timer-cb-fail
SVC connection timer callback failure:
This condition occurs when there is a failed attempt to place an event on the async
lock queue for that connection.
Recommendation:
None.
Syslogs:
None.
----------------------------------------------------------------
Name: svc-udp-conn-timer-cb-fail
SVC UDP connection timer callback failure:
This condition occurs when there is a failed attempt to place an event on the async
lock queue for that connection.
Recommendation:
None.