Cisco Cisco ASA 5510 Adaptive Security Appliance Leaflet

Page of 1264
 
3-82
Cisco ASA Series 명령 참조 , S 명령
  
3      show as-path-access-list through show auto-update 명령              
  show asp drop
NP socket new connection failure:
    This counter is incremented for new socket connection failures.
Recommendation:
    This indicates that a software error should be reported to the Cisco TAC.
Syslog:
    None.
----------------------------------------------------------------
Name: np-socket-transport-closed
NP socket transport closed:
    This counter is incremented when the transport attached to the socket is abruptly 
closed.
Recommendation:
    It is possible to see this counter increment as part of normal operation. However, if 
the counter is rapidly incrementing and there is a major malfunction of socket-based 
applications, then this may be caused by a software defect. Contact the Cisco TAC to 
investigate the issue further.
Syslog:
    None.
----------------------------------------------------------------
Name: np-socket-block-conv-failure
NP socket block conversion failure:
    This counter is incremented for socket block conversion failures.
Recommendation:
    This indicates that a software error should be reported to the Cisco TAC.
Syslog:
    None.
----------------------------------------------------------------
Name: ssl-received-close-alert
SSL received close alert:
    This counter is incremented each time the security appliance receives a close alert 
from the remote client. This indicates that the client has notified us they are going to 
drop the connection. It is part of the normal disconnect process.
Recommendation:
    None.
Syslog:
    725007.
----------------------------------------------------------------
Name: children-limit
Max per-flow children limit exceeded:
    The number of children flows associated with one parent flow exceeds the internal 
limit of 200.
Recommendation:
    This message indicates either a misbehaving application or an active attempt to 
exhaust the firewall memory. Use "set connection per-client-max" command to further fine 
tune the limit. For FTP, additionally enable the "strict" option in "inspect ftp". 
Syslogs: