Cisco Cisco ASA 5510 Adaptive Security Appliance Leaflet
3-82
Cisco ASA Series 명령 참조 , S 명령
3장 show as-path-access-list through show auto-update 명령
show asp drop
NP socket new connection failure:
This counter is incremented for new socket connection failures.
Recommendation:
This indicates that a software error should be reported to the Cisco TAC.
Syslog:
None.
----------------------------------------------------------------
Name: np-socket-transport-closed
NP socket transport closed:
This counter is incremented when the transport attached to the socket is abruptly
closed.
Recommendation:
It is possible to see this counter increment as part of normal operation. However, if
the counter is rapidly incrementing and there is a major malfunction of socket-based
applications, then this may be caused by a software defect. Contact the Cisco TAC to
investigate the issue further.
Syslog:
None.
----------------------------------------------------------------
Name: np-socket-block-conv-failure
NP socket block conversion failure:
This counter is incremented for socket block conversion failures.
Recommendation:
This indicates that a software error should be reported to the Cisco TAC.
Syslog:
None.
----------------------------------------------------------------
Name: ssl-received-close-alert
SSL received close alert:
This counter is incremented each time the security appliance receives a close alert
from the remote client. This indicates that the client has notified us they are going to
drop the connection. It is part of the normal disconnect process.
Recommendation:
None.
Syslog:
725007.
----------------------------------------------------------------
Name: children-limit
Max per-flow children limit exceeded:
The number of children flows associated with one parent flow exceeds the internal
limit of 200.
Recommendation:
This message indicates either a misbehaving application or an active attempt to
exhaust the firewall memory. Use "set connection per-client-max" command to further fine
tune the limit. For FTP, additionally enable the "strict" option in "inspect ftp".
Syslogs: