Cisco Firewall :: 5540 ASA Interface Input Error On Outside Interface

May 28, 2013

We are having Cisco ASA 5540 having Cisco Adaptive Security Appliance Software Version 8.0(5)23 at certain time of moment daily wer are facing latency and packetdrop wherin when I checked for ASA Interface which gives me " Input Errors" on outside interface ,so can any one tell me what are the causes to get input errors on cisco asa outisde interface.

View 2 Replies


Cisco Firewall :: How To Clear Input Errors In ASA5540 Interface

Feb 26, 2013

My Expertise with Cisco ASA is Very less. I have observed Input errors in a Couple of Interfaces in Cisco ASA 5540 Firewall.   [code] I need to Clear the Input errors on this particular Interface.Will Clear interface GigabitEthernet 0/0 will work?

View 4 Replies View Related

Cisco Firewall :: ASA 5540 Redundant Interface Failover

May 8, 2011

I have two ASA 5540s, ver 8.4 configured in Active/Standby failover.I am also using the redundant interface feature for my Inside interface.  Gig0/0 is the active primary and Gig0/1 is standby.
I will activate failover monitoring of the Inside interface using the monitor inside command.
My question concerns the failover monitoring of the redundant interface.  If the gig0/0 connection were to fail would the Gig0/1 interface become Active, AND simultaneously result in a full device failover?
Or, does Gig0/1 of the Inside interface redundant pair simply become active and not change the Inside interface device failover state?  Thus NOT resulting in a device failover.

View 1 Replies View Related

Cisco Firewall :: 5580-40 - Input Errors / Overruns And Reset Drops On 10Gig Interface?

May 10, 2012

I have an issue with input errors, overruns, and input reset drops on the inside interface of an 5580-40 (v8.2.5: Transparent mode)  The box is not stressed at all according to the 'show' commands in the Cisco troubleshooting performance document for PIX/ASA v8.2.5.  Nothing stands out because is pretty much normal, nothing (processes, RAM, blocks, IO...) really being highly utilized.  I have replaced the 10Gig card and that seemed to work because the rate of errors has gone down tremedously.  The next step is to RMA the whole box.My question is what would be the cause of the inside interface to stop processing traffic (I say that because the syslog server stops receiving messages) for some periods of 30 seconds periodically throughout the day and clients lose their connections (ie Outlook, IBM Sametime, Oracle, MSSQL..etc).  Can the issue be somewhere related to the overruns and input errors?

View 2 Replies View Related

Cisco Firewall :: ASA 5510 7.2.1 High Traffic On Outside Interface Very High Input?

Oct 13, 2011

Today I've received reports of slow internet access/activity and have noticed myself that it seems a bit slow today.  On the dashboard of our asa 5510 the "outside interface" traffic usage is running constantly high. It's at the top of the graph. How can I tell what is causing the spike in utilization. It usually runs at about 1500-2000 Kbps, and now it's up over 10,000.

View 6 Replies View Related

Cisco Firewall :: ASA 106001 Error Most Likely Due To Interface Subnetting

Sep 16, 2012

I have a slew of 106001 messages coming into ASA log, from the outside interface. it appears like most of them are for standard traffic, such as TCP 80/443. i suspect these messages are from clients on the inside who have initiated connections to the internet, but then the client abruptly terminates application of something similar. Server side finally issues a close connection, reset or something else. Here is an example, with the ASA address being (changed to protect the innocent ).
Another theory is that the NAT ip for clients is different than the actual interface IP, so that is behaving differently. For example, once the xlate times out, the IP used for the xlate is no longer active and any return packets to the interface would also error out - be refused. If the xlate was using the interface IP, that it would always respond in some way?
I can bump 106001 down to notification (5) or informational (6) level.

View 5 Replies View Related

Cisco WAN :: Input Errors On 1841 LAN Interface

Nov 4, 2011

I use an 1841 router as an internet facing firewall with a 10MB MetroE connection.  Lately users started reporting slow internet download speeds and web pages timing out.  Bandwidth reports do not show the link as being saturated so I looked at the interfaces on the 1841.   The interface connected to the provider shows OK as far as errors but the LAN side of the router shows steadily increasing input errors.  It doesn't show any other errors, no CRC, frame, runts, giants or overruns, just generic input errors.  What type of errors are those?  Nothing is being logged on the console.
I moved the connection to another switch ports and the errors continue.  I switched it down to 10MB and also changed the switch and the errors slow down but don't stop.  Interestingly, the switch side never shows any errors.  What can I do here?  I guess it can be a bad interface but that is such a rare thing that I am hesitant to replace the router.

View 11 Replies View Related

Cisco Firewall :: Enabling RIP On PIX 535 / Error / OSPF / RIP Cannot Be Enabled On Failover Interface

Jun 29, 2012

I am getting this error on my PIX 535 with 8.0.4 code. The error is Error : OSPF/RIP cannot be enabled on failover interface, I am getting this error while trying to enable RIP on the firewall. The context is single mode and failover is enabled. When I am disabling the failover the Firewall is accepting the RIP configurations.

View 2 Replies View Related

Cisco Switching/Routing :: Input Errors On Many Interface WS-C3750G-12S

Apr 16, 2013

We are facing since one month in our two Cisco WS-C3750G-12S on many interfaces input errors when data transer or ping (ICMP) increase input erros. Not only port 1 but many interface has same issue, i have change new IOS but still same issue, once i have erase startup config but same issue we are facing and finaly i have replace same new switch with the same IOS it's working fine.(c3750-ipservicesk9-mz.122-55.SE4.bin) [code]

View 11 Replies View Related

Cisco WAN :: 2911 Forward Packet Based On Input Interface

Mar 25, 2013

I have a 2911 router connected to two different ISP. Is it posible to route traffic based on what interface the traffic came first?Lets say I have the deault route to use interface gig0/0(ISP1),  but a certain ip packet reach the router by interface gig0/1(ISP2). Is there any way (if possible without using source NAT) that I could route traffic back to that ip address using interface gig0/1. The source Ip addresses are not fixed, so I can not use Policy Based Routing.

View 1 Replies View Related

Cisco Security :: ASA5540 Interface Input Errors - Overrun

Nov 16, 2009

Why packets overrun are incrementing on the ASA even when I've only 40Mbps of throughput traffic?All interface are 1000- Full Duplex, both on ASA and on Catalyst3750.I've test the ASA5540 generating GET HTTP, about 40Mbit of traffic.When I use one ingress interface and one egress interface, interface input overrun counter is zero.When I use the same traffic with 3 ingress interfaces(slot0) and 3 egress interfaces(slot1), interface input overrun counter increase(60k overrun in only 2 minutes).

View 4 Replies View Related

Cisco WAN :: Input Queue Drops On 6500 VLan Interface?

Dec 6, 2011

Vlan interface would be dropping packets on the input queue? Refer to the drops/flushes below.  This is from a 6500 with a Sup720, there are a number of vlans on it. This 6500 and it's HSRP partner are exhibiting the same symptoms on all the vlans I bothered to check.  This particular vlan is quite lightly used, there are only about fifteen user PC's (each with 100 Mb interfaces) on it.
There is a bit of information on input queue drops on Cisco, but this is focused on physical interfaces where I can understand some packets being dropped.  I would think that Vlan interfaces would have different issues.I note the "no buffer" errors as well, that also concerns me, especially as that counter is quite close to the "flushes".
Vlan123 is up, line protocol is up  Hardware is EtherSVI, address is 00d0.04fd.6000 (bia 00d0.04fd.6000)  Description: Vlan123  Internet address is  MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255  Encapsulation ARPA, loopback not set  Keepalive not supported  ARP type: ARPA, ARP Timeout 04:00:00 
[Code] .......

View 3 Replies View Related

Cisco WAN :: Input Errors On Fastethernet Interface Router 2811

Feb 22, 2012

I have this output from show interfaces command for the fastethernet interface on a 2811 router.
find the causes of the crc and the ignored input errors on the interface?
The interface  configuration is:
interface FastEthernet0/0description VLANS_CHILE
no ip address


View 6 Replies View Related

Cisco Firewall :: PIX 501 / Can Traffic Goes From Inside Interface To Outside Interface

Oct 9, 2011

I have Pix 501 firewall and I'm just configuring the device for "Email Server" to allowing POP/SMTP.
Inside Interface Address:
Outside Interface Address: ISP provided IP address
My question is can my traffic goes from inside interface to outside interface? (because the inside interface address not from 10.0/172./192.168 private address)Also I'm allowing internet from this email server ( so what my access list to be configured? and what my subnet mask shoud be there?
Pix(config)#access-list outbound permit tcp any eq 80
Pix(config)#access-list outbound permit udp any eq 53
Pix(config)#access-group outbound in interface inside

View 7 Replies View Related

Cisco Firewall :: ASA 5550 - Interface Failover / Interface Goes Down

Mar 18, 2013

I've got a ASA 5550 firewall interface failover issue. (File attached).
when I shut down the inside interface Gi 1/1 of the left firewall(Active firewall), It failed to failover. but when I shut down the Gi 1/12 of the Core 1 switch, The firewall failover very well.
I followed this guide but I was not able to failover. [URL]
how can I configure so that when the Gi 1/1 or Gi 1/0 interface goes down, it can failover ? Code...

View 6 Replies View Related

Cisco Switching/Routing :: Catalyst 4506 Count Interface Input / Output Rate Always 0

Jan 20, 2013

Our customer get the problem that the switch count the 5mins input/output rate of connected traffic interface always ZERO.The problem only occur in the module 3,4 and 5 interface, module 2 has no problems.
Catayst 4506E
 Chassis Type : WS-C4506-E
Power consumed by backplane : 0 Watts
Mod Ports Card Type                              Model              Serial No.---+-----+--------------------------------------+------------------+-----------1     6  Sup 6-E 10GE (X2), 1000BaseX (SFP)     WS-X45-SUP6-E       2    48  10/100/1000BaseT (RJ45)                WS-X4548-GB-RJ45   3    48  10/100/1000BaseT (RJ45)                WS-X4648-RJ45-E    4    48  10/100/1000BaseT (RJ45)                WS-X4648-RJ45-E    5    48  10/100/1000BaseT (RJ45)                WS-X4648-RJ45-E   


View 2 Replies View Related

Cisco Switching/Routing :: WS-X4548-GB-RJ45 Frequent Input Errors Of Module Interface

Oct 21, 2012

I have been making effort to solve frequent input errors of module interface(WS-X4548-GB-RJ45) in our Backbone Switch(Cat4506).Let me show you show interface information.Rx-No-pkt-buff value is increased continuously even though traffic rate of interfaces is lower than 20Mbps.We have two Backbone Switch which is operated by HA via HSRP.What bring buffer shortage to our network ? [code]

View 2 Replies View Related

Cisco Switching/Routing :: 2921 / Catalyst 3560 - Router Interface Input Queue Drops?

Nov 6, 2011

i have an 2921 connected to an Catalyst 3560. My router interface shows quite a lot of input queue drops. Load is not too much max 5/255.

View 1 Replies View Related

Cisco Firewall :: Getting ASA 5505 Invalid Input Error

Apr 15, 2012

Whenever I use the following command I get an invalid input error
ciscoasa#conf t
ciscoasa (config) # crypto isakmp enable outside
ciscoasa (config) #object network net-local
ciscoasa (config-network) # subnet
I have reset the firewall (cisco 5505) to factory default. The marker ^ is under the subnet

View 10 Replies View Related

Cisco Firewall :: 5540 - Extended Access-list Error Using FQDN

Nov 7, 2011

I'm trying to add an access-list rule to allow internal servers to connect an outside host on a asa 5540. The hostname translates to multiple ip's. Normally I just lookup the ip address or one of the ip's the hostname translates too and use that in the access-list as the host. For some reason the actual ip's, which are a few, are not always available so using a specific ip sometimes does not work, thus the reason I have to use the hostname instead of the ip. I have 2 hostnames. and
This is how I normally add these rules (the ip addresses are fictive): access-list internet_access extended permit tcp host host eq www log
When I try to add this using the hostname on our asa I get an error: access-list internet_access extended permit tcp host host  ?ERROR: % Unrecognized command
I've tried it without the 'www', so but same error.

View 4 Replies View Related

Cisco Switching/Routing :: Input Error And CRC Error On Router 1841?

Mar 12, 2013

The router 1841 is connected directly to the layer switch. the network diagram is below:
Office A --> Switch (L3) --> Router 1841 --> Internet --> Office B
However, when I transfer the file from Office A to office B, the speed very slow ( only around 40 kb/second), and there are an input error and CRC error:
Cisco-R1841#sh interfaces FA0/1
FastEthernet0/1 is up, line protocol is up
Hardware is Gt96k FE, address is 0019.e02f.03dd (bia 0019.e02f.03dd)


View 5 Replies View Related

Cisco WAN :: 3660 Interface Always Went Down And Shows Error Message

Aug 20, 2012

I am having a problem with my cisco 3660 router. I have installed a wic 2T interface card and every time i set it to "no shutdown" the interface always went down and keep getting the following message " %FECPM-2-SCCFAIL: Init of SCC2 for int 0/0 failed to do fecpm_dma_init" .

View 2 Replies View Related

Cisco WAN :: 1841 Router - HWIC Interface Card - Cannot See Interface In Configuration File

May 9, 2012

i have a 1841 cisco router and i recently purchased a 1 port HWIC wan interface card. My problem is that I cannot see the interface in my config file. Is there something i am missing?

View 8 Replies View Related

Cisco Switching/Routing :: ASA 5505 Cannot Ping From Inside Interface To Outside Interface

May 1, 2012

I have a Cisco ASA 5505 and I have my internal and external interfaces configured but I currently cannot ping from the inside to an IP Address on the outside.  I had this setup and working and I have another set of equirement that I am replacing that is working with my service provider so I know it is a configuration issue.  When I ping for example I get:
Destination host unreachable
Do I need to add a static route from my inside interface to my outside interfaces?   

: Saved
ASA Version 8.2(5)
hostname pxasa


View 2 Replies View Related

Cisco WAN :: Set Up WAN Interface On Fast Ethernet Interface Of 877 Adsl Router

Apr 9, 2011

Is it possible to set up a WAN interface on a FastEthernet interface of a Cisco 877 Adsl Router ?Due to my ISP, i've to use an external VDSL modem and must connect it to my cisco 877 router (and leave it's adsl interface unused).But i don't know how to set up a wan port, other than the adsl interface itself (dialer0), on my cisco.

View 7 Replies View Related

Release Interface Loopback Pseudo - Interface 1 / System Do Not Find File

Oct 31, 2011

I share a modem and router with my building, and connect to the internet using an ethernet cable which plus right into the wall in my apartment. When I hover over the network/internet icon it tells me that I have a local connection only and can't get online. No changes were made to my computer between it working and not working - I have not installed any new software and the modem+router have not been changed.

When I try ipconfig/release is says it can't perform the operation while the media is disconnected. It also tells me that "an error occurred while releasing interface Loopback Pseudo-Interface 1: The system cannot find the fie specified".


View 1 Replies View Related

Cisco WAN :: 1T3 / E3 / 2951 - No Interface Corresponding To Module When Show IP Interface Brief

Feb 13, 2012

I have a 1t3/e3 card in a new 2951. When I statred the router, I found no interface corresponding to this module when do "show ip interface brief"

View 3 Replies View Related

Cisco WAN :: 2900 - Bridge From WIC Interface To Ethernet Interface

Apr 22, 2012

Needing to bridge from my wic interface to an ethernet interface on a 2900 series router so that I can pass through the ip address given to the WIC, to my ASA so that I don't have to give my ASA a private range address. (Just like a service provider might do when bringing a T1 with managed router in to my prem)

View 1 Replies View Related

An Error Occurred While Releasing Interface Wireless Network Connection

Feb 24, 2011

OS: Windows Vista Home Premium?Trying unsuccessfully so far to reconnect a client machine to a wireless network that it has been on for a year or so.ISP was down for about 2 hours the other day and when it came back up, the client machine started getting the IP address conflict. Went in to release and renew and got the following error messages:

on release: An error occurred while releasing interface Wireless Network Connection: An address has not yet been associated with the network endpoint.

on renew: The DHCP client has obtained an IP address that is use on the network. The local interface will be disabled until the DHCP client can obtain a new address.

The next thing I tried was to go in an give a manual IP address to the Wireless Adapter. But the TCP/IP properties are greyed out and I receive the following error message:Some of the controls on this property sheet are already open. To use these controls, close all these property sheets and then reopen this one.

View 1 Replies View Related

Cisco Switching/Routing :: Ping Loss On Nexus 3k But No Error Under Interface?

Mar 4, 2013

I'm facing a problem regarding loss of ping packets when i do ping test from nexus3k to another nexus3k connected directly.however there is no error counters on the interfaces on both of devices.the ping failutre is occurring only whenever i do ping test with a large number of ping packets.I don't see the ping loss symptom with default ping test (default ping test is 5 packets).
H/W : N3K-C3548P-10G
S/W : 5.0(3)A1(1) 
nexus3k# ping
PING ( 56 data bytes
64 bytes from icmp_seq=0 ttl=254 time=2.732 ms
64 bytes from icmp_seq=0 ttl=254 time=2.732 ms


View 2 Replies View Related

Cisco Switching/Routing :: C2950G / No Interface Error Messages In Logs

Sep 30, 2012

We use C2950G switches with IOS 12.1(22)EA12 . Switches are set up to send logs to a server (informationnal level). On this server, we receive many of logs from those switches, but none about interfaces errors (even if interfaces statistics show interfaces errors). On C3548 switches it's work fine.How should I be sure the set up of switches is correct ? Why do I never receive messages as %LINK-4-ERROR:[char] is experiencing errors ?

View 2 Replies View Related

Cisco Switching/Routing :: 1841 No Error On Connected Switch Interface

Feb 18, 2013

We are using Cisco Router 1841 and users reporting issue related to VoIP. After investigation, seeing input errors on Router LAN interface, but there is no error on connected switch interface. [code]

View 2 Replies View Related

Cisco Wireless :: 1130AG IOS Error Interface BVI Ethernet Dot11Radio0 Changed

Nov 12, 2012

Several 1130AG AP, auto IOS, are showing the same three errors;
1. 'Error' Interface BVI1 Changed to up
2. 'Error' Interface Fast Ethernet0 Changed to up
3. 'Error' Interface Dot11Radio0 Changed to up
Why these interfaces coming 'up' would be an 'error'? Seems almost like hardware failure/s. So we have been investigating on several 1130AGs bought from different places, with different configs and still get the errors. The APs appear to 'work' (i.e. basic config, wireless working, clients assoss., data flows to internet and back through APs) but the error causes the event log to show 'error' and for the status LED to turn 'yellow', instead of 'light green' (light green when working normally and no clients assos).
I have worked with many cisco APs and never ran across these two errors.
At first I thought it was a power issue, as the AP will boot up in low power if it doesnt think it's getting enough power, which could cause the IOS error possibly. But all of our APs are powered by wall plug cisco 48v OEM plugs, no POE injectors or switches. We even changed the settings in power of the IOS to 'pre-compatiable' POE and similar and still recieve the error and yellow LED status light. We looked into this power issue because we wanted to rule out if these was what was producing the errors that were reporting.
The second thing we did was setup the test APs with a very basic config, one ssid, no security, as to rule out a config error and also, no config will make the radios disabled, so without a basic config the APs cant be tested anyway (since the radios are now disabled from default). so we tested very basic configs and still getting the error and yellow LED (which all manuals say it should be light green normally working and no clients). all config changes brought wireless up and we can connect clients and data flows but still the errors stay and yellow LED once all clients disconnect. Note; when clients connect the yellow LED turns to light green, but thats not the colors the manual states they should be which is odd).
Third, a couple engineers suggested this error was from the AP scanning channels to choose the least congested (default config) and it will pick a channel but produce this error still and go yellow. We changed the configs to the least congested channels and it reboots and still gets these errors.
We have tried several IOS software packages, some newer, some older, all auto. though, no LAP.
We googled the errors but could only find ONE post with these errors. Some engineers said these errors are 'normal' and they have seen them before, but theres nothing on the web about the errors and we have owned 20-40 different cisco IOS APs and never seen this, and we have the same issues with 4 1130AGs, all in almost new condition, bought from different places.
Unless you have opened a 1130 many people dont know  the status LED is actually 3 LEDs (one assembly with 3 micro LEDs, blue, green and red) that combine in color (the micro LEDs light up in different intensities causing many final color combintations), and the LEDs colors mix together via a plastic light guide on the top to show the status LED, and we believe the error is causing the status LED color to be off because the error is making the yellow light up and mix with the other colors causing all the other colors to be incorrect. we have researched trying to clear the error by 'clear logging' CLI command, hoping that may clear out the interface error and turn the yellow LED off because there would be no log of the error, but we have not succeded.

View 2 Replies View Related

Copyrights 2005-15, All rights reserved