Preview Tool

Cisco Bug: CSCub09591 - OOO packets seen in asp drop counter in asymmetric clustering set-up

Last Modified

Nov 08, 2016

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

100.8(0.205) 9.0(1)

Description (partial)

For both IPv4 & IPv6, with asymmetric traffic and inspect HTTP enabled, large amount of "TCP Out-of-Order packet buffer full (tcp-buffer-full)" id observed. Throughput of TCP (HTTP download) session will drop by 40%.
Also, "show interface detail" on the forwarder ASA has "overrun" drops.

There are several conditions where this can happen (assuming HTTP server & client are connected to switch using 1Gb interface):
1. CCL link is using 1Gb interface (single or as part of a port-channel). 
2. CCL link MTU is set to 1500 (same as data interface).
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.