This command displays how many monitored packets have been dropped by a port in inline mode.
Syntax:
show inlinepktdropstats <port>
Parameter | Description |
|---|---|
<port> | sets the port for which the statistics is to be displayed. Valid port numbers for NS-series are: g0/1 | g0/2 | g0/3 | g0/4 | g1/1 | g1/2 | g1/3 | g1/4 | g1/5 | g1/6 | g1/7 | g1/8 | g1/9 | g1/10 | g1/11 | g1/12 | g2/1 | g2/2 | g2/3 | g2/4 | g2/5 | g2/6 | g2/7 | g2/8 | g2/9 | g2/10 | g2/11 | g2/12 | g3/1 | g3/2 | g3/3 | g3/4 | g3/5 | g3/6 | g3/7 | g3/8 | all |
Takes a single argument which is the port for which to show statistics.
Information displayed by the show inlinepktdropstats command includes the count for each of the following categories:
IP checksum errors
TCP checksum errors
UDP checksum errors
ICMP checksum errors
ACL-related packets dropped
Out-Of-Context/Bad packets dropped
Sensor cold-start-related packets dropped
Off/HdrLen error packets dropped
dropped attack packets (or, blocked packets)
IP reassembly timeout packets dropped
TCP Out-Of-Order timeout packets dropped
Dropped packets containing TCP protocol errors
Dropped packets containing UDP protocol errors
Dropped packets containing ICMP protocol errors
Dropped packets containing IP protocol errors
Packets dropped due to the Sensor being out of resources
Dropped packets containing CRC errors
Dropped IP-spoofed packets
ICMPv6 checksum error drop count
IPv6 reassembly timeout drop count
ICMPv6 Protocol error drop count
IPv6 Protocol error drop count
Host Quarantine IPv4 packet drop count
Host Quarantine IPv6 packet drop count
Other Layer-2 error packets dropped
IP sanity check packets dropped
IPv6 sanity check packets dropped
Total IP No Credit Packets dropped
Count of other Layer-2 packets dropped
The count for the following categories is displayed only when you run the show inlinepktdropstats all command.
Total Inline Forward dropped
Count of miscellaneous packets dropped at front-end
Count of miscellaneous packets dropped at back-end
Count of miscellaneous packets dropped at NIC
Count of miscellaneous packets dropped at BMC switch
(Applicable to NS7600 Sensor only) Count of packets dropped due to oversubscription. This count is triggered when the throughput exceeds the subscription limit. This is a subset of
Total Other Layer-2 Packets Dropped.(Applicable to NS7600 Sensor only) Count of packets not dropped though oversubscribed. This count is triggered when when the subscribed license capacity is reached but packets are not dropped.
Sample Output:
intruShell@john> show inlinepktdropstats all
IP Checksum Error Drop Count : 0
TCP Checksum Error Drop Count : 0
UDP Checksum Error Drop Count : 0
ICMP Checksum Error Drop Count : 0
ICMPv6 Checksum Error Drop Count : 0
ACL Drop Count : 0
Out-Of-Context/Bad Packet Drop Count : 0
Cold Start Drop Count : 0
Off/HdrLen Error Drop Count : 0
Attack Packet Drop Count : 0
IP Reassembly Timeout Drop Count : 0
IPv6 Reassembly Timeout Drop Count : 0
TCP Out-Of-Order Timeout Drop Count : 0
TCP Protocol Error Drop Count : 0
UDP Protocol Error Drop Count : 0
ICMP Protocol Error Drop Count : 0
ICMPv6 Protocol Error Drop Count : 0
IP Protocol Error Drop Count : 0
IPv6 Protocol Error Drop Count : 0
System Out-of-Resource Drop Count : 0
Host Quarantine IPv4 Packet Drop Count : 0
Host Quarantine IPv6 Packet Drop Count : 0
Conn Limiting Packet Drop Count : 0
Frontend Misc Packet Drop Count : 44243
Misc Backend Pkt Drop Count : 0
DoS Attack Packets Dropped : 0
Stateless ACL Drop Count : 0
Total CRC Error Packets Dropped : 0
Total Other Layer-2 Error Packets Dropped : 0
Total Other Layer-2 Packets Dropped : 27903423745
Total IP Spoofed Packets dropped : 0
Total IP Sanity Check Packets dropped : 0
Total IPv6 Sanity Check Packets dropped : 0
Total IP No Credit Packets dropped : 0
Total Inline Forward dropped : 0
Switch Misc Packets Drop Count : 27625
Misc NIC Pkt Drop Count : 183086
Packets dropped due to oversubscription : 41145921942 (Subset of "Total Other Layer-2 Packets Dropped")
Packets NOT dropped though oversubscribed: 23547617804
Example:
show inlinepktdropstats g0/2
Applicable to:
NS-series Sensors