Get rid Cisco IOS router message: %FW-4-TCP_OoO_SEG: Dropping TCP Segment

Some times you will see on a Cisco IOS router the following message in your show logging:

009357: Jul 8 09:28:22.214 CDT: %FW-4-TCP_OoO_SEG: Dropping TCP Segment: 
seq:104330552 1492 bytes is out-of-order; expected seq:104304632. Reason: 
TCP reassembly queue overflow - session <internal host>:1535 to <external host>:80

This message can be very annoying if you see it. And sometimes it looks that the device is really busy or is getting trouble. There are 2 lines which solve this message and you won’t see it again.

These 2 commands you have to add in your configuration:

ip inspect tcp reassembly queue length 128
ip inspect tcp reassembly timeout 10

After you have entered this command you will see that there aren’t any messages anymore in you logging of you IOS router.

Advertisements

2 thoughts on “Get rid Cisco IOS router message: %FW-4-TCP_OoO_SEG: Dropping TCP Segment

  1. With zone-based firewall in place, these settings are configured under

    “parameter-map type ooo global”

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s