Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2

Description

Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2.2-14n firmware)

Resolution

When viewing output on the System > Packet Capture page, there are two fields that display potentially useful diagnosticinformation in numeric format. The Module-ID field provides information on the specific area of the firewall (UTM) appliance'sfirmware that handled a particular packet. The Drop-Code field provides a reason why the appliance dropped a particularpacket. This article provides a list of the Module-ID and Drop-Code numbers along with their meanings.

Please Note: The following Drop Codes were extracted from SonicOS Enhanced 6.1.2.2 -14n  firmware version. These codes may change when a new firmware is available. If unsure, please contact SonicWall support.

 

1             adminTools
2             attacks
3             av
4             bwmmgmt
5             CIA
6             cli
7             clients
8             config
9             connection Cache
10           contentFilter
11           dea
12           debug
13           dhcpRelay
14           dhtml
15           fileSystem
16           fwCore
17           ha
18           idp
19           ipHelper
20           ipSec
21              lib
22              log
23              modem
24              netObj
25              network
26              packetFilter
27              policy
28              pppStack
29              RADIUS acct
30              redirector
31              reports
32              resource
33              sarc
34              servers
35              snmp
36              spdpp
37              stateful
38              system
39              TRAV2
40              TSA
41              USER
42              version
43              wizards
44              wlan
45              wlb
46              zones
47              ARP
48              system stack
49              PPTP
50              L2TP
51              PPP-Dialup
52              IGMP
53              PPPOE
54              NAT
55              anti-spam
56              NetMonitor
57              Mirroring
58              SIP
59              BandOpt
60              GMSFlow server
61              APPFlow server
62 
     
   
 
DROP CODES
Drop Code ID and name

0

1 PIP handling error in CP

2 PIP handling error in DP

3 Packet on the backup aggregate interface, but no Sonic END can be found.

4 Broadcast packet on the backup redundant port when primary port is up.

5 Packet the redundancy port, but no Sonic END can be found.

6 CP throttled DP for stack traffic

7 Packet dropped due to pass to stack failed.

8 Packet dropped by outputhook.

9 Inter-blade Packet dropped due to CP pass to stack failed.

10 HA active data packet processing failed.

11 Packet dropped due to CP pass to stack failed.

12 Dispatching IEEE802 BPDU packet failed.

13 IEEE 802 BPDU support module has not been initialized yet.

14 Invalide Ether type for IEEE 802 BPDU packet.

15 Invalide source address for IEEE 802 BPDU packet.

16 Unknown Ether type ingress.

17 Unknown Ether type egress.

18 IPv6 packets not supported.

19 Packet on invalid vlan

20 Packet ingress on invalid interface

21 Packet egress on invalid interface

22 Packet on invalid device

23 Destination MAC address is not our interface

24 Device is not attached.

25 Packet on invalid svrrp group

26 Invalid HA packet

27 Invalid HA ARP packet

28 PPPoE discover packet not allowed

29 Invalid HA SDP packet

30 Routing packet not allowed

31 VLAN filtered.

32 Unicast MACADDR not mine

33 L2B Learning-Bridge filtered

34 Invalid NET-ID found on mist if write.

35 Invalid NET-ID found on if write arp real.

36 Invalid NET-ID found on write ip fast.

37 Invalid NET-ID found on if write.

38 Invalid NET-ID found on if write no mbuf.

39 Invalid Run-time NET data on mist if write.

40 Invalid Run-time NET data on if write arp real.

41 Invalid Run-time NET data on write ip fast.

42 Invalid Run-time NET data on if write.

43 Invalid parent Run-time NET data on if write.

44 Invalid Run-time NET data on if write no mbuf.

45 Invalid parent Run-time NET data on if write no mbuf.

46 Unknown ARP type.

47 Arp reply ignored.

48 IP address not for our subnet

49 ARP unexpected link ip

50 ARP source ip not connected

51 NULL source IP address

52 Own gratuitous arp

53 IP address not on our lan subnet

54 Classical mode, ARP bridge not supported

55 ARP proxy, subnet mismatch

56 Not for me.

57 ARP request from stack

58 ARP response from stack

59 ARP fail to resolve from SonicPoint

60 ARP unknown ethernet address format

61 Invalid TCP Flag

62 Invalid TCP Options

63 IP sanity test failed

64 IP sanity test failed in out hook

65 IP advanced sanity test failed

66 Non sonicpoint traffic in wlan zone

67 Multicast spank attack

68 Multicast Data packet dropped

69 Load Balancing Probe error

70 Syn Flood Protection

71 Duplicated in Syn Flood Protection

72 Syn Flood Protection #3

73 IP source route option found

74 Invalid connection cache.

75 Unknown destination

76 Unknown destination for bridged bcast pkt

77 Bounce traffic detected

78 Access Rule Policy not found

79 AV detection

80 DEA detection

81 Bad TFTP packets

82 Enforced firewall rule

83 LICENSE drop

84 IDP detection

85 IDP detection, bad tcp checksum

86 IDP detection, bad ip checksum in tcp checking

87 IDP detection, bad ip checksum in tcp packet

88 IDP detection, bad udp checksum

89 IDP detection, bad ip checksum in udp checking

90 IDP detection, bad ip checksum in udp packet

91 IDP detection, bad icmp checksum

92 IDP detection, bad ip checksum in icmp checking

93 IDP detection, bad ip checksum in icmp packet

94 Packet to public IP from inside firewall

95 Bad TTL

96 IP check failed

97 Bad source IP

98 Bad destination MAC address

99 Broadcast not allowed on bridge.

100 Antispam: Going to blacklisted server.

101 Going to blacklisted server.

102 coming from blacklisted server.

103 Broadcast traffic not handled.

104 Multicast forwarding not configured

105 Multicast IGMP state not found

106 Multicast IP not in the allowed list

107 Anti-Spam Connection Limit Reached

108 Active/Active DPI drop offload packet

109 UDP Flood Protection

110 ICMP Flood Protection

111 Guest Service not allowed

112 Unknown Ether type

113 Incorrect IP Version

114 Blacklisted MAC address

115 Wrong IP Length

116 Packet length mismatch with interface MTU

117 Wrong fragmentation boundary.

118 Wrong IP checksum value.

119 Wrong TCP Checksum value.

120 Wrong UDP Checksum value.

121 Wrong ICMP Checksum value.

122 NULL Udp port number

123 Non PPP-GRE traffic

124 Missing ESP Header

125 Missing AH Header

126 Missing IPCOMP Header

127 Unknown IP protocol type

128 TTL value is zero.

129 l2 mcast but dest ip is unicast

130 Null Source Zone.

131 Wrong UDP Length.

132 RECV: IP pkt recvd without IPCP session

133 RECV: IP pkt recvd without contiguous buf

134 RECV: IP pkt recvd without combuf

135 RECV: TNMP can't alloc contiguous buf

136 XMIT: AHDLC encap no buf

137 XMIT: TNMP can't alloc contiguous buf

138 XMIT: Device not ready to forward traffic

139 XMIT: No IPCP session

140 XMIT: IPCP is down

141 XMIT: No Dialup Msg Buffer available

142 Non Zero GIAddr field in DHCP packet from client

143 Source MAC is different from chAddr field in DHCP client packet

144 Iphelper policy not found for DHCP relay.

145 Iphelper cache not found for DHCP.

146 Zero NSID in Netbios request packet.

147 Iphelper policy not found for Netbios.

148 Iphelper cache not found for Netbios.

149 Zero NSID in Netbios reply packet when recv from server.

150 Zero NSID in Netbios reply packet when recv from client.

151 Zero NSID in Netbios reply packet.

152 Netbios client no egress element

153 Netbios server no egress element

154 Netbios client fail to create record

155 DHCP server fail to relay to client

156 DHCP client no egress element

157 DHCP client fail to create record

158 DHCP server, Ingress interface is same as egress interface.

159 Firewall, Ingress interface is same as egress interface.

160 Other Application, Ingress interface is same as egress interface.

161 Ingress interface is same as egress interface.

162 DHCP server packet dropped, RPF check failed.

163 Netbios client packet dropped, RPF check failed.

164 Netbios server packet dropped, RPF check failed.

165 Other Application relay to client failed

166 Other Application no egress element

167 Other Application fail to create record

168 Other Application packet dropped, RPF check failed.

169 Other Application client packet dropped, RPF check failed.

170 Other Application server packet dropped, RPF check failed.

171 Iphelper policy not found for other Application.

172 Iphelper policy not found for other Application when creating record.

173 Combuf Allocation Error.

174 Memory Allocation Error.

175 BSEG Memory Allocation Error.

176 Length Mismatch. Cant forward pkt!!!.

177 Control message header size error.

178 Drop GRE packet as call not yet established.

179 Invalid GRE Flags or Caller ID.

180 Invalid GRE sequence number.

181 No payload for GRE packet.

182 PPTP Tunnel is not up yet.

183 PPTP Client is not enabled.

184 PPTP WAN Write Spin Lock Error.

185 PPTP Spin Lock Error.

186 PPTP Flow Control Queuing Error.

187 Error copying PPTP combuf chain to continuous buffer.

188 Error fragmenting packet that is larger than PPTP MTU.

189 Enforced Dial-on-Data restriction.

190 PPPDU has not completed initialization.

191 Error fragmenting packet that is larger than PPPDU MTU.

192 PPPDU dropped packet because packet that is larger then PPPDU MTU and fragmentation is disabled.

193 Packet received with DF bit Set and large than MTU

194 PPP MLP link is not up/available.

195 PPP link is not up/available.

196 PPP link is not up.

197 PPP link is not opened.

198 The PPP buffer processing failed.

199 LCP: The PPP buffer is truncated.

200 The PPP buffer decompressing failed.

201 NCP: The PPP buffer is truncated.

202 PPP MLP pre-xmit error.

203 PPP MLP encapsulate error.

204 PPP MLP null pointer found.

205 PPP MLP no data packet.

206 PPP MLP link is not opened.

207 PPP MLP buffer decompressing failed.

208 PPP MLP BAP no netif nlinfo.

209 PPP MLP IP no netif nlinfo.

210 PPP MLP NBF no netif nlinfo.

211 PPP MLP VJCOMP no netif nlinfo.

212 PPP MLP VJCOMP decompressing failed.

213 PPP MLP VJUNCOMP no netif nlinfo.

214 PPP MLP VJUNCOMP decompressing failed.

215 PPP MLP IPX no netif nlinfo.

216 PPP MLP IPX decompressing failed.

217 PPP MLP AT no netif nlinfo.

218 PPP MLP 802.1 no netif nlinfo.

219 PPP MLP IBMSR no netif nlinfo.

220 PPP MLP DECLAN no netif nlinfo.

221 PPP MLP BRIDGE no netif nlinfo.

222 PPP MLP NBFCP no netif nlinfo.

223 PPP MLP IPCP no netif nlinfo.

224 The PPP PAP buffer processing failed.

225 The PPP CHAP buffer processing failed.

226 The PPP NCP buffer processing failed.

227 The PPP LCP buffer processing failed.

228 Received PPP pkt but there is no existing PPP information.

229 PPP Network Interface structure is NULL.

230 PPP Virtual Interface structure is NULL.

231 PPP no active link.

232 PPP dropped packet because it contains unknown protocol.

233 PPP dropped packet because of transmission failure.

234 PPP MLP NCP processing failed

235 PPP dropped packet because NCP is not open.

236 PPP dropped packet because the LCP code is unacceptable.

237 PPP dropped packet because the LCP code is unknown.

238 PPP HDLC PPPOE packet has no payload.

239 PPPOE packet has no payload.

240 The PPPOE buffer processing failed.

241 The PPPOE ingress buffer processing failed.

242 The PPPOE egress buffer processing failed.

243 PPPOE packet dropped because of NULL pointer.

244 PPPOE packet dropped because of NULL pointer in DP.

245 PPPOE packet dropped because BSEG allocation failed.

246 PPPOE packet dropped because buf put head action failed.

247 PPPOE packet dropped because PADO create PAD packet failed.

248 PPPOE packet dropped because PADI create PAD packet failed.

249 PPPOE packet dropped because PADR create PAD packet failed.

250 The PPP HDLC ingress buffer processing failed.

251 The PPP HDLC egress buffer processing failed.

252 The PPP HDLC dropped because of NULL pointer.

253 The PPP HDLC dropped because of NULL pointer in DP.

254 PPP HDLC packet dropped because BSEG allocation failed.

255 PPP HDLC packet dropped because buf put head action failed.

256 The PPP HDLC buffer processing failed.

257 The PPP HDLC PPPOE IPCP is not up.

258 The PPP HDLC PPPOE is not ready.

259 The PPP HDLC PPPOE is not ready in DP.

260 The PPPOE IPCP is not up.

261 The PPPOE module is not yet ready.

262 The PPPOE module is not yet ready in DP.

263 The PPP HDLC PPPOE is not enabled.

264 The PPP HDLC PPPOE is not enabled in DP.

265 The PPPOE module is not enabled.

266 The PPPOE module is not enabled in DP.

267 The PPP HDLC PPPOE is not re/started with NTP packets.

268 The PPP HDLC PPPOE is not re/started with NTP packets in DP.

269 The PPPOE module is not re/started with NTP packets.

270 The PPPOE module is not re/started with NTP packets in DP.

271 The PPP HDLC PPPOE is not re/started with non-IP packets.

272 The PPP HDLC PPPOE is not re/started with non-IP packets in DP.

273 The PPPOE module dropped the packet because it was non-IP.

274 The PPPOE module dropped the packet because it was non-IP in DP.

275 PPP HDLC PPPoE packet has unsupported version.

276 PPPoE packet has unsupported version.

277 Received PPP HDLC PPPOE packet for non-existent PPP session.

278 Received PPP HDLC PPPOE packet for non-existent PPP session in DP.

279 Received PPPoE packet for non-existent PPP session.

280 Received PPPoE packet for non-existent PPP session in DP.

281 PPPoE packet has an illegal session id.

282 PPPoE packet has unknown ethertype.

283 PPPoE packet is missing the service name tag.

284 PPPoE packet was not transmitted.

285 PPPoE packet dropped due to failure in adding enet header.

286 L2TP Length Mismatch

287 L2TP UDP checksum error

288 L2TP buffer corrupted

289 L2TP invalid tunnel

290 L2TP invalid session

291 L2TP Invalid source interface

292 L2TP packet not encrypted

293 L2TP Drop PPP control packet, session not established yet

294 L2TP Tunnel/Seesion Invalid

295 L2TP invalid pkt type

296 L2TP invalid control msg

297 L2TP unsupported version

298 L2TP invalid packet

299 L2TP not enabled on this interface

300 L2TP invalid runtime data

301 L2TP connection not UP

302 L2TP memory allocation failed

303 No IPSec tunnel active for this connection ,

304 Invalid L2TP Mode ,

305 Pkt pass to stack failed

306 UDP length greater than 1500

307 IP length greater than 1500

308 Pkt authentication failed

309 SA not found on lookup by SPI after decryption

310 SA not found on lookup by SPI after encryption

311 Failed to copy frag chain to contiguous buffer

312 Pkt with SPI less than 256

313 SA not found on lookup by SPI for inbound packet

314 Pkt length smaller than expected

315 Replayed Pkt

316 Pkt received on invalid interface

317 Expecting udp encapsulation

318 Not expecting udp encapsulation

319 Throughput regulator drop inbound pkt

320 Throughput regulator drop inbound pkt in CP

321 HW processing request error for inbound pkt

322 AH auth failed

323 ESP auth failed

324 ESP decrypt failed

325 Unknown protocol

326 Nested tunnels not supported

327 Pkt is not thru tunnell

328 Pkt is not thru tunnel or l2tp transport mode

329 Pkt not destined to mgmt interface

330 Pkt not destined to mgmt interface in CP

331 Pkt not destined to mgmt interface (non-octeon)

332 Pkt from invalid peer

333 VPN access list check failure

334 VPN access list check failure in CP

335 VPN access list check failure (non-octeon)

336 Pkt does not match traffic selectors

337 Pkt fragment not allowed

338 DHCP pkt invalid IP length

339 Octeon Decrypyion Failed for inbound packet

340 Incoming packet's combuf Ip Length Error

341 Combuf Ip Ptr Null Error

342 Multicast sa not found

343 SA not found on lookup by SPI for outbound pkt

344 Incorrect src IP on mgmt SA

345 Throughput regulator drop outbound pkt

346 Throughput regulator drop outbound pkt in CP

347 Insufficient command context for outbound pkt

348 HW processing request error for outbound pkt

349 Software esp decrypt processing request error

350 Software esp auth processing request error

351 Software ah auth processing request error

352 Software null sa processing request error

353 Software processing request error

354 Software malloc combuf fragment error

355 Combuf Fragmentation error

356 Combuf Fragmentation error after encryption

357 Combuf Fragmentation error after encryption in CP

358 Packet is large than MTU

359 Packet is large than MTU after encryption

360 Packet received with DF bit Set and large than MTU

361 Sequence overflow while encryting packet

362 Encption error for out going packet

363 Combuf Ip Ptr NUll Error

364 Combuf Ip Length Error

365 Next Hope MAC ARP error

366 Next Hope ARP not Resolved

367 Multicast buffer error

368 No IGMP entry found when leaving

369 No IGMP entry found when forwarding

370 No IGMP interface entry found

371 Combuf fields mismatch iplen-enet not equal to etherhdr size

372 IGMP wrong Checksum

373 Multicast not enabled

374 IGMPv2 state table error

375 IGMPv3 state table error

376 IGMP message has invalid length

377 IGMP message has invalid destination

378 IGMP message has invalid subtype

379 IGMPv3 message has invalid data length

380 IGMPv3 message has less data record

381 IGMPv3 message is invalid

382 IGMP query message version is not supported

383 IGMP report message version is not supported

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?