Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2.0-11

Description

Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2.0-11n firmware)

Resolution

When viewing output on the System > Packet Capture page, there are two fields that display potentially useful diagnosticinformation in numeric format. The Module-ID field provides information on the specific area of the firewall (UTM) appliance'sfirmware that handled a particular packet. The Drop-Code field provides a reason why the appliance dropped a particularpacket. This article provides a list of the Module-ID and Drop-Code numbers along with their meanings.

Please Note: The following Drop Codes were extracted from SonicOS Enhanced 6.1.2.0 -11n  firmware version. These codes may change when a new firmware is available. If unsure, please contact SonicWall support.

 

1             adminTools
2             attacks
3             av
4             bwmmgmt
5             CIA
6             cli
7             clients
8             config
9             connection Cache
10           contentFilter
11           dea
12           debug
13           dhcpRelay
14           dhtml
15           fileSystem
16           fwCore
17           ha
18           idp
19           ipHelper
20           ipSec
21              lib
22              log
23              modem
24              netObj
25              network
26              packetFilter
27              policy
28              pppStack
29              RADIUS acct
30              redirector
31              reports
32              resource
33              sarc
34              servers
35              snmp
36              spdpp
37              stateful
38              system
39              TRAV2
40              TSA
41              USER
42              version
43              wizards
44              wlan
45              wlb
46              zones
47              ARP
48              system stack
49              PPTP
50              L2TP
51              PPP-Dialup
52              IGMP
53              PPPOE
54              NAT
55              anti-spam
56              NetMonitor
57              Mirroring
58              SIP
59              BandOpt
60          
  
 
DROP CODES
Drop Code ID and name
 

Error Code Error

0

1 Unknown Ether type.

2 IPv6 packets not supported.

3 Packet on invalid vlan

4 Packet on invalid interface

5 Invalid HA packet

6 Invalid HA ARP packet

7 PPPoE discover packet not allowed

8 Invalid HA SDP packet

9 Routing packet not allowed

10 VLAN filtered.

11 Unicast MACADDR not mine

12 L2B Learning-Bridge filtered

13 Invalid NET-ID found.

14 Invalid Run-time NET data.

15 Unknown ARP type.

16 Arp reply ignored.

17 IP address not for our subnet

18 NULL source IP address

19 Own gratuitous arp

20 IP address not on our lan subnet

21 Classical mode, ARP bridge not supported

22 ARP proxy, subnet mismatch

23 Not for me.

24 Invalid TCP Flag

25 Invalid TCP Options

26 IP sanity test failed

27 Non sonicpoint traffic in wlan zone

28 Multicast spank attack

29 Multicast Data packet dropped

30 Load Balancing Probe error

31 Syn Flood Protection

32 IP source route option found

33 Invalid connection cache.

34 Unknown destination

35 Bounce traffic detected

36 Access Rule Policy not found

37 AV detection

38 DEA detection

39 Bad TFTP packets

40 Enforced firewall rule

41 LICENSE drop

42 IDP detection

43 Packet to public IP from inside firewall

44 Bad TTL

45 IP check failed

46 Bad source IP

47 Bad destination MAC address

48 Broadcast not allowed on bridge.

49 Going to blacklisted server.

50 coming from blacklisted server.

51 Broadcast traffic not handled.

52 Multicast forwarding not configured

53 Multicast IGMP state not found

54 Multicast IP not in the allowed list

55 Anti-Spam Connection Limit Reached

56 Active/Active DPI drop offload packet

57 UDP Flood Protection

58 ICMP Flood Protection

59 Guest Service not allowed

60 Unknown Ether type

61 Incorrect IP Version

62 Blacklisted MAC address

63 Wrong IP Length

64 Packet length mismatch with interface MTU

65 Wrong fragmentation boundary.

66 Wrong IP checksum value.

67 Wrong TCP Checksum value.

68 Wrong UDP Checksum value.

69 Wrong ICMP Checksum value.

70 NULL Udp port number

71 Non PPP-GRE traffic

72 Missing ESP Header

73 Missing AH Header

74 Missing IPCOMP Header

75 Unknown IP protocol type

76 TTL value is zero.

77 l2 mcast but dest ip is unicast

78 Null Source Zone.

79 Wrong UDP Length.

80 RECV: IP pkt recvd without IPCP session

81 RECV: TNMP can't alloc contiguous buf

82 XMIT: AHDLC encap no buf

83 XMIT: TNMP can't alloc contiguous buf

84 XMIT: Device not ready to forward traffic

85 XMIT: No IPCP session

86 XMIT: No Dialup Msg Buffer available

87 Non Zero GIAddr field in DHCP packet from client

88 Source MAC is different from chAddr field in DHCP client packet

89 Iphelper policy not found for DHCP relay.

90 Iphelper cache not found for DHCP.

91 Zero NSID in Netbios request packet.

92 Iphelper policy not found for Netbios.

93 Iphelper cache not found for Netbios.

94 Zero NSID in Netbios reply packet.

95 Ingress interface is same as egress interface.

96 DHCP server packet dropped, RPF check failed.

97 Netbios packet dropped, RPF check failed.

98 Other Application packet dropped, RPF check failed.

99 Iphelper policy not found for other Application.

100 Memory Allocation Error.

101 Length Mismatch. Cant forward pkt!!!.

102 Control message header size error.

103 Drop GRE packet as call not yet established.

104 Invalid GRE Flags or Caller ID.

105 Invalid GRE sequence number.

106 No payload for GRE packet.

107 PPTP Tunnel is not up yet.

108 PPTP Client is not enabled.

109 PPTP Spin Lock Error.

110 PPTP Flow Control Queuing Error.

111 Error copying PPTP combuf chain to continuous buffer.

112 Error fragmenting packet that is larger than PPTP MTU.

113 Enforced Dial-on-Data restriction.

114 PPPDU has not completed initialization.

115 Error fragmenting packet that is larger than PPPDU MTU.

116 PPPDU dropped packet because packet that is larger then PPPDU MTU and fragmentation is disabled.

117 Packet received with DF bit Set and large than MTU

118 PPP link is not up/available.

119 The PPP buffer processing failed.

120 Received PPP pkt but there is no existing PPP information.

121 PPP Network Interface structure is NULL.

122 PPP Virtual Interface structure is NULL.

123 PPP dropped packet because it contains unknown protocol.

124 PPP dropped packet because of transmission failure.

125 PPP dropped packet because NCP is not open.

126 PPP dropped packet because the LCP code is unacceptable.

127 PPPOE packet has no payload.

128 The PPPOE buffer processing failed.

129 The PPPOE module is not yet ready.

130 The PPPOE module is not enabled.

131 The PPPOE module is not re/started with NTP packets.

132 The PPPOE module dropped the packet because it was non-IP.

133 PPPoE packet has unsupported version.

134 Received PPPoE packet for non-existent PPP session

135 PPPoE packet has an illegal session id.

136 PPPoE packet has unknown ethertype.

137 PPPoE packet is missing the service name tag.

138 PPPoE packet was not transmitted.

139 PPPoE packet dropped due to failure in adding enet header.

140 L2TP Length Mismatch

141 L2TP UDP checksum error

142 L2TP buffer corrupted

143 L2TP invalid tunnel

144 L2TP invalid session

145 L2TP Invalid source interface

146 L2TP packet not encrypted

147 L2TP Drop PPP control packet, session not established yet

148 L2TP Tunnel/Seesion Invalid

149 L2TP invalid pkt type

150 L2TP invalid control msg

151 L2TP unsupported version

152 L2TP not enabled on this interface

153 L2TP invalid packet

154 L2TP invalid runtime data

155 L2TP connection not UP

156 L2TP memory allocation failed

157 No IPSec tunnel active for this connection ,

158 Invalid L2TP Mode ,

159 Pkt pass to stack failed

160 UDP length greater than 1500

161 IP length greater than 1500

162 Pkt authentication failed

163 SA not found on lookup by SPI after decryption

164 SA not found on lookup by SPI after encryption

165 Failed to copy frag chain to contiguous buffer

166 Pkt with SPI less than 256

167 SA not found on lookup by SPI for inbound packet

168 Pkt length smaller than expected

169 Replayed Pkt

170 Pkt received on invalid interface

171 Expecting udp encapsulation

172 Not expecting udp encapsulation

173 Throughput regulator drop inbound pkt

174 HW processing request error for inbound pkt

175 AH auth failed

176 ESP auth failed

177 ESP decrypt failed

178 Unknown protocol

179 Nested tunnels not supported

180 Pkt is not thru tunnell

181 Pkt is not thru tunnel or l2tp transport mode

182 Pkt not destined to mgmt interface

183 Pkt from invalid peer

184 VPN access list check failure

185 Pkt does not match traffic selectors

186 Pkt fragment not allowed

187 DHCP pkt invalid IP length

188 Octeon Decrypyion Failed for inbound packet

189 Incoming packet's combuf Ip Length Error

190 Combuf Ip Ptr Null Error

191 Multicast sa not found

192 SA not found on lookup by SPI for outbound pkt

193 Incorrect src IP on mgmt SA

194 Throughput regulator drop outbound pkt

195 Insufficient command context for outbound pkt

196 HW processing request error for outbound pkt

197 Software esp decrypt processing request error

198 Software esp auth processing request error

199 Software ah auth processing request error

200 Software null sa processing request error

201 Software processing request error

202 Combuf Fragmentation error

203 Packet is large than MTU

204 Packet received with DF bit Set and large than MTU

205 Sequence overflow while encryting packet

206 Encption error for out going packet

207 Combuf Ip Ptr NUll Error

208 Combuf Ip Length Error

209 Next Hope ARP not Resolved

210 Multicast buffer error

211 No IGMP entry found

212 No IGMP interface entry found

213 Combuf fields mismatch iplen-enet not equal to etherhdr size

214 IGMP wrong Checksum

215 Multicast not enabled

216 IGMP state table error

217 IGMP message error

218 IGMPV3 message error

219 IGMP version not supported

220 Multicast RTP stateful failed

221 IP Spoof check failed

222 OutGoing interface not available

223 Cache pointer is NULL. NAT policy lookup cannot be performed

224 NAT policy remap failed

225 NAT policy unique remap port failed

226 NAT policy lookup failed. Cache add aborted

227 Connection cache is full

228 Get VPN tunnel interface from policy failed

229 Packet from bounced path

230 Half open ESP connection

231 Half open IPCOMP connection

232 Allocate memory for connection cache failed

233 Packet marked to be dropped on ingress

234 Packet marked to be dropped on egress

235 Packet dropped by BWM CBQ as there is no default queue

236 Packet dropped by BWM CBQ as the queue is full

237 Packet dropped by BWM ACKQ as the queue is full

238 Packet dropped by BWM ACKQ as there is no default queue

239 Packet dropped due to BWM spin lock error

240 MAC-IP Anti-spoof check enforced for hosts.

241 MAC-IP Anti-spoof cache not found for this router.

242 MAC-IP Anti-spoof cache found, but it is not a router.

243 MAC-IP Anti-spoof cache found, but it is blacklisted device.

244 Packet dropped - IDP failure on sslspy packet

245 Packet droppedd - Content filter failure on sslspy packet

246 Packet dropped - failed processing

247 Packet dropped - failed SIP pre-processing

248 Packet dropped - failed SIP post-processing

249 Packet dropped - unknown SIP method

250 Packet dropped - unknown Call-ID in method

251 Packet dropped - invalid Contact:

252 Packet dropped - invalid Call-ID:

253 Packet dropped - invalid Via:

254 Packet dropped - invalid From:

255 Packet dropped - invalid To:

256 Packet dropped - invalid RecordRoute:

257 Packet dropped - invalid Maddr:

258 Packet dropped - invalid Route:

259 Packet dropped - invalid ACK

260 Packet dropped - invalid method

261 Packet dropped - invalid ReferredBy:

262 Packet dropped - invalid ReferredTo:

263 Packet dropped - invalid BYE

264 Packet dropped - invalid CANCEL

265 Packet dropped - invalid INVITE

266 Packet dropped - invalid REGISTER

267 Packet dropped - SDP body not found

268 Packet dropped - bad SDP content length

269 Packet dropped - bad SDP c=

270 Packet dropped - bad SDP m=

271 Packet dropped - failed SDP processing

272 Packet dropped - Geo-IP block for init country

273 Packet dropped - Geo-IP block for resp country

274 Packet dropped - BOTNET block for init command and control center

275 Packet dropped - BOTNET block for resp command and control center

276 -

 

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?