Main Menu
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • English English English en
  • BLOG
  • CONTACT SALES
  • FREE TRIALS
  • English English English en
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • Menu

Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2.0-11

03/26/2020 1,016 People found this article helpful 102,899 Views

    Download
    Print
    Share
    • LinkedIn
    • Twitter
    • Facebook
    • Email
    • Copy URL The link has been copied to clipboard

    Description

    Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS Enhanced 6.1.2.0-11n firmware)

    Resolution

    When viewing output on the System > Packet Capture page, there are two fields that display potentially useful diagnosticinformation in numeric format. The Module-ID field provides information on the specific area of the firewall (UTM) appliance'sfirmware that handled a particular packet. The Drop-Code field provides a reason why the appliance dropped a particularpacket. This article provides a list of the Module-ID and Drop-Code numbers along with their meanings.

    Please Note: The following Drop Codes were extracted from SonicOS Enhanced 6.1.2.0 -11n  firmware version. These codes may change when a new firmware is available. If unsure, please contact SonicWall support.

     

    1             adminTools
    2             attacks
    3             av
    4             bwmmgmt
    5             CIA
    6             cli
    7             clients
    8             config
    9             connection Cache
    10           contentFilter
    11           dea
    12           debug
    13           dhcpRelay
    14           dhtml
    15           fileSystem
    16           fwCore
    17           ha
    18           idp
    19           ipHelper
    20           ipSec
    21              lib
    22              log
    23              modem
    24              netObj
    25              network
    26              packetFilter
    27              policy
    28              pppStack
    29              RADIUS acct
    30              redirector
    31              reports
    32              resource
    33              sarc
    34              servers
    35              snmp
    36              spdpp
    37              stateful
    38              system
    39              TRAV2
    40              TSA
    41              USER
    42              version
    43              wizards
    44              wlan
    45              wlb
    46              zones
    47              ARP
    48              system stack
    49              PPTP
    50              L2TP
    51              PPP-Dialup
    52              IGMP
    53              PPPOE
    54              NAT
    55              anti-spam
    56              NetMonitor
    57              Mirroring
    58              SIP
    59              BandOpt
    60          
      
     
    DROP CODES
    Drop Code ID and name
     

    Error Code Error

    0

    1 Unknown Ether type.

    2 IPv6 packets not supported.

    3 Packet on invalid vlan

    4 Packet on invalid interface

    5 Invalid HA packet

    6 Invalid HA ARP packet

    7 PPPoE discover packet not allowed

    8 Invalid HA SDP packet

    9 Routing packet not allowed

    10 VLAN filtered.

    11 Unicast MACADDR not mine

    12 L2B Learning-Bridge filtered

    13 Invalid NET-ID found.

    14 Invalid Run-time NET data.

    15 Unknown ARP type.

    16 Arp reply ignored.

    17 IP address not for our subnet

    18 NULL source IP address

    19 Own gratuitous arp

    20 IP address not on our lan subnet

    21 Classical mode, ARP bridge not supported

    22 ARP proxy, subnet mismatch

    23 Not for me.

    24 Invalid TCP Flag

    25 Invalid TCP Options

    26 IP sanity test failed

    27 Non sonicpoint traffic in wlan zone

    28 Multicast spank attack

    29 Multicast Data packet dropped

    30 Load Balancing Probe error

    31 Syn Flood Protection

    32 IP source route option found

    33 Invalid connection cache.

    34 Unknown destination

    35 Bounce traffic detected

    36 Access Rule Policy not found

    37 AV detection

    38 DEA detection

    39 Bad TFTP packets

    40 Enforced firewall rule

    41 LICENSE drop

    42 IDP detection

    43 Packet to public IP from inside firewall

    44 Bad TTL

    45 IP check failed

    46 Bad source IP

    47 Bad destination MAC address

    48 Broadcast not allowed on bridge.

    49 Going to blacklisted server.

    50 coming from blacklisted server.

    51 Broadcast traffic not handled.

    52 Multicast forwarding not configured

    53 Multicast IGMP state not found

    54 Multicast IP not in the allowed list

    55 Anti-Spam Connection Limit Reached

    56 Active/Active DPI drop offload packet

    57 UDP Flood Protection

    58 ICMP Flood Protection

    59 Guest Service not allowed

    60 Unknown Ether type

    61 Incorrect IP Version

    62 Blacklisted MAC address

    63 Wrong IP Length

    64 Packet length mismatch with interface MTU

    65 Wrong fragmentation boundary.

    66 Wrong IP checksum value.

    67 Wrong TCP Checksum value.

    68 Wrong UDP Checksum value.

    69 Wrong ICMP Checksum value.

    70 NULL Udp port number

    71 Non PPP-GRE traffic

    72 Missing ESP Header

    73 Missing AH Header

    74 Missing IPCOMP Header

    75 Unknown IP protocol type

    76 TTL value is zero.

    77 l2 mcast but dest ip is unicast

    78 Null Source Zone.

    79 Wrong UDP Length.

    80 RECV: IP pkt recvd without IPCP session

    81 RECV: TNMP can't alloc contiguous buf

    82 XMIT: AHDLC encap no buf

    83 XMIT: TNMP can't alloc contiguous buf

    84 XMIT: Device not ready to forward traffic

    85 XMIT: No IPCP session

    86 XMIT: No Dialup Msg Buffer available

    87 Non Zero GIAddr field in DHCP packet from client

    88 Source MAC is different from chAddr field in DHCP client packet

    89 Iphelper policy not found for DHCP relay.

    90 Iphelper cache not found for DHCP.

    91 Zero NSID in Netbios request packet.

    92 Iphelper policy not found for Netbios.

    93 Iphelper cache not found for Netbios.

    94 Zero NSID in Netbios reply packet.

    95 Ingress interface is same as egress interface.

    96 DHCP server packet dropped, RPF check failed.

    97 Netbios packet dropped, RPF check failed.

    98 Other Application packet dropped, RPF check failed.

    99 Iphelper policy not found for other Application.

    100 Memory Allocation Error.

    101 Length Mismatch. Cant forward pkt!!!.

    102 Control message header size error.

    103 Drop GRE packet as call not yet established.

    104 Invalid GRE Flags or Caller ID.

    105 Invalid GRE sequence number.

    106 No payload for GRE packet.

    107 PPTP Tunnel is not up yet.

    108 PPTP Client is not enabled.

    109 PPTP Spin Lock Error.

    110 PPTP Flow Control Queuing Error.

    111 Error copying PPTP combuf chain to continuous buffer.

    112 Error fragmenting packet that is larger than PPTP MTU.

    113 Enforced Dial-on-Data restriction.

    114 PPPDU has not completed initialization.

    115 Error fragmenting packet that is larger than PPPDU MTU.

    116 PPPDU dropped packet because packet that is larger then PPPDU MTU and fragmentation is disabled.

    117 Packet received with DF bit Set and large than MTU

    118 PPP link is not up/available.

    119 The PPP buffer processing failed.

    120 Received PPP pkt but there is no existing PPP information.

    121 PPP Network Interface structure is NULL.

    122 PPP Virtual Interface structure is NULL.

    123 PPP dropped packet because it contains unknown protocol.

    124 PPP dropped packet because of transmission failure.

    125 PPP dropped packet because NCP is not open.

    126 PPP dropped packet because the LCP code is unacceptable.

    127 PPPOE packet has no payload.

    128 The PPPOE buffer processing failed.

    129 The PPPOE module is not yet ready.

    130 The PPPOE module is not enabled.

    131 The PPPOE module is not re/started with NTP packets.

    132 The PPPOE module dropped the packet because it was non-IP.

    133 PPPoE packet has unsupported version.

    134 Received PPPoE packet for non-existent PPP session

    135 PPPoE packet has an illegal session id.

    136 PPPoE packet has unknown ethertype.

    137 PPPoE packet is missing the service name tag.

    138 PPPoE packet was not transmitted.

    139 PPPoE packet dropped due to failure in adding enet header.

    140 L2TP Length Mismatch

    141 L2TP UDP checksum error

    142 L2TP buffer corrupted

    143 L2TP invalid tunnel

    144 L2TP invalid session

    145 L2TP Invalid source interface

    146 L2TP packet not encrypted

    147 L2TP Drop PPP control packet, session not established yet

    148 L2TP Tunnel/Seesion Invalid

    149 L2TP invalid pkt type

    150 L2TP invalid control msg

    151 L2TP unsupported version

    152 L2TP not enabled on this interface

    153 L2TP invalid packet

    154 L2TP invalid runtime data

    155 L2TP connection not UP

    156 L2TP memory allocation failed

    157 No IPSec tunnel active for this connection ,

    158 Invalid L2TP Mode ,

    159 Pkt pass to stack failed

    160 UDP length greater than 1500

    161 IP length greater than 1500

    162 Pkt authentication failed

    163 SA not found on lookup by SPI after decryption

    164 SA not found on lookup by SPI after encryption

    165 Failed to copy frag chain to contiguous buffer

    166 Pkt with SPI less than 256

    167 SA not found on lookup by SPI for inbound packet

    168 Pkt length smaller than expected

    169 Replayed Pkt

    170 Pkt received on invalid interface

    171 Expecting udp encapsulation

    172 Not expecting udp encapsulation

    173 Throughput regulator drop inbound pkt

    174 HW processing request error for inbound pkt

    175 AH auth failed

    176 ESP auth failed

    177 ESP decrypt failed

    178 Unknown protocol

    179 Nested tunnels not supported

    180 Pkt is not thru tunnell

    181 Pkt is not thru tunnel or l2tp transport mode

    182 Pkt not destined to mgmt interface

    183 Pkt from invalid peer

    184 VPN access list check failure

    185 Pkt does not match traffic selectors

    186 Pkt fragment not allowed

    187 DHCP pkt invalid IP length

    188 Octeon Decrypyion Failed for inbound packet

    189 Incoming packet's combuf Ip Length Error

    190 Combuf Ip Ptr Null Error

    191 Multicast sa not found

    192 SA not found on lookup by SPI for outbound pkt

    193 Incorrect src IP on mgmt SA

    194 Throughput regulator drop outbound pkt

    195 Insufficient command context for outbound pkt

    196 HW processing request error for outbound pkt

    197 Software esp decrypt processing request error

    198 Software esp auth processing request error

    199 Software ah auth processing request error

    200 Software null sa processing request error

    201 Software processing request error

    202 Combuf Fragmentation error

    203 Packet is large than MTU

    204 Packet received with DF bit Set and large than MTU

    205 Sequence overflow while encryting packet

    206 Encption error for out going packet

    207 Combuf Ip Ptr NUll Error

    208 Combuf Ip Length Error

    209 Next Hope ARP not Resolved

    210 Multicast buffer error

    211 No IGMP entry found

    212 No IGMP interface entry found

    213 Combuf fields mismatch iplen-enet not equal to etherhdr size

    214 IGMP wrong Checksum

    215 Multicast not enabled

    216 IGMP state table error

    217 IGMP message error

    218 IGMPV3 message error

    219 IGMP version not supported

    220 Multicast RTP stateful failed

    221 IP Spoof check failed

    222 OutGoing interface not available

    223 Cache pointer is NULL. NAT policy lookup cannot be performed

    224 NAT policy remap failed

    225 NAT policy unique remap port failed

    226 NAT policy lookup failed. Cache add aborted

    227 Connection cache is full

    228 Get VPN tunnel interface from policy failed

    229 Packet from bounced path

    230 Half open ESP connection

    231 Half open IPCOMP connection

    232 Allocate memory for connection cache failed

    233 Packet marked to be dropped on ingress

    234 Packet marked to be dropped on egress

    235 Packet dropped by BWM CBQ as there is no default queue

    236 Packet dropped by BWM CBQ as the queue is full

    237 Packet dropped by BWM ACKQ as the queue is full

    238 Packet dropped by BWM ACKQ as there is no default queue

    239 Packet dropped due to BWM spin lock error

    240 MAC-IP Anti-spoof check enforced for hosts.

    241 MAC-IP Anti-spoof cache not found for this router.

    242 MAC-IP Anti-spoof cache found, but it is not a router.

    243 MAC-IP Anti-spoof cache found, but it is blacklisted device.

    244 Packet dropped - IDP failure on sslspy packet

    245 Packet droppedd - Content filter failure on sslspy packet

    246 Packet dropped - failed processing

    247 Packet dropped - failed SIP pre-processing

    248 Packet dropped - failed SIP post-processing

    249 Packet dropped - unknown SIP method

    250 Packet dropped - unknown Call-ID in method

    251 Packet dropped - invalid Contact:

    252 Packet dropped - invalid Call-ID:

    253 Packet dropped - invalid Via:

    254 Packet dropped - invalid From:

    255 Packet dropped - invalid To:

    256 Packet dropped - invalid RecordRoute:

    257 Packet dropped - invalid Maddr:

    258 Packet dropped - invalid Route:

    259 Packet dropped - invalid ACK

    260 Packet dropped - invalid method

    261 Packet dropped - invalid ReferredBy:

    262 Packet dropped - invalid ReferredTo:

    263 Packet dropped - invalid BYE

    264 Packet dropped - invalid CANCEL

    265 Packet dropped - invalid INVITE

    266 Packet dropped - invalid REGISTER

    267 Packet dropped - SDP body not found

    268 Packet dropped - bad SDP content length

    269 Packet dropped - bad SDP c=

    270 Packet dropped - bad SDP m=

    271 Packet dropped - failed SDP processing

    272 Packet dropped - Geo-IP block for init country

    273 Packet dropped - Geo-IP block for resp country

    274 Packet dropped - BOTNET block for init command and control center

    275 Packet dropped - BOTNET block for resp command and control center

    276 -

     

    Related Articles

    • SSL Control and DPI-SSL Compatibility
    • FIPS Mode: Radius protected with IPSEC VPN
    • Maximum DHCP Leases

    Categories

    • Firewalls > TZ Series
    • Firewalls > SonicWall SuperMassive E10000 Series
    • Firewalls > SonicWall SuperMassive 9000 Series
    • Firewalls > SonicWall NSA Series

    Not Finding Your Answers?

    ASK THE COMMUNITY

    Was This Article Helpful?

    YESNO

    Article Helpful Form

    Article Not Helpful Form

    Company
    • Careers
    • News
    • Leadership
    • Awards
    • Press Kit
    • Contact Us
    Popular resources
    • Communities
    • Blog
    • SonicWall Capture Labs

    Stay In Touch

    • By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time from the Preference Center.
    • This field is for validation purposes and should be left unchanged.
    • Facebook
    • Twitter
    • Linkedin
    • Youtube
    • Instagram

    © 2022 SonicWall. All Rights Reserved.

    • Legal
    • Privacy
    • English
    Scroll to top
    Trace:4ee82ce2006b54d95245027ae7978e4a-89