Main Menu
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • English English English en
  • BLOG
  • CONTACT SALES
  • FREE TRIALS
  • English English English en
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • Menu

SM9800: Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS 6.2.1.1-28n

03/26/2020 4 People found this article helpful 103,346 Views

    Download
    Print
    Share
    • LinkedIn
    • Twitter
    • Facebook
    • Email
    • Copy URL The link has been copied to clipboard

    Description

    SM9800: Explanation of Drop code and Module-ID Values in Packet Capture Output (SonicOS 6.2.1.1-28n firmware) for SuperMassive SM9800

    Resolution

    Resolution: 

    When viewing output on the System > Packet Capture page, there are two fields that display potentially useful diagnosticinformation in numeric format. The Module-ID field provides information on the specific area of the firewall (UTM) appliance'sfirmware that handled a particular packet. The Drop-Code field provides a reason why the appliance dropped a particularpacket. This article provides a list of the Module-ID and Drop-Code numbers along with their meanings.

    Please Note: The following Drop Codes were extracted from SonicOS Enhanced 6.2.1.1-28n  firmware version for SM9800. These codes may change when a new firmware is available. If unsure, please contact SonicWall support.

     

    Module Id          Module NameModule Id      Module NameModule Id      Module Name
    0              
    1              adminTools
    2              attacks
    3              av
    4              bwmmgmt
    5              CIA
    6              cli
    7              clients
    8              config
    9              connectionCache
    10              contentFilter
    11              dea
    12              debug
    13              dhcpRelay
    14              dhtml
    15              fileSystem
    16              fwCore
    17              ha
    18              idp
    19              ipHelper
    20              ipSec
    21              lib
    22              log
    23              modem
    24              netObj
    25              network
    26              packetFilter
    27              policy
    28              pppStack
    29              RADIUS acct
    30              redirector
    31              reports
    32              resource
    33              sarc
    34              servers
    35              snmp
    36              spdpp
    37              stateful
    38              system
    39              TRAV2
    40              TSA
    41              USERS
    42              version
    43              wizards
    44              wlan
    45              wlb
    46              zones
    47              ARP
    48              system stack
    49              PPTP
    50              L2TP
    51              PPP-Dialup
    52              IGMP
    53              PPPOE
    54              NAT
    55              anti-spam
    56              NetMonitor
    57              Mirroring
    58              SIP
    59              BandOpt
    60              GMSFlow server
    61              APPFlow server
    62              QoS
    63              IPv6
    64              ICMPv6
    65              WireMode
    66              Packet Queue
    67              SSO
    68              


     
    DROP CODES
    Drop Code ID and name
    0              
    1              PIP handling error in CP
    2              PIP handling error in DP
    3              Packet on the backup aggregate interface, but no Sonic END can be found.
    4              Broadcast packet on the backup redundant port when primary port is up.
    5              Packet the redundancy port, but no Sonic END can be found.
    6              CP throttled DP for stack traffic
    7              Packet dropped due to pass to stack failed.
    8              Packet dropped by outputhook.
    9              Inter-blade Packet dropped due to CP pass to stack failed.
    10              HA active data packet processing failed.
    11              Packet dropped due to CP pass to stack failed.
    12              Dispatching IEEE802 BPDU packet failed.
    13              IEEE 802 BPDU support module has not been initialized yet.
    14              Invalide Ether type for IEEE 802 BPDU packet.
    15              Invalide source address for IEEE 802 BPDU packet.
    16              Unknown Ether type ingress.
    17              Null Ether header egress.
    18              Unknown Ether type egress.
    19              IPv6 packets not supported.
    20              Packet on invalid vlan
    21              Packet ingress on invalid interface
    22              Packet egress on invalid interface
    23              Packet on invalid device
    24              IPv6 Packet on invalid device
    25              Destination MAC address is not our interface
    26              IPv6 packet dropped: Destination MAC address is not our interface
    27              Device is not attached.
    28              Packet on invalid svrrp group
    29              Invalid HA packet
    30              Invalid IPv6 HA packet
    31              Invalid HA ARP packet
    32              PPPoE discover packet not allowed
    33              Invalid HA SDP packet
    34              Routing packet not allowed
    35              Routing packet not allowed for BGP packet
    36              Routing packet not allowed for ZebOS
    37              Routing packet not allowed for v6 ZebOS
    38              VLAN filtered.
    39              Unicast MACADDR not mine
    40              L2B Learning-Bridge filtered
    41              Invalid NET-ID found on mist if write.
    42              Invalid NET-ID found on if write arp real.
    43              Invalid NET-ID found on write ip fast.
    44              Invalid NET-ID found on if write.
    45              Invalid NET-ID found on if write no mbuf.
    46              Invalid Run-time NET data on mist if write.
    47              Invalid Run-time NET data on if write arp real.
    48              Invalid Run-time NET data on write ip fast.
    49              Invalid Run-time NET data on if write.
    50              Invalid parent Run-time NET data on if write.
    51              Invalid Run-time NET data on if write no mbuf.
    52              Invalid parent Run-time NET data on if write no mbuf.
    53              Unknown ARP type.
    54              Arp reply ignored.
    55              IP address not for our subnet
    56              ARP unexpected link ip
    57              ARP source ip not connected
    58              NULL source IP address
    59              Own gratuitous arp
    60              IP address not on our lan subnet
    61              Classical mode, ARP bridge not supported
    62              ARP proxy, subnet mismatch
    63              Not for me.
    64              ARP glean disabled.
    65              ARP request from stack
    66              ARP response from stack
    67              ARP fail to resolve from SonicPoint
    68              ARP unknown ethernet address format
    69              IP length of fragment UDP packets is too big(>65535), drop
    70              Invalid TCP Flag(#1)
    71              Invalid TCP Flag(#2)
    72              Invalid TCP Options(#1)
    73              Invalid TCP Options(#2)
    74              Invalid TCP Options(#3)
    75              Invalid TCP Options(#4)
    76              IP sanity test failed
    77              IP sanity test failed in out hook
    78              IP advanced sanity test failed
    79              Non sonicpoint traffic in wlan zone
    80              Multicast spank attack
    81              Multicast Data packet dropped
    82              Load Balancing Probe error
    83              Syn Flood Protection(#1)
    84              Syn Flood Protection(#2)
    85              Syn Flood Protection(#3)
    86              Duplicated in Syn Flood Protection
    87              IP source route option found
    88              Invalid connection cache.
    89              Invalid connection cache after lookup.
    90              Unknown destination(#1)
    91              Unknown destination(#2)
    92              Unknown destination for bridged bcast pkt
    93              Bounce traffic detected
    94              Access Rule Policy not found
    95              AV detection
    96              SEC detection
    97              DEA detection
    98              Bad TFTP packets
    99              Handle TFTP fails to add connection
    100              Bad SIP packets
    101              Bad VoIP stream
    102              SIP disabled
    103              Bad RTP stream
    104              Bad RAS stream
    105              Bad Microsoft ILS stream
    106              Drop after stateful inspection
    107              SSL Control cert block
    108              Content Filter block
    109              Drop invalid FTP data port packet
    110              GeoIP hook drop
    111              Packet dropped when write IPSec packet
    112              Enforced firewall rule(#1)
    113              Enforced firewall rule(#2)
    114              Enforced Content Filter Policy
    115              LICENSE drop
    116              IDP detection
    117              IDP detection Relaod Signatures Database
    118              IDP detection Attack Prevented(#1)
    119              IDP detection Attack Prevented(#2)
    120              IDP detection Fragmentation
    121              IDP detection Block Retry Exception
    122              IDP detection OOO Exceeded Max
    123              IDP detection OOO Out of Buffers
    124              IDP detection Keep Original
    125              IDP detection, bad tcp checksum
    126              IDP detection, bad ip checksum in tcp checking
    127              IDP detection, bad ip checksum in tcp packet
    128              IDP detection, bad udp checksum
    129              IDP detection, bad ip checksum in udp checking
    130              IDP detection, bad ip checksum in udp packet
    131              IDP detection, bad icmp checksum
    132              IDP detection, bad ip checksum in icmp checking
    133              IDP detection, bad ip checksum in icmp packet
    134              Packet to public IP from inside firewall
    135              Bad TTL
    136              IP MCast Bad TTL
    137              IP check failed
    138              Bad source IP(#1)
    139              Bad source IP(#2)
    140              Bad output source IP
    141              Bad destination MAC address
    142              Broadcast not allowed on bridge.
    143              Antispam: Going to blacklisted server.
    144              Going to blacklisted server.
    145              coming from blacklisted server.
    146              Broadcast traffic not handled.
    147              Multicast forwarding not configured
    148              Multicast IGMP state not found 
    149              Multicast IP not in the allowed list
    150              Anti-Spam Connection Limit Reached
    151              Active/Active DPI drop offload packet
    152              UDP Flood Protection
    153              ICMP Flood Protection
    154              Guest Service not allowed
    155              WLAN Guest Service not allowed
    156              Unknown Ether type
    157              Incorrect IP Version
    158              Blacklisted MAC address
    159              Greater IP Length
    160              Less IP Length
    161              TCP packet length mismatch with interface MTU
    162              UDP packet length mismatch with interface MTU
    163              Other protocol packet length mismatch with interface MTU
    164              First fragment length less than minimum IP MTU
    165              Wrong fragmentation boundary(#1).
    166              Wrong fragmentation boundary(#2).
    167              Wrong IP checksum value(#1).
    168              Wrong IP checksum value(#2).
    169              Tcp struct init fail(#1).
    170              Tcp struct init fail(#2).
    171              Wrong TCP Checksum value.
    172              Wrong TCP Checksum value(#1).
    173              Wrong TCP Checksum value(#2).
    174              Wrong UDP Checksum value.
    175              Wrong ICMP Checksum value(#1).
    176              Wrong ICMP Checksum value(#2).
    177              ICMP High perf error.
    178              NULL Udp port number
    179              Non PPP-GRE traffic 
    180              Missing ESP Header
    181              Missing AH Header
    182              Missing IPCOMP Header
    183              Unknown IP protocol type(#1)
    184              Unknown IP protocol type(#2)
    185              TTL value is zero.
    186              TTL value is zero, case two.
    187              l2 mcast but dest ip is unicast(#1)
    188              l2 mcast but dest ip is unicast(#2)
    189              Null Source Zone.
    190              Wrong UDP Length.
    191              IGMP packets could not be fragmented    
    192              RECV: IP pkt recvd without IPCP session
    193              RECV: IP pkt recvd without contiguous buf
    194              RECV: IP pkt recvd without combuf
    195              RECV: TNMP can't alloc contiguous buf
    196              XMIT: AHDLC encap no buf
    197              XMIT: TNMP can't alloc contiguous buf
    198              XMIT: Device not ready to forward traffic
    199              XMIT: No IPCP session
    200              XMIT: IPCP is down
    201              XMIT: No Dialup Msg Buffer available
    202              Non Zero GIAddr field in DHCP packet from client
    203              Source MAC is different from chAddr field in DHCP client packet
    204              Iphelper policy not found for DHCP relay.
    205              Iphelper cache not found for DHCP.
    206              Zero NSID in Netbios request packet.
    207              Iphelper policy not found for Netbios.
    208              Iphelper cache not found for Netbios.
    209              Zero NSID in Netbios reply packet when recv from server.
    210              Zero NSID in Netbios reply packet when recv from client.
    211              Zero NSID in Netbios reply packet.
    212              Netbios client no egress element
    213              Netbios server no egress element
    214              Netbios client fail to create record
    215              DHCP server fail to relay to client
    216              DHCP client no egress element
    217              DHCP client fail to create record
    218              DHCP server, Ingress interface is same as egress interface.
    219              Firewall, Ingress interface is same as egress interface.
    220              Other Application, Ingress interface is same as egress interface.
    221              Ingress interface is same as egress interface.
    222              DHCP server packet dropped, RPF check failed.
    223              Netbios client packet dropped, RPF check failed.
    224              Netbios server packet dropped, RPF check failed.
    225              Other Application relay to client failed
    226              Other Application no egress element
    227              Other Application fail to create record
    228              Other Application packet dropped, RPF check failed.
    229              Other Application client packet dropped, RPF check failed.
    230              Other Application server packet dropped, RPF check failed.
    231              Iphelper policy not found for other Application.
    232              Iphelper policy not found for other Application when creating record.
    233              Combuf Allocation Error.
    234              Memory Allocation Error.
    235              BSEG Memory Allocation Error.
    236              Length Mismatch. Cant forward pkt!!!.
    237              Control message header size error.
    238              Drop GRE packet as call not yet established.
    239              Invalid GRE Flags or Caller ID.
    240              Invalid GRE sequence number.
    241              No payload for GRE packet.
    242              PPTP Tunnel is not up yet.
    243              PPTP Client is not enabled.
    244              PPTP WAN Write Spin Lock Error.
    245              PPTP Spin Lock Error.
    246              PPTP Flow Control Queuing Error.
    247              Error copying PPTP combuf chain to continuous buffer.
    248              Error fragmenting packet that is larger than PPTP MTU.
    249              Enforced Dial-on-Data restriction.
    250              PPPDU has not completed initialization.
    251              Error fragmenting packet that is larger than PPPDU MTU.
    252              PPPDU dropped packet because packet that is larger then PPPDU MTU and fragmentation is disabled.
    253              Packet received with DF bit Set and large than MTU 
    254              PPP MLP link is not up/available.
    255              PPP link is not up/available.
    256              PPP link is not up.
    257              PPP link is not opened.
    258              The PPP buffer processing failed.
    259              LCP: The PPP buffer is truncated.
    260              The PPP buffer decompressing failed.
    261              NCP: The PPP buffer is truncated.
    262              PPP MLP pre-xmit error.
    263              PPP MLP encapsulate error.
    264              PPP MLP null pointer found.
    265              PPP MLP no data packet.
    266              PPP MLP link is not opened.
    267              PPP MLP buffer decompressing failed.
    268              PPP MLP BAP no netif nlinfo.
    269              PPP MLP IP no netif nlinfo.
    270              PPP MLP NBF no netif nlinfo.
    271              PPP MLP VJCOMP no netif nlinfo.
    272              PPP MLP VJCOMP decompressing failed.
    273          

    Related Articles

    • SSL Control and DPI-SSL Compatibility
    • FIPS Mode: Radius protected with IPSEC VPN
    • Maximum DHCP Leases

    Categories

    • Firewalls > TZ Series
    • Firewalls > SonicWall SuperMassive E10000 Series
    • Firewalls > SonicWall SuperMassive 9000 Series
    • Firewalls > SonicWall NSA Series

    Not Finding Your Answers?

    ASK THE COMMUNITY

    Was This Article Helpful?

    YESNO

    Article Helpful Form

    Article Not Helpful Form

    Company
    • Careers
    • News
    • Leadership
    • Awards
    • Press Kit
    • Contact Us
    Popular resources
    • Communities
    • Blog
    • SonicWall Capture Labs

    Stay In Touch

    • By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time from the Preference Center.
    • This field is for validation purposes and should be left unchanged.
    • Facebook
    • Twitter
    • Linkedin
    • Youtube
    • Instagram

    © 2022 SonicWall. All Rights Reserved.

    • Legal
    • Privacy
    • English
      Scroll to top
      Trace:dd05288e52973a5809ba22c373a5ba22-70