Forum Discussion
AFM Drops drop_reason="Connection Flow Miss"
Hi
We have AFM logs going to a SIEM and they are generating thousands per hour drops for the reason drop_reason="Connection Flow Miss". Google yielded not much so didn't know if anyone has seen this and what might be causing it. I understand it maybe down to seeing a non-SYN or not matching TCP packet but there's just so many.
It seems to be mostly from Server-to-F5 FloatIP communication
Regards
Stuart
1 Reply
- Jinshu
Cirrus
Hi mate,
Packets that were dropped because of a flow table miss. A flow table miss occurs when a TCP non-SYN packet does not match an existing flow.
You can disable this logging to SIEM if you would like to.
Hope this helps.
-Jinshu
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com