Troubleshooting Questions
1. Media does not work when the RTSP ALG is configured. What do I do?
- Check RTSP conversations to see whether both TCP and UDP flows exist.
- The ALG protocol should be displayed as
rtsp.
2. How do I check for ALG errors?
- You can check for errors by issuing the following command. Each ALG has a separate field for ALG packet errors.
user@host#show services stateful-firewall statistics extensiveInterface: sp-3/2/0Service set: svc_setNew flows:Accepts: 1347, Discards: 0, Rejects: 0Existing flows:Accepts: 144187, Discards: 0, Rejects: 0Drops:IP option: 0, TCP SYN defense: 0NAT ports exhausted: 0Errors:IP: 0, TCP: 276UDP: 0, ICMP: 0Non-IP packets: 0, ALG: 0IP errors:IP packet length inconsistencies: 0Minimum IP header length check failures: 0Reassembled packet exceeds maximum IP length: 0Illegal source address: 0Illegal destination address: 0TTL zero errors: 0, Illegal IP protocol number (0 or 255): 0Land attack: 0Non-IPv4 packets: 0, Bad checksum: 0Illegal IP fragment length: 0IP fragment overlap: 0IP fragment reassembly timeout: 0Unknown: 0TCP errors:TCP header length inconsistencies: 0Source or destination port number is zero: 0Illegal sequence number and flags combinations: 0SYN attack (multiple SYN messages seen for the same flow): 276First packet not a SYN message: 0TCP port scan (TCP handshake, RST seen from server for SYN): 0Bad SYN cookie response: 0UDP errors:IP data length less than minimum UDP header length (8 bytes): 0Source or destination port number is zero: 0UDP port scan (ICMP error seen for UDP flow): 0ICMP errors:IP data length less than minimum ICMP header length (8 bytes): 0ICMP error length inconsistencies: 0Duplicate ping sequence number: 0Mismatched ping sequence number: 0ALG errors:BOOTP: 0, DCE-RPC: 0, DCE-RPC portmap: 0DNS: 0, Exec: 0, FTP: 0H323: 0, ICMP: 0, IIOP: 0Login: 0, NetBIOS: 0, NetShow: 0Real Audio: 0, RPC: 0, RPC portmap: 0RTSP: 0, Shell: 0, SIP: 0SNMP: 0, SQLNet: 0, TFTP: 0Traceroute: 0