Description | This article discusses how to troubleshoot increasing error counters on the DROP_IHP1_PKTCHK counter for NP6 and NP6xlite devices. |
Scope | FortiGate NP6 and NP6xlite devices. |
Solution |
If a packet is dropped by the NP6 or Np6xlite process, run the 'diagnose npu np6/np6xlite dce <int>' command to verify which register is dropping the packet: Firewall-01 # diagnose npu np6xlite dce 0 The 'drop_ihp1_pktchk' counter refers to the number of dropped IP packets at the IHP1 level. This counter indicates the quantity of IP packets that were not successfully processed and were therefore dropped at this specific processing level within the NP6 processor.
To address packet drops at the IHP1 level, it is essential to review the configuration, monitor system resources, and optimize traffic shaping policies. |