Fix the "dropped retransmit" event detected by the Deep Security Network Engine, and not solely by the Firewall module. This solution applies whether the event was detected by a Deep Security Virtual Appliance (DSVA), by an installed Deep Security Agent (DSA), or by an agentless machine.
The "dropped retransmit" event means that a duplicated packet was dropped by the network engine. Since the first packet was successfully received, the duplicated packet dropped by DSA or DSVA has no impact. On the other hand, "rxjammed" means that a received packet was mixed up. These firewall events are not recorded by default.
The issue can be prevented by using a bypass rule. The following procedure can also be considered to resolve the event:
- Open the Deep Security Manager (DSM) console.
- Go to Settings > Network Engine.
- Select the Advanced tab.
- On the Advanced Logging Policy drop-down list, choose Default. This enables the logging to switch to Tap Mode if the engine is in Tap Mode, and to Normal Mode if the engine is in Inline Mode.
If the issue persists after doing the procedure above, please contact Trend Micro Technical Support.