Symptom
Transit TCP packet drops at ZBFW due to Invalid L4 Header.
Error in logs:
%FW-6-DROP_PKT: Dropping tcp pkt from Tunnel1100 :646 => :34793(target:class)-(none:none) due to Invalid L4 header with ip ident 2399 tcp flag 0x0, seq 4126168512, ack 3361546304
Conditions
Multiple levels of encapsulation terminating at router with ZBFW.
Types of encapsulation can include Q-in-Q and IPsec.
Workaround
Remove Q-in-Q and/or IPsec encryption.
Further Problem Description
Router# show platform hardware qfp active statistics drop detail
188 FirewallL4 116741 11676254 << Drops Increment