Please advise if we have any guide or help which we can share with our network team to help them reduce sequence number gap rate on our AMD. Anything which can be provided from network perspective , like SPAN configuration best practice for clean traffic or something related would be helpful.
I don't think there is a guide as such.
If it is being caused by the monitoring point being overloaded you could:
Hopefully this helps a little!
This can be caused by not getting the full bi-directional TCP session traffic on the SPAN due to incorrect SPAN setup e.g not all the vlans are configured that you need etc (or you have some partially configured vlans that you don't need!). Get the network team to work out exactly what vlans should be part of the SPAN that gives you the traffic you want. We did have one very strange problem that was caused by to incorrect rate limits set on the SPAN port configuration for Nexus 7000 switching down stream edge traffic. Some flows in the SPAN were being rate limited incorrectly even though the configuration was correct which caused a large sequence number gap rate on the AMD. Upgrading the Cisco switch software fixed the problem after a few months of troubleshooting...:-(
Seqence number gaps are most commonly caused by missing packets (due to an overloaded or mis-configured span) or getting packets from both sides of a firewall (with different sequence numbers). Troubleshoot this by getting a packet capture. The CAS packet capture utility from the traffic diagnostic screen is the easiest way to get it.
Load the capture into wireshark. Add some columns in wireshark to show the hardware source and destination MAC address. Adding the VLAN and tcp.seq numbers (a custom column) will help as well. Sequence number changes and ack'd unseen segments should help get you to the root-cause.