I wouldn't think any average would be acceptable.
I would want to confirm that these packets aren't a DoS attack.
After ruling that out, I would identify if the packets were the same protocol (e.g ESP) and determine if
there is a hardware issue related to a common device in the network path of those packets.

I’m in the process of analyzing traffic from our network and I’m coming across some malformed packets.  Before I start going capture crazy.   What is a good (average) of malformed packets on a network?


