<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 6.2.3 - preserve-connection query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3739772#M1004737</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;, just want to ask because i have an issue regarding constant SNORT CPU high utilization and the TAC said it is somehow related to this snort preserved-connection. Do you have any experiences before that when I have a lot of preserved-connections the CPU will go high? thanks&lt;/P&gt;</description>
    <pubDate>Tue, 06 Nov 2018 05:20:04 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2018-11-06T05:20:04Z</dc:date>
    <item>
      <title>FTD 6.2.3 - preserve-connection query</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3695385#M1004734</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm running FTD 6.2.3.3 (Build 76) and the 'show conn count' output now includes figures for the 'snort preserve-connection' feature which is enabled by default in 6.2.3. My output shows a figure of over 28M for enabled, and a similar figure for max-enabled. I've 100K connections through the device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show conn cou&lt;BR /&gt;105257 in use, 135542 most used&lt;BR /&gt;Inspect Snort:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; preserve-connection: 28096416 enabled, 251 in effect, 28096428 most enabled, 9306 most in effect&lt;/P&gt;
&lt;P&gt;The enabled figure contsantly rises e.g. last week it was 19M and the max-enabled was about 19M also. Can anyone tell me if that enabled figure is correct or is there a potential bug?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Piaras Walsh&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3695385#M1004734</guid>
      <dc:creator>plwalsh</dc:creator>
      <dc:date>2020-02-21T16:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.2.3 - preserve-connection query</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3695402#M1004735</link>
      <description>I don't think its a bug. It keeps ramping up indicating the total number of&lt;BR /&gt;preserved connections since last reboot. The in effect indicate the&lt;BR /&gt;concurrent ones.&lt;BR /&gt;&lt;BR /&gt;It should be same or close to most enabled one. However, they can different&lt;BR /&gt;if some connections were dropped during snort restart&lt;BR /&gt;</description>
      <pubDate>Mon, 27 Aug 2018 10:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3695402#M1004735</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-08-27T10:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.2.3 - preserve-connection query</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3739772#M1004737</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;, just want to ask because i have an issue regarding constant SNORT CPU high utilization and the TAC said it is somehow related to this snort preserved-connection. Do you have any experiences before that when I have a lot of preserved-connections the CPU will go high? thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 05:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3739772#M1004737</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2018-11-06T05:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.2.3 - preserve-connection query</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3739786#M1004738</link>
      <description>&lt;P&gt;Hi, Check with TAC may be you are hitting with below bug, this is not visible to customer.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CSCvj83264 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ABHEESH&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 05:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-2-3-preserve-connection-query/m-p/3739786#M1004738</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-06T05:46:37Z</dc:date>
    </item>
  </channel>
</rss>

