<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FirePOWER Module on ASA 5555-X hits over 95% in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997642#M1009323</link>
    <description>&lt;P style="margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;We have configured a Cisco ASA 5555-X with FirePOWER version 6.0.0.1. The ASA firewall has an ASA OS version&amp;nbsp;9.2(2)4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;This FirePOWER module has been configured with Protect, Control and AMP (TAM License).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;From the management center, health monitor, we noticed alerts showing the firewall is using an average of 98.69% CPU utilization. This utilization seems to be in only one CPU i.e. at any time the CPU is over 95% in CPU00 or CPU01 or CPU02 or CPU03 or CPU04 or CPU005.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;What could be the cause of this high CPU utilization, and how can it be fixed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;Andrew J.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:12:03 GMT</pubDate>
    <dc:creator>Andrew Mathu</dc:creator>
    <dc:date>2019-03-12T13:12:03Z</dc:date>
    <item>
      <title>FirePOWER Module on ASA 5555-X hits over 95%</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997642#M1009323</link>
      <description>&lt;P style="margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;We have configured a Cisco ASA 5555-X with FirePOWER version 6.0.0.1. The ASA firewall has an ASA OS version&amp;nbsp;9.2(2)4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;This FirePOWER module has been configured with Protect, Control and AMP (TAM License).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;From the management center, health monitor, we noticed alerts showing the firewall is using an average of 98.69% CPU utilization. This utilization seems to be in only one CPU i.e. at any time the CPU is over 95% in CPU00 or CPU01 or CPU02 or CPU03 or CPU04 or CPU005.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;What could be the cause of this high CPU utilization, and how can it be fixed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P style="outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; word-spacing: 0px; margin: 0in 0in 7.5pt 0in;"&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;Andrew J.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997642#M1009323</guid>
      <dc:creator>Andrew Mathu</dc:creator>
      <dc:date>2019-03-12T13:12:03Z</dc:date>
    </item>
    <item>
      <title>For FP 6.0.x you need at</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997643#M1009324</link>
      <description>&lt;P&gt;For FP 6.0.x you need at least ASA OS 9.4.x.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 21:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997643#M1009324</guid>
      <dc:creator>ilukeberry</dc:creator>
      <dc:date>2016-11-16T21:18:28Z</dc:date>
    </item>
    <item>
      <title>Hi ilukeberry,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997644#M1009325</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A href="https://supportforums.cisco.com/users/ilukeberry" title="View user profile." class="username" lang="" about="/users/ilukeberry" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;ilukeberry&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. We will try and upgrade to a version greater than 9.4.X and observe if this helps. However, we have other firewalls running &lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;9.2(2)4 and FirePOWER 6.0.0.1. and they have no CPU spikes. Coould it be a configuration issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #58585b;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 08:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997644#M1009325</guid>
      <dc:creator>Andrew Mathu</dc:creator>
      <dc:date>2016-11-17T08:41:59Z</dc:date>
    </item>
    <item>
      <title>You should upgrade to get</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997645#M1009326</link>
      <description>&lt;P&gt;You should upgrade to get into a supported state again. Your CPU issue is probably not an issue. Traffic is load balanced across multiple snort (ips) processes on your firepower module which can results in certain cores being under high load.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you want to verify which process is causing this issue issue the following command on your module&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; system support utilization&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In case you see snort process hogging your CPU constantly you might wanna open up a TAC case or try restarting snort (might cause short traffic disruption) using pmtool&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; pmtool RestartByType DetectionEngine&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 23:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997645#M1009326</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-11-17T23:32:30Z</dc:date>
    </item>
    <item>
      <title>Hi Kaisero,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997646#M1009327</link>
      <description>&lt;P&gt;Hi Kaisero,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When we look at the CPU utilization, the process snort (user - sfsnort) is using the most CPU. We'll try and restart the process after production hours.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 05:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/2997646#M1009327</guid>
      <dc:creator>Andrew Mathu</dc:creator>
      <dc:date>2016-11-18T05:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER Module on ASA 5555-X hits over 95%</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/3306364#M1009328</link>
      <description>&lt;P&gt;I have the same issue, but I am running asa 9.6(3)1.&amp;nbsp; Must be something else.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 21:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-on-asa-5555-x-hits-over-95/m-p/3306364#M1009328</guid>
      <dc:creator>dbogdan</dc:creator>
      <dc:date>2018-01-04T21:18:42Z</dc:date>
    </item>
  </channel>
</rss>

