<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall utilisation very high in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682166#M1037182</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A sudden increased of cpu utilization/processing can be anything, i.e PIX handling simultaneous/thousands of attack like DoS/DDoS, viruses, unreachable external syslog server and so on. Hard to pinpoint exact reason, but you need to check the PIX, i.e log entries for a clue, connection (who has highest no of connection and using which port, like 1 IP having hundreds of connected ports) and many more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CPU utilization depends on how intensive of traffic inspection need to be performed by PIX. Basically, PIX handling bigger network with thousands on of clients probably has higher CPU utilization compared to smaller network with small no of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But at any time, it probably should not exceed 40% or even less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 18 Nov 2006 18:33:36 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-11-18T18:33:36Z</dc:date>
    <item>
      <title>firewall utilisation very high</title>
      <link>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682165#M1037177</link>
      <description>&lt;P&gt;Hi recentely i am facing problem in enterprice pix firewall.its  goes up to 95&lt;/P&gt;&lt;P&gt;%.what is the average  cpu utilisation and maximum utilisation for pix 525 series.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682165#M1037177</guid>
      <dc:creator>Elango Murugan</dc:creator>
      <dc:date>2019-03-11T08:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: firewall utilisation very high</title>
      <link>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682166#M1037182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A sudden increased of cpu utilization/processing can be anything, i.e PIX handling simultaneous/thousands of attack like DoS/DDoS, viruses, unreachable external syslog server and so on. Hard to pinpoint exact reason, but you need to check the PIX, i.e log entries for a clue, connection (who has highest no of connection and using which port, like 1 IP having hundreds of connected ports) and many more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CPU utilization depends on how intensive of traffic inspection need to be performed by PIX. Basically, PIX handling bigger network with thousands on of clients probably has higher CPU utilization compared to smaller network with small no of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But at any time, it probably should not exceed 40% or even less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Nov 2006 18:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682166#M1037182</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-11-18T18:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: firewall utilisation very high</title>
      <link>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682167#M1037197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Monitoring PIX Performance:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General Troubleshooting Technotes:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_tech_notes_list.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_tech_notes_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that give a starting point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Nov 2006 01:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682167#M1037197</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2006-11-19T01:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: firewall utilisation very high</title>
      <link>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682168#M1037201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you experience high CPU utilization on your PIX issue the following command to show the number of connections:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show conn count&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the "in used" connections is both high and near the same level as "most used" then you're probably under denial-of-service attack such as TCP SYN half-open.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2006 15:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-utilisation-very-high/m-p/682168#M1037201</guid>
      <dc:creator>lbhoang</dc:creator>
      <dc:date>2006-11-20T15:00:16Z</dc:date>
    </item>
  </channel>
</rss>

