<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU Usage on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196692#M1076578</link>
    <description>&lt;P&gt;make sure you size them correctly including future requirement.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2020 15:24:34 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-12-10T15:24:34Z</dc:date>
    <item>
      <title>High CPU Usage on ASA</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196235#M1076561</link>
      <description>&lt;P&gt;CPU on the ASA is varying from 90-99%, which is impacting performance for everyone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show proc cpu-usage sorted non-zero&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;shows that "Dispatch Unit" is taking around 90% of the CPU.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"cap test type asp-drop all real-time" shows a bulk of the entries similar to the following:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2: 10:53:04.583725 802.1Q vlan#500 P0 146.112.240.93.443 &amp;gt; 100.100.100.44897: . ack 269608873 win 83 Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;3: 10:53:04.618605 802.1Q vlan#500 P0 146.112.240.76.443 &amp;gt; 100.100.100.39232: . ack 4226217548 win 83 Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;4: 10:53:04.618711 802.1Q vlan#500 P0 146.112.240.80.443 &amp;gt; 100.100.100.19873: . ack 2735895955 win 83 Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;5: 10:53:04.641690 802.1Q vlan#500 P0 205.185.216.10.443 &amp;gt; 100.100.100.13428: . ack 2760386342 win 129 Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;6: 10:53:04.697565 802.1Q vlan#500 P0 146.112.240.92.443 &amp;gt; 100.100.100.17175: . ack 2788027061 win 83 Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It appears traffic is being sourced from various public IPs with a port of 443/tcp to the public IP of our firewall. I ended up putting a ACL entry at the tail end of our outside ACL that reads "access-list OUTSIDE ext deny tcp any4 eq 443 any4" and the hits light up with the drops. This may be a DoS attack, but does anyone have another idea as to what I can try?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196235#M1076561</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2020-12-09T20:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on ASA</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196238#M1076562</link>
      <description>&lt;P&gt;I left out some detail. The interface overruns on the outside interface is around 400-500 every 10 seconds with peaks significantly higher.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196238#M1076562</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2020-12-09T20:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on ASA</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196270#M1076563</link>
      <description>&lt;P&gt;Looks for me like some config issue here on a high level again we need to understand your config other aspects&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please post device model and version of code running, along with show run (removing some confidential information)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the bandwidth you expect to handle this FW ? what is your internet speed ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 22:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196270#M1076563</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-09T22:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on ASA</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196664#M1076576</link>
      <description>&lt;P&gt;Thanks for the reply. It's an older ASA-5520 running 9.1(7) with a 1 Gbps Internet speed and 2 dozen site-to-site VPN tunnels. We have a pair of [configured] FTDs to replace the 5520's, but it's been difficult to get this scheduled. The CPU normally runs high (85-87%), but we went high enough yesterday to degrade the traffic flow. I'm pretty sure it's not a configuration issue but the firewall isn't power enough to handle the traffic. Yesterday was not an isolated incident, but I'm going to drop any further troubleshooting on this, as management is now pushing to get the FTDs cutover by the end of the year.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:32:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196664#M1076576</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2020-12-10T14:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on ASA</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196692#M1076578</link>
      <description>&lt;P&gt;make sure you size them correctly including future requirement.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 15:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-usage-on-asa/m-p/4196692#M1076578</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-10T15:24:34Z</dc:date>
    </item>
  </channel>
</rss>

