<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall CPU Usage in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701958#M1094206</link>
    <description>&lt;P&gt;East# show processes cpu-usage sorted non-zero&lt;BR /&gt;Hardware: NGFWv&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.14(3)15&lt;BR /&gt;ASLR enabled, text region 561a4a4ff000-56xxx&lt;BR /&gt;PC Thread 5Sec 1Min 5Min Process&lt;BR /&gt;- - 75.7% 78.1% 75.2% DATAPATH-0-3700&lt;BR /&gt;East#&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 13:43:20 GMT</pubDate>
    <dc:creator>loc.nguyen</dc:creator>
    <dc:date>2022-10-12T13:43:20Z</dc:date>
    <item>
      <title>Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701661#M1094203</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an issue with&amp;nbsp;Cisco Firepower Threat Defense for Azure. It often alert&amp;nbsp;severity critical for&amp;nbsp;CPU Usage.&lt;/P&gt;&lt;P&gt;Randomly check shows CPU around 50%. Could you advise where I should check further?&lt;/P&gt;&lt;P&gt;Below is detail:&amp;nbsp;&lt;/P&gt;&lt;P&gt;FP-East# sh cpu detail&lt;/P&gt;&lt;P&gt;Break down of per-core data path versus control point cpu usage:&lt;BR /&gt;Core 5 sec 1 min 5 min&lt;BR /&gt;Core 0 45.6 (45.6 + 0.0) 49.0 (48.9 + 0.0) 45.0 (45.0 + 0.0)&lt;/P&gt;&lt;P&gt;Current control point elapsed versus the data and control point elapsed for:&lt;BR /&gt;5 seconds = 3.0%; 1 minute: 3.0%; 5 minutes: 2.9%&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CPU utilization of external processes for:&lt;BR /&gt;5 seconds = 0.0%; 1 minute: 0.1%; 5 minutes: 0.0%&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Total CPU utilization for:&lt;BR /&gt;5 seconds = 45.8%; 1 minute: 49.2%; 5 minutes: 45.3%&lt;/P&gt;&lt;P&gt;FP-East#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;East# show version&lt;BR /&gt;--------------------[ FP-East ]---------------------&lt;BR /&gt;Model : Cisco Firepower Threat Defense for Azure (75) Version 6.6.5.1 (Build 15)&lt;BR /&gt;UUID : xxxxx&lt;BR /&gt;Rules update version : 2022-10-10-001-vrt&lt;BR /&gt;VDB version : 359&lt;BR /&gt;----------------------------------------------------&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.14(3)15&lt;BR /&gt;SSP Operating System Version 2.8(1.165)&lt;/P&gt;&lt;P&gt;Compiled on Tue 09-Nov-21 17:50 GMT by builders&lt;BR /&gt;System image file is "boot:/asa9143-6-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;FP-East up 2 days 11 hours&lt;/P&gt;&lt;P&gt;Hardware: NGFWv, 14336 MB RAM, CPU Xeon E5 series 2400 MHz, 1 CPU (4 cores)&lt;BR /&gt;Internal ATA Compact Flash, 65536MB&lt;BR /&gt;Slot 1: ATA Compact Flash, 65536MB&lt;BR /&gt;BIOS Flash Firmware Hub @ 0x0, 0KB&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;0: Int: Internal-Data0/0 : address is 000d.3a11.49f8, irq 0&lt;BR /&gt;1: Ext: GigabitEthernet0/0 : address is 000d.3a11.4146, irq 0&lt;BR /&gt;2: Ext: GigabitEthernet0/1 : address is 000d.3a11.4e77, irq 0&lt;BR /&gt;3: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0&lt;BR /&gt;4: Int: Internal-Data0/0 : address is 0000.0000.0000, irq 0&lt;BR /&gt;5: Ext: Management0/0 : address is 000d.3a11.49f8, irq 0&lt;BR /&gt;6: Int: Internal-Data0/1 : address is 0000.0100.0001, irq 0&lt;BR /&gt;7: Int: Internal-Data0/2 : address is 0000.0000.0000, irq 0&lt;BR /&gt;8: Int: Internal-Control0/1 : address is 0000.0001.0001, irq 0&lt;/P&gt;&lt;P&gt;Serial Number: xxxxx&lt;/P&gt;&lt;P&gt;Image type : Release&lt;BR /&gt;Key version : A&lt;/P&gt;&lt;P&gt;Configuration last modified by enable_1 at 05:10:28.683 UTC Wed Oct 12 2022&lt;BR /&gt;East#&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Loc&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 06:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701661#M1094203</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-12T06:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701685#M1094204</link>
      <description>&lt;LI-CODE lang="markup"&gt;Total CPU utilization for:
5 seconds = 45.8%; 1 minute: 49.2%; 5 minutes: 45.3%&lt;/LI-CODE&gt;
&lt;P&gt;every 5min you may be getting the alerts. Maybe you can increase this level to 70% to see if that suppresses alarms?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 07:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701685#M1094204</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-12T07:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701954#M1094205</link>
      <description>&lt;P&gt;Do we have a command to check which ones are using most of the CPU?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701954#M1094205</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-12T13:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701958#M1094206</link>
      <description>&lt;P&gt;East# show processes cpu-usage sorted non-zero&lt;BR /&gt;Hardware: NGFWv&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.14(3)15&lt;BR /&gt;ASLR enabled, text region 561a4a4ff000-56xxx&lt;BR /&gt;PC Thread 5Sec 1Min 5Min Process&lt;BR /&gt;- - 75.7% 78.1% 75.2% DATAPATH-0-3700&lt;BR /&gt;East#&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 13:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4701958#M1094206</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-12T13:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702034#M1094207</link>
      <description>&lt;P&gt;&lt;EM&gt;post below information ;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show cpu usage&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show processes cpu-usage sorted non-zero&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 15:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702034#M1094207</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-12T15:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702064#M1094208</link>
      <description>&lt;P&gt;Yeah, I did. Pls see the above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 16:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702064#M1094208</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-12T16:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702220#M1094209</link>
      <description>&lt;P&gt;&lt;EM&gt;show cpu usage&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 19:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702220#M1094209</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-12T19:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702806#M1094210</link>
      <description>&lt;P&gt;FP-East# show cpu usage&lt;BR /&gt;CPU utilization for 5 seconds = 34%; 1 minute: 35%; 5 minutes: 42%&lt;/P&gt;&lt;P&gt;FP-East#&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 16:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702806#M1094210</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-13T16:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702847#M1094215</link>
      <description>&lt;P&gt;&lt;SPAN&gt;asa# show asp drop&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please share the output&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 17:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4702847#M1094215</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-10-13T17:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4703354#M1094252</link>
      <description>&lt;P&gt;FP-East# show asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;NAT-T keepalive message (natt-keepalive) 203335&lt;BR /&gt;IPSEC tunnel is down (ipsec-tun-down) 130&lt;BR /&gt;SVC Module does not have a channel for reinjection (mp-svc-no-channel) 530&lt;BR /&gt;SVC Module does not have a session (mp-svc-no-session) 381&lt;BR /&gt;SVC Module is in flow control (mp-svc-flow-control) 126555&lt;BR /&gt;SVC Module unable to fragment packet (mp-svc-no-fragment) 151&lt;BR /&gt;Flow is being freed (flow-being-freed) 5646&lt;BR /&gt;No route to host (no-route) 12734&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 3983837&lt;BR /&gt;Invalid SPI (np-sp-invalid-spi) 99&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 834711&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 4446&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 5748&lt;BR /&gt;TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 36&lt;BR /&gt;TCP packet SEQ past window (tcp-seq-past-win) 27&lt;BR /&gt;TCP invalid ACK (tcp-invalid-ack) 36&lt;BR /&gt;TCP RST/SYN in window (tcp-rst-syn-in-win) 606&lt;BR /&gt;TCP packet failed PAWS test (tcp-paws-fail) 10&lt;BR /&gt;CTM returned error (ctm-error) 661&lt;BR /&gt;ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched) 3&lt;BR /&gt;DNS Inspect id not matched (inspect-dns-id-not-matched) 481&lt;BR /&gt;Snort requested to drop the frame (snort-drop) 415547&lt;BR /&gt;Snort instance is down (snort-down) 2932&lt;BR /&gt;Snort instance is busy (snort-busy) 19142191&lt;BR /&gt;FP L2 rule drop (l2_acl) 26&lt;BR /&gt;Dropped pending packets in a closed socket (np-socket-closed) 148749&lt;BR /&gt;Connection to PAT address without pre-existing xlate (nat-no-xlate-to-pat-pool) 2781&lt;BR /&gt;TCP Proxy retransmited packet drop (tcp-proxy-retransmit-drop) 52&lt;BR /&gt;Blocked or blacklisted by the firewall preprocessor (firewall) 574198&lt;BR /&gt;Blocked or blacklisted by the SI preprocessor (si) 2&lt;BR /&gt;Blocked or blacklisted by the session preprocessor (session-preproc) 10&lt;BR /&gt;Blocked or blacklisted by the reputation preprocessor (reputation) 426&lt;BR /&gt;Blocked or blacklisted by the file process preprocessor (file-process) 2711&lt;BR /&gt;Blocked or blacklisted by the IPS preprocessor (ips-preproc) 28&lt;BR /&gt;Fragment reassembly failed (fragment-reassembly-failed) 652690&lt;BR /&gt;Packet is blacklisted by snort (snort-blacklist) 2967995&lt;BR /&gt;Packet is blocked as requested by snort (snort-block) 29223311&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;Tunnel being brought up or torn down (tunnel-pending) 6&lt;BR /&gt;Need to start IKE negotiation (need-ike) 2&lt;BR /&gt;VPN overlap conflict (vpn-overlap-conflict) 57292&lt;BR /&gt;VPN decryption missing (vpn-missing-decrypt) 23876&lt;BR /&gt;NAT reverse path failed (nat-rpf-failed) 180&lt;BR /&gt;Inspection failure (inspect-fail) 11968&lt;BR /&gt;SSL bad record detected (ssl-bad-record-detect) 122&lt;BR /&gt;SSL handshake failed (ssl-handshake-failed) 2123&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;BR /&gt;FP-East#&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 12:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4703354#M1094252</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-14T12:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4711462#M1094542</link>
      <description>&lt;P&gt;Do you have any ideas why it happens?&lt;/P&gt;&lt;P&gt;if you need more information, pls let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 04:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4711462#M1094542</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-27T04:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4711486#M1094543</link>
      <description>&lt;P&gt;Health Monitor Alert from fp-east.internal.cloudapp.net&lt;/P&gt;&lt;P&gt;Time: Wed Oct&amp;nbsp; 5 06:04:24 2022 UTC&lt;/P&gt;&lt;P&gt;Severity: critical&lt;/P&gt;&lt;P&gt;Module: CPU Usage&lt;/P&gt;&lt;P&gt;Description: Using CPU03 150.00%&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 05:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4711486#M1094543</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-10-27T05:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall CPU Usage</title>
      <link>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4712677#M1094591</link>
      <description>&lt;P&gt;You remember the sysopt we add before to preserve the TCP through VPN,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/switching/asa-drops-sftp-connections/td-p/4698759" target="_blank"&gt;https://community.cisco.com/t5/switching/asa-drops-sftp-connections/td-p/4698759&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;sysopt connection preserve-vpn-flows&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&amp;nbsp;""Enabling this feature does not create any additional overload on the internal CPU processing of the ASA because it is going to keep the same TCP connections that the device has when the tunnel is up.""&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113014-asa-userapp-vpntunnel.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113014-asa-userapp-vpntunnel.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;so I will ask you are you face this issue after add this command ?&lt;BR /&gt;if yes then remove it and check CPU level.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;the high CPU utilize of DataPath usually because VPN traffic.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 09:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-cpu-usage/m-p/4712677#M1094591</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-10-28T09:52:11Z</dc:date>
    </item>
  </channel>
</rss>

