<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DATAPAHT high load in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754191#M1096717</link>
    <description>&lt;P&gt;What do you mean with BW Link (Failover Link) ?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jan 2023 09:32:20 GMT</pubDate>
    <dc:creator>mackermann</dc:creator>
    <dc:date>2023-01-13T09:32:20Z</dc:date>
    <item>
      <title>DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753702#M1096697</link>
      <description>&lt;P&gt;Hello&amp;nbsp;@ all&lt;/P&gt;&lt;P&gt;can someone explain to me why the load is too high.&lt;/P&gt;&lt;P&gt;If more information needed please tell me&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;show processes cpu-usage sorted non-zero&lt;BR /&gt;Hardware: ASA5516&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.14(2)8&lt;BR /&gt;ASLR enabled, text region 55b6780b3000-55b67cc65025&lt;BR /&gt;PC Thread 5Sec 1Min 5Min Process&lt;BR /&gt;- - 31.3% 31.2% 31.1% DATAPATH-0-1593&lt;BR /&gt;- - 30.5% 30.6% 30.6% DATAPATH-1-1594&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 14:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753702#M1096697</guid>
      <dc:creator>mackermann</dc:creator>
      <dc:date>2023-01-12T14:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753731#M1096698</link>
      <description>&lt;P&gt;can I see&amp;nbsp;&lt;/P&gt;&lt;P&gt;show asp drop ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 15:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753731#M1096698</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-12T15:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753815#M1096704</link>
      <description>&lt;P&gt;May be bug here :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCuy94787" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCuy94787&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;is this with SFR ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 17:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4753815#M1096704</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-12T17:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754132#M1096712</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;I think it has to do with NAT, could that bee?&lt;/P&gt;&lt;P&gt;----------------------&lt;/P&gt;&lt;P&gt;sh asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;Flow is being freed (flow-being-freed) 1&lt;BR /&gt;Invalid IP header (invalid-ip-header) 3485710&lt;BR /&gt;No valid adjacency (no-adjacency) 57&lt;BR /&gt;No route to host (no-route) 39&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 3952862&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 15836&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 168&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 2848&lt;BR /&gt;TCP packet SEQ past window (tcp-seq-past-win) 90&lt;BR /&gt;TCP Out-of-Order packet buffer full (tcp-buffer-full) 1968868&lt;BR /&gt;TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) 34067&lt;BR /&gt;TCP RST/SYN in window (tcp-rst-syn-in-win) 2&lt;BR /&gt;TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue) 1224&lt;BR /&gt;Slowpath security checks failed (sp-security-failed) 29671380&lt;BR /&gt;Expired flow (flow-expired) 7&lt;BR /&gt;FP L2 rule drop (l2_acl) 533745&lt;BR /&gt;Interface is down (interface-down) 386&lt;BR /&gt;Dropped pending packets in a closed socket (np-socket-closed) 18&lt;BR /&gt;Dispatch queue tail drops (dispatch-queue-limit) 880361&lt;BR /&gt;Connection to PAT address without pre-existing xlate (nat-no-xlate-to-pat-pool) 274&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;NAT reverse path failed (nat-rpf-failed) 2204&lt;BR /&gt;Inspection failure (inspect-fail) 6&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 07:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754132#M1096712</guid>
      <dc:creator>mackermann</dc:creator>
      <dc:date>2023-01-13T07:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754142#M1096713</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Only active/active Cluster&lt;/P&gt;&lt;P&gt;No SFR&lt;/P&gt;&lt;P&gt;No FirePOWER services activated.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 07:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754142#M1096713</guid>
      <dc:creator>mackermann</dc:creator>
      <dc:date>2023-01-13T07:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754153#M1096714</link>
      <description>&lt;P&gt;I have seen similar issues on FTD, in my case it was related to the number of access control entries in the ACP.&amp;nbsp; So I would recommend checking how many access-list entries there are.&lt;/P&gt;
&lt;P&gt;Also, have you verified that the traffic load on the firewall is within the limits of what it can handle?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 08:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754153#M1096714</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-13T08:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754183#M1096715</link>
      <description>&lt;PRE&gt;Name: tcp-global-buffer-full
TCP global Out-of-Order packet buffer full:
    This counter is incremented and the packet is dropped when the security appliance receives an out-of-order TCP packet on a connection and there are no more global buffers available. Typically TCP packets are put into order on connections that are inspected by the security appliance or when packets are sent to the SSM for inspection. When the global Out-of-Order buffer queue is full, the packet will be dropped and this counter will increment.

Recommendations:
    This is a temporary condition when all global buffers are used. If this counter is constantly incrementing, then please check your network for large amounts of Out-of-Order traffic, which could be caused by traffic of the same flow taking different routes through the network.&lt;/PRE&gt;&lt;P&gt;this with high CPU and with you mention that you run ASA active/active.&lt;BR /&gt;&lt;BR /&gt;are both ASA pair have same BW link ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 09:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754183#M1096715</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-13T09:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754191#M1096717</link>
      <description>&lt;P&gt;What do you mean with BW Link (Failover Link) ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 09:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754191#M1096717</guid>
      <dc:creator>mackermann</dc:creator>
      <dc:date>2023-01-13T09:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754193#M1096718</link>
      <description>&lt;P&gt;No, Link connect to IN and OUT of ASA,&amp;nbsp;&lt;BR /&gt;the failover link interconnect two ASA so it sure same.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 09:39:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754193#M1096718</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-13T09:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754211#M1096722</link>
      <description>&lt;P&gt;Hello @ all&lt;/P&gt;&lt;P&gt;Many thanks for your support!&lt;/P&gt;&lt;P&gt;your answers put me on the right track&lt;/P&gt;&lt;P&gt;It was part of my routing entries.&lt;BR /&gt;I have several ip segments "/28" and one segment is part of the firewall himself.&lt;BR /&gt;The others segments are behind an other firewall.&lt;BR /&gt;My mistake was to route the whole net xxx.xxx.1.0/24 to the other firewall.&lt;BR /&gt;After i splitted the routing entrys the error was gone&lt;/P&gt;&lt;P&gt;Again Thanks for your fast support&lt;BR /&gt;Regards Michael&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 10:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754211#M1096722</guid>
      <dc:creator>mackermann</dc:creator>
      <dc:date>2023-01-13T10:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: DATAPAHT high load</title>
      <link>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754214#M1096723</link>
      <description>&lt;P&gt;You are so so welcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 10:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/datapaht-high-load/m-p/4754214#M1096723</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-13T10:29:02Z</dc:date>
    </item>
  </channel>
</rss>

