<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD instance on Firepower has high CPU utilization on lina process in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755444#M1096821</link>
    <description>&lt;P&gt;if this is not effecting all working as expected, check below FAQ :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200950-Clarifying-the-Firepower-Threat-Defense.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200950-Clarifying-the-Firepower-Threat-Defense.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 15:07:24 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-01-16T15:07:24Z</dc:date>
    <item>
      <title>FTD instance on Firepower has high CPU utilization on lina process</title>
      <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755409#M1096811</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have Firepower 4115. I am seeing high CPU on o&lt;FONT color="#FF0000"&gt;ne of the FTD instances&lt;/FONT&gt;. There are no complaints of slowness or packet drops from users so far. Any recommendations to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show cpu usage core all&lt;/P&gt;&lt;P&gt;Core&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 sec&amp;nbsp; 1 min&amp;nbsp; 5 min&lt;/P&gt;&lt;P&gt;Core 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT color="#FF0000"&gt;&amp;nbsp; 90.5%&amp;nbsp; 92.8%&amp;nbsp; 92.6%&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Core 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#FF0000"&gt;90.6%&amp;nbsp; 92.8%&amp;nbsp; 92.6%&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show processes cpu-usage sorted&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; FPR4K-SM-24S&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.16(3)11&lt;/P&gt;&lt;P&gt;ASLR enabled, text region 55abc60b5000-55abca6c7475&lt;/P&gt;&lt;P&gt;PC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thread&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5Sec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1Min&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5Min&amp;nbsp;&amp;nbsp; Process&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#FF0000"&gt;85.4%&amp;nbsp;&amp;nbsp;&amp;nbsp; 85.2%&amp;nbsp;&amp;nbsp;&amp;nbsp; 84.8%&amp;nbsp;&amp;nbsp; DATAPATH-1-3116&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;FONT color="#FF0000"&gt;85.3%&amp;nbsp;&amp;nbsp;&amp;nbsp; 85.2%&amp;nbsp;&amp;nbsp;&amp;nbsp; 84.8%&amp;nbsp;&amp;nbsp; DATAPATH-0-3115&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;0x000055abc7c54d66&amp;nbsp;&amp;nbsp; 0x0000151701eb29e0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.2%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.2%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.2%&amp;nbsp;&amp;nbsp; CP Processing&lt;/P&gt;&lt;P&gt;0x000055abc7a603c3&amp;nbsp;&amp;nbsp; 0x0000151701e9ee80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.1%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.1%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.1%&amp;nbsp;&amp;nbsp; appagent_async_client_receive_thread&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;root@cmq-dcfw-ftd-01:~# top&lt;/P&gt;&lt;P&gt;Tasks:&amp;nbsp; 81 total,&amp;nbsp;&amp;nbsp; 3 running,&amp;nbsp; 68 sleeping,&amp;nbsp;&amp;nbsp; 0 stopped,&amp;nbsp; 10 zombie&lt;/P&gt;&lt;P&gt;%Cpu(s): 21.7 us,&amp;nbsp; 7.2 sy,&amp;nbsp; 0.0 ni, 71.0 id,&amp;nbsp; 0.0 wa,&amp;nbsp; 0.0 hi,&amp;nbsp; 0.0 si,&amp;nbsp; 0.0 st&lt;/P&gt;&lt;P&gt;MiB Mem : 192162.5 total, 137596.8 free,&amp;nbsp; 45892.9 used,&amp;nbsp;&amp;nbsp; 8672.8 buff/cache&lt;/P&gt;&lt;P&gt;MiB Swap:&amp;nbsp; 49152.0 total,&amp;nbsp; 45719.7 free,&amp;nbsp;&amp;nbsp; 3432.2 used. 138505.6 avail Mem&lt;/P&gt;&lt;P&gt;PID USER&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PR&amp;nbsp; NI&amp;nbsp;&amp;nbsp;&amp;nbsp; VIRT&amp;nbsp;&amp;nbsp;&amp;nbsp; RES&amp;nbsp;&amp;nbsp;&amp;nbsp; SHR S&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%CPU&amp;nbsp; &amp;nbsp;&amp;nbsp;%MEM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TIME+ COMMAND&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2997 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 -20 3716024&amp;nbsp;&amp;nbsp; 1.6g&amp;nbsp;&amp;nbsp; 1.1g S &amp;nbsp;&amp;nbsp;&lt;FONT color="#FF0000"&gt;195.7&amp;nbsp;&lt;/FONT&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;0.9 311260:57&lt;FONT color="#FF0000"&gt; lina&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4790 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 -19 7949784&amp;nbsp;&amp;nbsp; 5.6g&amp;nbsp; 89844 S&amp;nbsp;&amp;nbsp; 8.7&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;3.0&amp;nbsp;&amp;nbsp; 8256:04 snort3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2863 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 680204&amp;nbsp; 21208&amp;nbsp;&amp;nbsp; 7412 S&amp;nbsp;&amp;nbsp; 4.3&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;0.0&amp;nbsp;&amp;nbsp; 3022:10 sftunnel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 13:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755409#M1096811</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2023-01-16T13:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD instance on Firepower has high CPU utilization on lina process</title>
      <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755444#M1096821</link>
      <description>&lt;P&gt;if this is not effecting all working as expected, check below FAQ :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200950-Clarifying-the-Firepower-Threat-Defense.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200950-Clarifying-the-Firepower-Threat-Defense.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 15:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755444#M1096821</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-16T15:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD instance on Firepower has high CPU utilization on lina process</title>
      <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755473#M1096824</link>
      <description>&lt;P&gt;show asp drop &amp;lt;&amp;lt;- please share this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 16:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755473#M1096824</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-16T16:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD instance on Firepower has high CPU utilization on lina process</title>
      <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755754#M1096850</link>
      <description>&lt;P&gt;It turned out that it was due to a bunch of VMs migration that drove the Lina process so high. Once the migration was completed the CPU utilization was back to normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am curious about when it starts&amp;nbsp; dropping&amp;nbsp;packets due to high CPU. Where in the the 'show asp drop' it tells you this? And do I need to consider the drops in one FTD instance only that has the traffic flow or other instances will be impacted too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the output of 'show asp drop' in the instance where CPU was high.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;Invalid TCP Length (invalid-tcp-hdr-length) 8&lt;BR /&gt;No valid adjacency (no-adjacency) 45&lt;BR /&gt;No route to host (no-route) 17763&lt;BR /&gt;Reverse-path verify failed (rpf-violated) 632691&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 487309531&lt;BR /&gt;Invalid SPI (np-sp-invalid-spi) 131&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 11874558&lt;BR /&gt;Bad TCP flags (bad-tcp-flags) 5&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 3520718&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 6643683&lt;BR /&gt;TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 13736&lt;BR /&gt;TCP SYNACK on established conn (tcp-synack-ooo) 64&lt;BR /&gt;TCP packet SEQ past window (tcp-seq-past-win) 277799&lt;BR /&gt;TCP invalid ACK (tcp-invalid-ack) 17&lt;BR /&gt;TCP RST/SYN in window (tcp-rst-syn-in-win) 22938&lt;BR /&gt;TCP packet failed PAWS test (tcp-paws-fail) 7590&lt;BR /&gt;Slowpath security checks failed (sp-security-failed) 16774557&lt;BR /&gt;IP option drop (invalid-ip-option) 63256&lt;BR /&gt;Invalid LU packet (lu-invalid-pkt) 3437&lt;BR /&gt;Dropped by standby unit (fo-standby) 5&lt;BR /&gt;Flow drop (flow-expired-drop) 1&lt;BR /&gt;ICMP Inspect bad icmp code (inspect-icmp-bad-code) 46012&lt;BR /&gt;ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched) 20837&lt;BR /&gt;ICMP Error Inspect no existing conn (inspect-icmp-error-no-existing-conn) 15897&lt;BR /&gt;Snort instance is busy (snort-busy) 70996&lt;BR /&gt;FP L2 rule drop (l2_acl) 75421438&lt;BR /&gt;Unable to obtain connection lock (connection-lock) 2110&lt;BR /&gt;Interface is down (interface-down) 3066&lt;BR /&gt;Packet shunned (shunned) 33&lt;BR /&gt;Received a multicast packet in the non-active device (mcast-in-nonactive-device) 22819515&lt;BR /&gt;Per-flow block limit reached on flows fast-forwarded by Snort (snort-blist-full) 27160&lt;BR /&gt;Blocked or blacklisted by the firewall preprocessor (firewall) 47292&lt;BR /&gt;Blocked or blacklisted by the session preprocessor (session-preproc) 2896&lt;BR /&gt;Blocked or blacklisted by the reputation preprocessor (reputation) 220&lt;BR /&gt;Fragment reassembly failed (fragment-reassembly-failed) 17326250&lt;BR /&gt;Packet is blacklisted by snort (snort-blacklist) 130&lt;BR /&gt;Failover link is not ready for processing NLP packets (ha-nlp-lu-link-not-ready) 5&lt;BR /&gt;Dispatch queue tail drops (dispatch-queue-limit) 7635491&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;Flow is denied by access rule (acl-drop) 2&lt;BR /&gt;Flow shunned (shunned) 4&lt;BR /&gt;Inspection failure (inspect-fail) 1023570&lt;BR /&gt;SSL bad record detected (ssl-bad-record-detect) 99&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;BR /&gt;&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 05:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755754#M1096850</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2023-01-17T05:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD instance on Firepower has high CPU utilization on lina process</title>
      <link>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755875#M1096855</link>
      <description>&lt;P&gt;I suggest clearing the asp drop counter to have better idea of which is increasing the fastest.&amp;nbsp; Also, check the output of show access-list element-count and be sure that you are not exceeding the ACL limit.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 08:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-instance-on-firepower-has-high-cpu-utilization-on-lina/m-p/4755875#M1096855</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-17T08:56:37Z</dc:date>
    </item>
  </channel>
</rss>

