<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reduce CPU usage for AnyConnect during online all-employee meeting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773008#M1097664</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1102856"&gt;@DaveNoonan26775&lt;/a&gt; split tunneling was going to be my first suggestion.&lt;/P&gt;
&lt;P&gt;Is the FPR2120 doing other services that could be consuming the CPU? Or is this a dedicated VPN concentrator?&lt;/P&gt;
&lt;P&gt;The other suggestion is check the tunnel protocol which use lower overhead - DTLS 1.2.&lt;/P&gt;
&lt;P&gt;Have you seen this AnyConnect performance guide? &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331-anyconnect-implementation-and-performanc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331-anyconnect-implementation-and-performanc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2023 20:25:07 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-02-10T20:25:07Z</dc:date>
    <item>
      <title>Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773000#M1097663</link>
      <description>&lt;P&gt;We have an ASA, actually an FPR-2120 running ASA code 9.14(2)4, terminating AnyConnect VPN.&amp;nbsp; During an&amp;nbsp;online all-hands meeting this device has previously gone to 90+%&amp;nbsp; CPU and stayed there for the duration of the meeting which made it unusable for call center folks who were still working during the meeting.&lt;/P&gt;&lt;P&gt;I expect the first suggestion to be split-tunneling and we do have that in place for the meeting provider. However, it was in place during the last meeting (minus two subnets) and the CPU still maxed out. I find it doubtful that we happened to have a LOT of traffic on those two subnets.&lt;/P&gt;&lt;P&gt;Bigger firewalls are on order but not due till after the next meeting so I'm looking for any other options that might be available as a stop gap.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 19:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773000#M1097663</guid>
      <dc:creator>DaveNoonan26775</dc:creator>
      <dc:date>2023-02-10T19:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773008#M1097664</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1102856"&gt;@DaveNoonan26775&lt;/a&gt; split tunneling was going to be my first suggestion.&lt;/P&gt;
&lt;P&gt;Is the FPR2120 doing other services that could be consuming the CPU? Or is this a dedicated VPN concentrator?&lt;/P&gt;
&lt;P&gt;The other suggestion is check the tunnel protocol which use lower overhead - DTLS 1.2.&lt;/P&gt;
&lt;P&gt;Have you seen this AnyConnect performance guide? &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331-anyconnect-implementation-and-performanc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215331-anyconnect-implementation-and-performanc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 20:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773008#M1097664</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-10T20:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773031#M1097666</link>
      <description>&lt;P&gt;It's a dedicated AnyConnect box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll check the link and the protocol, Thanks for those suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 21:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773031#M1097666</guid>
      <dc:creator>DaveNoonan26775</dc:creator>
      <dc:date>2023-02-10T21:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773034#M1097667</link>
      <description>&lt;P&gt;Related question, the firewall is an HA pair so how much effort would be involved in moving it to active/active for VPN?&lt;BR /&gt;&lt;BR /&gt;I haven't made that change before and it just occurred to me so I'm off to the search engines but thought someone else might have experience with it.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 21:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773034#M1097667</guid>
      <dc:creator>DaveNoonan26775</dc:creator>
      <dc:date>2023-02-10T21:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773051#M1097668</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1102856"&gt;@DaveNoonan26775&lt;/a&gt;&amp;nbsp;in that case consider reconfiguring the 2 ASAs using VPN load balancer. That will distribute the load evenly over the 2 devices.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2020/03/14/asa-vpn-load-balancing/" target="_blank"&gt;https://integratingit.wordpress.com/2020/03/14/asa-vpn-load-balancing/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 21:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773051#M1097668</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-10T21:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce CPU usage for AnyConnect during online all-employee meeting</title>
      <link>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773058#M1097669</link>
      <description>&lt;P&gt;I was just on that site reading their active/active article and I had also bumped into VPN load-balancing which I'd forgotten about.&amp;nbsp; The joys of being a geek-of-all-trades, you do things and then forget how you did them or that you did them at all.&amp;nbsp; I've learned to make notes.&lt;BR /&gt;&lt;BR /&gt;Thank you, Rob.&amp;nbsp; I think vpn load-balancing is going to my answer.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 21:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reduce-cpu-usage-for-anyconnect-during-online-all-employee/m-p/4773058#M1097669</guid>
      <dc:creator>DaveNoonan26775</dc:creator>
      <dc:date>2023-02-10T21:48:57Z</dc:date>
    </item>
  </channel>
</rss>

