<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPR-1010 High memory usage - FTD code in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955691#M1105672</link>
    <description>&lt;P&gt;The most common condition I have seen for high memory usage is an excessive number of ACL entries.&amp;nbsp; Issue the command "show access-list element-count" (without quotes) in CLI and see what it comes back with.&lt;/P&gt;
&lt;P&gt;have you enabled Object Group Search and / or Interface Object Optimization?&amp;nbsp; If not and you have a high access-list entry count, consider enabling them.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 12:27:26 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2023-11-08T12:27:26Z</dc:date>
    <item>
      <title>FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4653004#M1091979</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a FPR-1010 with the FTD code 6.6.x code and also being managed by FDM and not FMC which has high memory since day one.&lt;/P&gt;&lt;P&gt;I noticed since these FPRs should have 8 GB of memory but when i type show memory or show version it only shows close to 3 GB of total memory. Can someone let me know why this is that?&lt;/P&gt;&lt;P&gt;Hardware: FPR-1010, 2830 MB RAM, CPU Atom C3000 series 2200 MHz, 1 CPU (4 cores)&lt;/P&gt;&lt;P&gt;# show memory&lt;BR /&gt;Free memory: 726218050 bytes (24%)&lt;BR /&gt;Used memory: 2241345152 bytes (76%)&lt;BR /&gt;------------- ------------------&lt;BR /&gt;Total memory: 2967563202 bytes (100%)&lt;/P&gt;&lt;P&gt;Note: Free memory is the free system memory. Additional memory may&lt;BR /&gt;be available from memory pools internal to the firewall process.&lt;BR /&gt;Use 'show memory detail' to see this information, but use it&lt;BR /&gt;with care since it may cause CPU hogs and packet loss under load.&lt;/P&gt;&lt;P&gt;But when I go to the expert mode it shows 8 GB of memory&lt;/P&gt;&lt;P&gt;FTD1:/home/admin# grep MemTotal /proc/meminfo&lt;/P&gt;&lt;P&gt;MemTotal:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8114616 kB&lt;/P&gt;&lt;P&gt;I would appreciate if someone could help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 13:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4653004#M1091979</guid>
      <dc:creator>SinRez</dc:creator>
      <dc:date>2022-07-19T13:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4653923#M1092007</link>
      <description>&lt;P&gt;This is an interesting issue, please let us know if you find a solution.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 13:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4653923#M1092007</guid>
      <dc:creator>McHildinger</dc:creator>
      <dc:date>2022-07-20T13:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4662984#M1092361</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was wondering if anyone can help me with this.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sina&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 13:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4662984#M1092361</guid>
      <dc:creator>SinRez</dc:creator>
      <dc:date>2022-08-03T13:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663016#M1092362</link>
      <description>&lt;P&gt;show memory (from diagnostic-cli and ftd prompt &amp;gt;) will show the memory allocated to LINA while show memory system from FTD &amp;gt; prompt will show all memory for the system&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:11:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663016#M1092362</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-08-03T14:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663022#M1092363</link>
      <description>&lt;P&gt;Thanks alot for the information, is it possible to allocate more memory to LINA. Because the firewalls are using only 3GB of memory and the memory usage is at 70 % at the moment.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663022#M1092363</guid>
      <dc:creator>SinRez</dc:creator>
      <dc:date>2022-08-03T14:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663066#M1092369</link>
      <description>&lt;P&gt;I am not entirely sure if it is possible to manually allocate memory.&amp;nbsp; Remember that you dont just have LINA.&amp;nbsp; LINA is probably the one that uses the least amount of memory.&amp;nbsp; You also have SNORT which does all IPS, URL filtering, Malware lookups and filtering, file analysis, SSL decryption, etc. which require a lot more memory than the regular packet filtering that LINA does.&amp;nbsp; Even if it is possible I would not suggest doing the changes on your own and recommend that you do this with Cisco TAC.&amp;nbsp; This way you will still be able to get support for your product if something goes wrong...but again, I don't even know if it is possible.&lt;/P&gt;
&lt;P&gt;Although 70% is a bit high, it is not warrant for concern, in my opinion, yet.&amp;nbsp; Perhaps look into how much traffic is passing through your firewall, how many access rules you have, how many network objects you have as this can have an affect on memory.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 15:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4663066#M1092369</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-08-03T15:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4707918#M1094428</link>
      <description>&lt;P&gt;Mine are using 83% for LINA dataplane memory (virtual FTD)&lt;/P&gt;
&lt;P&gt;There is nothing online about this, whether it is safe or normal or something which needs to be fixed which is how I found and came here. Default warning is set to 80% consumed of total with critical being 90%.&lt;/P&gt;
&lt;P&gt;So with yours at 70% it's completely in the normal and I would not be concerned at all. Remember, everything gets loaded to memory first. Any unused memory is wasted memory because if something is required to be loaded then it first has to copy it to memory. The caveat is free memory buffer in case of X/Y/Z.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 05:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4707918#M1094428</guid>
      <dc:creator>tonypearce1</dc:creator>
      <dc:date>2022-10-24T05:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955102#M1105649</link>
      <description>&lt;P&gt;Any condition in particular would cause memory usage on a FTD to be over 80%?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 17:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955102#M1105649</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2023-11-07T17:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955106#M1105650</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FPR-1010 High memory usage - FTD code" suggests a technical issue related to the Cisco Firepower 1010 security appliance. High memory usage in the FTD (Firepower Threat Defense) code can impact the device's performance and security functions. It typically requires troubleshooting and optimization to ensure the device operates efficiently and effectively, maintaining network security and stability.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 17:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955106#M1105650</guid>
      <dc:creator>Usman Mushtaq</dc:creator>
      <dc:date>2023-11-07T17:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955691#M1105672</link>
      <description>&lt;P&gt;The most common condition I have seen for high memory usage is an excessive number of ACL entries.&amp;nbsp; Issue the command "show access-list element-count" (without quotes) in CLI and see what it comes back with.&lt;/P&gt;
&lt;P&gt;have you enabled Object Group Search and / or Interface Object Optimization?&amp;nbsp; If not and you have a high access-list entry count, consider enabling them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 12:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/4955691#M1105672</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-11-08T12:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253886#M1119152</link>
      <description>&lt;P&gt;Folks, hi there, I realize this is a little old, but I just ran into this issue recently with a new FPR-1010. Mine was running at 97% and when it got that high it would cause AnyConnect connections that use SAML for MFA to fail. Apparently there's a bug when there are multiple instances of the AnyConnect client on the device to cause LINA / dataplane memory to skyrocket. I had 3 and have removed 2. Now my memory is down to 84.1%, still a little high. I'm working with Cisco TAC on this now. If you are still seeing this issue and running AnyConnect or SecureClient, check to see how many client versions you have on the box.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 18:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253886#M1119152</guid>
      <dc:creator>jpergolizzi</dc:creator>
      <dc:date>2025-01-28T18:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253928#M1119154</link>
      <description>&lt;P&gt;we had a similar issue in production the work around to fix the issue was we have to move our anyconnect from TLS to ikev2. once we moved our cpu usage come down to 70% prior to this we were always on 90-95%. might this help others.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253928#M1119154</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-01-28T21:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253945#M1119157</link>
      <description>&lt;P&gt;Btw, here's the bug:&amp;nbsp; &lt;SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc82675" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc82675&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5253945#M1119157</guid>
      <dc:creator>jpergolizzi</dc:creator>
      <dc:date>2025-01-28T21:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254033#M1119168</link>
      <description>&lt;P&gt;what happens is that each anyconnect/secure client package has to be cached in memory as users need to access it and also for upgrades etc.. thus the increase in memory... apparently some of these platforms have limited memory and there can be constraints.. work with TAC to get to the bottom of this ...&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 03:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254033#M1119168</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-29T03:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254640#M1119210</link>
      <description>&lt;P&gt;Technically it is not a defect/bug..It is marked as a severity 6 which is enhancement, but then&amp;nbsp; it is just documenting that lower platforms will be impacted... in reality, it is just that lower end platforms really dont have enough memory to be honest (:&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 09:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254640#M1119210</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-30T09:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-1010 High memory usage - FTD code</title>
      <link>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254928#M1119245</link>
      <description>&lt;P&gt;Hi there. While Cisco is tagging this with a bugid, I do see what you mean about it not technically being a bug. The workaround is pretty simple but in the event multiple images are required, that is a real problem on the lower end platforms for sure. Anyway, after removing 2 of the 3 images that were essentially "duplicates" and rebooting the firewall, my FPR-1010 is now down to 76% and holding steady. So hopefully we have this solved.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 16:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-1010-high-memory-usage-ftd-code/m-p/5254928#M1119245</guid>
      <dc:creator>jpergolizzi</dc:creator>
      <dc:date>2025-01-30T16:58:54Z</dc:date>
    </item>
  </channel>
</rss>

