<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cisco asa overrun issue / Dt.6_7_2015 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677899#M194045</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;im experiencing an asa cpu utilization issue (80%) running with 8.0 version and process hitting on Dispatch unit. At the same time, found only overruns are increasing in the firewall interfaces. Like router or checkpoint, is there any way to increase the buffer size of firewall interfaces ?&lt;/P&gt;&lt;P&gt;Below are my observations --&lt;/P&gt;&lt;P&gt;1-connection count is normal&lt;/P&gt;&lt;P&gt;2-show block shows less low on 1550 blocks, as highlighted below.&lt;/P&gt;&lt;P&gt;SIZE &amp;nbsp; &amp;nbsp;MAX &amp;nbsp; &amp;nbsp;LOW &amp;nbsp; &amp;nbsp;CNT&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 83 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;4 &amp;nbsp; &amp;nbsp;600 &amp;nbsp; &amp;nbsp;599 &amp;nbsp; &amp;nbsp;599&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 80 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 56 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; &amp;nbsp;256 &amp;nbsp; &amp;nbsp;862 &amp;nbsp; &amp;nbsp;748 &amp;nbsp; &amp;nbsp;862&lt;BR /&gt;&amp;nbsp; 1550 &amp;nbsp; 9261 &amp;nbsp; &lt;STRONG&gt;6504 &amp;nbsp; &lt;/STRONG&gt;7726&lt;BR /&gt;&amp;nbsp; 2048 &amp;nbsp; 2100 &amp;nbsp; 2081 &amp;nbsp; 2100&lt;BR /&gt;&amp;nbsp; 2560 &amp;nbsp; &amp;nbsp;164 &amp;nbsp; &amp;nbsp;163 &amp;nbsp; &amp;nbsp;164&lt;BR /&gt;&amp;nbsp; 4096 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 98 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; 8192 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp;16384 &amp;nbsp; &amp;nbsp;102 &amp;nbsp; &amp;nbsp;102 &amp;nbsp; &amp;nbsp;102&lt;BR /&gt;&amp;nbsp;65536 &amp;nbsp; &amp;nbsp; 16 &amp;nbsp; &amp;nbsp; 16 &amp;nbsp; &amp;nbsp; 16&lt;/P&gt;&lt;P&gt;3- show cpu&lt;BR /&gt;CPU utilization for 5 seconds = 78%; 1 minute: 83%; 5 minutes: 74%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4-throughput of the firewall never exceeded 60Mbps as per the calculation from the below link&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/12495046/calculating-throughput-asa" target="_blank"&gt;https://supportforums.cisco.com/document/12495046/calculating-throughput-asa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;5- Observed overruns are increasing in Gig1&amp;nbsp;and Gig2&amp;nbsp;interfaces (inside and outside respectively)&lt;/P&gt;&lt;P&gt;Gig1&amp;nbsp;2450000 to 2625000 with in 5 minutes&lt;BR /&gt;Gig2&amp;nbsp;540000 to 581000 with in 5 minutes&lt;/P&gt;&lt;P&gt;Now my query :- is there any command to increase interface buffers ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SecIT()&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:13:44 GMT</pubDate>
    <dc:creator>secureIT</dc:creator>
    <dc:date>2019-03-12T06:13:44Z</dc:date>
    <item>
      <title>cisco asa overrun issue / Dt.6_7_2015</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677899#M194045</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;im experiencing an asa cpu utilization issue (80%) running with 8.0 version and process hitting on Dispatch unit. At the same time, found only overruns are increasing in the firewall interfaces. Like router or checkpoint, is there any way to increase the buffer size of firewall interfaces ?&lt;/P&gt;&lt;P&gt;Below are my observations --&lt;/P&gt;&lt;P&gt;1-connection count is normal&lt;/P&gt;&lt;P&gt;2-show block shows less low on 1550 blocks, as highlighted below.&lt;/P&gt;&lt;P&gt;SIZE &amp;nbsp; &amp;nbsp;MAX &amp;nbsp; &amp;nbsp;LOW &amp;nbsp; &amp;nbsp;CNT&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 83 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;4 &amp;nbsp; &amp;nbsp;600 &amp;nbsp; &amp;nbsp;599 &amp;nbsp; &amp;nbsp;599&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 80 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 56 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; &amp;nbsp;256 &amp;nbsp; &amp;nbsp;862 &amp;nbsp; &amp;nbsp;748 &amp;nbsp; &amp;nbsp;862&lt;BR /&gt;&amp;nbsp; 1550 &amp;nbsp; 9261 &amp;nbsp; &lt;STRONG&gt;6504 &amp;nbsp; &lt;/STRONG&gt;7726&lt;BR /&gt;&amp;nbsp; 2048 &amp;nbsp; 2100 &amp;nbsp; 2081 &amp;nbsp; 2100&lt;BR /&gt;&amp;nbsp; 2560 &amp;nbsp; &amp;nbsp;164 &amp;nbsp; &amp;nbsp;163 &amp;nbsp; &amp;nbsp;164&lt;BR /&gt;&amp;nbsp; 4096 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp; 98 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp; 8192 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp;100 &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;&amp;nbsp;16384 &amp;nbsp; &amp;nbsp;102 &amp;nbsp; &amp;nbsp;102 &amp;nbsp; &amp;nbsp;102&lt;BR /&gt;&amp;nbsp;65536 &amp;nbsp; &amp;nbsp; 16 &amp;nbsp; &amp;nbsp; 16 &amp;nbsp; &amp;nbsp; 16&lt;/P&gt;&lt;P&gt;3- show cpu&lt;BR /&gt;CPU utilization for 5 seconds = 78%; 1 minute: 83%; 5 minutes: 74%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4-throughput of the firewall never exceeded 60Mbps as per the calculation from the below link&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/12495046/calculating-throughput-asa" target="_blank"&gt;https://supportforums.cisco.com/document/12495046/calculating-throughput-asa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;5- Observed overruns are increasing in Gig1&amp;nbsp;and Gig2&amp;nbsp;interfaces (inside and outside respectively)&lt;/P&gt;&lt;P&gt;Gig1&amp;nbsp;2450000 to 2625000 with in 5 minutes&lt;BR /&gt;Gig2&amp;nbsp;540000 to 581000 with in 5 minutes&lt;/P&gt;&lt;P&gt;Now my query :- is there any command to increase interface buffers ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SecIT()&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677899#M194045</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2019-03-12T06:13:44Z</dc:date>
    </item>
    <item>
      <title>Hi SecIT,Please check the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677900#M194046</link>
      <description>&lt;P&gt;Hi SecIT,&lt;/P&gt;&lt;P&gt;Please check the below things:&lt;/P&gt;&lt;P&gt;- 'show run logging' and 'show run snmp-server'. Make sure snmp and syslog servers are reachable from ASA. if there is any log server which is not reachable exist, i would suggest you to remove the same.&lt;/P&gt;&lt;P&gt;- Also check for loop on these interface. Check if the interface packet counters are very high on these interfaces as compared to other interfaces. This could give you some indication of what is happening on these interface.&lt;/P&gt;&lt;P&gt;- For detail, take header captures on these interfaces. 'cap capi interface inside headers-only' and try to see the mac-addresses with 'show cap capi detail'. &amp;nbsp;Check if the mac-address are same and looping in that&amp;nbsp;interface (try to see the ttl value as well).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 15:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677900#M194046</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-07-07T15:44:46Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,Is there anyway to</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677901#M194047</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;&lt;P&gt;Is there anyway to increase the interface buffersize in ASA ? as far as i know the only option is to enable flowcontrol that too only in 8.2.5 - any other options ? i do see the overruns (only) are increasing..&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2015 16:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677901#M194047</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2015-07-12T16:31:07Z</dc:date>
    </item>
    <item>
      <title>Hi Sec IT,Unfortunately flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677902#M194048</link>
      <description>&lt;P&gt;Hi Sec IT,&lt;/P&gt;&lt;P&gt;Unfortunately flow control is the only way to control the traffic flow coming to the interfaces interfaces.&lt;/P&gt;&lt;P&gt;You could try with QoS on ASA or on Switch connected to interface and see if that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 08:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-overrun-issue-dt-6-7-2015/m-p/2677902#M194048</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-07-13T08:28:45Z</dc:date>
    </item>
  </channel>
</rss>

