<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you are just going by the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583800#M199370</link>
    <description>&lt;P&gt;If you are just going by the input errors and interface overruns I would not think this is a CPU issue. Most likely there is more traffic passing through the interface than it can handle, or perhaps the packets are too large.&amp;nbsp; Do you see the jumbo frame counter tick upward?&amp;nbsp; Do the input errors and overruns steadily tick upward or does it only increase slowly?&amp;nbsp; When was the last time you cleard the interface counters?&lt;/P&gt;&lt;P&gt;It would not hurt to move management traffic to the dedicated management port.&amp;nbsp; This way you can monitor the ports for the overruns and input errors, as well as keep an eye on the CPU Hog output.&lt;/P&gt;&lt;P&gt;if you issue the commands &lt;STRONG&gt;show cpu usage&lt;/STRONG&gt; and &lt;STRONG&gt;show processes cpu-hog&lt;/STRONG&gt;.&amp;nbsp; When viewing the CPU usage do you see any CPU spikes up to 80%-100% that last more than a few seconds?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2014 13:46:30 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-12-30T13:46:30Z</dc:date>
    <item>
      <title>ASA 5510 Management port</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583796#M199350</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm encountering CPU-hog issue (packet drops) each time our monitor system monitor the ASA (via SNMP) due to 1 core CPU.&lt;/P&gt;&lt;P&gt;The ASA is monitored via non management interface (all others),which is a&amp;nbsp;production interface, my question is, if we move to the dedicated &amp;nbsp;management port will solve the CPU-hog issue or it's using the same CPU as all other interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10x&lt;/P&gt;&lt;P&gt;Eyal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583796#M199350</guid>
      <dc:creator>eyalhezi77</dc:creator>
      <dc:date>2019-03-12T05:16:41Z</dc:date>
    </item>
    <item>
      <title>Hello Eyal-I am not saying</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583797#M199357</link>
      <description>&lt;P&gt;Hello Eyal-&lt;/P&gt;&lt;P&gt;I am not saying that it is not possible and that it is not the cause of the issue here but I don't think the problem is the interface. Most of the ASAs that I have managed/configured in the past were managed via the "Inside" interface vs a dedicated management port.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My guess is that the issue is with either high throughput running through the ASA or the monitoring software itself. Can you tell us:&lt;/P&gt;&lt;P&gt;1. What is the average throughput running through the ASA&lt;/P&gt;&lt;P&gt;2. What services are you using (IPSec tunnels, remote access VPN, how many DMZs, etc)&lt;/P&gt;&lt;P&gt;3. What type of SNMP solution are you trying to implement and what are its configs (polling intervals)&lt;/P&gt;&lt;P&gt;4. Post your ASA SNMP configs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 20:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583797#M199357</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-29T20:17:56Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,1. in &amp; out - MAX 203</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583798#M199362</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;1. in &amp;amp; out - MAX 203.648 kbit/s&lt;/P&gt;&lt;P&gt;2.IPSEC tunnels - ~ 20 tunnels / DMZ - 5 sub interfaces for DMZ&lt;/P&gt;&lt;P&gt;3.PRTG with SNMP interval 30 sec&lt;/P&gt;&lt;P&gt;4. Please note that many of the hosts are not active (working on eliminate them).&lt;/P&gt;&lt;P&gt;5.attached is 'sh int | i overrun'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1927529 input errors, 0 CRC, 0 frame, 1927529 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4389 input errors, 0 CRC, 0 frame, 4389 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 07:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583798#M199362</guid>
      <dc:creator>eyalhezi77</dc:creator>
      <dc:date>2014-12-30T07:48:56Z</dc:date>
    </item>
    <item>
      <title>Hi,Seeing CPU-HOGS on the ASA</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583799#M199366</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Seeing CPU-HOGS on the ASA device is not harmful on most of the cases.&lt;/P&gt;&lt;P&gt;How much is the duration of the hogs which you see on the ASA device.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 10:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583799#M199366</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-12-30T10:05:09Z</dc:date>
    </item>
    <item>
      <title>If you are just going by the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583800#M199370</link>
      <description>&lt;P&gt;If you are just going by the input errors and interface overruns I would not think this is a CPU issue. Most likely there is more traffic passing through the interface than it can handle, or perhaps the packets are too large.&amp;nbsp; Do you see the jumbo frame counter tick upward?&amp;nbsp; Do the input errors and overruns steadily tick upward or does it only increase slowly?&amp;nbsp; When was the last time you cleard the interface counters?&lt;/P&gt;&lt;P&gt;It would not hurt to move management traffic to the dedicated management port.&amp;nbsp; This way you can monitor the ports for the overruns and input errors, as well as keep an eye on the CPU Hog output.&lt;/P&gt;&lt;P&gt;if you issue the commands &lt;STRONG&gt;show cpu usage&lt;/STRONG&gt; and &lt;STRONG&gt;show processes cpu-hog&lt;/STRONG&gt;.&amp;nbsp; When viewing the CPU usage do you see any CPU spikes up to 80%-100% that last more than a few seconds?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 13:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583800#M199370</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-12-30T13:46:30Z</dc:date>
    </item>
    <item>
      <title>by this Cisco link, it looks</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583801#M199374</link>
      <description>&lt;P&gt;by this Cisco link, it looks like that is a CPU-HOG issue specially with 1 Core FWs:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115985-asa-overrun-product-tech-note-00.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 07:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-management-port/m-p/2583801#M199374</guid>
      <dc:creator>eyalhezi77</dc:creator>
      <dc:date>2014-12-31T07:11:56Z</dc:date>
    </item>
  </channel>
</rss>

