<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa 5520 has a high cpu utilization ip spoofing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871961#M25692</link>
    <description>&lt;P&gt;Hello RJI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reaching out I did perform&amp;nbsp;&lt;SPAN&gt;"clear asp drop" here is the output&lt;/SPAN&gt;&amp;nbsp;after the clear asp drop:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;Invalid encapsulation (invalid-encap) 4&lt;BR /&gt;No route to host (no-route) 2&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 189268&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 3&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 3&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 11&lt;BR /&gt;TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) 1&lt;BR /&gt;TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue) 70&lt;BR /&gt;Slowpath security checks failed (sp-security-failed) 1&lt;BR /&gt;FP L2 rule drop (l2_acl) 95&lt;BR /&gt;Connection to PAT address without pre-existing xlate (nat-no-xlate-to-pat-pool) 23&lt;/P&gt;&lt;P&gt;Last clearing: 14:26:28 EDT Jun 12 2019 by enable_15&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;Last clearing: 14:26:28 EDT Jun 12 2019 by enable_15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging standby&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging queue 4096&lt;BR /&gt;logging host management 172.x.x.253&lt;BR /&gt;logging host outside 172.x.x.50&lt;BR /&gt;no logging message 110003&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh capture asp-drop&lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2019 18:32:53 GMT</pubDate>
    <dc:creator>jdumorne03</dc:creator>
    <dc:date>2019-06-12T18:32:53Z</dc:date>
    <item>
      <title>asa 5520 has a high cpu utilization ip spoofing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871896#M25684</link>
      <description>&lt;P&gt;Hello can anyone provide there assistance in guiding me as to what I can do to resolve this issue if you have experienced this issue in your career. I'm at a complete lost. I would be grateful. I try to fail over to the second same issue took place. failed back over still the same high cpu spike.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my logs are displaying please review attachment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh cpu detailed&lt;/P&gt;&lt;P&gt;Break down of per-core data path versus control point cpu usage:&lt;BR /&gt;Core 5 sec 1 min 5 min&lt;BR /&gt;Core 0 99.0 (0.0 + 99.0) 98.8 (0.0 + 98.8) 99.1 (0.0 + 99.1)&lt;/P&gt;&lt;P&gt;Current control point elapsed versus the maximum control point elapsed for:&lt;BR /&gt;5 seconds = 99.0%; 1 minute: 99.8%; 5 minutes: 100.0%&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CPU utilization of external processes for:&lt;BR /&gt;5 seconds = 0.2%; 1 minute: 0.0%; 5 minutes: 0.0%&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Total CPU utilization for:&lt;BR /&gt;5 seconds = 99.2%; 1 minute: 98.9%; 5 minutes: 99.1%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh processes cpu-usage sorted non-zero&lt;BR /&gt;PC Thread 5Sec 1Min 5Min Process&lt;BR /&gt;0x0915f0f1 0x6edcb07c 52.7% 52.7% 53.2% Logger&lt;BR /&gt;0x082a445c 0x6edd4ee4 42.3% 41.2% 41.3% Dispatch Unit&lt;BR /&gt;0x090451e4 0x6edbeb8c 3.8% 3.7% 3.7% SNMP Notify Thread&lt;BR /&gt;0x0911079d 0x6edbcfb8 0.2% 0.1% 0.1% ssh&lt;BR /&gt;0x087cb14e 0x6edc00f4 0.1% 0.1% 0.1% ARP Thread&lt;BR /&gt;0x091b4cd9 0x6edbba50 0.0% 0.1% 0.0% snmp&lt;BR /&gt;0x098da690 0x6edcce74 0.0% 0.1% 0.0% Checkheaps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh asp drop&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;Invalid encapsulation (invalid-encap) 6125&lt;BR /&gt;Invalid TCP Length (invalid-tcp-hdr-length) 19&lt;BR /&gt;No valid adjacency (no-adjacency) 1&lt;BR /&gt;No route to host (no-route) 8432&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 566916559&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 3624&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 26012&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 26153&lt;BR /&gt;TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 43&lt;BR /&gt;TCP SYNACK on established conn (tcp-synack-ooo) 23&lt;BR /&gt;TCP packet SEQ past window (tcp-seq-past-win) 1517&lt;BR /&gt;TCP Out-of-Order packet buffer full (tcp-buffer-full) 339663&lt;BR /&gt;TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) 47233&lt;BR /&gt;TCP RST/SYN in window (tcp-rst-syn-in-win) 42&lt;BR /&gt;TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue) 16653&lt;BR /&gt;TCP packet failed PAWS test (tcp-paws-fail) 11&lt;BR /&gt;Slowpath security checks failed (sp-security-failed) 959&lt;BR /&gt;Expired flow (flow-expired) 20&lt;BR /&gt;ICMP Inspect bad icmp code (inspect-icmp-bad-code) 136&lt;BR /&gt;DNS Inspect id not matched (inspect-dns-id-not-matched) 3280&lt;BR /&gt;IPS Module requested drop (ips-request) 23&lt;BR /&gt;FP L2 rule drop (l2_acl) 271555&lt;BR /&gt;Interface is down (interface-down) 382&lt;BR /&gt;Dropped pending packets in a closed socket (np-socket-closed) 106&lt;BR /&gt;Connection to PAT address without pre-existing xlate (nat-no-xlate-to-pat-pool) 34142&lt;BR /&gt;Received a multicast packet in the non-active device (mcast-in-nonactive-device) 167&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;Flow terminated by IPS (ips-request) 2&lt;BR /&gt;Inspection failure (inspect-fail) 336&lt;BR /&gt;SSL handshake failed (ssl-handshake-failed) 1&lt;/P&gt;&lt;P&gt;Last clearing: Never&lt;/P&gt;&lt;P&gt;--------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh int gig0/0&lt;BR /&gt;Interface GigabitEthernet0/0 "outside", is up, line protocol is up&lt;BR /&gt;Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is off&lt;BR /&gt;MAC address 0018.199e.170b, MTU 1500&lt;BR /&gt;IP address 199.x.x.202, subnet mask 255.255.255.248&lt;BR /&gt;598178974 packets input, 118399863686 bytes, 0 no buffer&lt;BR /&gt;Received 2185 broadcasts, 0 runts, 0 giants&lt;BR /&gt;1474192 input errors, 0 CRC, 0 frame, 1474192 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;591417100 packets output, 82812234733 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 2 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt;input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;output queue (blocks free curr/low): hardware (234/168)&lt;BR /&gt;Traffic Statistics for "outside":&lt;BR /&gt;598178890 packets input, 107605901731 bytes&lt;BR /&gt;591417100 packets output, 72125301733 bytes&lt;BR /&gt;567431045 packets dropped&lt;BR /&gt;1 minute input rate 7972 pkts/sec, 1151620 bytes/sec&lt;BR /&gt;1 minute output rate 7983 pkts/sec, 995376 bytes/sec&lt;BR /&gt;1 minute drop rate, 7763 pkts/sec&lt;BR /&gt;5 minute input rate 8092 pkts/sec, 1263597 bytes/sec&lt;BR /&gt;5 minute output rate 8101 pkts/sec, 1003485 bytes/sec&lt;BR /&gt;5 minute drop rate, 7801 pkts/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 17:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871896#M25684</guid>
      <dc:creator>jdumorne03</dc:creator>
      <dc:date>2019-06-12T17:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 has a high cpu utilization ip spoofing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871949#M25688</link>
      <description>Hi,&lt;BR /&gt;Run "clear asp drop" to reset the counts, wait a couple of minutes and then re-run "show asp drop", upload the output for review.&lt;BR /&gt;&lt;BR /&gt;Also run a capture "capture asp-drop type asp-drop all" and then uplaod the output of "show capture asp-drop"&lt;BR /&gt;&lt;BR /&gt;What logging levels do you have configured? Run "show run logging" or "show logging"</description>
      <pubDate>Wed, 12 Jun 2019 17:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871949#M25688</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-06-12T17:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 has a high cpu utilization ip spoofing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871961#M25692</link>
      <description>&lt;P&gt;Hello RJI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reaching out I did perform&amp;nbsp;&lt;SPAN&gt;"clear asp drop" here is the output&lt;/SPAN&gt;&amp;nbsp;after the clear asp drop:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;Invalid encapsulation (invalid-encap) 4&lt;BR /&gt;No route to host (no-route) 2&lt;BR /&gt;Flow is denied by configured rule (acl-drop) 189268&lt;BR /&gt;First TCP packet not SYN (tcp-not-syn) 3&lt;BR /&gt;TCP failed 3 way handshake (tcp-3whs-failed) 3&lt;BR /&gt;TCP RST/FIN out of order (tcp-rstfin-ooo) 11&lt;BR /&gt;TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) 1&lt;BR /&gt;TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue) 70&lt;BR /&gt;Slowpath security checks failed (sp-security-failed) 1&lt;BR /&gt;FP L2 rule drop (l2_acl) 95&lt;BR /&gt;Connection to PAT address without pre-existing xlate (nat-no-xlate-to-pat-pool) 23&lt;/P&gt;&lt;P&gt;Last clearing: 14:26:28 EDT Jun 12 2019 by enable_15&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;Last clearing: 14:26:28 EDT Jun 12 2019 by enable_15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging standby&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging queue 4096&lt;BR /&gt;logging host management 172.x.x.253&lt;BR /&gt;logging host outside 172.x.x.50&lt;BR /&gt;no logging message 110003&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# sh capture asp-drop&lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 18:32:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871961#M25692</guid>
      <dc:creator>jdumorne03</dc:creator>
      <dc:date>2019-06-12T18:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 has a high cpu utilization ip spoofing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871977#M25696</link>
      <description>You have a lot of drops "Flow is denied by configured rule (acl-drop) 189268" this would be traffic denied in an ACL - possibly an attack. The logger process has high CPU utilisation, which could be explained if you are logging each deny. Potentially rate-limit logging until the attack stops.&lt;BR /&gt;&lt;BR /&gt;199.x.x.202 is your outside interface IP address? What is the destination address?&lt;BR /&gt;&lt;BR /&gt;You've edited the screenshot, does it not display the src/dst ports?&lt;BR /&gt;&lt;BR /&gt;Can you run a packet capture from src to destination and upload the pcap.</description>
      <pubDate>Wed, 12 Jun 2019 19:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-has-a-high-cpu-utilization-ip-spoofing/m-p/3871977#M25696</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-06-12T19:19:42Z</dc:date>
    </item>
  </channel>
</rss>

