<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This is bug - CSCtl74475. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475657#M45616</link>
    <description>&lt;P&gt;This is bug - CSCtl74475.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2014 20:45:52 GMT</pubDate>
    <dc:creator>Ravi Singh</dc:creator>
    <dc:date>2014-04-16T20:45:52Z</dc:date>
    <item>
      <title>High cpu utiization on IPS module</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475655#M45612</link>
      <description>&lt;P&gt;I have two Cisco ASA5540X firewalls with IPS modules configured in a failover pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Behind this firewall pair (on the inside) are about 140 hosts that use various web-enabled applications, minimal Internet, some email (maybe 10 hosts), and some light file-sharing/access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My IPS is configured for inline analysis, but I have noticed that the cpu runs 100% all the time (6 cores). Since I don't want any traffic by-passing the IPS, my configuration on the firewall looks like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit udp any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;match access-list ips_traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;ips inline fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is the utilization so high on the IPS? Anything I can do here?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475655#M45612</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-10T13:11:04Z</dc:date>
    </item>
    <item>
      <title>Hi, Although not an expert in</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475656#M45613</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although not an expert in this particular field I have installed a handful of these and all of them have had a a CPU load of 100%, I was told by our support that the CPU load on an IPS is very inaccurate way of determining load, it is much better to use the inspection processing load.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After further digging I found this&amp;nbsp; - the issue is discussed as part of this bug - CSCtl74475&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 14:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475656#M45613</guid>
      <dc:creator>luckymike33</dc:creator>
      <dc:date>2014-04-14T14:20:20Z</dc:date>
    </item>
    <item>
      <title>This is bug - CSCtl74475.</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475657#M45616</link>
      <description>&lt;P&gt;This is bug - CSCtl74475.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 20:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-utiization-on-ips-module/m-p/2475657#M45616</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2014-04-16T20:45:52Z</dc:date>
    </item>
  </channel>
</rss>

