<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM hight cpu utilization in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922396#M458675</link>
    <description>&lt;P&gt;My FWSM is having high cpu utilization and only happen in the morning around 8am-9am. From the show process, I can tell the fixup feature is occupying the highest runtime. Question is ... is there any show command to tell which particular fixup feature is using the most?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:36:36 GMT</pubDate>
    <dc:creator>ricky.eng</dc:creator>
    <dc:date>2019-03-11T22:36:36Z</dc:date>
    <item>
      <title>FWSM hight cpu utilization</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922396#M458675</link>
      <description>&lt;P&gt;My FWSM is having high cpu utilization and only happen in the morning around 8am-9am. From the show process, I can tell the fixup feature is occupying the highest runtime. Question is ... is there any show command to tell which particular fixup feature is using the most?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922396#M458675</guid>
      <dc:creator>ricky.eng</dc:creator>
      <dc:date>2019-03-11T22:36:36Z</dc:date>
    </item>
    <item>
      <title>FWSM hight cpu utilization</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922397#M458678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;show perfmon &lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;show np 3 stats | i FIX &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Could be useful (not syntax checked). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the way FWSM's hardware architecure is designed typical fixups (ICMP,TCP,UDP) should be done on NP3 and not in CPU. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I suggest opening a TAC case. TAC will collect:&lt;/P&gt;&lt;P&gt;- CPU profiler&lt;/P&gt;&lt;P&gt;- show proc a few times &lt;/P&gt;&lt;P&gt;(others)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And will tell you exectly what's going on. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 10:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922397#M458678</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-02-29T10:20:38Z</dc:date>
    </item>
    <item>
      <title>FWSM hight cpu utilization</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922398#M458682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marcin,&lt;/P&gt;&lt;P&gt;I understand the three NP...What I notices is all three NP block threshold are hit and base on Cisco documentation, it said the FWSM is oversubsribed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh np block&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAX&amp;nbsp;&amp;nbsp; FREE&amp;nbsp;&amp;nbsp; THRESH_0&amp;nbsp;&amp;nbsp; THRESH_1&amp;nbsp;&amp;nbsp; THRESH_2&lt;/P&gt;&lt;P&gt;NP1 (ingress)&amp;nbsp; 32768&amp;nbsp; 32768&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 899&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 36385&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (egress)&amp;nbsp; 521206 521206&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;NP2 (ingress)&amp;nbsp; 32768&amp;nbsp; 32768&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1344&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41968&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (egress)&amp;nbsp; 521206 521206&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;NP3 (ingress)&amp;nbsp; 32768&amp;nbsp; 32768&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 99&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5519&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34275&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (egress)&amp;nbsp; 521206 521206&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I go TAC, they probably will conclude the firewall is oversubsribed and require hardware upgrade and increase of capacity. &lt;/P&gt;&lt;P&gt;So, I am more interested to find out exactly what traffic causing the CPU statistis to go up but limited to know that the top run time is the fixup. &lt;/P&gt;&lt;P&gt;So, my next step is to find out which interface is the most congested so that I can SPAN the traffic to Sniffer/Ethereal for more detail traffic analysis. However, base on many of the #show traffic output gathered during CPU went high/down, the pkts/s counter didn't really fluactuate according to CPU.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 09:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922398#M458682</guid>
      <dc:creator>ricky.eng</dc:creator>
      <dc:date>2012-03-01T09:15:55Z</dc:date>
    </item>
    <item>
      <title>FWSM hight cpu utilization</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922399#M458686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Give the guys in TAC some credit &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Oversubscription might be contributing to your CPU problemem, but ...&lt;/P&gt;&lt;P&gt; Consider that traffic should not hit the CPU on FWSM unless it's inspected/IPv6 (and several other conditions). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the looks of it, the box is not that oversubscribed ... thr 0 was only reached a few times doublesigits don't indicte a heavy oversubscription. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show perfmon &lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;is where you should start&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 09:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922399#M458686</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-03-01T09:22:05Z</dc:date>
    </item>
    <item>
      <title>FWSM hight cpu utilization</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922400#M458689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;diasble syslog and check once &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 07:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-hight-cpu-utilization/m-p/1922400#M458689</guid>
      <dc:creator>sumani1984</dc:creator>
      <dc:date>2014-03-07T07:02:02Z</dc:date>
    </item>
  </channel>
</rss>

