<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515E - High Memory Utilization in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811927#M459422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-perform the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show blocks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look for any blocks that have a low count at or near 0.&amp;nbsp; The 1550 block being exhausted is indicative of your interfaces being overrun.&amp;nbsp; You will likely see large 'no buffer' counters when you perform a 'show interfaces' command.&amp;nbsp; If other blows show low counts near 0, you can likely pinpoint your issue from there by checking the command reference for explanations of the other blocks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Is your NAT 0 configuration large?&amp;nbsp; Poorly appied NAT 0 configurations can cause a huge amount of entries in the NAT table which can consume memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Similarly, very large crypto configurations with large crypto access-list configurations can cause the&amp;nbsp; security association database and the security policy database to grow very large which can also consume memory &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's your config like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Feb 2012 05:59:23 GMT</pubDate>
    <dc:creator>Patrick0711</dc:creator>
    <dc:date>2012-02-16T05:59:23Z</dc:date>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811925#M459420</link>
      <description>&lt;P&gt;Hi Experts ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are experiencing high memory utilization in PIX 515E firewall . It has 128MB DRAM and the average utilization stays mostly at 99% which is quite a concern now . Remote Access VPN Users are unable to connect with the following error when tried connecting &lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #ff0000;"&gt;Secure VPN Connection terminated by Peer . Reason 433 (Reason Not Specified by Peer )&lt;/SPAN&gt; " &lt;/P&gt;&lt;P&gt;Can it be because of the high memory utilization ?&lt;/P&gt;&lt;P&gt;Also note that we have Failover mechnism enabled with Primary/Secondary , Active /Standby configuration. Due to the high memory utilization we are also unable to write the configuration to memory as well . The following error shows up &lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;C17440-BJ08-PIX2# write memory&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;No memory available&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error executing command&lt;/P&gt;&lt;P&gt;[FAILED]&lt;/P&gt;&lt;P&gt;-------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The #show memory statistics are as given below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------&lt;/P&gt;&lt;P&gt;C17440-BJ08-PIX2# sh memory&lt;/P&gt;&lt;P&gt;Free memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1819856 bytes ( 1%)&lt;/P&gt;&lt;P&gt;Used memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 132397872 bytes (99%)&lt;/P&gt;&lt;P&gt;-------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------------&lt;/P&gt;&lt;P&gt;Total memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 134217728 bytes (100%)&lt;/P&gt;&lt;P&gt;C17440-BJ08-PIX2#&lt;/P&gt;&lt;P&gt;---------------------------------------------------&lt;/P&gt;&lt;P&gt;The # sh version details are as given below &lt;/P&gt;&lt;P&gt;---------------------------------------------------&lt;/P&gt;&lt;P&gt;C17440-BJ08-PIX2# sh ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PIX Security Appliance Software Version 7.2(4)&lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Sun 06-Apr-08 13:39 by builders&lt;/P&gt;&lt;P&gt;System image file is "flash:/image.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C17440-BJ08-PIX2 up 1 hour 39 mins&lt;/P&gt;&lt;P&gt;failover cluster up 1 year 49 days&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; PIX-515E, 128 MB RAM, CPU Pentium II 433 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0xfff00000, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 0: Ext: Ethernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 001d.a215.5878, irq 10&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 001d.a215.5879, irq 11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : 6&lt;/P&gt;&lt;P&gt;Maximum VLANs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 25&lt;/P&gt;&lt;P&gt;Inside Hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Unlimited&lt;/P&gt;&lt;P&gt;Failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Active/Active&lt;/P&gt;&lt;P&gt;VPN-DES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;/P&gt;&lt;P&gt;Cut-through Proxy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;/P&gt;&lt;P&gt;Guards&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;/P&gt;&lt;P&gt;URL Filtering&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;/P&gt;&lt;P&gt;Security Contexts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&lt;/P&gt;&lt;P&gt;GTP/GPRS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&lt;/P&gt;&lt;P&gt;VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an Unrestricted (UR) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: 907380160&lt;/P&gt;&lt;P&gt;Running Activation Key: 0xf72c7fe2 0x81fb96d9 0x70dab81b 0x67d49718&lt;/P&gt;&lt;P&gt;Configuration last modified by enable_1 at 12:26:39.880 UTC Tue Feb 14 2012&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt; Is it normal for the PIX to have such high memory utilization ? How I can I probably reduce the memory utilization ?How can I upgrade the memory if I need to ? What kind of a memory should I be using for upgrade ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks ,&lt;/P&gt;&lt;P&gt;Anup&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811925#M459420</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2019-03-11T22:29:45Z</dc:date>
    </item>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811926#M459421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; 99% is definitely issue. Based on the below link, it appears 128MB is max for the failover pair. Did you check the translations (show xlate)? Try to clear the translations if this seems to be the issue. Also, try reboot and if the issue still exists, you may be hitting a bug. Try to contact TAC. Iam not sure if the support is still available for PIX, but give a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/prod_bulletin0900aecd8023c8d4.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/prod_bulletin0900aecd8023c8d4.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Feb 2012 02:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811926#M459421</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-02-15T02:58:36Z</dc:date>
    </item>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811927#M459422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-perform the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show blocks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look for any blocks that have a low count at or near 0.&amp;nbsp; The 1550 block being exhausted is indicative of your interfaces being overrun.&amp;nbsp; You will likely see large 'no buffer' counters when you perform a 'show interfaces' command.&amp;nbsp; If other blows show low counts near 0, you can likely pinpoint your issue from there by checking the command reference for explanations of the other blocks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Is your NAT 0 configuration large?&amp;nbsp; Poorly appied NAT 0 configurations can cause a huge amount of entries in the NAT table which can consume memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Similarly, very large crypto configurations with large crypto access-list configurations can cause the&amp;nbsp; security association database and the security policy database to grow very large which can also consume memory &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's your config like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 05:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811927#M459422</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-02-16T05:59:23Z</dc:date>
    </item>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811928#M459423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi MS , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A valid Service Contract for the device is required to contact TAC , right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ,&lt;/P&gt;&lt;P&gt;Anup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811928#M459423</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2012-02-21T08:31:51Z</dc:date>
    </item>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811929#M459424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can a large running congiguration with lots of IP based blocking be the cause of a memory utilization issue ? &lt;/P&gt;&lt;P&gt;We have provided access to external servers by adding those into an object group and then mentioning the group into an access list . Would reconfguring them based on a network or a subnet help in reducing the memory utilization . Is it someway related ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ,&lt;/P&gt;&lt;P&gt;Anup &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811929#M459424</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2012-02-21T08:35:26Z</dc:date>
    </item>
    <item>
      <title>PIX 515E - High Memory Utilization</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811930#M459425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is been successfully resolved now . The&amp;nbsp; configuration had a huge number of network objects which was public IP&amp;nbsp; based . It was all summarized to networks and the new network objects&amp;nbsp; were created with summarized networks . The IP based network objects&amp;nbsp; were removed from the onfiguration as well. As soon as the objects were&amp;nbsp; removed the memory utilization went down and it is now at a less&amp;nbsp; critical 78% . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks , &lt;/P&gt;&lt;P&gt;Anup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 21:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-high-memory-utilization/m-p/1811930#M459425</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2012-02-22T21:04:11Z</dc:date>
    </item>
  </channel>
</rss>

