<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: connection limits on pix 525 , high cpu usage in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97249#M624416</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 525 will max out at around 500,000 connections, although this is a rough estimate.  I've seen them go up higher, but you wouldn't want to do that.  There shouldn't be any issue at around 70,000 connections.  How much traffic are you seeing thru this PIX?  Are you doing stateful failover?  Can you provide a config?  And a "sho tech" when the problem is occurring?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jul 2002 04:48:01 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2002-07-24T04:48:01Z</dc:date>
    <item>
      <title>connection limits on pix 525 , high cpu usage</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97248#M624391</link>
      <description>&lt;P&gt;Hi to all of you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anybody informations about "realworld" connection limits on a PIX?&lt;/P&gt;&lt;P&gt;We experienced high cpu utilization (99%) if we reached connetion counts above 70000. Our highest counts are about 135000 connections. (!!! No yoke, and no DOS/DDOS, we have so much hits!!!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this time we tuned our connection timeouts to minimum, but this seems as we try to buy us time :-).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hint would be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.2(2)&lt;/P&gt;&lt;P&gt;Cisco PIX Device Manager Version 2.0(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-525, 256 MB RAM, CPU Pentium III 600 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0x300, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 0006.d75c.ea04, irq 10&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 0006.d75c.ea05, irq 11&lt;/P&gt;&lt;P&gt;2: ethernet2: address is 0002.b303.bec2, irq 5&lt;/P&gt;&lt;P&gt;3: ethernet3: address is 00e0.b603.468c, irq 11&lt;/P&gt;&lt;P&gt;4: ethernet4: address is 00e0.b603.468b, irq 10&lt;/P&gt;&lt;P&gt;5: ethernet5: address is 00e0.b603.468a, irq 9&lt;/P&gt;&lt;P&gt;6: ethernet6: address is 00e0.b603.4689, irq 5&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:           Enabled&lt;/P&gt;&lt;P&gt;VPN-DES:            Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES:           Enabled&lt;/P&gt;&lt;P&gt;Maximum Interfaces: 8&lt;/P&gt;&lt;P&gt;Cut-through Proxy:  Enabled&lt;/P&gt;&lt;P&gt;Guards:             Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:      Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:       Unlimited&lt;/P&gt;&lt;P&gt;Throughput:         Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:          Unlimited&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97248#M624391</guid>
      <dc:creator>mle</dc:creator>
      <dc:date>2020-02-21T06:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: connection limits on pix 525 , high cpu usage</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97249#M624416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 525 will max out at around 500,000 connections, although this is a rough estimate.  I've seen them go up higher, but you wouldn't want to do that.  There shouldn't be any issue at around 70,000 connections.  How much traffic are you seeing thru this PIX?  Are you doing stateful failover?  Can you provide a config?  And a "sho tech" when the problem is occurring?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2002 04:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97249#M624416</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2002-07-24T04:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: connection limits on pix 525 , high cpu usage</title>
      <link>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97250#M624445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Glenn!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. &lt;/P&gt;&lt;P&gt;We experience a mostly linear rise of cpu usage and connections. For example 10000 conn / 10 % cpu and 70000 / 99. If we are reaching 60000 conn free memory on PIX decreases about 1 MB. &lt;/P&gt;&lt;P&gt;After an update of our webpages we have per client about 10 TCP (HTTP/HTTPS) and 10 UDP (RPC/..) connections on PIX. Seems 3 times more than before. Our traffic rates are about 5 - 8 Mbit/s normal and 10 -12 Mbit/s at peak rate. We have a 34 Mbit/s connection to our provider.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, we have stateful failover and http replication with dedicated interface, but NOT LAN-based failover.&lt;/P&gt;&lt;P&gt;Maybe i found another limitation of our system, our customers reach our webfarm over one IP-Address and we balance on several servers. Do you think there are another limitiation about port allocation and addressing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About show tech and config i ´ll have to discuss with my colleagues. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank a lot for your kind response&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mathias&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2002 09:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-limits-on-pix-525-high-cpu-usage/m-p/97250#M624445</guid>
      <dc:creator>mle</dc:creator>
      <dc:date>2002-07-24T09:59:11Z</dc:date>
    </item>
  </channel>
</rss>

