<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: high CPU on AIP-SSM-20 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343513#M68323</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you`re right there are a lot of packets going throutgh IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to find on the IME &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which ip address to generate packets ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Nov 2009 08:55:46 GMT</pubDate>
    <dc:creator>Leeyoungsoo</dc:creator>
    <dc:date>2009-11-02T08:55:46Z</dc:date>
    <item>
      <title>high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343511#M68321</link>
      <description>&lt;P&gt;Dear Experts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have several  AIP-SSM-20s on the ASA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and one of the AIP-SSM-20 has seen high &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cpu status one hours ago and it still going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;another AIP-SSM-20 has 2~20% cpu load.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal status? Do you have same &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;experience?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more question,where can I find&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ips Manager Express configuraiton manual on the cisco site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found manual anywhere on the cisco site for the configuration IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really appreciate for any help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;======================================&lt;/P&gt;&lt;P&gt;CPU Statistics&lt;/P&gt;&lt;P&gt;   Usage over last 5 seconds = 97&lt;/P&gt;&lt;P&gt;   Usage over last minute = 93&lt;/P&gt;&lt;P&gt;   Usage over last 5 minutes = 72&lt;/P&gt;&lt;P&gt;Memory Statistics&lt;/P&gt;&lt;P&gt;   Memory usage (bytes) = 1026400256&lt;/P&gt;&lt;P&gt;   Memory free (bytes) = 1067204608&lt;/P&gt;&lt;P&gt;========================================&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343511#M68321</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2019-03-10T11:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343512#M68322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the amount of packets going through IPS. May be there are lot of small packets processed by it and so CPU is high.&lt;/P&gt;&lt;P&gt;IME guide is here: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/ime/imeguide7.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/ime/imeguide7.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;it is a manual how to configure IPS too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Nov 2009 08:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343512#M68322</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-02T08:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343513#M68323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you`re right there are a lot of packets going throutgh IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to find on the IME &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which ip address to generate packets ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Nov 2009 08:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343513#M68323</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-02T08:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343514#M68324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you`re right there are a lot of packets going throutgh IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to find on the IME &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which ip address to generate packets ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Nov 2009 08:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343514#M68324</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-02T08:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343515#M68325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Analyze events for time of high CPU utilization and see if there were alarms for some flood, for example, DNS flood, SYN flood etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Nov 2009 09:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343515#M68325</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-02T09:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343516#M68326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andrey!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found a lot attack of TCP SYN HOST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sweep.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it relate with high cpu on the IPS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 04:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343516#M68326</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-03T04:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343517#M68327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be.&lt;/P&gt;&lt;P&gt;If this attack was absent in time of normal CPU load I think that this event may cause it.&lt;/P&gt;&lt;P&gt;You may check it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 10:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343517#M68327</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-03T10:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343518#M68328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is difficult to say, I'm not seeing the exact signature.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is 3030/0, it is my understanding (from experience and TAC) that it is quite common that a busy host(user)/SMTP server/proxy server fire this alarm.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that 3030/0 is based on the source port of the initial SYN.  So an internal host initiates a TCP connection to an internet host, its source TCP port is (for example) 1049.  The IPS tracks that.  The user powers off their PC at the end of the day.  Next day, user powers up the host and TCP source ports begin all over at 1024 (XP, don't know about Vista/7.) The user connects to TCP hosts in the Internet, one of those TCP SYNs is sourced by TCP 1049.  3030/0 fires.  My understanding from TAC is that the IPS module remembers this TCP communication as long as the IPS itself hasn't been rebooted.  So, one may see a whole lot of 3030/0 alarms.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An SMTP server can make this fire a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Potential resolution options may be; disabling 3030/0 or write and EAF (and try to be specific on the source host(s).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 19:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343518#M68328</guid>
      <dc:creator>bnidacoc</dc:creator>
      <dc:date>2009-11-03T19:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343519#M68329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your relpy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes your`r right, that`s Sig.Id is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3030/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As your opinion ,Sig.ID 3030/0 is not &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cause high cpu on IPS Module?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 00:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343519#M68329</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-04T00:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343520#M68330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sig 3030/0 fires when there are 15 destination hosts were seen with 1 src host.&lt;/P&gt;&lt;P&gt;I don't know about your network but usually this signature don't cause high CPU load.&lt;/P&gt;&lt;P&gt;May be if you have 1000 hosts generating sweep it may cause the high CPU load.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case you may turn off this signature and then see if it causes high CPU utilization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 12:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343520#M68330</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-04T12:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343521#M68331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, my attempt was primarily to point out there is a sig that may fire very often from legitimate authorized hosts.  You were discussing a sig firing a lot. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a test, you could disable 3030/0 temporarily to see if it changes your CPU usage.  However, my suspicion is that it may not have much effect.  Someone else here may disagree.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A whole lot of signature have been created and enabled by default over the past year.  And maybe you are on a version of IPS OS SW which enables the Atomic Engine (I think that is the engine) sigs, maybe there is more CPU cycle consumption with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a TAC case is suitable for your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 14:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343521#M68331</guid>
      <dc:creator>bnidacoc</dc:creator>
      <dc:date>2009-11-04T14:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343522#M68332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all thanks for your relpy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As your opinion,I did disalbe sig no.3030&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it did not effect high cpu situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found strange status on gigabit interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There through a lot of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attaching gigabit 0/1 interface status.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think that is relate on high cpu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;consumption?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 08:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343522#M68332</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-05T08:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343523#M68333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does Gi0/1 subinterfaced to process the traffic and return the clear one to ASA or you use it in promiscuous mode?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 12:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343523#M68333</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-05T12:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343524#M68334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try clear the interface counter but I have not found commands on the AIP-SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me how can I clear interface counter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 01:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343524#M68334</guid>
      <dc:creator>Leeyoungsoo</dc:creator>
      <dc:date>2009-11-06T01:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343525#M68335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;# show interfaces clear&lt;/P&gt;&lt;P&gt;it will clear all interfaces counters not specific one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 08:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343525#M68335</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-06T08:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: high CPU on AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343526#M68336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I really appreciate for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 08:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-aip-ssm-20/m-p/1343526#M68336</guid>
      <dc:creator>yeundu</dc:creator>
      <dc:date>2009-11-06T08:39:32Z</dc:date>
    </item>
  </channel>
</rss>

